Windows
Analysis Report
https://ho8d1o.s3.amazonaws.com/index.html?AWSAccessKeyId=AKIAWPPO57XS4BTHJAEO&Signature=h4n%2BY6bT0YHF44DbJkmJeHwDnn0%3D&Expires=1734860434#mandy.pullen@peterborough.gov.uk
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6480 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6600 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2156 --fi eld-trial- handle=198 0,i,777355 9348717949 78,9478023 5391080398 12,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction /pre fetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6572 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://ho8d1 o.s3.amazo naws.com/i ndex.html? AWSAccessK eyId=AKIAW PPO57XS4BT HJAEO&Sign ature=h4n% 2BY6bT0YHF 44DbJkmJeH wDnn0%3D&E xpires=173 4860434#ma ndy.pullen @peterboro ugh.gov.uk " MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FakeCaptcha | Yara detected Fake Captcha | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FakeCaptcha | Yara detected Fake Captcha | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Phishing |
---|
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: |
Source: | Sample URL: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s3-w.us-east-1.amazonaws.com | 52.216.142.68 | true | false | high | |
22web30.esedigital-dev.ovh | 37.59.203.111 | true | false | unknown | |
www.google.com | 142.250.181.132 | true | false | high | |
ho8d1o.s3.amazonaws.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
37.59.203.111 | 22web30.esedigital-dev.ovh | France | 16276 | OVHFR | false | |
52.216.142.68 | s3-w.us-east-1.amazonaws.com | United States | 16509 | AMAZON-02US | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.181.132 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1578792 |
Start date and time: | 2024-12-20 13:03:12 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://ho8d1o.s3.amazonaws.com/index.html?AWSAccessKeyId=AKIAWPPO57XS4BTHJAEO&Signature=h4n%2BY6bT0YHF44DbJkmJeHwDnn0%3D&Expires=1734860434#mandy.pullen@peterborough.gov.uk |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.phis.win@22/8@6/5 |
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.181.99, 172.217.19.206, 64.233.164.84, 172.217.17.46, 142.250.181.142, 172.217.17.35, 92.122.16.236, 172.202.163.200
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://ho8d1o.s3.amazonaws.com/index.html?AWSAccessKeyId=AKIAWPPO57XS4BTHJAEO&Signature=h4n%2BY6bT0YHF44DbJkmJeHwDnn0%3D&Expires=1734860434#mandy.pullen@peterborough.gov.uk
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.983455653331797 |
Encrypted: | false |
SSDEEP: | 48:88OdHTfTKEHLidAKZdA1FehwiZUklqeh3y+3:88KHd8y |
MD5: | EF5744DEF9B1ED4CB0646092E78879D2 |
SHA1: | 898415EC1EC34B918E053159BC97A17D9C045C56 |
SHA-256: | A1DE414851DCAC8D19E4A2D34299EA4E45613EC3ABDA8CB9D1AB50094CE5D02F |
SHA-512: | F49DE02F52A94D1453763F3AF23FC766261755B3525681E1218892C295CD531934592C95A00179B26CED7C98E50E7749CF250058A202494F0F01927F807B2881 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.998142151856316 |
Encrypted: | false |
SSDEEP: | 48:8TOdHTfTKEHLidAKZdA1seh/iZUkAQkqehsy+2:8TKHT9Qly |
MD5: | E9CF5B1F09326C25CE0DAC8F08F20FC8 |
SHA1: | CFEE7B3BBC60C2781AEDDEE198FC26E002CCFFF4 |
SHA-256: | 9D47181FA82B79A9B3AEDD863E987E133FE15B2C3BE95E9743797BB617B2C169 |
SHA-512: | CE29804C35FB56068B3A85860747794C4C5FED5153D420981A3C7012031C24FE03CBD720476FE48C3BCF00B353B14595657CB9D40156BC597F95DA8EAED9352F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.009248468612741 |
Encrypted: | false |
SSDEEP: | 48:8vOdHTfTAHLidAKZdA14meh7sFiZUkmgqeh7syy+BX:8vKHingy |
MD5: | 14288EB420D4A80252B8B62842879411 |
SHA1: | 3F8955AAE8E9A8B5ABCAD2D71CC135EBE1190FAC |
SHA-256: | 95B4D06E26D4A2DF6F01B896C3E71A4F5AF36C12F2850091E092501F93702FC4 |
SHA-512: | 9F6DCDB26E6B6EF50460EDA1175CBBFE2719459B8B65DCBC09D2F02FB8BA74E1AA28EE10043C8CABDD09BF5054E6B89A2783C5F521AEEEAD60F0335938E0AF73 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.996865075737731 |
Encrypted: | false |
SSDEEP: | 48:8VOdHTfTKEHLidAKZdA1TehDiZUkwqeh4y+R:8VKHgKy |
MD5: | 449141C99AAB5A3CE195A058D977AD5B |
SHA1: | BB40467CE92E9D4E1BE36989AF56953AB16D4754 |
SHA-256: | 16BAEB1EF0FB0E5C7DBE86B0B7D1597CF3235654E6D0082D0DD973E99442656E |
SHA-512: | C7868FF0C7148ED73BFECB35CD51D988EFFDCD03519CA85109BB7EA6F81A8655A17F59D6CE5ADEB8916D476F20DA1AE4B310EB3A2755B3B16E658BAEBFA08495 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9871373764529925 |
Encrypted: | false |
SSDEEP: | 48:8zOdHTfTKEHLidAKZdA1dehBiZUk1W1qehmy+C:8zKHg9Gy |
MD5: | 8F1EB000CFC9F7B65412C4F786CA836A |
SHA1: | 0CE49619ABB7B55368CABDD634522A6651D6A45F |
SHA-256: | 7425ECA8C349D52D74604173CD2F95DF01FA21951B70F46BB884CEB9D2682874 |
SHA-512: | AECCA932E0ADF39564ADB7234DDFF8E82080B230729C3C84416141D2C0D4EEF88534AB93B6709E2FED400209DBE6B016EF52762433D0AEF162FD9EDA2A28A968 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.996522447104709 |
Encrypted: | false |
SSDEEP: | 48:8vOdHTfTKEHLidAKZdA1duTeehOuTbbiZUk5OjqehOuTbgy+yT+:8vKHyTfTbxWOvTbgy7T |
MD5: | D3C3985D7661CB5CC45B797C914A703A |
SHA1: | 9760575439A004790D7744791CE4867EB1CF758A |
SHA-256: | 48D5471EB9A987150504AB631F31486CB3F00DDE09673430C2EB8E56FA6431E9 |
SHA-512: | DE9C04DCE67F02FE8812649DD428E22F1EB39D3225DB20788E44DCC0D17ABB5B9A62237832EAAC32A8CE0BF7B5A208D6A260B111DCD430E70E25005676A980DB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 238472 |
Entropy (8bit): | 6.089807646548581 |
Encrypted: | false |
SSDEEP: | 3072:810dDCffNfgM2vahjF0XgK5M4TT+458v7StSzXsMmGQHebaEqerEsOXs1i7WWw9J:QAD8eahZ8bISt3+QTEqeasQeWMXx |
MD5: | CF0E3DFD238E9A130DF939CFE91CA782 |
SHA1: | 914F76FFE65AED89C59BC12690A4748536956405 |
SHA-256: | 3257A8D28FBA309F99727DA7D95DB0EE2F26C1FA52B2F613E919584937BA553B |
SHA-512: | ABD79D8D5E69BC93FE62D114D476013BC4A701B44817745185DF574346315FBFBDB0B01DDE9699C1888A66044BDCB19CFB36C9D7BCCACE569A6E49C252B05236 |
Malicious: | false |
Reputation: | low |
URL: | https://ho8d1o.s3.amazonaws.com/index.html?AWSAccessKeyId=AKIAWPPO57XS4BTHJAEO&Signature=h4n%2BY6bT0YHF44DbJkmJeHwDnn0%3D&Expires=1734860434 |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 20, 2024 13:03:42.992693901 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:03:43.293421030 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:03:43.901412964 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:03:45.109405994 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:03:47.518403053 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:03:47.587029934 CET | 49690 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:03:48.270765066 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:48.270809889 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:48.270883083 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:48.271501064 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:48.271564007 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:48.271626949 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:48.271786928 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:48.271810055 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:48.272066116 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:48.272083998 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.693829060 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.694128036 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.694158077 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.697299957 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.697382927 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.697829962 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.698129892 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.698163986 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.698416948 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.698527098 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.698590994 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.698615074 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.699815035 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.699887991 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.700968027 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.701072931 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.751409054 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.751421928 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:49.751454115 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:49.799398899 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.138796091 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.183440924 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.192460060 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.192473888 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.192519903 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.192559004 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.192579985 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.192600965 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.192616940 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.192643881 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.192643881 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.192643881 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.192676067 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.192688942 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.247407913 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.366691113 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.366704941 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.366749048 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.366770029 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.366780996 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.366797924 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.366815090 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.366835117 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.366868019 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.374402046 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.412739992 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.412753105 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.412770987 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.412781000 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.412894011 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.412894011 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.412930965 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.417928934 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.417987108 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.417999983 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.470416069 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.529736996 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.529750109 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.529890060 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.529942036 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.556561947 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.556611061 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.556629896 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.556643963 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.556660891 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.556674004 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.556694031 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.556713104 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.581720114 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.581734896 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.581777096 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.581785917 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.581809998 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.581871033 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.581903934 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.581950903 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.606924057 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.606950998 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.606988907 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.607057095 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.607125998 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.607161045 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.661412954 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.722029924 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.722047091 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.722079039 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.722106934 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.722156048 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.722167969 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.722207069 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.724755049 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.743031025 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.743052006 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.743087053 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.743141890 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.743175983 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.743200064 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.760351896 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.760381937 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.760416031 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.760435104 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.760453939 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.777378082 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.777441025 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.777476072 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.777492046 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.777508974 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.777522087 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.777549028 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.793396950 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.793421030 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.793508053 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.793524981 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.795604944 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.795772076 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.813045025 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.813069105 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.813144922 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.813179970 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.813205004 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.830137968 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.830167055 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.830240965 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.830276966 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.830293894 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.832537889 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.832626104 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.832639933 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.832654953 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:50.832703114 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.832850933 CET | 49710 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:03:50.832870007 CET | 443 | 49710 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:03:51.180083990 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:03:51.488472939 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:03:51.867248058 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:51.867291927 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:51.867381096 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:51.867667913 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:51.867681980 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:52.091418982 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:03:52.331362963 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:03:53.299462080 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:03:53.569386959 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:53.569725037 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:53.569762945 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:53.571212053 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:53.571294069 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:53.575961113 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:53.576046944 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:53.618432045 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:53.618458033 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:03:53.668565035 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:03:55.627587080 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:03:55.707427025 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:03:55.931426048 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:03:56.538431883 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:03:57.750423908 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:04:00.162596941 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:04:00.518558025 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:04:01.934509039 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 20, 2024 13:04:03.264986992 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:03.265075922 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:03.265135050 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:04.977406979 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:04:05.198084116 CET | 49715 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:05.198117018 CET | 443 | 49715 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:08.751768112 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:08.751815081 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:08.751893997 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:08.752216101 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:08.752229929 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:08.752799988 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:08.752851963 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:08.752945900 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:08.753087997 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:08.753098965 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.128535032 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 20, 2024 13:04:10.132622957 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.132952929 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.132968903 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.134541035 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.134602070 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.134615898 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.135205030 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.135267973 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.135900021 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.135982990 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.136097908 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.136106968 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.136778116 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.136857033 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.137191057 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.137275934 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.176511049 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.192512989 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.192548037 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.240490913 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.636012077 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.636214018 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.636425018 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.636595011 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.636626005 CET | 443 | 49717 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:10.636639118 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.636682034 CET | 49717 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.639538050 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:10.687352896 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.042753935 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.042814970 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.042918921 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.042952061 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.042987108 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.043005943 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.043041945 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.044158936 CET | 49718 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.044186115 CET | 443 | 49718 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.184185028 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.184230089 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.184324980 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.184524059 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.184571028 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.184648991 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.184777021 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.184806108 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:11.184948921 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:11.184966087 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.554946899 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.555339098 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:12.555362940 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.556525946 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.556925058 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:12.557099104 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.557112932 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:12.565140963 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.565490961 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:12.565521002 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.566660881 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.567020893 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:12.567197084 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.603326082 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:12.604516983 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:12.620521069 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:13.015043974 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:04:13.015265942 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:04:13.015332937 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:04:13.085844040 CET | 49711 | 443 | 192.168.2.16 | 52.216.142.68 |
Dec 20, 2024 13:04:13.085875034 CET | 443 | 49711 | 52.216.142.68 | 192.168.2.16 |
Dec 20, 2024 13:04:13.327884912 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:13.328078032 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:13.328253984 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:13.328798056 CET | 49719 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:13.328815937 CET | 443 | 49719 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:14.585979939 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 20, 2024 13:04:19.373472929 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:19.373550892 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:19.373663902 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:19.406769991 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:19.406800032 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:19.416342020 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:19.459368944 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.121925116 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.122164011 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.122243881 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:20.122639894 CET | 49720 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:20.122687101 CET | 443 | 49720 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.778888941 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.779330015 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:20.779408932 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.780554056 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.780864000 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:20.781048059 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:20.826530933 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:30.891516924 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:30.891621113 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:30.891715050 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:30.892246008 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:30.892288923 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:30.895306110 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:30.943322897 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:31.169977903 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:31.170151949 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:31.170258045 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:31.170294046 CET | 49721 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:31.170308113 CET | 443 | 49721 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:32.274857044 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:32.275223017 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:32.275259972 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:32.276535988 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:32.277009010 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:32.277163982 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:32.277172089 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:32.277211905 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:32.324590921 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:33.046329021 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:33.046478033 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:33.046766996 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:33.047146082 CET | 49722 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:04:33.047188044 CET | 443 | 49722 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:04:38.172869921 CET | 49699 | 80 | 192.168.2.16 | 23.32.238.74 |
Dec 20, 2024 13:04:38.172979116 CET | 49700 | 80 | 192.168.2.16 | 23.32.238.74 |
Dec 20, 2024 13:04:38.292985916 CET | 80 | 49699 | 23.32.238.74 | 192.168.2.16 |
Dec 20, 2024 13:04:38.293076038 CET | 49699 | 80 | 192.168.2.16 | 23.32.238.74 |
Dec 20, 2024 13:04:38.293307066 CET | 80 | 49700 | 23.32.238.74 | 192.168.2.16 |
Dec 20, 2024 13:04:38.293363094 CET | 49700 | 80 | 192.168.2.16 | 23.32.238.74 |
Dec 20, 2024 13:04:51.786938906 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:51.786983013 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:51.787127018 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:51.787416935 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:51.787434101 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:53.479980946 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:53.480320930 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:53.480343103 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:53.480817080 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:53.481214046 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:04:53.481342077 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:04:53.526664972 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:05:03.189173937 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:05:03.189341068 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:05:03.189434052 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:05:03.197416067 CET | 49725 | 443 | 192.168.2.16 | 142.250.181.132 |
Dec 20, 2024 13:05:03.197443008 CET | 443 | 49725 | 142.250.181.132 | 192.168.2.16 |
Dec 20, 2024 13:05:06.486037970 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:06.486064911 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:06.486151934 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:06.486583948 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:06.486682892 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:06.486773014 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:06.486967087 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:06.486979961 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:06.487219095 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:06.487257004 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.853108883 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.853425980 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:07.853462934 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.853957891 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.854279995 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:07.854363918 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.854425907 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:07.865739107 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.866031885 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:07.866063118 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.867243052 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.867635965 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:07.867815018 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.895335913 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:07.914726973 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:08.630775928 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:08.630892992 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:08.631001949 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:08.631601095 CET | 49727 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:08.631643057 CET | 443 | 49727 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:18.259815931 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:18.259917974 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:18.259987116 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:19.199819088 CET | 49726 | 443 | 192.168.2.16 | 37.59.203.111 |
Dec 20, 2024 13:05:19.199855089 CET | 443 | 49726 | 37.59.203.111 | 192.168.2.16 |
Dec 20, 2024 13:05:22.916986942 CET | 49696 | 443 | 192.168.2.16 | 20.190.177.23 |
Dec 20, 2024 13:05:22.916990995 CET | 49698 | 80 | 192.168.2.16 | 192.229.221.95 |
Dec 20, 2024 13:05:23.038249016 CET | 80 | 49698 | 192.229.221.95 | 192.168.2.16 |
Dec 20, 2024 13:05:23.038321972 CET | 49698 | 80 | 192.168.2.16 | 192.229.221.95 |
Dec 20, 2024 13:05:23.038933992 CET | 443 | 49696 | 20.190.177.23 | 192.168.2.16 |
Dec 20, 2024 13:05:23.039017916 CET | 49696 | 443 | 192.168.2.16 | 20.190.177.23 |
Dec 20, 2024 13:05:27.709933996 CET | 49701 | 443 | 192.168.2.16 | 20.190.177.23 |
Dec 20, 2024 13:05:27.830117941 CET | 443 | 49701 | 20.190.177.23 | 192.168.2.16 |
Dec 20, 2024 13:05:27.830197096 CET | 49701 | 443 | 192.168.2.16 | 20.190.177.23 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 20, 2024 13:03:47.043450117 CET | 53 | 56833 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:03:47.135174036 CET | 53 | 57149 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:03:47.811341047 CET | 50906 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 20, 2024 13:03:47.811861038 CET | 54441 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 20, 2024 13:03:48.238745928 CET | 53 | 50906 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:03:48.269880056 CET | 53 | 54441 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:03:49.937375069 CET | 53 | 65090 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:03:51.728456974 CET | 60373 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 20, 2024 13:03:51.728646040 CET | 53811 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 20, 2024 13:03:51.865932941 CET | 53 | 60373 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:03:51.865952969 CET | 53 | 53811 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:04:06.802314997 CET | 53 | 61347 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:04:08.106801033 CET | 55566 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 20, 2024 13:04:08.107064962 CET | 54927 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 20, 2024 13:04:08.750752926 CET | 53 | 55566 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:04:08.751040936 CET | 53 | 54927 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:04:25.566103935 CET | 53 | 56466 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:04:47.038065910 CET | 53 | 51314 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:04:47.320012093 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Dec 20, 2024 13:04:48.492067099 CET | 53 | 61681 | 1.1.1.1 | 192.168.2.16 |
Dec 20, 2024 13:05:19.497540951 CET | 53 | 52958 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 20, 2024 13:03:47.811341047 CET | 192.168.2.16 | 1.1.1.1 | 0xfc9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 20, 2024 13:03:47.811861038 CET | 192.168.2.16 | 1.1.1.1 | 0xa46a | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 20, 2024 13:03:51.728456974 CET | 192.168.2.16 | 1.1.1.1 | 0x231f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 20, 2024 13:03:51.728646040 CET | 192.168.2.16 | 1.1.1.1 | 0xad41 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 20, 2024 13:04:08.106801033 CET | 192.168.2.16 | 1.1.1.1 | 0xb77b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 20, 2024 13:04:08.107064962 CET | 192.168.2.16 | 1.1.1.1 | 0xdb17 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | s3-1-w.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | s3-w.us-east-1.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 52.216.142.68 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 3.5.10.150 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 52.216.249.188 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 3.5.25.250 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 3.5.22.135 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 16.15.192.238 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 3.5.28.148 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.238745928 CET | 1.1.1.1 | 192.168.2.16 | 0xfc9 | No error (0) | 52.217.72.228 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.269880056 CET | 1.1.1.1 | 192.168.2.16 | 0xa46a | No error (0) | s3-1-w.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:48.269880056 CET | 1.1.1.1 | 192.168.2.16 | 0xa46a | No error (0) | s3-w.us-east-1.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:51.865932941 CET | 1.1.1.1 | 192.168.2.16 | 0x231f | No error (0) | 142.250.181.132 | A (IP address) | IN (0x0001) | false | ||
Dec 20, 2024 13:03:51.865952969 CET | 1.1.1.1 | 192.168.2.16 | 0xad41 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 20, 2024 13:04:08.750752926 CET | 1.1.1.1 | 192.168.2.16 | 0xb77b | No error (0) | 37.59.203.111 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49710 | 52.216.142.68 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:03:49 UTC | 774 | OUT | |
2024-12-20 12:03:50 UTC | 416 | IN | |
2024-12-20 12:03:50 UTC | 16384 | IN | |
2024-12-20 12:03:50 UTC | 608 | IN | |
2024-12-20 12:03:50 UTC | 16384 | IN | |
2024-12-20 12:03:50 UTC | 1024 | IN | |
2024-12-20 12:03:50 UTC | 16384 | IN | |
2024-12-20 12:03:50 UTC | 1024 | IN | |
2024-12-20 12:03:50 UTC | 1749 | IN | |
2024-12-20 12:03:50 UTC | 9000 | IN | |
2024-12-20 12:03:50 UTC | 16384 | IN | |
2024-12-20 12:03:50 UTC | 1024 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49717 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:04:10 UTC | 783 | OUT | |
2024-12-20 12:04:10 UTC | 291 | IN | |
2024-12-20 12:04:10 UTC | 313 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49718 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:04:10 UTC | 784 | OUT | |
2024-12-20 12:04:11 UTC | 207 | IN | |
2024-12-20 12:04:11 UTC | 3561 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49719 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:04:12 UTC | 1274 | OUT | |
2024-12-20 12:04:13 UTC | 191 | IN | |
2024-12-20 12:04:13 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49720 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:04:19 UTC | 1293 | OUT | |
2024-12-20 12:04:20 UTC | 191 | IN | |
2024-12-20 12:04:20 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49721 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:04:30 UTC | 1293 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49722 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:04:32 UTC | 1293 | OUT | |
2024-12-20 12:04:33 UTC | 191 | IN | |
2024-12-20 12:04:33 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49727 | 37.59.203.111 | 443 | 6600 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-20 12:05:07 UTC | 1293 | OUT | |
2024-12-20 12:05:08 UTC | 191 | IN | |
2024-12-20 12:05:08 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 07:03:45 |
Start date: | 20/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 07:03:45 |
Start date: | 20/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 07:03:46 |
Start date: | 20/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |