Windows
Analysis Report
https://shorturl.at/UrAsB
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 6896 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 7080 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2152 --fi eld-trial- handle=192 0,i,535991 9322221688 024,176651 1426044822 9658,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6620 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://short url.at/UrA sB" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
www.shorturl.at | 104.26.8.129 | true | false | high | |
shorturl.at | 172.67.69.88 | true | false | high | |
www.google.com | 142.250.181.36 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.26.9.129 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
172.67.69.88 | shorturl.at | United States | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.181.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
104.26.8.129 | www.shorturl.at | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1573962 |
Start date and time: | 2024-12-12 18:53:01 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://shorturl.at/UrAsB |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@17/30@10/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, SIHClient.exe, Sgr mBroker.exe, conhost.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.181.99, 17 2.217.17.78, 74.125.131.84, 17 2.217.17.46, 199.232.214.172, 172.217.19.10, 172.217.17.67, 216.58.208.232, 142.250.181.78 , 172.217.17.35, 172.217.19.20 6, 23.218.208.109, 172.202.163 .200 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fonts.googleapis.com, f s.microsoft.com, accounts.goog le.com, slscr.update.microsoft .com, fonts.gstatic.com, ctldl .windowsupdate.com, clientserv ices.googleapis.com, fe3cr.del ivery.mp.microsoft.com, client s2.google.com, edgedl.me.gvt1. com, redirector.gvt1.com, www. googletagmanager.com, update.g oogleapis.com, clients.l.googl e.com, www.google-analytics.co m - Not all processes where analyz
ed, report is missing behavior information - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data. - VT rate limit hit for: https:
//shorturl.at/UrAsB
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9847187975280183 |
Encrypted: | false |
SSDEEP: | 48:8AOdITswBHDeidAKZdA1FehwiZUklqeh+y+3:8A9vZMhy |
MD5: | 192382FC8D8DD29D4B2058F2D072FCAB |
SHA1: | 28AA34DE2E70A62138A192692E0255A035172016 |
SHA-256: | 78EC2A809AD7CF2DD46E6274B5941A5ECED7383F095690BD9E422952AD1FB63F |
SHA-512: | AC81A06B5B68ACFF67EE9446D4B6A9351453C3DC973E5A80E6D45CB4D441446739E1C6B79AB51FBD1712C638A34CBC5FE75156328431AE79867AF35301B4B9C2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.003612328977221 |
Encrypted: | false |
SSDEEP: | 48:89OdITswBHDeidAKZdA1seh/iZUkAQkqehRy+2:899vZi9Qoy |
MD5: | CF40A4AB13E00B38191F53F6EBFD9EF6 |
SHA1: | 4BB3CCC6AB478885F842AE823DD283BCF1D98205 |
SHA-256: | 66192D714964BF0AB9F1E20D8E421D082BAE4BFCB6FF4AEABDA061DE2B83B568 |
SHA-512: | 18C0AE0A60473F3E9D0133B2403F8899462C7A620D94BAAA7923179FCE93DB73DD5B3015CC8D2BB2A94E78E055105E70C67EA6E4FCD63B5416B01A82ECC75988 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.009519513733222 |
Encrypted: | false |
SSDEEP: | 48:8qOdITswAHDeidAKZdA14meh7sFiZUkmgqeh7sby+BX:8q9vm2nly |
MD5: | F46D4A8ABF60D169A1000B1B29B9A719 |
SHA1: | 638AAC0615BD7D537AFDCCB16C8DF6A3EE4C4B7E |
SHA-256: | E564CC4ACF2640EB0BCB9A8C5FE0DF8838C14218E55C38B73F5B659E9C86FE76 |
SHA-512: | 465BF6BC1F9DF6C2568FF18D07DEEB58662650A93EDE5D3CD83523D29C73CF329E5E76D9DCAB08E97FB63B46E897C038DA45ACC4286A8333EA684E36B7695ECF |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.001974398294117 |
Encrypted: | false |
SSDEEP: | 48:8/OdITswBHDeidAKZdA1TehDiZUkwqehNy+R:8/9vZ5Dy |
MD5: | 34911013C06332F337E74FF889345031 |
SHA1: | FBAED340C21D36036A9FC93B1D53D1FD41AB4BC7 |
SHA-256: | 7AE29D751EFEDF762AD90C4B17CA2962D36B81F128ADC78AF2838664C3679E86 |
SHA-512: | FCFBF5FE9FDDF1B04D246FDAF48B6D73F11018A6B32DB263A8F96F6F00BAF70599FEB6956C9C5DC6CD450618A63B0744FBF6478A1A3794E5D2B3B3D81755D351 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9887812949622394 |
Encrypted: | false |
SSDEEP: | 48:86OdITswBHDeidAKZdA1dehBiZUk1W1qeh/y+C:869vZp9fy |
MD5: | 752AEC06AE256A3BC98D3F7E203BF455 |
SHA1: | D555F085FFE35DD020E4D386188BD3C0C9A8C0D4 |
SHA-256: | 29EBB9F9D3B984FA2963F84DFE4860E876E6C77FBD1C144408F7DDE4D11D8599 |
SHA-512: | 716ECD716C06C48EE94963A660C498ECE94F4D15183831A44F4D56C395ABEDB60EBC74A04E719FDE204E3844082FC6F517139C93334BE76CE5816713FE403C5A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.996846051747462 |
Encrypted: | false |
SSDEEP: | 48:84OdITswBHDeidAKZdA1duTeehOuTbbiZUk5OjqehOuTbly+yT+:849vZRTfTbxWOvTbly7T |
MD5: | AE297C92F8715B387D5B775944989448 |
SHA1: | 4DF913C8457AFD6AB74C75A8F17F8E34E12097D8 |
SHA-256: | 9309EA406861E5C686C1D1E0CC29F3BD95735BD1548609A2EBB2BADF1FA726AF |
SHA-512: | A4CAB36ED26D1D035C3A2C01213949A8A839FE54A39EBF079149420F23114E0310893D7BF334B0F01A8A9B5A4BF79537EB9BD4F61963C1BD5D4C3FFB23B79EB8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12332 |
Entropy (8bit): | 5.0916439525688215 |
Encrypted: | false |
SSDEEP: | 192:3dArCS2Z+j/yQ9TCQxUhW2DPY808LE676SbHDc/7uN0VZG05w:NHSG+j/y2xa3bn7Q+0a0O |
MD5: | 88A769D2FE35899FD45A332A0A032CC0 |
SHA1: | 514C6C1D8475D17E412849A4C90159517D0FA10A |
SHA-256: | CCF00D1923B0131A10E0C6D26F95E5DEE6EBF8621A27E83C5A2F68A2E0093142 |
SHA-512: | 756CC5CD029FC4ADC9100D0DA2F2B0EFB3DF0F2BF894FBA2824019832FEA594EDD40A238A5FFACC205572CC0155F5632D70F54E37EDC0772460F44C69CB76AB8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 332912 |
Entropy (8bit): | 5.5781779832147995 |
Encrypted: | false |
SSDEEP: | 6144:z4ooGUiz8zXNiZD9Wy9nnQyDy4VEx7D4xge8:EofzCXaD58rZ |
MD5: | 8A47757777ABA578E6232497A8604595 |
SHA1: | A6DBA8E00CDF8622B6AAC5687DC03BADF7CDE09A |
SHA-256: | 87C5064760161A7CE208EAF7555BFC790DE970F6EED754D94CA5B04144B725E9 |
SHA-512: | D0868606906CCD012FEA3D349AFCA3B78D20C8047EE187D24019F800E16DD966944EF308948C1A2A4B95DE479A25B2BF6BE1F94B4F6E8E2A94F98C690C0B1981 |
Malicious: | false |
Reputation: | low |
URL: | https://www.googletagmanager.com/gtag/js?id=G-25YH9BB08G |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 10276 |
Entropy (8bit): | 5.458768610856901 |
Encrypted: | false |
SSDEEP: | 192:cNprUJ40rJ/M1C2MQk6vj+n6B3L0GgRqbPW33uzRZJ:cWGhDSw |
MD5: | 8D6974B092DF28C5BE785505F8BCAC3A |
SHA1: | D392FCCA4828B893151E6441B19A7AEF3F8EB880 |
SHA-256: | 79BF8BF9F27E983DE44FBD6BAA6D5F1269915C54460515EB66DF502C3204915A |
SHA-512: | 4E1764980DA54127DE8185734476BA86D84927F8937B2D62CCC80DB9B62BEA0CA974795D179E621D582FB03AC431682ECCCFB558CD5A01DD7D20F412FE164D5A |
Malicious: | false |
Reputation: | low |
URL: | "https://fonts.googleapis.com/css?family=Asap:400,700|Lato:400,700,900|Source+Sans+Pro:400,700&display=swap" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1150 |
Entropy (8bit): | 4.325439284131087 |
Encrypted: | false |
SSDEEP: | 24:C3iJcsSZrFi9K/a5hlaQih+tBVaQm+tbQqUUFJ/sI3iJXvTTT5:wiJcsSZrXaPfiyfllJ/sWiJ/TTT5 |
MD5: | C651D44F122DD752AB399838FD0B5A06 |
SHA1: | 81585767215C1CAF3EA92713A871651486532FE6 |
SHA-256: | 70214F63B7587F091A5177934A7DE1BE42EF361D20CBBC12C29AA8A3A847076B |
SHA-512: | 79C93E7D14D5E4C389DB649E0107B0C88DE3802B49DDF5968CF09607A5DCC7495F1E6D2499B054AB9B3399743A1A4A06D6997EA2AFD28D52DB433017E4417593 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 12332 |
Entropy (8bit): | 5.0916439525688215 |
Encrypted: | false |
SSDEEP: | 192:3dArCS2Z+j/yQ9TCQxUhW2DPY808LE676SbHDc/7uN0VZG05w:NHSG+j/y2xa3bn7Q+0a0O |
MD5: | 88A769D2FE35899FD45A332A0A032CC0 |
SHA1: | 514C6C1D8475D17E412849A4C90159517D0FA10A |
SHA-256: | CCF00D1923B0131A10E0C6D26F95E5DEE6EBF8621A27E83C5A2F68A2E0093142 |
SHA-512: | 756CC5CD029FC4ADC9100D0DA2F2B0EFB3DF0F2BF894FBA2824019832FEA594EDD40A238A5FFACC205572CC0155F5632D70F54E37EDC0772460F44C69CB76AB8 |
Malicious: | false |
Reputation: | low |
URL: | https://www.shorturl.at/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 23580 |
Entropy (8bit): | 7.990537110832721 |
Encrypted: | true |
SSDEEP: | 384:dRkIAJ8pVwWTW5VVjdVn8+2yvAMdriCEOY0kfW9GkAPqpPHi2vUuUSzB8:dKIAJ8pVHTZ+riY9oCpPHiodUeK |
MD5: | E1B3B5908C9CF23DFB2B9C52B9A023AB |
SHA1: | FCD4136085F2A03481D9958CC6793A5ED98E714C |
SHA-256: | 918B7DC3E2E2D015C16CE08B57BCB64D2253BAFC1707658F361E72865498E537 |
SHA-512: | B2DA7EF768385707AFED62CA1F178EFC6AA14519762E3F270129B3AFEE4D3782CB991E6FA66B3B08A2F81FF7CABA0B4C34C726D952198B2AC4A784B36EB2A828 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjx4wXg.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 23040 |
Entropy (8bit): | 7.990788476764561 |
Encrypted: | true |
SSDEEP: | 384:adpABC4a0HkBpR1HWtGu06B6lsoAKiwY0HcLKglV6Z+DVb35PJZDdiZeJ1vqYg:0AHa0Ezf2tZn6lsoABwTKK46ZQb3V7wD |
MD5: | DE69CF9E514DF447D1B0BB16F49D2457 |
SHA1: | 2AC78601179C3A63BA3F3F3081556B12DDCAF655 |
SHA-256: | C447DD7677B419DB7B21DBDFC6277C7816A913FFDA76FD2E52702DF538DE0E49 |
SHA-512: | 4AEBB7E54D88827D4A02808F04901C0D09B756C518202B056A6C0F664948F5585221D16967F546E064187C6545ACEF15D59B68D0A7A59897BD899D3E9DDA37B1 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/lato/v24/S6u9w4BMUTPHh6UVSwiPGQ.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1150 |
Entropy (8bit): | 4.325439284131087 |
Encrypted: | false |
SSDEEP: | 24:C3iJcsSZrFi9K/a5hlaQih+tBVaQm+tbQqUUFJ/sI3iJXvTTT5:wiJcsSZrXaPfiyfllJ/sWiJ/TTT5 |
MD5: | C651D44F122DD752AB399838FD0B5A06 |
SHA1: | 81585767215C1CAF3EA92713A871651486532FE6 |
SHA-256: | 70214F63B7587F091A5177934A7DE1BE42EF361D20CBBC12C29AA8A3A847076B |
SHA-512: | 79C93E7D14D5E4C389DB649E0107B0C88DE3802B49DDF5968CF09607A5DCC7495F1E6D2499B054AB9B3399743A1A4A06D6997EA2AFD28D52DB433017E4417593 |
Malicious: | false |
Reputation: | low |
URL: | https://www.shorturl.at/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8812 |
Entropy (8bit): | 5.737895071674621 |
Encrypted: | false |
SSDEEP: | 96:hLJwuvzrPc0+qseJijSipjSoaV4VuWnhf4/ehbFpUkI2x/OacuSSmpGpY3ldSfoq:1BvPc0+qseOzjfYWZR9FWccomYpYoonq |
MD5: | AC376F4826594AA3471DC783D751EED1 |
SHA1: | 3535F40685D0062F5901F8A06FBE4BBDB53362AA |
SHA-256: | C1AC0E3BCBD1825381AC8436F7BAFB83A970D47136077216AA0B029DBF623C01 |
SHA-512: | 89E0B13424A4068747B6879842013010CFBEE56699544FE45E9FCEF5EA0A0981EE7D66431CE7AB35B70506DFBB4FBD12CB4275829519E57D36F76615E0653854 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 14892 |
Entropy (8bit): | 7.98489201092774 |
Encrypted: | false |
SSDEEP: | 384:LKrbeS3uuEGg7o6yDdWa/TQcNc+rAsmnsTJ39cUZi:LKneSe4/6yDFU6rAGJZE |
MD5: | 9EC6DEAF6BADA919E20B98F9F7B718B1 |
SHA1: | 501D36403AD8205E4644532600019ECB10F5CB0A |
SHA-256: | 7B348B30EA1FE43857E68FC462C29E5C6E63C97666AF75135C4396A272E54762 |
SHA-512: | 03849431CEF204A1584FFE6F23DBE86730AFD076146AB3D1855B9C3402168A97FAA8A529E69FAE45EA24CFF7110C2930CB4744162BA0ED95D95600F6E777B322 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/sourcesanspro/v22/6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7l.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 8794 |
Entropy (8bit): | 5.730417446234288 |
Encrypted: | false |
SSDEEP: | 192:TWPj7Lo6p6LrTSyOR63xSIL82I6zSOu0H9ReL8Q5JnvYx0NpNP+Z:UE6pmrTSyORyxSIA2I6z1Jdk4Qnnv8k4 |
MD5: | 64901B187ED2E438A189A440627AFE81 |
SHA1: | 7036334296FBCD07A00ABF75860B9A1BF9621DA7 |
SHA-256: | FCACD1755B15AFA9DD5DF1A44B8DF433319B775C96C77975C96D4C4656C0B3D4 |
SHA-512: | 644541BB9DB7CED8E8F2889BAF60C5F0D184DDBDF9C8318F7D2C2FBF2EB668670B5A847CFCF09A77DC05EAE04A4B2C1ECB3EBB1F8FA2BB8FDFDAFA19C3933BC1 |
Malicious: | false |
Reputation: | low |
URL: | https://www.shorturl.at/cdn-cgi/challenge-platform/h/g/scripts/jsd/f9063374b04d/main.js? |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 42616 |
Entropy (8bit): | 7.994774657302207 |
Encrypted: | true |
SSDEEP: | 768:sCLKndwLdsHEvFV0KovT+FZHnWc7Y+rteiNDKxjMXJJI4LizLs8txQ/fuTBFz:snuLdsHEXovCr9hdcQX1iLsIQ/fU |
MD5: | 57716E51419E5143F8E1DD061D5CF8C2 |
SHA1: | D796688A0F3679B0536787315EE0386649C146AB |
SHA-256: | B1128ADB79C7208D410630C04FE6E8AC8886AEB778AAFB3F4195FE735ACC1D89 |
SHA-512: | BCC76E2AF4B718DB7799F4C2D15A2A4AEB7F5C6FF391560597780368EA59D8633B2E187E0A175BD5A59A97E8A44C93ABD078E4C41987B0A5B5325FCC40A714A4 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/asap/v30/KFO9CniXp96a4Tc2DaTeuDAoKsE615hJW34.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332912 |
Entropy (8bit): | 5.5781779832147995 |
Encrypted: | false |
SSDEEP: | 6144:z4ooGUiz8zXNiZD9Wy9nnQyDy4VEx7D4xge8:EofzCXaD58rZ |
MD5: | 8A47757777ABA578E6232497A8604595 |
SHA1: | A6DBA8E00CDF8622B6AAC5687DC03BADF7CDE09A |
SHA-256: | 87C5064760161A7CE208EAF7555BFC790DE970F6EED754D94CA5B04144B725E9 |
SHA-512: | D0868606906CCD012FEA3D349AFCA3B78D20C8047EE187D24019F800E16DD966944EF308948C1A2A4B95DE479A25B2BF6BE1F94B4F6E8E2A94F98C690C0B1981 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 13709 |
Entropy (8bit): | 5.293899173332471 |
Encrypted: | false |
SSDEEP: | 192:YyN8JcgoayghBzD/hANICjSqgqpEaEMyce5tnkNa/JAnx//:wq9gzzD/GNICjSRp/7nNGnx// |
MD5: | 34DADC01A7D672CB87BFF41548EDCE52 |
SHA1: | 34B5620C6396927F64F1C31444BD4C44A9FE5B89 |
SHA-256: | 207464BE6175F2CD25ACD5F13CF4140A06268BEBB90E5C356FCBF6C6261845CA |
SHA-512: | 03F8F436EFADFC41321572F3E0F9AEC0FF9A23536D9DC86C7BF0070039BD728186197F71EDA71235BCD0FF812E66FCD8F3296755EEB4FC0AEB03083BF2C8F5A5 |
Malicious: | false |
Reputation: | low |
URL: | https://www.shorturl.at/error.php |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 243
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 18:53:31.737063885 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:32.046750069 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:32.649873018 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:33.144067049 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:33.144160986 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:33.144244909 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:33.144586086 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:33.144633055 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:33.144737005 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:33.144840956 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:33.144876003 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:33.145050049 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:33.145087957 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:33.857741117 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:34.374023914 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.374072075 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.374495029 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.374532938 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.374557018 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.374582052 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.376015902 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.376085043 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.376279116 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.376353979 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.377630949 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.377734900 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.378025055 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.378043890 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.378151894 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.378247976 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.428723097 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.433870077 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.433901072 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.474812031 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.826499939 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.826622009 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.826704979 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.827263117 CET | 49698 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:34.827306986 CET | 443 | 49698 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:34.975554943 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:34.975591898 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:34.975658894 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:34.975929976 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:34.975940943 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.196611881 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.198175907 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.198195934 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.199635029 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.199733019 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.200786114 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.200856924 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.201023102 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.201031923 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.245738029 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.261749029 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:36.281399012 CET | 49690 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:36.940670967 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.940762043 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.940813065 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.941324949 CET | 49702 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.941339970 CET | 443 | 49702 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.943233967 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.943341970 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:36.943424940 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.943640947 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:36.943671942 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:37.041182995 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:37.041222095 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:37.041286945 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:37.041542053 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:37.041554928 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:38.196886063 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.197324038 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.197388887 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.198890924 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.199301004 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.199486971 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.199491978 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.199510098 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.243757963 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.662286043 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.662419081 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.662511110 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.662516117 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.662565947 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.662627935 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.662643909 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.662760019 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.662815094 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.662827969 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.670260906 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.670340061 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.670352936 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.687768936 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.687868118 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.687880993 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.690598011 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.690639019 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.690756083 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.690968990 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.690989971 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.692445993 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.692523956 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.692774057 CET | 49705 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:38.692802906 CET | 443 | 49705 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:38.826452971 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:38.826778889 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:38.826793909 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:38.827687979 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:38.827760935 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:38.829045057 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:38.829088926 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:38.883709908 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:38.883722067 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:38.931761026 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:39.890758991 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:53:40.022607088 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.022876024 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.022896051 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.024029970 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.024311066 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.024440050 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.024487972 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.078739882 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.204848051 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:53:40.459920883 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.460093021 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.460177898 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.460180998 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.460211039 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.460258961 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.460316896 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.468198061 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.468450069 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.468478918 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.479820967 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.480098963 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.480128050 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.488157034 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.488444090 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.488965988 CET | 49709 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:40.488997936 CET | 443 | 49709 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.641338110 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:40.641432047 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.641530037 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:40.641725063 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:40.641762972 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:40.810779095 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:53:41.064742088 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:41.857413054 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:41.857724905 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:41.857762098 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:41.859199047 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:41.859281063 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:41.859589100 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:41.859677076 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:41.859730959 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:41.907337904 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:41.911746979 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:41.911767006 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:41.959745884 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.023741961 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:53:42.300256014 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.300390959 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.300468922 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.300540924 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.300558090 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.300590038 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.300647020 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.300678015 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.300731897 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.300781965 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.308247089 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.308307886 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.308326006 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.316602945 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.316684008 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.316696882 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.316771030 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:42.316833973 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.316931963 CET | 49712 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:42.316951036 CET | 443 | 49712 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:44.288306952 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:44.288337946 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:44.288422108 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:44.288638115 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:44.288655996 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:44.365020037 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:44.427258968 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:44.427284956 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:44.427351952 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:44.427550077 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:44.427563906 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:44.428730965 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:53:44.667757034 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:45.267759085 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:45.521362066 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.521913052 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.521946907 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.523067951 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.523427963 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.523581982 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.523591042 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.523608923 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.570921898 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.690279961 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.690772057 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.690795898 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.691266060 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.691653013 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.691751003 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.691829920 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.739331961 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.996299982 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.996826887 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:45.996925116 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.997755051 CET | 49719 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:45.997775078 CET | 443 | 49719 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.001526117 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:46.001565933 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.001663923 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:46.001943111 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:46.001976013 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.140382051 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.140434980 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.140495062 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:46.141067982 CET | 49721 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:46.141083002 CET | 443 | 49721 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.143023968 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:46.143069983 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.143146992 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:46.143415928 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:46.143431902 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:46.480739117 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:47.222171068 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.222434044 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.222496033 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.223617077 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.223910093 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.224025965 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.224086046 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.277759075 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.440835953 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.442140102 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.442168951 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.442490101 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.443034887 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.443034887 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.443058014 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.443105936 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.484771967 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.685062885 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.685209036 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.686275959 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.686722040 CET | 49724 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.686742067 CET | 443 | 49724 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.887597084 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.887630939 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.887676001 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.888362885 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.888385057 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.888770103 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.895859003 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.904299974 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.904352903 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.904401064 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.904402018 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.904555082 CET | 49725 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.904571056 CET | 443 | 49725 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.907181978 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.907274008 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.907370090 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.907706022 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:47.907738924 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.975330114 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.975356102 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:47.975559950 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.975630045 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:47.975639105 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:48.035358906 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:48.035372019 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:48.036537886 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:48.037055016 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:48.037067890 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:48.441158056 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:48.441217899 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:48.441267014 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:48.876557112 CET | 49706 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:53:48.876590967 CET | 443 | 49706 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:53:48.888752937 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:49.172046900 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:49.172195911 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:49.172305107 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:49.233787060 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.234179974 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.234217882 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.234738111 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.235148907 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.235235929 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.235271931 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.236768007 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:53:49.275331974 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.284781933 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.427958965 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.428208113 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.428232908 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.428261042 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.428428888 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.428437948 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.428697109 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.428898096 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.429047108 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.429131031 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.429263115 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.429344893 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.429394007 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.429505110 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.429542065 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.429595947 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.429886103 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.429946899 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.430011034 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.430068970 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.471333981 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.471374035 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.687422037 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.687478065 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.687557936 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.687606096 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.687788010 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.687829018 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.699775934 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.699856043 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.699901104 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.699942112 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.700118065 CET | 49726 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.700150013 CET | 443 | 49726 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.702291012 CET | 49699 | 443 | 192.168.2.16 | 172.67.69.88 |
Dec 12, 2024 18:53:49.702336073 CET | 443 | 49699 | 172.67.69.88 | 192.168.2.16 |
Dec 12, 2024 18:53:49.941037893 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.941173077 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.941235065 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.944590092 CET | 49728 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.944616079 CET | 443 | 49728 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.946537018 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.946682930 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.946747065 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.951652050 CET | 49727 | 443 | 192.168.2.16 | 104.26.8.129 |
Dec 12, 2024 18:53:49.951662064 CET | 443 | 49727 | 104.26.8.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.958933115 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.958980083 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:49.959187031 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.959599972 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:49.959614038 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:50.667779922 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 12, 2024 18:53:51.183414936 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.183933973 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.183981895 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.184519053 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.185034037 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.185144901 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.185226917 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.227335930 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.636872053 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.636948109 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.637032032 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.637908936 CET | 49729 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.637949944 CET | 443 | 49729 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.639797926 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.639846087 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.639931917 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.640265942 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:51.640295982 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:51.777915001 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:51.777951002 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:51.778043032 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:51.778311014 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:51.778326988 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:52.917071104 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:52.917407036 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:52.917470932 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:52.917956114 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:52.918335915 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:52.918401957 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:52.918438911 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:52.970927954 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:53.002196074 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.002634048 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.002657890 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.004108906 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.004313946 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.005857944 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.006011009 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.006067991 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.047333956 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.050735950 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.050755978 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.098756075 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.380511999 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:53.380598068 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:53.380691051 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:53.381434917 CET | 49731 | 443 | 192.168.2.16 | 104.26.9.129 |
Dec 12, 2024 18:53:53.381469965 CET | 443 | 49731 | 104.26.9.129 | 192.168.2.16 |
Dec 12, 2024 18:53:53.457849026 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.458060980 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.458141088 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.458307028 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.458323956 CET | 443 | 49732 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.458337069 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.458383083 CET | 49732 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.459191084 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.459274054 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.459382057 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.459700108 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:53.459732056 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:53.689902067 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:53:54.677927971 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:54.678503990 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:54.678569078 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:54.680998087 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:54.681543112 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:54.681622028 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:54.681636095 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:54.682213068 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:54.725895882 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:55.139379978 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:55.139492989 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:55.139698029 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:55.139883041 CET | 49733 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:53:55.139899969 CET | 443 | 49733 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:53:58.850873947 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 12, 2024 18:54:03.301981926 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 12, 2024 18:54:36.956090927 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:36.956183910 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:36.956305981 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:36.956540108 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:36.956562042 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:38.655486107 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:38.655930996 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:38.655961037 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:38.656649113 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:38.657052994 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:38.657146931 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:38.697807074 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:48.360079050 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:48.360230923 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:48.360460043 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:50.258852959 CET | 49736 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:54:50.258929968 CET | 443 | 49736 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:54:51.648376942 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:51.648441076 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:51.648883104 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:51.649265051 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:51.649288893 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:52.866978884 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:52.867472887 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:52.867544889 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:52.868053913 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:52.868480921 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:52.868585110 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:52.868648052 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:52.911354065 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:52.922918081 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:53.330528975 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:53.330627918 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:53.330842018 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:53.331166029 CET | 49737 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:53.331239939 CET | 443 | 49737 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:53.331842899 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:53.331944942 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:53.332103014 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:53.332365036 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:53.332406044 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:54.558763981 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:54.560028076 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:54.560098886 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:54.561712980 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:54.562907934 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:54.563110113 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:54.563393116 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:54.607436895 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:55.030473948 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:55.030673981 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:54:55.030874014 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:55.031462908 CET | 49738 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 12, 2024 18:54:55.031513929 CET | 443 | 49738 | 35.190.80.1 | 192.168.2.16 |
Dec 12, 2024 18:55:37.014025927 CET | 49740 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:55:37.014062881 CET | 443 | 49740 | 142.250.181.36 | 192.168.2.16 |
Dec 12, 2024 18:55:37.014194012 CET | 49740 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:55:37.014682055 CET | 49740 | 443 | 192.168.2.16 | 142.250.181.36 |
Dec 12, 2024 18:55:37.014695883 CET | 443 | 49740 | 142.250.181.36 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 18:53:32.211973906 CET | 53 | 50288 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:32.222533941 CET | 53 | 60584 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:32.988035917 CET | 52165 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:32.988166094 CET | 63384 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:33.128092051 CET | 53 | 52165 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:33.143420935 CET | 53 | 63384 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:34.830667973 CET | 56234 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:34.830779076 CET | 61374 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:34.974566936 CET | 53 | 56234 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:34.974962950 CET | 53 | 61374 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:35.168876886 CET | 53 | 60086 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:36.898993015 CET | 65061 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:36.899157047 CET | 51402 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:37.040122032 CET | 53 | 65061 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:37.040337086 CET | 53 | 51402 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:38.820630074 CET | 53 | 58591 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:40.501724005 CET | 51702 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:40.501854897 CET | 50349 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:40.640475988 CET | 53 | 51702 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:40.640876055 CET | 53 | 50349 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:41.555738926 CET | 53 | 56859 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:45.306381941 CET | 53 | 54541 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:45.394412994 CET | 53 | 61638 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:51.639094114 CET | 60519 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:51.639281034 CET | 58034 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 12, 2024 18:53:51.776402950 CET | 53 | 60519 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:51.777364969 CET | 53 | 58034 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:53:52.086262941 CET | 53 | 49943 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:54:11.166266918 CET | 53 | 55239 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:54:32.162211895 CET | 53 | 50087 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:54:33.582119942 CET | 53 | 57827 | 1.1.1.1 | 192.168.2.16 |
Dec 12, 2024 18:54:36.073065042 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Dec 12, 2024 18:55:04.759155989 CET | 53 | 59918 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 12, 2024 18:53:32.988035917 CET | 192.168.2.16 | 1.1.1.1 | 0x6032 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 18:53:32.988166094 CET | 192.168.2.16 | 1.1.1.1 | 0xcf35 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 12, 2024 18:53:34.830667973 CET | 192.168.2.16 | 1.1.1.1 | 0x537b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 18:53:34.830779076 CET | 192.168.2.16 | 1.1.1.1 | 0x7aaa | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 12, 2024 18:53:36.898993015 CET | 192.168.2.16 | 1.1.1.1 | 0xd07a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 18:53:36.899157047 CET | 192.168.2.16 | 1.1.1.1 | 0x39cf | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 12, 2024 18:53:40.501724005 CET | 192.168.2.16 | 1.1.1.1 | 0x7aa9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 18:53:40.501854897 CET | 192.168.2.16 | 1.1.1.1 | 0x2886 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 12, 2024 18:53:51.639094114 CET | 192.168.2.16 | 1.1.1.1 | 0x5871 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 18:53:51.639281034 CET | 192.168.2.16 | 1.1.1.1 | 0x35c9 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 12, 2024 18:53:33.128092051 CET | 1.1.1.1 | 192.168.2.16 | 0x6032 | No error (0) | 172.67.69.88 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:33.128092051 CET | 1.1.1.1 | 192.168.2.16 | 0x6032 | No error (0) | 104.26.9.129 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:33.128092051 CET | 1.1.1.1 | 192.168.2.16 | 0x6032 | No error (0) | 104.26.8.129 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:33.143420935 CET | 1.1.1.1 | 192.168.2.16 | 0xcf35 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 12, 2024 18:53:34.974566936 CET | 1.1.1.1 | 192.168.2.16 | 0x537b | No error (0) | 104.26.8.129 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:34.974566936 CET | 1.1.1.1 | 192.168.2.16 | 0x537b | No error (0) | 172.67.69.88 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:34.974566936 CET | 1.1.1.1 | 192.168.2.16 | 0x537b | No error (0) | 104.26.9.129 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:34.974962950 CET | 1.1.1.1 | 192.168.2.16 | 0x7aaa | No error (0) | 65 | IN (0x0001) | false | |||
Dec 12, 2024 18:53:37.040122032 CET | 1.1.1.1 | 192.168.2.16 | 0xd07a | No error (0) | 142.250.181.36 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:37.040337086 CET | 1.1.1.1 | 192.168.2.16 | 0x39cf | No error (0) | 65 | IN (0x0001) | false | |||
Dec 12, 2024 18:53:40.640475988 CET | 1.1.1.1 | 192.168.2.16 | 0x7aa9 | No error (0) | 104.26.9.129 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:40.640475988 CET | 1.1.1.1 | 192.168.2.16 | 0x7aa9 | No error (0) | 104.26.8.129 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:40.640475988 CET | 1.1.1.1 | 192.168.2.16 | 0x7aa9 | No error (0) | 172.67.69.88 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 18:53:40.640876055 CET | 1.1.1.1 | 192.168.2.16 | 0x2886 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 12, 2024 18:53:51.776402950 CET | 1.1.1.1 | 192.168.2.16 | 0x5871 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49698 | 172.67.69.88 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:34 UTC | 659 | OUT | |
2024-12-12 17:53:34 UTC | 948 | IN | |
2024-12-12 17:53:34 UTC | 243 | IN | |
2024-12-12 17:53:34 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49702 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:36 UTC | 663 | OUT | |
2024-12-12 17:53:36 UTC | 972 | IN | |
2024-12-12 17:53:36 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49705 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:38 UTC | 667 | OUT | |
2024-12-12 17:53:38 UTC | 925 | IN | |
2024-12-12 17:53:38 UTC | 444 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN | |
2024-12-12 17:53:38 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49709 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:40 UTC | 587 | OUT | |
2024-12-12 17:53:40 UTC | 752 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 1369 | IN | |
2024-12-12 17:53:40 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49712 | 104.26.9.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:41 UTC | 402 | OUT | |
2024-12-12 17:53:42 UTC | 754 | IN | |
2024-12-12 17:53:42 UTC | 615 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 1369 | IN | |
2024-12-12 17:53:42 UTC | 765 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49719 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:45 UTC | 595 | OUT | |
2024-12-12 17:53:45 UTC | 1036 | IN | |
2024-12-12 17:53:45 UTC | 333 | IN | |
2024-12-12 17:53:45 UTC | 824 | IN | |
2024-12-12 17:53:45 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49721 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:45 UTC | 526 | OUT | |
2024-12-12 17:53:46 UTC | 888 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49724 | 104.26.9.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:47 UTC | 444 | OUT | |
2024-12-12 17:53:47 UTC | 1036 | IN | |
2024-12-12 17:53:47 UTC | 333 | IN | |
2024-12-12 17:53:47 UTC | 824 | IN | |
2024-12-12 17:53:47 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49725 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:47 UTC | 638 | OUT | |
2024-12-12 17:53:47 UTC | 862 | IN | |
2024-12-12 17:53:47 UTC | 507 | IN | |
2024-12-12 17:53:47 UTC | 1369 | IN | |
2024-12-12 17:53:47 UTC | 1369 | IN | |
2024-12-12 17:53:47 UTC | 1369 | IN | |
2024-12-12 17:53:47 UTC | 1369 | IN | |
2024-12-12 17:53:47 UTC | 1369 | IN | |
2024-12-12 17:53:47 UTC | 1369 | IN | |
2024-12-12 17:53:47 UTC | 73 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49726 | 104.26.9.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:49 UTC | 497 | OUT | |
2024-12-12 17:53:49 UTC | 865 | IN | |
2024-12-12 17:53:49 UTC | 504 | IN | |
2024-12-12 17:53:49 UTC | 1369 | IN | |
2024-12-12 17:53:49 UTC | 1369 | IN | |
2024-12-12 17:53:49 UTC | 1369 | IN | |
2024-12-12 17:53:49 UTC | 1369 | IN | |
2024-12-12 17:53:49 UTC | 1369 | IN | |
2024-12-12 17:53:49 UTC | 1369 | IN | |
2024-12-12 17:53:49 UTC | 94 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.16 | 49727 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:49 UTC | 712 | OUT | |
2024-12-12 17:53:49 UTC | 15802 | OUT | |
2024-12-12 17:53:49 UTC | 1254 | IN | |
2024-12-12 17:53:49 UTC | 217 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.16 | 49728 | 104.26.8.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:49 UTC | 712 | OUT | |
2024-12-12 17:53:49 UTC | 15802 | OUT | |
2024-12-12 17:53:49 UTC | 1250 | IN | |
2024-12-12 17:53:49 UTC | 217 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.16 | 49729 | 104.26.9.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:51 UTC | 486 | OUT | |
2024-12-12 17:53:51 UTC | 713 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.16 | 49731 | 104.26.9.129 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:52 UTC | 486 | OUT | |
2024-12-12 17:53:53 UTC | 719 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.16 | 49732 | 35.190.80.1 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:53 UTC | 536 | OUT | |
2024-12-12 17:53:53 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.16 | 49733 | 35.190.80.1 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:53:54 UTC | 478 | OUT | |
2024-12-12 17:53:54 UTC | 438 | OUT | |
2024-12-12 17:53:55 UTC | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.16 | 49737 | 35.190.80.1 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:54:52 UTC | 540 | OUT | |
2024-12-12 17:54:53 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.16 | 49738 | 35.190.80.1 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 17:54:54 UTC | 482 | OUT | |
2024-12-12 17:54:54 UTC | 442 | OUT | |
2024-12-12 17:54:55 UTC | 168 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 12:53:30 |
Start date: | 12/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 12:53:31 |
Start date: | 12/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 12:53:32 |
Start date: | 12/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |