Windows
Analysis Report
https://147y3.trk.elasticemail.com/tracking/click?d=l6DX1ZxoYxoIu3Ps_nHCw2dpTGYsp50KhPgdcLAPZ98lDQqXluI2jbk2Kz6cWaRjWchw5Igbhe-BSjXhcIk5khB6_31XWJ3KxF070e3rxxM9hJmShBhAM7tP0jesqnjYkgFpEuivEIV6QQKt0-F18YQ1#out/0023m/435/85jy1/26p0/41/77
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 2484 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5436 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2452 --fi eld-trial- handle=225 6,i,118398 1916880748 1049,20722 8776340161 0699,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://147y3 .trk.elast icemail.co m/tracking /click?d=l 6DX1ZxoYxo Iu3Ps_nHCw 2dpTGYsp50 KhPgdcLAPZ 98lDQqXluI 2jbk2Kz6cW aRjWchw5Ig bhe-BSjXhc Ik5khB6_31 XWJ3KxF070 e3rxxM9hJm ShBhAM7tP0 jesqnjYkgF pEuivEIV6Q QKt0-F18YQ 1#out/0023 m/435/85jy 1/26p0/41/ 77" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
147y3.trk.elasticemail.com | 164.132.95.126 | true | false | unknown | |
www.google.com | 142.250.185.164 | true | false | high | |
trackdaily.co.uk | 52.191.212.24 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
164.132.95.126 | 147y3.trk.elasticemail.com | France | 16276 | OVHFR | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
52.191.212.24 | trackdaily.co.uk | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1585186 |
Start date and time: | 2025-01-07 09:20:35 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://147y3.trk.elasticemail.com/tracking/click?d=l6DX1ZxoYxoIu3Ps_nHCw2dpTGYsp50KhPgdcLAPZ98lDQqXluI2jbk2Kz6cWaRjWchw5Igbhe-BSjXhcIk5khB6_31XWJ3KxF070e3rxxM9hJmShBhAM7tP0jesqnjYkgFpEuivEIV6QQKt0-F18YQ1#out/0023m/435/85jy1/26p0/41/77 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@22/7@8/5 |
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.185.206, 64.233.184.84, 142.250.181.238, 172.217.18.14, 217.20.57.19, 192.229.221.95, 142.250.186.142, 172.217.16.206, 142.250.74.206, 142.250.65.206, 74.125.0.102, 216.58.206.67, 23.56.254.164, 4.245.163.56, 13.107.246.45
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, r1---sn-t0aekn7e.gvt1.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://147y3.trk.elasticemail.com/tracking/click?d=l6DX1ZxoYxoIu3Ps_nHCw2dpTGYsp50KhPgdcLAPZ98lDQqXluI2jbk2Kz6cWaRjWchw5Igbhe-BSjXhcIk5khB6_31XWJ3KxF070e3rxxM9hJmShBhAM7tP0jesqnjYkgFpEuivEIV6QQKt0-F18YQ1#out/0023m/435/85jy1/26p0/41/77
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29315 |
Entropy (8bit): | 4.922759688981543 |
Encrypted: | false |
SSDEEP: | 768:73BqxdhkpnF9ePHy+GcFULYSJGWLP0fCwi:Yw4PBULYSJGEP0fCwi |
MD5: | A8D5577E12383FF69600CE4A11BCFE65 |
SHA1: | 2E3A992126F7991599EA8C798593C5E11546555A |
SHA-256: | D4C4BEA4AAD837B447F501B91032243549D685FB7752047D870A5C9821E171E5 |
SHA-512: | 4AB45839174B613366CB47DBF059E895951306FDC9FF731BB5A0B92F975692322A6C4D4DB618BA4163AD1271B07A591A1ECA50229ECEAA50BFCAE372F572C611 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:3:3 |
MD5: | E1C06D85AE7B8B032BEF47E42E4C08F9 |
SHA1: | 71853C6197A6A7F222DB0F1978C7CB232B87C5EE |
SHA-256: | 75A11DA44C802486BC6F65640AA48A730F0F684C5C07A42BA3CD1735EB3FB070 |
SHA-512: | 016BA8C4CFDE65AF99CB5FA8B8A37E2EB73F481B3AE34991666DF2E04FEB6C038666EBD1EC2B6F623967756033C702DDE5F423F7D47AB6ED1827FF53783731F7 |
Malicious: | false |
Reputation: | low |
URL: | http://trackdaily.co.uk/redirect.html/out/0023m/435/85jy1/26p0/41/77 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 29315 |
Entropy (8bit): | 4.922759688981543 |
Encrypted: | false |
SSDEEP: | 768:73BqxdhkpnF9ePHy+GcFULYSJGWLP0fCwi:Yw4PBULYSJGEP0fCwi |
MD5: | A8D5577E12383FF69600CE4A11BCFE65 |
SHA1: | 2E3A992126F7991599EA8C798593C5E11546555A |
SHA-256: | D4C4BEA4AAD837B447F501B91032243549D685FB7752047D870A5C9821E171E5 |
SHA-512: | 4AB45839174B613366CB47DBF059E895951306FDC9FF731BB5A0B92F975692322A6C4D4DB618BA4163AD1271B07A591A1ECA50229ECEAA50BFCAE372F572C611 |
Malicious: | false |
Reputation: | low |
URL: | http://trackdaily.co.uk/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 300 |
Entropy (8bit): | 4.793600045161175 |
Encrypted: | false |
SSDEEP: | 6:NzMXAwKXvPMsLEjKwxmeiFZ6TNGJZ64cq75Z2K9lg4cWFMMmJdL7YmmJ7vVL:ZtwMvPE2wxpiFZ6hGf639K9lg3WFAcxT |
MD5: | D647FF52C88AD01AC6F9092C3EC06AE4 |
SHA1: | CB4714E3CDC81C57835DF5602B8FB169FE051E27 |
SHA-256: | 0F5346607D5631EAE0B39F55C14A46E5925D6392AF075E80FFB8DAA9BF3EA4AB |
SHA-512: | 961FF2D3F6BFB491E23E36043D61417CD9F66EC54A806E11BFEAA456A4F2D0FBA9C7B25801C7E132BCCF4B75889DFAAD4A0E2126E4959D73807732D56338ABBA |
Malicious: | false |
Reputation: | low |
URL: | http://trackdaily.co.uk/redirect.html |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 7, 2025 09:21:29.176299095 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 7, 2025 09:21:33.218261003 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.218305111 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.218496084 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.218744040 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.218754053 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.850774050 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.851068020 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.851089001 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.851948977 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.852010965 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.853112936 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.853167057 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.896853924 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:33.896863937 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:33.943708897 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:34.007765055 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.007805109 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.007869959 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.008182049 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.008213997 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.008300066 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.008615971 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.008630037 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.008831978 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.008847952 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.790606022 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.810221910 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.834034920 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.851711988 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.854027987 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.854038954 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.854281902 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.854289055 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.854975939 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.855031967 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.855184078 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.855233908 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.862272024 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.862333059 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.862759113 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.862812996 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.863579988 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.863589048 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.906733990 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.906744957 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:34.913472891 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:34.960211039 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:35.036953926 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:35.037070036 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:35.037126064 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:35.038408041 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:35.038425922 CET | 443 | 49741 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:21:35.038434982 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:35.038469076 CET | 49741 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:21:35.054866076 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.059729099 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:35.059784889 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.059930086 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.064719915 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:35.516486883 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:35.569061995 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.583904982 CET | 49744 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.584181070 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.588793993 CET | 80 | 49744 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:35.588872910 CET | 49744 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:35.589011908 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.220248938 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.245724916 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.250623941 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.740169048 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.742872953 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.747703075 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843393087 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843410015 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843420982 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843430042 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843439102 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843450069 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843463898 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843473911 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843483925 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.843494892 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.844013929 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.844023943 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.844049931 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.844177008 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.844211102 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.848905087 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.856379986 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.930087090 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930114985 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930134058 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930144072 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930155039 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930439949 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930474043 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.930679083 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930696011 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930706978 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930708885 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.930717945 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930728912 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.930741072 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.931405067 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.931421995 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.931431055 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.932382107 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.971394062 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.976233006 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:36.976425886 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.976636887 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:36.981393099 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.432902098 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.432920933 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.432934046 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.432969093 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.432971001 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.432981968 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.432995081 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.433008909 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.433024883 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.433038950 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.433092117 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.433139086 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.433145046 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.433151960 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.433193922 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.437863111 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.437879086 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.437891960 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.437920094 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.504991055 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.520447016 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.520461082 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.520473003 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.520510912 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.520561934 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.520574093 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.520606041 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.520993948 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521006107 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521017075 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521028042 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521051884 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.521559954 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521570921 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521583080 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521594048 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:37.521603107 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.521620989 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:37.583317995 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:41.848510027 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:41.849654913 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:42.438029051 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:42.438100100 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:43.164015055 CET | 49745 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:43.164051056 CET | 49743 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:21:43.168917894 CET | 80 | 49745 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:43.168931961 CET | 80 | 49743 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:21:43.771044016 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:43.771111965 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:43.771187067 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:45.168400049 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:21:45.168423891 CET | 443 | 49738 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:21:51.996115923 CET | 60229 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:52.002043009 CET | 53 | 60229 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:52.002134085 CET | 60229 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:52.002162933 CET | 60229 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:52.006892920 CET | 53 | 60229 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:52.460192919 CET | 53 | 60229 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:52.461011887 CET | 60229 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:52.466048002 CET | 53 | 60229 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:52.466121912 CET | 60229 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:56.997054100 CET | 65485 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:57.001905918 CET | 53 | 65485 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:57.002021074 CET | 65485 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:57.002080917 CET | 65485 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:57.006875038 CET | 53 | 65485 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:57.479074955 CET | 53 | 65485 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:57.479415894 CET | 65485 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:57.488286018 CET | 53 | 65485 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:57.488389969 CET | 65485 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:22:19.912724018 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:22:19.912746906 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:22:20.600095987 CET | 49744 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:22:20.605022907 CET | 80 | 49744 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:22:27.245203018 CET | 80 | 49744 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:22:27.245310068 CET | 49744 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:22:29.163122892 CET | 49744 | 80 | 192.168.2.4 | 52.191.212.24 |
Jan 7, 2025 09:22:29.167920113 CET | 80 | 49744 | 52.191.212.24 | 192.168.2.4 |
Jan 7, 2025 09:22:33.272396088 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:33.272494078 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:33.272578955 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:33.272799015 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:33.272830963 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:33.910216093 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:33.910537958 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:33.910595894 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:33.910887957 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:33.911215067 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:33.911281109 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:33.958592892 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:35.164594889 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:22:35.164696932 CET | 443 | 49740 | 164.132.95.126 | 192.168.2.4 |
Jan 7, 2025 09:22:35.164761066 CET | 49740 | 443 | 192.168.2.4 | 164.132.95.126 |
Jan 7, 2025 09:22:37.005821943 CET | 49724 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 7, 2025 09:22:37.005824089 CET | 49723 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 7, 2025 09:22:37.010812998 CET | 80 | 49724 | 199.232.214.172 | 192.168.2.4 |
Jan 7, 2025 09:22:37.010869980 CET | 49724 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 7, 2025 09:22:37.011142969 CET | 80 | 49723 | 199.232.214.172 | 192.168.2.4 |
Jan 7, 2025 09:22:37.011225939 CET | 49723 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 7, 2025 09:22:43.825875044 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:43.825922012 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Jan 7, 2025 09:22:43.825969934 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:45.163225889 CET | 49161 | 443 | 192.168.2.4 | 142.250.185.164 |
Jan 7, 2025 09:22:45.163255930 CET | 443 | 49161 | 142.250.185.164 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 7, 2025 09:21:28.985742092 CET | 53 | 54045 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:29.011868000 CET | 53 | 50633 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:29.989367962 CET | 53 | 55759 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:33.210355043 CET | 54518 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:33.210517883 CET | 54005 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:33.217235088 CET | 53 | 54005 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:33.217247009 CET | 53 | 54518 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:33.992415905 CET | 51940 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:33.992640972 CET | 51406 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:34.006509066 CET | 53 | 51406 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:34.006972075 CET | 53 | 51940 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:35.042922974 CET | 54853 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:35.043169022 CET | 51793 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:35.053879976 CET | 53 | 54853 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:35.054397106 CET | 53 | 51793 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:36.942611933 CET | 57099 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:36.943130970 CET | 49437 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 7, 2025 09:21:36.954802036 CET | 53 | 57099 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:36.968012094 CET | 53 | 49437 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:46.920228004 CET | 53 | 49416 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:48.575771093 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Jan 7, 2025 09:21:51.995739937 CET | 53 | 61209 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:21:56.996582985 CET | 53 | 53726 | 1.1.1.1 | 192.168.2.4 |
Jan 7, 2025 09:22:28.515331984 CET | 53 | 56517 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 7, 2025 09:21:33.210355043 CET | 192.168.2.4 | 1.1.1.1 | 0xf45 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 09:21:33.210517883 CET | 192.168.2.4 | 1.1.1.1 | 0x4c93 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 7, 2025 09:21:33.992415905 CET | 192.168.2.4 | 1.1.1.1 | 0x19a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 09:21:33.992640972 CET | 192.168.2.4 | 1.1.1.1 | 0x54e8 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 7, 2025 09:21:35.042922974 CET | 192.168.2.4 | 1.1.1.1 | 0x2465 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 09:21:35.043169022 CET | 192.168.2.4 | 1.1.1.1 | 0x61ba | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 7, 2025 09:21:36.942611933 CET | 192.168.2.4 | 1.1.1.1 | 0xff9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 09:21:36.943130970 CET | 192.168.2.4 | 1.1.1.1 | 0xc2fe | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 7, 2025 09:21:33.217235088 CET | 1.1.1.1 | 192.168.2.4 | 0x4c93 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 7, 2025 09:21:33.217247009 CET | 1.1.1.1 | 192.168.2.4 | 0xf45 | No error (0) | 142.250.185.164 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:34.006972075 CET | 1.1.1.1 | 192.168.2.4 | 0x19a8 | No error (0) | 164.132.95.126 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:34.006972075 CET | 1.1.1.1 | 192.168.2.4 | 0x19a8 | No error (0) | 87.98.174.124 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:34.006972075 CET | 1.1.1.1 | 192.168.2.4 | 0x19a8 | No error (0) | 91.134.146.190 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:34.006972075 CET | 1.1.1.1 | 192.168.2.4 | 0x19a8 | No error (0) | 91.134.146.191 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:34.006972075 CET | 1.1.1.1 | 192.168.2.4 | 0x19a8 | No error (0) | 91.134.188.169 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:35.053879976 CET | 1.1.1.1 | 192.168.2.4 | 0x2465 | No error (0) | 52.191.212.24 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 09:21:36.954802036 CET | 1.1.1.1 | 192.168.2.4 | 0xff9f | No error (0) | 52.191.212.24 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49743 | 52.191.212.24 | 80 | 5436 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 7, 2025 09:21:35.059930086 CET | 444 | OUT | |
Jan 7, 2025 09:21:35.516486883 CET | 630 | IN | |
Jan 7, 2025 09:21:35.584181070 CET | 523 | OUT | |
Jan 7, 2025 09:21:36.220248938 CET | 275 | IN | |
Jan 7, 2025 09:21:36.245724916 CET | 420 | OUT | |
Jan 7, 2025 09:21:36.740169048 CET | 274 | IN | |
Jan 7, 2025 09:21:36.742872953 CET | 409 | OUT | |
Jan 7, 2025 09:21:36.843393087 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843410015 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843420982 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843430042 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843439102 CET | 896 | IN | |
Jan 7, 2025 09:21:36.843450069 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843463898 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843473911 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843483925 CET | 1236 | IN | |
Jan 7, 2025 09:21:36.843494892 CET | 896 | IN | |
Jan 7, 2025 09:21:36.844013929 CET | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49745 | 52.191.212.24 | 80 | 5436 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 7, 2025 09:21:36.976636887 CET | 269 | OUT | |
Jan 7, 2025 09:21:37.432902098 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.432920933 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.432934046 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.432969093 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.432981968 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.432995081 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.433008909 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.433092117 CET | 108 | IN | |
Jan 7, 2025 09:21:37.433139086 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.433151960 CET | 1236 | IN | |
Jan 7, 2025 09:21:37.437863111 CET | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49744 | 52.191.212.24 | 80 | 5436 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 7, 2025 09:22:20.600095987 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49741 | 164.132.95.126 | 443 | 5436 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 08:21:34 UTC | 838 | OUT | |
2025-01-07 08:21:35 UTC | 255 | IN | |
2025-01-07 08:21:35 UTC | 163 | IN | |
2025-01-07 08:21:35 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 03:21:25 |
Start date: | 07/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 03:21:27 |
Start date: | 07/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 03:21:33 |
Start date: | 07/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |