Windows
Analysis Report
https://www.google.co.id/url?q=sf_rand(2000)CHARtTPSJ3J3wDyycT&sa=t&esrc=sf_rand(2000)gECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=sf_rand(2000)RlDJVS0YXpPkDfJ6C&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp/apcarpetcleaning.com.au%2Fkom%2Fwp-images%2Fpoom%0A%2Fsf_rand_string_mixed(24)/tmitchell@enco
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6952 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7136 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2200 --fi eld-trial- handle=197 2,i,839762 9688700943 437,155950 5034341735 4946,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 3168 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://www.g oogle.co.i d/url?q=sf _rand(2000 )CHARtTPSJ 3J3wDyycT& sa=t&esrc= sf_rand(20 00)gECA0xy s8Em2FL&so urce=&cd=H XUursu8uEc r4eTiw9XH& cad=sf_ran d(2000)RlD JVS0YXpPkD fJ6C&ved=x jnktlqryYW wZIBRrgvK& uact=&url= amp/apcarp etcleaning .com.au%2F kom%2Fwp-i mages%2Fpo om%0A%2Fsf _rand_stri ng_mixed(2 4)/tmitche ll@encorec ompliance. com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T17:25:42.467993+0100 | 2057333 | 1 | Successful Credential Theft Detected | 192.168.2.16 | 49709 | 203.170.84.122 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Source: | Sample URL: |
Source: | HTTP Parser: |
Networking |
---|
Source: | Suricata IDS: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.co.id | 142.250.181.131 | true | false | high | |
civiltraxconstructiongroup.com | 203.170.84.122 | true | true | unknown | |
google.com | 172.217.17.78 | true | false | high | |
www.google.com | 142.250.181.132 | true | false | high | |
apcarpetcleaning.com.au | 192.185.170.197 | true | false | high | |
www.civiltraxconstructiongroup.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
true | unknown | ||
false | high | ||
false | high | ||
false | unknown | ||
false | unknown | ||
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
192.185.170.197 | apcarpetcleaning.com.au | United States | 46606 | UNIFIEDLAYER-AS-1US | false | |
203.170.84.122 | civiltraxconstructiongroup.com | Australia | 38719 | DREAMSCAPE-AS-APDreamscapeNetworksLimitedAU | true | |
142.250.181.131 | www.google.co.id | United States | 15169 | GOOGLEUS | false | |
142.250.181.132 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1578430 |
Start date and time: | 2024-12-19 17:25:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 19s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://www.google.co.id/url?q=sf_rand(2000)CHARtTPSJ3J3wDyycT&sa=t&esrc=sf_rand(2000)gECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=sf_rand(2000)RlDJVS0YXpPkDfJ6C&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp/apcarpetcleaning.com.au%2Fkom%2Fwp-images%2Fpoom%0A%2Fsf_rand_string_mixed(24)/tmitchell@encorecompliance.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@20/20@14/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 23.193.114.26, 142.250.181.99, 172.217.17.78, 64.233.162.84, 172.217.17.46, 172.217.17.35, 172.217.19.206, 23.218.208.109, 52.149.20.212
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://www.google.co.id/url?q=sf_rand(2000)CHARtTPSJ3J3wDyycT&sa=t&esrc=sf_rand(2000)gECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=sf_rand(2000)RlDJVS0YXpPkDfJ6C&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp/apcarpetcleaning.com.au%2Fkom%2Fwp-images%2Fpoom%0A%2Fsf_rand_string_mixed(24)/tmitchell@encorecompliance.com
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.980536255957969 |
Encrypted: | false |
SSDEEP: | 48:8tmdQTUMJHjOidAKZdA1FehwiZUklqehty+3:8t9fOay |
MD5: | 6FCA0DA5D0F20B874BB18BA56BAB272B |
SHA1: | 20204D03DC6A1FEA4C835D5748B34E2D7309CBEB |
SHA-256: | E194706FC8817C5BB427EEC045760A7FC5B3E4C289A0F0806711DE4A4682D167 |
SHA-512: | CB08D96C1A42C0C0EF538CFCDADF9A8ED397143758C14CB39ED5E043E306275EB96B6E597ED7C37E2B513ECA9E18293EA1F15B52FC01532FF788D71F61978468 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9990885239836222 |
Encrypted: | false |
SSDEEP: | 48:8ydQTUMJHjOidAKZdA1seh/iZUkAQkqehKy+2:8Zfo9QLy |
MD5: | 0390E881224F7CA6597976389272D8A6 |
SHA1: | BFBAC992E7B88460FC9B75E22CE2C7EF61283227 |
SHA-256: | 24FBDEE12065D6108D97641502578F443D6EE972190CDF19B5ABB82577506881 |
SHA-512: | 0C74E76AC9008B7F431FD25499CCD15641F85AC916F5382BF992B8227F79CB799B352F48661398ADC5FA185DCD17E8B3236F41C99ABB8C890FF32673E02EB4F1 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.007074637409712 |
Encrypted: | false |
SSDEEP: | 48:8pdQTUMAHjOidAKZdA14meh7sFiZUkmgqeh7sAy+BX:8MfPnWy |
MD5: | 0C8B0479F2C89D5B90AD45B24E026009 |
SHA1: | 52B0C40D37D84A01B8D3A63E4305CBEE9057D170 |
SHA-256: | 09FB34EC3DED0C46217F61369C6CDC1D3E252D53F7CC5C7C158AA5E3F2F6ABD3 |
SHA-512: | 400BB7CB9567ECC4E7AC162AC5F64BBFC7090A3CF6D568D56B5F3A2786D40B541DFE11EFC1FFFF0C9EF59F189BE64F4F239177AB2C5DF43EC1B2A50736D1520C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9949585913550774 |
Encrypted: | false |
SSDEEP: | 48:8qdQTUMJHjOidAKZdA1TehDiZUkwqehOy+R:8xfDYy |
MD5: | 2D783CB77E4D92E50E543FBD53415959 |
SHA1: | E9DF7459F8C5D24A4A48E9173D73BB8127949ED3 |
SHA-256: | 149ED965FDECA5F0F3D5005D81618B6495F0B7D2A41E4265E36A0F0DBE8563A1 |
SHA-512: | 5D791365A39F51915CFF69A7593365959D2965490F2952B033261547DE15DF7B63C15742447DB2256147DFC1CE71A0DBB8F639A27EDE63E319C02D0E8FB9F8AD |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9848788323424023 |
Encrypted: | false |
SSDEEP: | 48:8AdQTUMJHjOidAKZdA1dehBiZUk1W1qeh8y+C:8ffz9cy |
MD5: | 8FDE077FB948DD0615D5B7ED328C8717 |
SHA1: | 50E78ACCE88B58E779DB78A7D2EC8BEBCBF20913 |
SHA-256: | E0FEEC130C1746840E18D408DDE780237FEA0EDF05E4444E6AC8B9814D9DBB74 |
SHA-512: | 8BC4AC90E1E0FDE25E230AA036788721244B0D5EB295FC05A0E5BCB4304F8B964D945DEA103350A6D6E1D06C5A9C232F808A8DE1D9F10C08300ECB947FEE06B6 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.993143039843582 |
Encrypted: | false |
SSDEEP: | 48:83dQTUMJHjOidAKZdA1duTeehOuTbbiZUk5OjqehOuTbWy+yT+:8yfXTfTbxWOvTbWy7T |
MD5: | 04AD16EA57866CE754CDB5085D4C1500 |
SHA1: | F52FA5038DBF6025D0A7223C308768B48374BAFB |
SHA-256: | 3E964395BC7D9FB320A293AE4C8DC37B0B59C0A7B6C860CD7F6DE7CCB85E9F5B |
SHA-512: | D66A1E86DF3A4BE0871A6B6B11281D0D65412FADCFC94011EDFED66B46948F156896145130F8A1BECB3540BD19CE07C68521D73DE8923C200179CD52956708B2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1292 |
Entropy (8bit): | 7.776057361542798 |
Encrypted: | false |
SSDEEP: | 24:0diF3RhMw/nvj1HPhIAfhwb5MzooIUkutfqjwe7b79fg95gXqQz+g:33XlvhXyb5MlkuStb798gXqQSg |
MD5: | C78D5E500B8CB13837D8F9D306965BD0 |
SHA1: | 3645E3A65D8671559C4E67CF7CDDD19F1F7863B9 |
SHA-256: | C91EA35E45FA31EA077322E1B61C8EBF3194D211E9D6D87E57D3267F5D97FFE5 |
SHA-512: | 488CC264847DEA82C79E8E2DE1844F65EAC0FE509381A755C7777EA1DCA8E2ECD5FD2FBB7C69793BDFF02A8AE5D2D4CB4988366A2E12C8269E59ED35573E806B |
Malicious: | false |
Reputation: | low |
URL: | http://apcarpetcleaning.com.au/wp-content/uploads/2023/03/fav.webp |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1292 |
Entropy (8bit): | 7.776057361542798 |
Encrypted: | false |
SSDEEP: | 24:0diF3RhMw/nvj1HPhIAfhwb5MzooIUkutfqjwe7b79fg95gXqQz+g:33XlvhXyb5MlkuStb798gXqQSg |
MD5: | C78D5E500B8CB13837D8F9D306965BD0 |
SHA1: | 3645E3A65D8671559C4E67CF7CDDD19F1F7863B9 |
SHA-256: | C91EA35E45FA31EA077322E1B61C8EBF3194D211E9D6D87E57D3267F5D97FFE5 |
SHA-512: | 488CC264847DEA82C79E8E2DE1844F65EAC0FE509381A755C7777EA1DCA8E2ECD5FD2FBB7C69793BDFF02A8AE5D2D4CB4988366A2E12C8269E59ED35573E806B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/images/errors/robot.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1565 |
Entropy (8bit): | 5.2675078899224985 |
Encrypted: | false |
SSDEEP: | 24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xKdS8f:3qD+2+pUAew85zsKQA |
MD5: | BC0AD2DB3272298238C3933EA0D944D1 |
SHA1: | CCB1767CAF616C73513DC921CD3F5DA072582A77 |
SHA-256: | 0A6AD5109827EFF80F61F2106F29D9FB38CE486FA397551E506BF5B6ED861F36 |
SHA-512: | 064388FD474E86ECB2D17082C79F6C9232DB605F62979598D9EA525600B8F9786716B758220D7C3ECC116E8E84AF8BB6AB6297C4005BCEF26E69DD64F4D61A72 |
Malicious: | false |
Reputation: | low |
URL: | https://google.com/404/ |
Preview: |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T17:25:42.467993+0100 | 2057333 | ET PHISHING MAMBA Credential Phish Landing Page 2024-11-08 | 1 | 192.168.2.16 | 49709 | 203.170.84.122 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 17:25:27.638528109 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 19, 2024 17:25:28.846472025 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 19, 2024 17:25:31.131701946 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:31.254887104 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 19, 2024 17:25:33.233963966 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:33.234009027 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:33.234070063 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:33.234342098 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:33.234359026 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:33.234772921 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:33.234806061 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:33.234869003 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:33.235104084 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:33.235116005 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.875097990 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:34.932817936 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.933166027 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.933178902 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.934216022 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.934350967 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.938752890 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.938818932 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.938919067 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.938926935 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.940150976 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.940359116 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.940388918 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.941415071 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.941484928 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.942354918 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.942420006 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.986421108 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:34.986429930 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:34.986438036 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:35.034384012 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:35.178472996 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:35.771382093 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:35.771523952 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:35.771617889 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:35.772907972 CET | 49704 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:35.772912979 CET | 443 | 49704 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:35.776145935 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:35.785912991 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:35.819329977 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:36.057419062 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 19, 2024 17:25:36.836025953 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:36.836231947 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:36.836312056 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:36.836709023 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:36.836723089 CET | 443 | 49705 | 142.250.181.131 | 192.168.2.16 |
Dec 19, 2024 17:25:36.836734056 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:36.836772919 CET | 49705 | 443 | 192.168.2.16 | 142.250.181.131 |
Dec 19, 2024 17:25:36.999432087 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:37.148592949 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:37.148633003 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:37.148749113 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:37.148981094 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:37.148996115 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:37.416884899 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:37.536519051 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:37.536753893 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:37.536912918 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:37.656621933 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:38.837193966 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:38.879411936 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:38.880625010 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:38.880964041 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:38.881030083 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:38.882010937 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:38.882112026 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:38.883225918 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:38.883304119 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:38.896672964 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:38.927488089 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:38.927552938 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:38.974431992 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:39.016264915 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:39.281466007 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:39.284326077 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:39.342644930 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:39.404117107 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:39.406550884 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:39.418097973 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:39.418170929 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:39.418265104 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:39.418589115 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:39.418642044 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:39.418925047 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:39.418956995 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:39.418998003 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:39.419260979 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:39.419279099 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:39.624553919 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:39.624778986 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:39.624861002 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:39.644465923 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:39.768476009 CET | 49711 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:39.882287025 CET | 49712 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:39.888245106 CET | 80 | 49711 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:39.888329983 CET | 49711 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:39.888627052 CET | 49711 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:40.002945900 CET | 80 | 49712 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:40.003068924 CET | 49712 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:40.009236097 CET | 80 | 49711 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:40.246412039 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:41.053510904 CET | 80 | 49711 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:41.053888083 CET | 80 | 49711 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:41.053952932 CET | 49711 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:41.259515047 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.259829998 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.259898901 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.260896921 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.260970116 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.262056112 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.262129068 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.262267113 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.270086050 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.270412922 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.270481110 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.271774054 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.271851063 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.272217989 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.272298098 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.303369999 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.311423063 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.311453104 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.326755047 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.326788902 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:41.358406067 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.373413086 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:41.453442097 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:42.467868090 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:42.467951059 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:42.468103886 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:42.472373962 CET | 49709 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:25:42.472434998 CET | 443 | 49709 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:25:43.860528946 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:44.211456060 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:44.625155926 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:44.625339031 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:45.194243908 CET | 49708 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:45.194523096 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.195199966 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.195223093 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.195288897 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.195508957 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.195521116 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.235325098 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.313941956 CET | 80 | 49708 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:45.667474031 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 19, 2024 17:25:45.733947039 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.734010935 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.734049082 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.734080076 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.734241009 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.734241009 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.734301090 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.738284111 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.738404989 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.738418102 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.738840103 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.738883018 CET | 443 | 49707 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.738940001 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.881544113 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.881642103 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:45.881752014 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.881973982 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:45.882020950 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:46.147912025 CET | 80 | 49711 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:46.147974014 CET | 49711 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:46.579744101 CET | 49711 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:25:46.699939966 CET | 80 | 49711 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:25:47.039650917 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.039962053 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.039973974 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.040931940 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.041003942 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.041347980 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.041404009 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.041778088 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.041784048 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.089413881 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.596971035 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.598484039 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.598498106 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.599922895 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.599989891 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.600296974 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.600373030 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.602165937 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.602174044 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.648467064 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.854737043 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.854784966 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.854887962 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.854912043 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.854928017 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.854965925 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.855813026 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.855868101 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.855922937 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.855922937 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.855973005 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.861814976 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.861866951 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:47.862147093 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.862502098 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:47.862526894 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.282387018 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.282495022 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.282546997 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.282582998 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.282630920 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:48.282650948 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.282697916 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:48.290400982 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.290458918 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:48.290465117 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.290626049 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:48.290664911 CET | 443 | 49716 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:48.290793896 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:48.663419962 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:25:49.560435057 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:49.561141968 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:49.561152935 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:49.562664032 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:49.562735081 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:49.563196898 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:49.563281059 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:49.563484907 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:49.563492060 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:49.607487917 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.258568048 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.258603096 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:50.258686066 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.258955002 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.258966923 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:50.402019978 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:50.402080059 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:50.402147055 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.402175903 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:50.402271986 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:50.402328014 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.403107882 CET | 49717 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:50.403122902 CET | 443 | 49717 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:51.961483955 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:51.961863041 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:51.961925983 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:51.962269068 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:51.962666988 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:51.962742090 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:51.962842941 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.007332087 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650543928 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650593042 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650687933 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.650719881 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650784969 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650809050 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650862932 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.650875092 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.650923967 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.651684046 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.651727915 CET | 443 | 49719 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.651792049 CET | 49719 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.654632092 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.654680014 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:52.654773951 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.655071974 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:52.655087948 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:53.815486908 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 19, 2024 17:25:54.406667948 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:54.406977892 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:54.406991959 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:54.407293081 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:54.407601118 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:54.407659054 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:54.407738924 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:54.451338053 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.134342909 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.134481907 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.134581089 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.134663105 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.134768963 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:55.134768963 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:55.134794950 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.135591984 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:55.135680914 CET | 443 | 49720 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:25:55.135747910 CET | 49720 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:25:58.269450903 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 19, 2024 17:26:01.816942930 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:26:01.817167997 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:26:01.817250967 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:26:02.587119102 CET | 49710 | 443 | 192.168.2.16 | 203.170.84.122 |
Dec 19, 2024 17:26:02.587141991 CET | 443 | 49710 | 203.170.84.122 | 192.168.2.16 |
Dec 19, 2024 17:26:25.011519909 CET | 49712 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:26:25.131227016 CET | 80 | 49712 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:26:37.068754911 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:37.068820953 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:37.068952084 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:37.069185019 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:37.069204092 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:38.762649059 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:38.762985945 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:38.763020992 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:38.763916016 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:38.763998032 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:38.764431000 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:38.764487028 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:38.808443069 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:38.808490992 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:38.856458902 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:40.583359003 CET | 49712 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:26:40.703450918 CET | 80 | 49712 | 192.185.170.197 | 192.168.2.16 |
Dec 19, 2024 17:26:40.703531027 CET | 49712 | 80 | 192.168.2.16 | 192.185.170.197 |
Dec 19, 2024 17:26:48.487910032 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:48.487998009 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:26:48.488214970 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:48.590080023 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:26:48.590132952 CET | 443 | 49723 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:27:37.124660015 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:27:37.124706984 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:27:37.124876976 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:27:37.125267982 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 19, 2024 17:27:37.125288010 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:27:38.832546949 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 19, 2024 17:27:38.879502058 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 17:25:32.394974947 CET | 53 | 56169 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:32.497849941 CET | 53 | 55859 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:33.089962006 CET | 56676 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:33.090290070 CET | 57344 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:33.226871967 CET | 53 | 56676 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:33.233280897 CET | 53 | 57344 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:35.238804102 CET | 53 | 58032 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:36.840115070 CET | 61950 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:36.840279102 CET | 62218 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:37.007775068 CET | 60683 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:37.008232117 CET | 59957 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:37.147402048 CET | 53 | 60683 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:37.147483110 CET | 53 | 59957 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:37.415914059 CET | 53 | 61950 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:37.415954113 CET | 53 | 62218 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:38.894105911 CET | 55051 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:38.894320965 CET | 60538 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:39.415736914 CET | 53 | 55051 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:39.417396069 CET | 53 | 60538 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:39.629926920 CET | 64878 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:39.630104065 CET | 56077 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:39.767786026 CET | 53 | 56077 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:39.767827034 CET | 53 | 64878 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:42.473546982 CET | 51267 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:42.473762989 CET | 53781 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:42.610631943 CET | 53 | 53781 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:42.610801935 CET | 53 | 51267 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:45.741611004 CET | 53755 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:45.741839886 CET | 49798 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 19, 2024 17:25:45.880012989 CET | 53 | 53755 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:45.880976915 CET | 53 | 49798 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:25:52.239383936 CET | 53 | 60889 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:26:11.146033049 CET | 53 | 61956 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:26:31.052818060 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Dec 19, 2024 17:26:32.384087086 CET | 53 | 65213 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:26:33.612121105 CET | 53 | 57739 | 1.1.1.1 | 192.168.2.16 |
Dec 19, 2024 17:27:03.600852966 CET | 53 | 61309 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 19, 2024 17:25:33.089962006 CET | 192.168.2.16 | 1.1.1.1 | 0x603a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:33.090290070 CET | 192.168.2.16 | 1.1.1.1 | 0x2b55 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 19, 2024 17:25:36.840115070 CET | 192.168.2.16 | 1.1.1.1 | 0xeb30 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:36.840279102 CET | 192.168.2.16 | 1.1.1.1 | 0xde42 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 19, 2024 17:25:37.007775068 CET | 192.168.2.16 | 1.1.1.1 | 0x63b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:37.008232117 CET | 192.168.2.16 | 1.1.1.1 | 0xdc4a | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 19, 2024 17:25:38.894105911 CET | 192.168.2.16 | 1.1.1.1 | 0xd716 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:38.894320965 CET | 192.168.2.16 | 1.1.1.1 | 0xcd6b | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 19, 2024 17:25:39.629926920 CET | 192.168.2.16 | 1.1.1.1 | 0x1ecc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:39.630104065 CET | 192.168.2.16 | 1.1.1.1 | 0xc415 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 19, 2024 17:25:42.473546982 CET | 192.168.2.16 | 1.1.1.1 | 0xf327 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:42.473762989 CET | 192.168.2.16 | 1.1.1.1 | 0xbcc5 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 19, 2024 17:25:45.741611004 CET | 192.168.2.16 | 1.1.1.1 | 0xe6af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 17:25:45.741839886 CET | 192.168.2.16 | 1.1.1.1 | 0x69d7 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 19, 2024 17:25:33.226871967 CET | 1.1.1.1 | 192.168.2.16 | 0x603a | No error (0) | 142.250.181.131 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:33.233280897 CET | 1.1.1.1 | 192.168.2.16 | 0x2b55 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 19, 2024 17:25:37.147402048 CET | 1.1.1.1 | 192.168.2.16 | 0x63b7 | No error (0) | 142.250.181.132 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:37.147483110 CET | 1.1.1.1 | 192.168.2.16 | 0xdc4a | No error (0) | 65 | IN (0x0001) | false | |||
Dec 19, 2024 17:25:37.415914059 CET | 1.1.1.1 | 192.168.2.16 | 0xeb30 | No error (0) | 192.185.170.197 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:39.415736914 CET | 1.1.1.1 | 192.168.2.16 | 0xd716 | No error (0) | civiltraxconstructiongroup.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:39.415736914 CET | 1.1.1.1 | 192.168.2.16 | 0xd716 | No error (0) | 203.170.84.122 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:39.417396069 CET | 1.1.1.1 | 192.168.2.16 | 0xcd6b | No error (0) | civiltraxconstructiongroup.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:39.767827034 CET | 1.1.1.1 | 192.168.2.16 | 0x1ecc | No error (0) | 192.185.170.197 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:42.610631943 CET | 1.1.1.1 | 192.168.2.16 | 0xbcc5 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 19, 2024 17:25:42.610801935 CET | 1.1.1.1 | 192.168.2.16 | 0xf327 | No error (0) | 172.217.17.78 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:45.880012989 CET | 1.1.1.1 | 192.168.2.16 | 0xe6af | No error (0) | 142.250.181.132 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 17:25:45.880976915 CET | 1.1.1.1 | 192.168.2.16 | 0x69d7 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49708 | 192.185.170.197 | 80 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 17:25:37.536912918 CET | 513 | OUT | |
Dec 19, 2024 17:25:38.837193966 CET | 383 | IN | |
Dec 19, 2024 17:25:38.896672964 CET | 465 | OUT | |
Dec 19, 2024 17:25:39.281466007 CET | 368 | IN | |
Dec 19, 2024 17:25:39.284326077 CET | 489 | OUT | |
Dec 19, 2024 17:25:39.624553919 CET | 1236 | IN | |
Dec 19, 2024 17:25:39.624778986 CET | 299 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49711 | 192.185.170.197 | 80 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 17:25:39.888627052 CET | 311 | OUT | |
Dec 19, 2024 17:25:41.053510904 CET | 1236 | IN | |
Dec 19, 2024 17:25:41.053888083 CET | 325 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49712 | 192.185.170.197 | 80 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 17:26:25.011519909 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49704 | 142.250.181.131 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:34 UTC | 1103 | OUT | |
2024-12-19 16:25:35 UTC | 1093 | IN | |
2024-12-19 16:25:35 UTC | 297 | IN | |
2024-12-19 16:25:35 UTC | 30 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49705 | 142.250.181.131 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:35 UTC | 1133 | OUT | |
2024-12-19 16:25:36 UTC | 875 | IN | |
2024-12-19 16:25:36 UTC | 303 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49709 | 203.170.84.122 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:41 UTC | 816 | OUT | |
2024-12-19 16:25:42 UTC | 309 | IN | |
2024-12-19 16:25:42 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49707 | 142.250.181.132 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:45 UTC | 743 | OUT | |
2024-12-19 16:25:45 UTC | 683 | IN | |
2024-12-19 16:25:45 UTC | 707 | IN | |
2024-12-19 16:25:45 UTC | 1390 | IN | |
2024-12-19 16:25:45 UTC | 1390 | IN | |
2024-12-19 16:25:45 UTC | 1390 | IN | |
2024-12-19 16:25:45 UTC | 1390 | IN | |
2024-12-19 16:25:45 UTC | 60 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49715 | 142.250.181.132 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:47 UTC | 779 | OUT | |
2024-12-19 16:25:47 UTC | 671 | IN | |
2024-12-19 16:25:47 UTC | 719 | IN | |
2024-12-19 16:25:47 UTC | 1390 | IN | |
2024-12-19 16:25:47 UTC | 1061 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49716 | 142.250.181.132 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:47 UTC | 454 | OUT | |
2024-12-19 16:25:48 UTC | 683 | IN | |
2024-12-19 16:25:48 UTC | 707 | IN | |
2024-12-19 16:25:48 UTC | 1390 | IN | |
2024-12-19 16:25:48 UTC | 1390 | IN | |
2024-12-19 16:25:48 UTC | 1390 | IN | |
2024-12-19 16:25:48 UTC | 1390 | IN | |
2024-12-19 16:25:48 UTC | 60 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49717 | 142.250.181.132 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:49 UTC | 490 | OUT | |
2024-12-19 16:25:50 UTC | 671 | IN | |
2024-12-19 16:25:50 UTC | 719 | IN | |
2024-12-19 16:25:50 UTC | 1390 | IN | |
2024-12-19 16:25:50 UTC | 1061 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49719 | 142.250.181.132 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:51 UTC | 701 | OUT | |
2024-12-19 16:25:52 UTC | 705 | IN | |
2024-12-19 16:25:52 UTC | 685 | IN | |
2024-12-19 16:25:52 UTC | 1390 | IN | |
2024-12-19 16:25:52 UTC | 1390 | IN | |
2024-12-19 16:25:52 UTC | 1390 | IN | |
2024-12-19 16:25:52 UTC | 575 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49720 | 142.250.181.132 | 443 | 7136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 16:25:54 UTC | 442 | OUT | |
2024-12-19 16:25:55 UTC | 705 | IN | |
2024-12-19 16:25:55 UTC | 685 | IN | |
2024-12-19 16:25:55 UTC | 1390 | IN | |
2024-12-19 16:25:55 UTC | 1390 | IN | |
2024-12-19 16:25:55 UTC | 1390 | IN | |
2024-12-19 16:25:55 UTC | 575 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 11:25:29 |
Start date: | 19/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 11:25:30 |
Start date: | 19/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 11:25:31 |
Start date: | 19/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |