Windows
Analysis Report
https://franoapas.co.in/
Overview
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 4248 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6856 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2168 --fi eld-trial- handle=196 4,i,112722 9261063291 812,288855 9015861262 328,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://frano apas.co.in /" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- Acrobat.exe (PID: 1428 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\P ALRGUCVEH. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7492 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 4808 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 68 --field -trial-han dle=1596,i ,579701358 2456589336 ,574309003 5759381609 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: |
Source: | Directory created: | Jump to behavior |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File opened: | Jump to behavior |
Source: | Window detected: |
Source: | Directory created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 3 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
www.google.com | 142.250.181.68 | true | false | high | |
franoapas.co.in | 172.67.221.200 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown | ||
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.67.221.200 | franoapas.co.in | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.181.68 | www.google.com | United States | 15169 | GOOGLEUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581454 |
Start date and time: | 2024-12-27 19:01:26 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 36s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://franoapas.co.in/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@33/27@6/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.21.35, 172.217.19.238, 64.233.161.84, 172.217.17.46, 172.217.17.74, 172.217.17.35, 23.218.208.137, 23.218.208.109, 20.12.23.50
- Excluded domains from analysis (whitelisted): clients1.google.com, e4578.dscg.akamaiedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ssl-delivery.adobe.com.edgekey.net, translate.googleapis.com, update.googleapis.com, clients.l.google.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://franoapas.co.in/
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.117412936503842 |
Encrypted: | false |
SSDEEP: | 6:Ay+q2PRN2nKuAl9OmbnIFUt8V5WZmw+VEVkwORN2nKuAl9OmbjLJ:t+vaHAahFUt83W/+CV5JHAaSJ |
MD5: | 28526A294F014DD11E335E2E2FC1F403 |
SHA1: | 852DC70E60DF0297DA3EAB903336804F12518A46 |
SHA-256: | F367A14BB6329D53A59C165917A1C02B39ABCA4DBCBEC71724F39E63893EA37C |
SHA-512: | D1AA8A0C864A98629042DFB295AD567EFAE9207B415C2562D2CE53592D160F79CB2E6321DB8029923A53AC09F4D0A64DFC6611EE67E7FBB8F082986A81AF1F7A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.117412936503842 |
Encrypted: | false |
SSDEEP: | 6:Ay+q2PRN2nKuAl9OmbnIFUt8V5WZmw+VEVkwORN2nKuAl9OmbjLJ:t+vaHAahFUt83W/+CV5JHAaSJ |
MD5: | 28526A294F014DD11E335E2E2FC1F403 |
SHA1: | 852DC70E60DF0297DA3EAB903336804F12518A46 |
SHA-256: | F367A14BB6329D53A59C165917A1C02B39ABCA4DBCBEC71724F39E63893EA37C |
SHA-512: | D1AA8A0C864A98629042DFB295AD567EFAE9207B415C2562D2CE53592D160F79CB2E6321DB8029923A53AC09F4D0A64DFC6611EE67E7FBB8F082986A81AF1F7A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.144635866758591 |
Encrypted: | false |
SSDEEP: | 6:AuGFN+q2PRN2nKuAl9Ombzo2jMGIFUt8V+Zmw+VdVkwORN2nKuAl9Ombzo2jMmLJ:W+vaHAa8uFUt8w/+PV5JHAa8RJ |
MD5: | 45303E5C5F996E2F6D4309B7F7FDC7D5 |
SHA1: | F5220D037B48E90A54F18023E8BDE8819E9504F5 |
SHA-256: | 0A7AB774C064BA074DD0CA735FDC43E3C7C93EA42ED4A984FE151602D75D6297 |
SHA-512: | A82881E6AED54E39AD593377E330B391A28CF664A20C5CB8A5066BB75252B303719539E4D18687B9F8B1B1D77E864B7352F1A259B714032E9C767EFF4113E30A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.144635866758591 |
Encrypted: | false |
SSDEEP: | 6:AuGFN+q2PRN2nKuAl9Ombzo2jMGIFUt8V+Zmw+VdVkwORN2nKuAl9Ombzo2jMmLJ:W+vaHAa8uFUt8w/+PV5JHAa8RJ |
MD5: | 45303E5C5F996E2F6D4309B7F7FDC7D5 |
SHA1: | F5220D037B48E90A54F18023E8BDE8819E9504F5 |
SHA-256: | 0A7AB774C064BA074DD0CA735FDC43E3C7C93EA42ED4A984FE151602D75D6297 |
SHA-512: | A82881E6AED54E39AD593377E330B391A28CF664A20C5CB8A5066BB75252B303719539E4D18687B9F8B1B1D77E864B7352F1A259B714032E9C767EFF4113E30A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.229344318934945 |
Encrypted: | false |
SSDEEP: | 96:OLSw0bSwIAnrRqLX2rSq1OUxu/0OZ0xRBTxekN8xeNlnJ7kk:OLT0bTIeYa51Ogu/0OZARBT8kN88NlJN |
MD5: | B2A0C2506138C6F17EF9F67735D757BC |
SHA1: | 39CF614B30507C7E2AD66262083163B1E7488301 |
SHA-256: | 922741D218208923474A30533D59715CFB7A95F9ED4029621245782BCECC8122 |
SHA-512: | 5CA196DFD2E2113C577DEAB990E8DB9983511B8191024F13356456C15C06D9724288061D26173D08E0C84B1A8F8EF7EB6DD27FA6AD48FECFB4C0CA7109BF1527 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.209831753124167 |
Encrypted: | false |
SSDEEP: | 6:AZI+q2PRN2nKuAl9OmbzNMxIFUt8VzdXmZmw+V9IVkwORN2nKuAl9OmbzNMFLJ:1+vaHAa8jFUt8dVm/+MV5JHAa84J |
MD5: | 0E8263A792E96E8C4C100558A5720762 |
SHA1: | D7400A2DDFF36D81BE9FA39D7FBDEF1F5F7E1A10 |
SHA-256: | E71D16AF3AEE98827898BDF7BC6832B18675DC6ACB95FEA34A5AB6A261374E8E |
SHA-512: | D6544C1AA749ED24D2090624275CEFE5579C3411A81AEDC5091EC23799DF4F8DABCFBB11BEFB11D241EF8247B00396683FBDC156A3199EA136C6BA0669565820 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.209831753124167 |
Encrypted: | false |
SSDEEP: | 6:AZI+q2PRN2nKuAl9OmbzNMxIFUt8VzdXmZmw+V9IVkwORN2nKuAl9OmbzNMFLJ:1+vaHAa8jFUt8dVm/+MV5JHAa84J |
MD5: | 0E8263A792E96E8C4C100558A5720762 |
SHA1: | D7400A2DDFF36D81BE9FA39D7FBDEF1F5F7E1A10 |
SHA-256: | E71D16AF3AEE98827898BDF7BC6832B18675DC6ACB95FEA34A5AB6A261374E8E |
SHA-512: | D6544C1AA749ED24D2090624275CEFE5579C3411A81AEDC5091EC23799DF4F8DABCFBB11BEFB11D241EF8247B00396683FBDC156A3199EA136C6BA0669565820 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1969 |
Entropy (8bit): | 5.060180685091034 |
Encrypted: | false |
SSDEEP: | 48:YsAiESbjWbj2CjxjZ4oijxi+0jPjrVbjBgajF:FXWP2ERaTx3y7BPBgMF |
MD5: | C34D094FE5C46F9ED879329C6C9B623C |
SHA1: | 1D29F6DA1C85FFC0A9D0D8AA31DD4D3D890EFFA0 |
SHA-256: | 552545CE28D3CDC2D7C7435876014C5EBD1F8A19190AB9F246E7CCF29F516112 |
SHA-512: | D799982DB87E367AB4B73151372D9D943E8EFDB38CCB2719B864F03D356433D1EE13C3E1B6013283BC981DBFAA9A65C4E58363774020496324A0D166D8055CF1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9876443845426572 |
Encrypted: | false |
SSDEEP: | 24:TLHRx/XYKQvGJF7urs67Y9QmQ6QeK6OtIcLESiAieS6OtF:TVl2GL7ms67YXtrKCcI8mb |
MD5: | 71B96B18985B32B5BEFB465BBB070F84 |
SHA1: | A9D2D82B56B363B75C2006FAA75859225FEDB5EA |
SHA-256: | FE166F33A9A1B4BDB910CA0835C5A1EFE4C178CD400504B4306596A6A85B39FC |
SHA-512: | 923918B14CFC1BD20F2A0EED7F158D37C806BC20504A030EFAE06CB61401DB192A0DA752E18BCE78B5C5C57394F9A3487ADFA9935667A576552E735A949A4F5A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3437188784839 |
Encrypted: | false |
SSDEEP: | 24:7+t6kASY9QmQ6QeK6Ot7cLESiAi0mY9Q2aqLBx/XYKQvGJF7ursE:7MBlYXtrKNcI8KYBaqll2GL7msE |
MD5: | CBA4EB2247637607C8D4D34630BF886C |
SHA1: | 684FAEE6C39E3296FA551476AC5B6C37AD0AC2C1 |
SHA-256: | 3CF180C24CBF9FE5229AADEF0E74D6E6D96C3A30E1341EC73170724205377212 |
SHA-512: | 8E8536AA26A8313341B4576E4F7E820C5C746282FD755828CE9184CF73E1560F86C241EEA0D64768339F687B245DAA7CA554B2A7C14DD764E9A60C231C9EF580 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-12-27 13-04-01-948.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.353642815103214 |
Encrypted: | false |
SSDEEP: | 384:tbxtsuP+XEWJJQbnR8L31M7HeltV+KYm3wsa2KjF4ODkr/O8r2IUHUHMWwEyZRN2:aPL |
MD5: | 91F06491552FC977E9E8AF47786EE7C1 |
SHA1: | 8FEB27904897FFCC2BE1A985D479D7F75F11CEFC |
SHA-256: | 06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB |
SHA-512: | A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.369014722158588 |
Encrypted: | false |
SSDEEP: | 384:prNyVPAFNo1nKWhwiwm/pPSrHEdJqvzJe1qwuawx4fJG7VhIe/031o1cZ2I9qNFa:jNI |
MD5: | 2B50119CFD0D01083BC264388EF776F1 |
SHA1: | 3C60F4B4E112B62D593B4660C830D3598EA050D3 |
SHA-256: | BB13852A5BD02A9A81C765D1C003E76409C932AB2B32CA49030EC972A1341533 |
SHA-512: | B042E9DC07B7E68B41BE431327F9D1C9C40D74BCF6A22EE1CBD722B176EBE9E15DD24E22ADA1AB36C4C3C1D9A03D19813AB0E7D7A935CB69AA1AB366EBC6F507 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.413656898160516 |
Encrypted: | false |
SSDEEP: | 192:0cbgIhPcbocbAIlncb2cbwI/RcbNcbQIVvcb9fcbC3IZ/cbKu:fhWlA/TViYZpu |
MD5: | 3D6B490F5C50A3205B0A472E1823E0BC |
SHA1: | D46267C9674F65EEA8603F65C7E8792DDDB9878C |
SHA-256: | C555E52117A0078CB4AD2073EA7936DF2BFA6BA08F0AACBF2040679725F29D25 |
SHA-512: | 3B654EE04902F89AE9E506DF1B228F086EB70D2940A70681E305B15462566091D24FF43A4A12DD0FCE65201C135DD3873B4EC153AD9D28F44B785837AF95AFB5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9847505840823016 |
Encrypted: | false |
SSDEEP: | 48:8BdJOTpK2RGHpidAKZdA1FehwiZUklqehgy+3:8I/Q/y |
MD5: | 6EC3375F0879F5E0C2F30EC34ACE85D0 |
SHA1: | 1EF71888A9577E96B444D4AF0613E6B91463B4C2 |
SHA-256: | 2E03DF99F4B1ACCB33FCB08E293C892418FC9C90282E212B9919F0D981AF4C1E |
SHA-512: | A9C0DDF4EAB2DB90BD50CCB81A19A6F7253CC85AB8CD075C09E58DDE4778DEC92E6A89A575DEBA880E27FA4FF1CDBD468C5BDAB562ED05FB7D739F3C97123752 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.999613094084823 |
Encrypted: | false |
SSDEEP: | 48:8WdJOTpK2RGHpidAKZdA1seh/iZUkAQkqehvy+2:8d/G9QWy |
MD5: | EF537361821FCFADC28D52A130245F52 |
SHA1: | C332BEAA35A1728C0C567E790C949A47E19D56D7 |
SHA-256: | B154534510EB1D275ED18CD7F9231D1344B4795C0DB76FD66556EBA5F587E917 |
SHA-512: | 2FD23DC44F7A27F20CE389B350F300DE79C93836FA926FB71E81578B68AF0BE965A0092462D2292C5CCEED3595BBC1A52265E2DE849CF2A8C90D74C96F8E5B91 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.010291409926875 |
Encrypted: | false |
SSDEEP: | 48:8IdJOTpK2RAHpidAKZdA14meh7sFiZUkmgqeh7sly+BX:8D/onLy |
MD5: | 59E827F6091BDC46A1D59F8979C589F9 |
SHA1: | 98C0843EE6C6ACFFC197DCD125BBD5E44A739868 |
SHA-256: | 91EB3E71881B289BA2E9B5B38C1C261C3C8A25ADF1E5880AEF99D4991CCE0D62 |
SHA-512: | D563CD99E8A1D8B503862A9F7E5C984BE99A2E009B79AC1FE7188385F65014F98EF259B9619B4D4F2C7F4487A72FD17590E27BBCC964C143E71D9367918C4BEB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.998646315951829 |
Encrypted: | false |
SSDEEP: | 48:86dJOTpK2RGHpidAKZdA1TehDiZUkwqehTy+R:8p/dNy |
MD5: | FB0909195B8F458B97BF8E58305B991D |
SHA1: | 3411B199E4A6511248DAD2B3950C7869AA6B3C92 |
SHA-256: | 438EDE3BE69EB644542A0BD86A6F40154F6CD1D75933FEE26D2C201A83A3C51B |
SHA-512: | B2DC946756B4C01B9F91C6E73E23725DF90DD12F1DE0035855EB590C46D8B78F2758EBF0FF4677A89AFCD3EB7AA042D27E0BC80A6EB83CAB5EBD355E7ECA2F30 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.984954096458537 |
Encrypted: | false |
SSDEEP: | 48:83tdJOTpK2RGHpidAKZdA1dehBiZUk1W1qehBy+C:8c/d9hy |
MD5: | EEEF2CB7921C41AD8F06F60370359C3D |
SHA1: | C1D35DB53DACAFF0C1F3D5FF633BBD856AD8FF4B |
SHA-256: | D9F44D44DAF8BAE71D422EA38CDE7D7C9BA8776D512F4B7147ED84596E92F395 |
SHA-512: | 943007EF613521CE9E90BC74DC053C1EFF7FD154228340D98B1FEAD999DDBCABB605396A7C5271B7E8E496903A7BB6999DA0FC7AEB16D074C8B888B307DCDDC9 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.99534732510501 |
Encrypted: | false |
SSDEEP: | 48:82dJOTpK2RGHpidAKZdA1duTeehOuTbbiZUk5OjqehOuTbLy+yT+:89/lTfTbxWOvTbLy7T |
MD5: | ACB9C8BBD6ECA596D8E979D425344286 |
SHA1: | A8E8BB83CB4A68011D3B54A6D60EBD20B34ADE59 |
SHA-256: | 29948AC807430F6164D3477AD1E83FDEE1C99624297A5B5400CDD3CD7E97F66F |
SHA-512: | CAF32E3F18D30C8391B9849CBD8448BB0429C35D2A11AA2826E59D53F11E4AC4E6426A9CEAF083ADB82A5B48C93936E404F983FF10D607A32F4158766BAF5CE6 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 564 |
Entropy (8bit): | 4.775290370533887 |
Encrypted: | false |
SSDEEP: | 12:TjeRHVIdtklI5rRCNGlTF5TF5TF5TF5TF5TFK:neRH688lTPTPTPTPTPTc |
MD5: | 5DA4C1420F84EC727D1B6BDD0D46E62E |
SHA1: | 280D08D142F7386283F420444EC48E1CDBFD61BB |
SHA-256: | 3C8CC37A98346BD0123B35E5CCD87BD07D69914DAE04F8B49F61C150D96E9D1F |
SHA-512: | 7C51A628831D0236E8D314C71732B8A62E06334431D10F7C293C49B23665B2A6A1DDBC4772009010955B5228EA4A5CD97FB93581CE391EE1792E8A198B76111A |
Malicious: | false |
Reputation: | low |
URL: | https://franoapas.co.in/favicon.ico |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 27, 2024 19:01:53.828459978 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.828501940 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.828519106 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.828593969 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.828609943 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.828632116 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.828716993 CET | 49701 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:01:53.828799009 CET | 49701 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:01:53.836724997 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.836821079 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.836910963 CET | 49701 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:01:53.845125914 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.845277071 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:01:53.845392942 CET | 49701 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:01:59.888315916 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:01:59.888365030 CET | 443 | 49708 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:01:59.888495922 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:01:59.888804913 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:01:59.888869047 CET | 443 | 49709 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:01:59.889106035 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:01:59.889123917 CET | 443 | 49708 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:01:59.889141083 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:01:59.889373064 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:01:59.889391899 CET | 443 | 49709 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:00.324986935 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:00.625785112 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:01.149375916 CET | 443 | 49709 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.149724007 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.149749041 CET | 443 | 49709 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.150804996 CET | 443 | 49709 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.150880098 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.152369976 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.152421951 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.152440071 CET | 443 | 49709 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.152506113 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.152533054 CET | 49709 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.153042078 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.153146982 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.153203011 CET | 443 | 49708 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.153248072 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.153493881 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.153546095 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.153683901 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.153702021 CET | 443 | 49708 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.155397892 CET | 443 | 49708 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.155489922 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156344891 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156394958 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156394958 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156440020 CET | 443 | 49708 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.156512976 CET | 49708 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156620979 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156652927 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.156718016 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156948090 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:01.156965017 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:01.230840921 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:02.433850050 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.434216022 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.434252977 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.435697079 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.435785055 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.436939001 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.437027931 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.437278032 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.437295914 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.437949896 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:02.466078043 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.466415882 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.466454029 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.467917919 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.467989922 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.468367100 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.468450069 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.485826015 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.517792940 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.517807961 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.564816952 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.959120989 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.959340096 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:02.959414005 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.960062981 CET | 49710 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:02.960089922 CET | 443 | 49710 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:03.004872084 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:03.051335096 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:03.510337114 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:03.510449886 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:03.510508060 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:03.512553930 CET | 49711 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:02:03.512590885 CET | 443 | 49711 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:02:03.643264055 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:03.643341064 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:03.643410921 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:03.643706083 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:03.643723011 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:03.652024031 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:03.652120113 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:03.652204037 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:03.652462006 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:03.652494907 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:04.841917992 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:04.909852028 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:04.926628113 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:04.927023888 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:04.927050114 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:04.928720951 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:04.928796053 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:04.929749012 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:04.929832935 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:04.929977894 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:04.969914913 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:04.969924927 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:05.017889977 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:05.389544964 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:05.389750004 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:05.389842033 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:05.390129089 CET | 49715 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:05.390173912 CET | 443 | 49715 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:05.390640974 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:05.390708923 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:05.394530058 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:05.394750118 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:05.394771099 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:05.433255911 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:05.433494091 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:05.433526039 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:05.434448004 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:05.434525013 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:05.435491085 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:05.435558081 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:05.480813026 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:05.480833054 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:05.531793118 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:06.701518059 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:06.701796055 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:06.701826096 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:06.702945948 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:06.703349113 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:06.703485966 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:06.703491926 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:06.703525066 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:06.756793976 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:07.182702065 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:07.182910919 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:07.182969093 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:07.183047056 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:07.183068037 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.16 |
Dec 27, 2024 19:02:07.183079004 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:07.183115005 CET | 49717 | 443 | 192.168.2.16 | 35.190.80.1 |
Dec 27, 2024 19:02:08.497298002 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:08.810813904 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:09.418832064 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:09.641868114 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:10.631798983 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:12.963963985 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:13.043812990 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:13.266969919 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:13.868885994 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:15.083822966 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:15.124310970 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:15.124377966 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:15.124469042 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:16.936389923 CET | 49714 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:02:16.936429024 CET | 443 | 49714 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:02:17.491933107 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:17.843857050 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:19.248847008 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Dec 27, 2024 19:02:22.298852921 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:27.449862003 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Dec 27, 2024 19:02:31.913877010 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Dec 27, 2024 19:02:51.545341015 CET | 80 | 49700 | 217.20.58.101 | 192.168.2.16 |
Dec 27, 2024 19:02:51.545525074 CET | 49700 | 80 | 192.168.2.16 | 217.20.58.101 |
Dec 27, 2024 19:02:51.545744896 CET | 49700 | 80 | 192.168.2.16 | 217.20.58.101 |
Dec 27, 2024 19:02:51.665303946 CET | 80 | 49700 | 217.20.58.101 | 192.168.2.16 |
Dec 27, 2024 19:02:53.144661903 CET | 80 | 49702 | 217.20.58.101 | 192.168.2.16 |
Dec 27, 2024 19:02:53.144761086 CET | 49702 | 80 | 192.168.2.16 | 217.20.58.101 |
Dec 27, 2024 19:02:53.144815922 CET | 49702 | 80 | 192.168.2.16 | 217.20.58.101 |
Dec 27, 2024 19:02:53.264533043 CET | 80 | 49702 | 217.20.58.101 | 192.168.2.16 |
Dec 27, 2024 19:03:03.564924002 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:03.565011978 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:03.565116882 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:03.565314054 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:03.565361977 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:05.301465034 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:05.301811934 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:05.301879883 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:05.302216053 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:05.302635908 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:05.302711010 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:05.352998972 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:15.003554106 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:15.003623962 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:15.003725052 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:16.942550898 CET | 49724 | 443 | 192.168.2.16 | 142.250.181.68 |
Dec 27, 2024 19:03:16.942620039 CET | 443 | 49724 | 142.250.181.68 | 192.168.2.16 |
Dec 27, 2024 19:03:17.761953115 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:17.762015104 CET | 443 | 49725 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:17.762108088 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:17.762352943 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:17.762391090 CET | 443 | 49726 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:17.762461901 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:17.762725115 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:17.762742043 CET | 443 | 49725 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:17.762969017 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:17.762980938 CET | 443 | 49726 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:18.979737043 CET | 443 | 49725 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:18.979959965 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.979983091 CET | 443 | 49725 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:18.980845928 CET | 443 | 49725 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:18.980931044 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981184006 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981184006 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981239080 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981244087 CET | 443 | 49725 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:18.981302977 CET | 49725 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981468916 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981494904 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:18.981569052 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981714964 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:18.981724024 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:19.029757023 CET | 443 | 49726 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:19.029982090 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.030006886 CET | 443 | 49726 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:19.033575058 CET | 443 | 49726 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:19.033668995 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.033934116 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.033934116 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.033970118 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.034113884 CET | 443 | 49726 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:19.034178019 CET | 49726 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.034200907 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.034213066 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:19.034282923 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.034488916 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:19.034498930 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.193276882 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.193576097 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.193603039 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.194612980 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.194688082 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.194991112 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.195045948 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.195287943 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.195295095 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.249038935 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.401868105 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.402152061 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.402163029 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.403188944 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.403258085 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.403539896 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.403601885 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.456969023 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.456981897 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.504065037 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.813288927 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.813360929 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:20.813430071 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.813867092 CET | 49727 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:20.813880920 CET | 443 | 49727 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:35.184981108 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:35.185050011 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:35.185230970 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:35.950170994 CET | 49699 | 80 | 192.168.2.16 | 192.229.221.95 |
Dec 27, 2024 19:03:35.950180054 CET | 49697 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:03:36.070185900 CET | 443 | 49697 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:03:36.070269108 CET | 49697 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:03:36.070543051 CET | 80 | 49699 | 192.229.221.95 | 192.168.2.16 |
Dec 27, 2024 19:03:36.070595980 CET | 49699 | 80 | 192.168.2.16 | 192.229.221.95 |
Dec 27, 2024 19:03:36.941723108 CET | 49728 | 443 | 192.168.2.16 | 172.67.221.200 |
Dec 27, 2024 19:03:36.941747904 CET | 443 | 49728 | 172.67.221.200 | 192.168.2.16 |
Dec 27, 2024 19:03:41.301291943 CET | 49701 | 443 | 192.168.2.16 | 40.126.53.6 |
Dec 27, 2024 19:03:41.421498060 CET | 443 | 49701 | 40.126.53.6 | 192.168.2.16 |
Dec 27, 2024 19:03:41.421789885 CET | 49701 | 443 | 192.168.2.16 | 40.126.53.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 27, 2024 19:01:58.781671047 CET | 53 | 52719 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:01:58.791136980 CET | 53 | 60019 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:01:59.580338001 CET | 58580 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 27, 2024 19:01:59.580630064 CET | 59896 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 27, 2024 19:01:59.887450933 CET | 53 | 58580 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:01:59.887476921 CET | 53 | 59896 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:01.603935957 CET | 53 | 51981 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:03.504810095 CET | 53543 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 27, 2024 19:02:03.505008936 CET | 59620 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 27, 2024 19:02:03.512176037 CET | 51272 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 27, 2024 19:02:03.512397051 CET | 56940 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 27, 2024 19:02:03.641603947 CET | 53 | 53543 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:03.642256975 CET | 53 | 59620 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:03.649033070 CET | 53 | 51272 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:03.651535988 CET | 53 | 56940 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:18.540962934 CET | 53 | 60246 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:22.925681114 CET | 53 | 60413 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:22.954054117 CET | 53 | 53282 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:37.283338070 CET | 53 | 64532 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:58.773303032 CET | 53 | 53769 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:02:59.728724957 CET | 53 | 61581 | 1.1.1.1 | 192.168.2.16 |
Dec 27, 2024 19:03:04.656337023 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Dec 27, 2024 19:03:29.639542103 CET | 53 | 49875 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 27, 2024 19:01:59.580338001 CET | 192.168.2.16 | 1.1.1.1 | 0x11e8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 19:01:59.580630064 CET | 192.168.2.16 | 1.1.1.1 | 0x8395 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 27, 2024 19:02:03.504810095 CET | 192.168.2.16 | 1.1.1.1 | 0xfa03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 19:02:03.505008936 CET | 192.168.2.16 | 1.1.1.1 | 0x9f65 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 27, 2024 19:02:03.512176037 CET | 192.168.2.16 | 1.1.1.1 | 0xdff8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 27, 2024 19:02:03.512397051 CET | 192.168.2.16 | 1.1.1.1 | 0xe3a9 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 27, 2024 19:01:59.887450933 CET | 1.1.1.1 | 192.168.2.16 | 0x11e8 | No error (0) | 172.67.221.200 | A (IP address) | IN (0x0001) | false | ||
Dec 27, 2024 19:01:59.887450933 CET | 1.1.1.1 | 192.168.2.16 | 0x11e8 | No error (0) | 104.21.75.109 | A (IP address) | IN (0x0001) | false | ||
Dec 27, 2024 19:01:59.887476921 CET | 1.1.1.1 | 192.168.2.16 | 0x8395 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 27, 2024 19:02:03.641603947 CET | 1.1.1.1 | 192.168.2.16 | 0xfa03 | No error (0) | 142.250.181.68 | A (IP address) | IN (0x0001) | false | ||
Dec 27, 2024 19:02:03.642256975 CET | 1.1.1.1 | 192.168.2.16 | 0x9f65 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 27, 2024 19:02:03.649033070 CET | 1.1.1.1 | 192.168.2.16 | 0xdff8 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49710 | 172.67.221.200 | 443 | 6856 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-27 18:02:02 UTC | 658 | OUT | |
2024-12-27 18:02:02 UTC | 845 | IN | |
2024-12-27 18:02:02 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49711 | 172.67.221.200 | 443 | 6856 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-27 18:02:03 UTC | 586 | OUT | |
2024-12-27 18:02:03 UTC | 813 | IN | |
2024-12-27 18:02:03 UTC | 556 | IN | |
2024-12-27 18:02:03 UTC | 15 | IN | |
2024-12-27 18:02:03 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49715 | 35.190.80.1 | 443 | 6856 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-27 18:02:04 UTC | 538 | OUT | |
2024-12-27 18:02:05 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49717 | 35.190.80.1 | 443 | 6856 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-27 18:02:06 UTC | 480 | OUT | |
2024-12-27 18:02:06 UTC | 421 | OUT | |
2024-12-27 18:02:07 UTC | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49727 | 172.67.221.200 | 443 | 6856 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-27 18:03:20 UTC | 734 | OUT | |
2024-12-27 18:03:20 UTC | 802 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 13:01:57 |
Start date: | 27/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 13:01:57 |
Start date: | 27/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 13:01:59 |
Start date: | 27/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 13 |
Start time: | 13:03:58 |
Start date: | 27/12/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79d5d0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 14 |
Start time: | 13:04:01 |
Start date: | 27/12/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61eee0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 15 |
Start time: | 13:04:02 |
Start date: | 27/12/2024 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61eee0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |