Windows
Analysis Report
https://specificallycries.com/askyhgxe?stixna=48&refer=https%3A%2F%2Fwww.bodyvitalspa.com%2F&kw=%5B%22welcome%22%2C%22to%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%2C%22-%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%5D&key=0b0f64ea0800e4174573a0e17513102f&scrWidth=1920&scrHeigh
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3228 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2056 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2556 --fi eld-trial- handle=251 2,i,163898 2781298880 1500,87659 3611437273 9484,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6520 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://speci ficallycri es.com/ask yhgxe?stix na=48&refe r=https%3A %2F%2Fwww. bodyvitals pa.com%2F& kw=%5B%22w elcome%22% 2C%22to%22 %2C%22body %22%2C%22v ital%22%2C %22foot%22 %2C%22spa% 22%2C%22-% 22%2C%22bo dy%22%2C%2 2vital%22% 2C%22foot% 22%2C%22sp a%22%5D&ke y=0b0f64ea 0800e41745 73a0e17513 102f&scrWi dth=1920&s crHeight=1 080&tz=-5& v=24.12.66 52&ship=&p sid=www.bo dyvitalspa .com,www.b odyvitalsp a.com&sub3 =invoke_la yer&res=14 .31&dev=r& adb=n&uuid =64597ca1- acf8-4c16- 8774-db4c7 f843adf%3A 3%3A1&adb= n" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AnonymousProxy | Yara detected Anonymous Proxy detection | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AnonymousProxy | Yara detected Anonymous Proxy detection | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.181.68 | true | false | high | |
specificallycries.com | 192.243.61.227 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
192.243.61.227 | specificallycries.com | Dominica | 39572 | ADVANCEDHOSTERS-ASNL | false | |
142.250.181.68 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1580102 |
Start date and time: | 2024-12-23 23:36:34 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://specificallycries.com/askyhgxe?stixna=48&refer=https%3A%2F%2Fwww.bodyvitalspa.com%2F&kw=%5B%22welcome%22%2C%22to%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%2C%22-%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%5D&key=0b0f64ea0800e4174573a0e17513102f&scrWidth=1920&scrHeight=1080&tz=-5&v=24.12.6652&ship=&psid=www.bodyvitalspa.com,www.bodyvitalspa.com&sub3=invoke_layer&res=14.31&dev=r&adb=n&uuid=64597ca1-acf8-4c16-8774-db4c7f843adf%3A3%3A1&adb=n |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal64.phis.win@16/2@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.19.227, 172.217.19.238, 64.233.161.84, 172.217.17.46, 199.232.210.172, 192.229.221.95, 172.217.17.35, 23.218.208.109, 172.202.163.200, 13.107.246.63
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://specificallycries.com/askyhgxe?stixna=48&refer=https%3A%2F%2Fwww.bodyvitalspa.com%2F&kw=%5B%22welcome%22%2C%22to%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%2C%22-%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%5D&key=0b0f64ea0800e4174573a0e17513102f&scrWidth=1920&scrHeight=1080&tz=-5&v=24.12.6652&ship=&psid=www.bodyvitalspa.com,www.bodyvitalspa.com&sub3=invoke_layer&res=14.31&dev=r&adb=n&uuid=64597ca1-acf8-4c16-8774-db4c7f843adf%3A3%3A1&adb=n
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 118 |
Entropy (8bit): | 4.7818237798351575 |
Encrypted: | false |
SSDEEP: | 3:PouVWJhquHbs0sJYkAK3BbZ6iFRDTiHj:h4hqIY0gYk/B96oTiD |
MD5: | B0F623103CD51D764412D46F8A7E0816 |
SHA1: | 3C88223ADEF88D7CB3EF5536B4B398EF54F31781 |
SHA-256: | FE40B26BCB3F34BA8F180D33623BB3B109597BA9B3F5596BA1BC6B665B8DCB67 |
SHA-512: | 1C052EE3706787FC215FF4808784BDE23EBA8DD4028FE6CF3BA7C0D30D2869A2A0BD5231523BB4F3435B3653A481858E861CF855E908D468E4A1C10FCA95D2EB |
Malicious: | false |
Reputation: | low |
URL: | "https://specificallycries.com/askyhgxe?stixna=48&refer=https%3A%2F%2Fwww.bodyvitalspa.com%2F&kw=%5B%22welcome%22%2C%22to%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%2C%22-%22%2C%22body%22%2C%22vital%22%2C%22foot%22%2C%22spa%22%5D&key=0b0f64ea0800e4174573a0e17513102f&scrWidth=1920&scrHeight=1080&tz=-5&v=24.12.6652&ship=&psid=www.bodyvitalspa.com,www.bodyvitalspa.com&sub3=invoke_layer&res=14.31&dev=r&adb=n&uuid=64597ca1-acf8-4c16-8774-db4c7f843adf%3A3%3A1&adb=n" |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 23, 2024 23:37:20.661009073 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Dec 23, 2024 23:37:30.270216942 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Dec 23, 2024 23:37:35.532958031 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:35.532994986 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:35.533075094 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:35.533266068 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:35.533282995 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:36.933557034 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:36.933619022 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:36.933814049 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:36.933917046 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:36.933938026 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:36.933989048 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:36.934125900 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:36.934145927 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:36.934354067 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:36.934369087 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:37.237966061 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:37.238684893 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:37.238701105 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:37.240351915 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:37.240422010 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:37.242485046 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:37.242572069 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:37.286988020 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:37.286998987 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:37.334252119 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:38.477054119 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.487976074 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.521303892 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.531860113 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.545736074 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.545742989 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.549300909 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.549314976 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.549698114 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.550405979 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.550443888 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.553297043 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.639892101 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.639987946 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.640211105 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.640213013 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.640717983 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.683351994 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.691330910 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.691335917 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.691344023 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.691344976 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:38.737453938 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:38.737519979 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.080497980 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.080569029 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.080621004 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.082434893 CET | 49740 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.082453012 CET | 443 | 49740 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.150640011 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.191335917 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.471688986 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.471873999 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.471941948 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.472460985 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.472476006 CET | 443 | 49741 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.472501040 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.472518921 CET | 49741 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.623842955 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.623872995 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:39.623933077 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.624135017 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:39.624145031 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.203525066 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.203809977 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.203850985 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.207422018 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.207513094 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.207863092 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.208017111 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.208039045 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.249934912 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.249959946 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.300750971 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.529305935 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.529468060 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.529535055 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.530325890 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.530325890 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:41.530345917 CET | 443 | 49743 | 192.243.61.227 | 192.168.2.4 |
Dec 23, 2024 23:37:41.530400991 CET | 49743 | 443 | 192.168.2.4 | 192.243.61.227 |
Dec 23, 2024 23:37:46.933845043 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:46.933988094 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:37:46.934056044 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:48.053601027 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:37:48.053608894 CET | 443 | 49738 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:35.458151102 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:35.458164930 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:35.458228111 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:35.458636999 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:35.458650112 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:37.159218073 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:37.159591913 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:37.159607887 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:37.160083055 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:37.160501003 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:37.160640955 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:37.206861019 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:46.858660936 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:46.858802080 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Dec 23, 2024 23:38:46.858968019 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:48.052660942 CET | 49773 | 443 | 192.168.2.4 | 142.250.181.68 |
Dec 23, 2024 23:38:48.052679062 CET | 443 | 49773 | 142.250.181.68 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 23, 2024 23:37:31.836174011 CET | 53 | 50200 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:31.844357014 CET | 53 | 64522 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:34.723942995 CET | 53 | 63981 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:35.395051956 CET | 49219 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 23, 2024 23:37:35.395185947 CET | 60633 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 23, 2024 23:37:35.531888008 CET | 53 | 49219 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:35.532032013 CET | 53 | 60633 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:36.794017076 CET | 54395 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 23, 2024 23:37:36.794420004 CET | 53319 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 23, 2024 23:37:36.931967020 CET | 53 | 53319 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:36.932729959 CET | 53 | 54395 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:39.475945950 CET | 49375 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 23, 2024 23:37:39.476079941 CET | 65318 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 23, 2024 23:37:39.612859011 CET | 53 | 49375 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:39.623466969 CET | 53 | 65318 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:37:48.495337009 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Dec 23, 2024 23:37:51.762341022 CET | 53 | 51704 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:38:10.706207991 CET | 53 | 59415 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:38:30.925074100 CET | 53 | 56925 | 1.1.1.1 | 192.168.2.4 |
Dec 23, 2024 23:38:33.637200117 CET | 53 | 56263 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 23, 2024 23:37:35.395051956 CET | 192.168.2.4 | 1.1.1.1 | 0xfe40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 23, 2024 23:37:35.395185947 CET | 192.168.2.4 | 1.1.1.1 | 0xf4c9 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 23, 2024 23:37:36.794017076 CET | 192.168.2.4 | 1.1.1.1 | 0x490 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 23, 2024 23:37:36.794420004 CET | 192.168.2.4 | 1.1.1.1 | 0x18bf | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 23, 2024 23:37:39.475945950 CET | 192.168.2.4 | 1.1.1.1 | 0x497f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 23, 2024 23:37:39.476079941 CET | 192.168.2.4 | 1.1.1.1 | 0x81aa | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 23, 2024 23:37:35.531888008 CET | 1.1.1.1 | 192.168.2.4 | 0xfe40 | No error (0) | 142.250.181.68 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:35.532032013 CET | 1.1.1.1 | 192.168.2.4 | 0xf4c9 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 192.243.61.227 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 192.243.61.225 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 172.240.108.76 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 172.240.108.68 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 192.243.59.13 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 172.240.127.234 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 172.240.253.132 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 192.243.59.20 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 192.243.59.12 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:36.932729959 CET | 1.1.1.1 | 192.168.2.4 | 0x490 | No error (0) | 172.240.108.84 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 192.243.61.227 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 192.243.59.20 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 172.240.108.84 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 172.240.108.68 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 172.240.127.234 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 172.240.108.76 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 172.240.253.132 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 192.243.59.12 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 192.243.59.13 | A (IP address) | IN (0x0001) | false | ||
Dec 23, 2024 23:37:39.612859011 CET | 1.1.1.1 | 192.168.2.4 | 0x497f | No error (0) | 192.243.61.225 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49740 | 192.243.61.227 | 443 | 2056 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-23 22:37:38 UTC | 1108 | OUT | |
2024-12-23 22:37:39 UTC | 827 | IN | |
2024-12-23 22:37:39 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49741 | 192.243.61.227 | 443 | 2056 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-23 22:37:39 UTC | 1290 | OUT | |
2024-12-23 22:37:39 UTC | 377 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49743 | 192.243.61.227 | 443 | 2056 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-23 22:37:41 UTC | 380 | OUT | |
2024-12-23 22:37:41 UTC | 377 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 17:37:24 |
Start date: | 23/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 17:37:29 |
Start date: | 23/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 17:37:36 |
Start date: | 23/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |