Windows
Analysis Report
http://www.gov.uk.companies-house.commerce-moment.top/ch.php?det=85wkhkw0362lzf4&ous=kh5wrgebh&her=9f4vz6xlon0r46xe8m&els=g8t6ydf&ID=qj7cyzfxruav
Overview
General Information
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1468 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) chrome.exe (PID: 3744 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2680 --fi eld-trial- handle=202 4,i,182940 6298040183 464,121807 1930519212 8719,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
chrome.exe (PID: 3412 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://www.go v.uk.compa nies-house .commerce- moment.top /ch.php?de t=85wkhkw0 362lzf4&ou s=kh5wrgeb h&her=9f4v z6xlon0r46 xe8m&els=g 8t6ydf&ID= qj7cyzfxru av" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.185.228 | true | false | high | |
www.gov.uk.companies-house.commerce-moment.top | 94.159.113.24 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.185.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
94.159.113.24 | www.gov.uk.companies-house.commerce-moment.top | Russian Federation | 49531 | NETCOM-R-ASRU | true |
IP |
---|
192.168.2.6 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582453 |
Start date and time: | 2024-12-30 16:56:22 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 44s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://www.gov.uk.companies-house.commerce-moment.top/ch.php?det=85wkhkw0362lzf4&ous=kh5wrgebh&her=9f4vz6xlon0r46xe8m&els=g8t6ydf&ID=qj7cyzfxruav |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.win@16/2@4/4 |
- Exclude process from analysis
(whitelisted): dllhost.exe, WM IADAP.exe, SIHClient.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.186.99, 17 3.194.76.84, 172.217.16.206, 1 42.250.185.78, 142.250.181.238 , 142.250.184.238, 192.229.221 .95, 2.22.50.144, 142.250.186. 78, 142.250.185.110, 142.250.1 85.174, 142.250.186.142, 142.2 50.185.131, 142.250.185.238, 1 84.28.90.27, 13.107.246.45, 52 .149.20.212 - Excluded domains from analysis
(whitelisted): client.wns.win dows.com, fs.microsoft.com, ac counts.google.com, otelrules.a zureedge.net, slscr.update.mic rosoft.com, ctldl.windowsupdat e.com, clientservices.googleap is.com, fe3cr.delivery.mp.micr osoft.com, clients2.google.com , ocsp.digicert.com, edgedl.me .gvt1.com, redirector.gvt1.com , update.googleapis.com, clien ts.l.google.com - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: http:/
/www.gov.uk.companies-house.co mmerce-moment.top/ch.php?det=8 5wkhkw0362lzf4&ous=kh5wrge bh&her=9f4vz6xlon0r46xe8m& amp;els=g8t6ydf&ID=qj7cyzf xruav
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 308 |
Entropy (8bit): | 5.260174115327809 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoIRMELMUbyZ6wcXaoD:J0+oxBeRmR9etdzRxGezHf2Hma+ |
MD5: | A56FD8DA48BB60FB12B5B8262B5A5E32 |
SHA1: | 42D5BCCFEAAC075653C34066A8899CF582A2F655 |
SHA-256: | E824562DF63C8AB4541A30C834C8C0EF3CDC5B901473429F93976B1262AA9D66 |
SHA-512: | 2FC64C7EBF15F5D81779B0515BF279B752FEDA0CA68BF1B905D5C570975E77C5906C645F4A19FFBFAE2C8E38A9DFC675B8485EAD9CECAE1CF8F251F64929DC66 |
Malicious: | false |
Reputation: | low |
URL: | http://www.gov.uk.companies-house.commerce-moment.top/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 92
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 16:57:07.724786997 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:07.724877119 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:08.021610975 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:11.391845942 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:11.391887903 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:11.391962051 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:11.410569906 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:11.410594940 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:12.207592964 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:12.207685947 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:13.807887077 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:13.807909012 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:13.808293104 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:13.856234074 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:13.856303930 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:13.856312037 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:13.856556892 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:13.903330088 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:14.028410912 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:14.028680086 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:14.028726101 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:14.029095888 CET | 49708 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:14.029110909 CET | 443 | 49708 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:16.846226931 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:16.846268892 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:16.846353054 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:16.846967936 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:16.846981049 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.329410076 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:17.332793951 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:17.629667044 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:17.646770954 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.646842957 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.649733067 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.649744987 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.650016069 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.651762962 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.651829004 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.651834011 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.652048111 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.695332050 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.823836088 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.823945045 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:17.824022055 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.824120998 CET | 49716 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:17.824134111 CET | 443 | 49716 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:19.285711050 CET | 443 | 49704 | 173.222.162.64 | 192.168.2.6 |
Dec 30, 2024 16:57:19.285871029 CET | 49704 | 443 | 192.168.2.6 | 173.222.162.64 |
Dec 30, 2024 16:57:19.498374939 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:19.498421907 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:19.498542070 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:19.498689890 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:19.498703003 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:20.132704973 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:20.133136034 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:20.133157969 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:20.134161949 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:20.134215117 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:20.135358095 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:20.135415077 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:20.176575899 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:20.176583052 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:20.223439932 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:21.163177967 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:21.163755894 CET | 49722 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:21.168009043 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:21.168067932 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:21.168220043 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:21.168510914 CET | 80 | 49722 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:21.168565035 CET | 49722 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:21.173048019 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:22.732901096 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:22.780529022 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:22.792558908 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:22.797405958 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:23.063261986 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:23.116548061 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:28.077548981 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:28.077599049 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:29.383636951 CET | 49721 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:57:29.390125990 CET | 80 | 49721 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:57:30.034262896 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:30.034331083 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:30.034560919 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:31.396616936 CET | 49718 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:57:31.396641970 CET | 443 | 49718 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:57:40.606760979 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:40.606848001 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:40.606935978 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:40.607458115 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:40.607491016 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.425106049 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.425173998 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.430437088 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.430459023 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.430675983 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.432432890 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.432564020 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.432575941 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.432729006 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.475333929 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.607234955 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.607363939 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:57:41.607412100 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.607558012 CET | 49845 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:57:41.607568979 CET | 443 | 49845 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:04.591881037 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:04.591952085 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:04.592039108 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:04.592681885 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:04.592698097 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.372724056 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.372812986 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.374711990 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.374727011 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.375016928 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.376950979 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.377011061 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.377017021 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.377134085 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.423343897 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.546998978 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.547142029 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:05.547214031 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.547329903 CET | 49993 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:05.547369003 CET | 443 | 49993 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:06.176512003 CET | 49722 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:58:06.181982994 CET | 80 | 49722 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:58:13.425183058 CET | 80 | 49722 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:58:13.425292015 CET | 49722 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:58:14.303922892 CET | 49722 | 80 | 192.168.2.6 | 94.159.113.24 |
Dec 30, 2024 16:58:14.309818983 CET | 80 | 49722 | 94.159.113.24 | 192.168.2.6 |
Dec 30, 2024 16:58:19.552817106 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:19.552876949 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:19.552948952 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:19.553247929 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:19.553263903 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:20.181252003 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:20.181581974 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:20.181602001 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:20.181917906 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:20.182373047 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:20.182423115 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:20.223514080 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:30.086127043 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:30.086216927 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:30.086282015 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:31.381524086 CET | 49996 | 443 | 192.168.2.6 | 142.250.185.228 |
Dec 30, 2024 16:58:31.381561041 CET | 443 | 49996 | 142.250.185.228 | 192.168.2.6 |
Dec 30, 2024 16:58:32.671143055 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:32.671256065 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:32.671452999 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:32.672317982 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:32.672353029 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.464757919 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.464930058 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.468882084 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.468900919 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.469234943 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.471298933 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.471435070 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.471445084 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.471549988 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.515336037 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.648226023 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.648451090 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Dec 30, 2024 16:58:33.648519993 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.648663998 CET | 49998 | 443 | 192.168.2.6 | 40.115.3.253 |
Dec 30, 2024 16:58:33.648696899 CET | 443 | 49998 | 40.115.3.253 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 16:57:15.126990080 CET | 53 | 58271 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:15.139395952 CET | 53 | 54498 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:16.127940893 CET | 53 | 57074 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:19.490118980 CET | 58156 | 53 | 192.168.2.6 | 1.1.1.1 |
Dec 30, 2024 16:57:19.490118980 CET | 60374 | 53 | 192.168.2.6 | 1.1.1.1 |
Dec 30, 2024 16:57:19.497211933 CET | 53 | 60374 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:19.497488022 CET | 53 | 58156 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:20.384037971 CET | 51453 | 53 | 192.168.2.6 | 1.1.1.1 |
Dec 30, 2024 16:57:20.384280920 CET | 52394 | 53 | 192.168.2.6 | 1.1.1.1 |
Dec 30, 2024 16:57:21.097512960 CET | 53 | 51453 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:21.185789108 CET | 53 | 52394 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:33.043598890 CET | 53 | 65113 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:57:51.997556925 CET | 53 | 49848 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:58:14.312100887 CET | 53 | 50785 | 1.1.1.1 | 192.168.2.6 |
Dec 30, 2024 16:58:14.750155926 CET | 53 | 65428 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Dec 30, 2024 16:57:21.185863018 CET | 192.168.2.6 | 1.1.1.1 | c242 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 30, 2024 16:57:19.490118980 CET | 192.168.2.6 | 1.1.1.1 | 0x3e46 | Standard query (0) | 65 | IN (0x0001) | false | |
Dec 30, 2024 16:57:19.490118980 CET | 192.168.2.6 | 1.1.1.1 | 0xf95a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 16:57:20.384037971 CET | 192.168.2.6 | 1.1.1.1 | 0xa998 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 30, 2024 16:57:20.384280920 CET | 192.168.2.6 | 1.1.1.1 | 0x894c | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 30, 2024 16:57:19.497211933 CET | 1.1.1.1 | 192.168.2.6 | 0xf95a | No error (0) | 142.250.185.228 | A (IP address) | IN (0x0001) | false | ||
Dec 30, 2024 16:57:19.497488022 CET | 1.1.1.1 | 192.168.2.6 | 0x3e46 | No error (0) | 65 | IN (0x0001) | false | |||
Dec 30, 2024 16:57:21.097512960 CET | 1.1.1.1 | 192.168.2.6 | 0xa998 | No error (0) | 94.159.113.24 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49721 | 94.159.113.24 | 80 | 3744 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 30, 2024 16:57:21.168220043 CET | 552 | OUT | |
Dec 30, 2024 16:57:22.732901096 CET | 203 | IN | |
Dec 30, 2024 16:57:22.792558908 CET | 527 | OUT | |
Dec 30, 2024 16:57:23.063261986 CET | 524 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49722 | 94.159.113.24 | 80 | 3744 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 30, 2024 16:58:06.176512003 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49708 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-30 15:57:13 UTC | 71 | OUT | |
2024-12-30 15:57:13 UTC | 249 | OUT | |
2024-12-30 15:57:13 UTC | 1076 | OUT | |
2024-12-30 15:57:13 UTC | 218 | OUT | |
2024-12-30 15:57:14 UTC | 14 | IN | |
2024-12-30 15:57:14 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.6 | 49716 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-30 15:57:17 UTC | 71 | OUT | |
2024-12-30 15:57:17 UTC | 249 | OUT | |
2024-12-30 15:57:17 UTC | 1084 | OUT | |
2024-12-30 15:57:17 UTC | 218 | OUT | |
2024-12-30 15:57:17 UTC | 14 | IN | |
2024-12-30 15:57:17 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.6 | 49845 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-30 15:57:41 UTC | 70 | OUT | |
2024-12-30 15:57:41 UTC | 249 | OUT | |
2024-12-30 15:57:41 UTC | 1083 | OUT | |
2024-12-30 15:57:41 UTC | 217 | OUT | |
2024-12-30 15:57:41 UTC | 14 | IN | |
2024-12-30 15:57:41 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.6 | 49993 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-30 15:58:05 UTC | 71 | OUT | |
2024-12-30 15:58:05 UTC | 249 | OUT | |
2024-12-30 15:58:05 UTC | 1084 | OUT | |
2024-12-30 15:58:05 UTC | 218 | OUT | |
2024-12-30 15:58:05 UTC | 14 | IN | |
2024-12-30 15:58:05 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.6 | 49998 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-30 15:58:33 UTC | 71 | OUT | |
2024-12-30 15:58:33 UTC | 249 | OUT | |
2024-12-30 15:58:33 UTC | 1084 | OUT | |
2024-12-30 15:58:33 UTC | 218 | OUT | |
2024-12-30 15:58:33 UTC | 14 | IN | |
2024-12-30 15:58:33 UTC | 58 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 10:57:08 |
Start date: | 30/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 10:57:13 |
Start date: | 30/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 10:57:18 |
Start date: | 30/12/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |