Windows
Analysis Report
https://ipfs.io/ipfs/bafybeifkk7tuizumzirz7qfuxbcoggonud2b6gcvttaa7ewfdgltpybls4/index1.html?err=KHPGKXW3AEO13L6ZGUK&dispatch=B34&id=2849c1C900c31C62B159B3002c63C5#engineering@vanas.eu
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 7004 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA) - chrome.exe (PID: 3084 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2080 --fi eld-trial- handle=198 0,i,169251 7557391575 8389,74709 7290576260 2225,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- chrome.exe (PID: 6452 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://ipfs. io/ipfs/ba fybeifkk7t uizumzirz7 qfuxbcoggo nud2b6gcvt taa7ewfdgl tpybls4/in dex1.html? err=KHPGKX W3AEO13L6Z GUK&dispat ch=B34&id= 2849c1C900 c31C62B159 B3002c63C5 #engineeri ng@vanas.e u" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | SlashNext: |
Source: | Sample URL: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cdnjs.cloudflare.com | 104.17.24.14 | true | false | high | |
www.google.com | 142.250.186.132 | true | false | high | |
ipfs.io | 209.94.90.1 | true | false | high | |
cdn.jsdelivr.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.17.24.14 | cdnjs.cloudflare.com | United States | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.186.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
209.94.90.1 | ipfs.io | United States | 40680 | PROTOCOLUS | false |
IP |
---|
192.168.2.18 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1585355 |
Start date and time: | 2025-01-07 14:57:37 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://ipfs.io/ipfs/bafybeifkk7tuizumzirz7qfuxbcoggonud2b6gcvttaa7ewfdgltpybls4/index1.html?err=KHPGKXW3AEO13L6ZGUK&dispatch=B34&id=2849c1C900c31C62B159B3002c63C5#engineering@vanas.eu |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@17/10@8/5 |
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.131, 216.58.206.46, 64.233.166.84, 142.250.185.206, 104.18.186.31, 104.18.187.31, 216.58.206.78, 142.250.181.238, 142.250.186.174, 142.250.186.78, 142.250.186.46, 216.58.212.174, 142.250.185.78, 216.58.206.67, 142.250.185.238, 142.250.185.174, 184.28.90.27, 4.245.163.56, 2.23.227.221
- Excluded domains from analysis (whitelisted): www.bing.com, clients1.google.com, cdn.jsdelivr.net.cdn.cloudflare.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://ipfs.io/ipfs/bafybeifkk7tuizumzirz7qfuxbcoggonud2b6gcvttaa7ewfdgltpybls4/index1.html?err=KHPGKXW3AEO13L6ZGUK&dispatch=B34&id=2849c1C900c31C62B159B3002c63C5#engineering@vanas.eu
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9685648698223193 |
Encrypted: | false |
SSDEEP: | 48:8kk3djT5hoEH8idAKZdA1rehwiZUklqehQy+3:8vBVhod/y |
MD5: | C634AB275B6ADEB723FA1D259E55E327 |
SHA1: | 22F32578B782A32E4C47D650A6FA6E2D567A2B33 |
SHA-256: | 10B85980D5682D79FD79F4B6AA2EE994D018DEC532E20F3A66B6B3DCC497926E |
SHA-512: | 30C772427D28AF76C4BD0B3C339CE8D0826501A1155A589A2F85A6560CD276FE8865C8A8B0F87AD35E4F293E9DDD6773F22BBE0E00FFC85FB27DD4F652173229 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.985062275293901 |
Encrypted: | false |
SSDEEP: | 48:8w3djT5hoEH8idAKZdA1ceh/iZUkAQkqehvy+2:8wBVhoh9QWy |
MD5: | 8500C70938418B48FF25BBDBF4DB00A4 |
SHA1: | E61DB4F535E6441D99A9167F5C7B38B3347885D3 |
SHA-256: | 18E49713E111C303D32DA913F6E648521125D6B5A260A89D8CBD327088CB4A75 |
SHA-512: | B2E0B71991A09C094757C586F97A4C4713DF90FA6A2EF2CD3CF029007031CFC8007537FAA0EDFCD19E5CEA8F67C9D0D5DCDE3C48FC4E3D70ECDC72E02C0FECA1 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2691 |
Entropy (8bit): | 3.996471606515541 |
Encrypted: | false |
SSDEEP: | 48:8XR3djT5hoSH8idAKZdA14Aeh7sFiZUkmgqeh7sdy+BX:8hBVhoFnLy |
MD5: | A7E11CC89EFFC88040D1FA6314A2411C |
SHA1: | FCDB358B8B7AFCD05888B435060BA242492B6DA1 |
SHA-256: | D8115F946BC47E1574437302457B1BA215EFADED1FF70F926CC7CCF4AF312072 |
SHA-512: | 794202BFEE134E4AA7A130693F0D53C2AD7F75F7ECC3059A2D99A490BC47B93037102F82F631C3F57DFBF645D861F80243272444688053E0519F84D78EB99393 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.981136831953252 |
Encrypted: | false |
SSDEEP: | 48:8sV3djT5hoEH8idAKZdA1JehDiZUkwqehjy+R:8sVBVhokVy |
MD5: | 8778291ED0A7EFE39484ED835151CE98 |
SHA1: | 8FD70CF18956FB7FA4A567BF6224E341548DD137 |
SHA-256: | 4653A96CD1EE23691744F1F11CD11BE687CE3120DE27D5D33779667F113FAB32 |
SHA-512: | 6D0026F40140DBC2965DBD89DE1AA99C479DEFBE30FA289064E605DE48846711FCDEA56ED0E40A69908A60EE57E936AA96C99ED1AA2653E04574B98220A6755F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.969688181105612 |
Encrypted: | false |
SSDEEP: | 48:803djT5hoEH8idAKZdA1XehBiZUk1W1qehJy+C:80BVho09py |
MD5: | 806210DDB553327D5454295D48941582 |
SHA1: | 4B05745BC43A811432133F33BF63A45280284ADD |
SHA-256: | 54D1E6258E2B8AE98787F00C09E822766E57937B808A1BC5F450F9C714B90255 |
SHA-512: | 64B3E8FA1A1F387A8BA20951C7668BAF9A23FB79B80BE882F64EA818AD17F0B0778B61C26AC9712397281F551263F99F64C464811EA1C5FA519A1E935B23860F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9832910227893192 |
Encrypted: | false |
SSDEEP: | 48:8i3djT5hoEH8idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:8iBVhoYT/TbxWOvTbLy7T |
MD5: | 8A188D46C94480B952EB192ABDB67826 |
SHA1: | 5FD25F700211C5806BA8540BB5D824D5FCA3C50A |
SHA-256: | EAB38F9542DF7253D9164944B657E2216D614C1A53B9052577AC62C947008285 |
SHA-512: | D24BDF8D739719F2C7D8A31E3B6BC2AC2D8965C5CC421CFD92C3119154C4BD6C596B6F4E603B984321DF1D8F685C09FA28484D769C52CF1258D78AD97D846873 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 59344 |
Entropy (8bit): | 4.717040228413791 |
Encrypted: | false |
SSDEEP: | 768:0Eh31IPiyXNq4YxBowbgJlkwF//zMQyYJYX9Bft6VSzl:0E0PxXE4YXJgndFTfy9lt5B |
MD5: | 74BAB4578692993514E7F882CC15C218 |
SHA1: | B6293BCFD851F963EDBE859498570C4C0C7EAAE4 |
SHA-256: | D87DDF917B7A1449AB45E2B8E3C98354629BDD65B6659C37E6023BBEA1CE1386 |
SHA-512: | 8810579BC7D6F74FA7B8B7122A56E6ACF70B6B4393F76C4ED4122C67ECB00D6642BEAB1681C715DE0168441BF4CFEF1D2C9832007221477E5565CDA833F808D7 |
Malicious: | false |
Reputation: | low |
URL: | https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 160392 |
Entropy (8bit): | 5.078030630836827 |
Encrypted: | false |
SSDEEP: | 1536:kw7CIJ0T+r+ryEIA1pDEBi8yNcuSEIA1/uypq3SYiLENM6HN26R:H7VKGGq3SYiLENM6HN26R |
MD5: | 023B3876BB73AA541367FC40A193D2B7 |
SHA1: | 8ED2D6350D23F857D92805737D0F97C675DE666B |
SHA-256: | F77C0D1739B618EDC4A01CA3F6B2990B01A3009030AF49EE8CF68E83052DF194 |
SHA-512: | A1CF7E5D2B351F6E37FC544DF51C3AD859FC12DC631185875D1BE34B8DD8B6E7847B06D2E8E6DF5DC24DCA88631EA54A14FA175D4C7073EAB52BB0DE7BABEFF6 |
Malicious: | false |
Reputation: | low |
URL: | https://cdn.jsdelivr.net/npm/bootstrap@4.5.3/dist/css/bootstrap.min.css |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 7, 2025 14:58:09.214920998 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.214945078 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.215003967 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.215241909 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.215257883 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.215620995 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.215647936 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.215698957 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.215919971 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.215934038 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.675976038 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.677122116 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.677158117 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.678266048 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.678333998 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.679338932 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.679410934 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.679526091 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.696820974 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.697065115 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.697077036 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.698153973 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.698219061 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.698513031 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.698575974 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.723332882 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.723824978 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.723844051 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.740190029 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.740197897 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.771861076 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.787821054 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.832093954 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832143068 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832169056 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832195044 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832238913 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832237005 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.832261086 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832289934 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.832314014 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.832318068 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832350969 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832392931 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.832397938 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832593918 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832622051 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832674980 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.832680941 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.832747936 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:09.836750984 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.856116056 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:09.856137991 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:09.856982946 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:09.857173920 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:09.857186079 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:09.883594990 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.105875969 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.105945110 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.105977058 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106007099 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106034994 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106034040 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106065035 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106089115 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106115103 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106121063 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106183052 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106215000 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106244087 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106256008 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106261015 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106287003 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106297016 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106329918 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106360912 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106383085 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106386900 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106409073 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106421947 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106453896 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106481075 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106508017 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106513977 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106518030 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.106542110 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106555939 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.106559992 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.110604048 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.110656977 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.110685110 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.110712051 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.110729933 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.110738039 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.110769033 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.110801935 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.110958099 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.111047029 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.111089945 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.111095905 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.111955881 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.111994982 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.112024069 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.112032890 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.112042904 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.112061024 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.112075090 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.112912893 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.112950087 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.112968922 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.112973928 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.112989902 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.113012075 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.115788937 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.115848064 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.115853071 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.115874052 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.115890980 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.115931988 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.116029978 CET | 49698 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:10.116045952 CET | 443 | 49698 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:10.323438883 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.323694944 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.323717117 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.324815035 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.324886084 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.325911999 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.325994968 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.326191902 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.326200962 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.375807047 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.472476959 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.472524881 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.472558022 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.472580910 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.472598076 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.472692966 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.472734928 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.472743034 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.472790003 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.472929955 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.473356962 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.473443031 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.473453999 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.477150917 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.477185011 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.477201939 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.477212906 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.477271080 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.477279902 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.518820047 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561074972 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561201096 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561233044 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561249018 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561271906 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561304092 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561317921 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561325073 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561366081 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561366081 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561373949 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561419010 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561424017 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561454058 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561485052 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561491013 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561511040 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.561542988 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.561578035 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562369108 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562416077 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.562422991 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562469006 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562498093 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562508106 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.562513113 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562551022 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562560081 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.562565088 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.562604904 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.562611103 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.606777906 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.606827974 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.606852055 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.606869936 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.606905937 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649055958 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649208069 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649255037 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649266005 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649276972 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649312973 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649323940 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649477959 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649512053 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649542093 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649550915 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649568081 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649641991 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:10.649683952 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649894953 CET | 49703 | 443 | 192.168.2.18 | 104.17.24.14 |
Jan 7, 2025 14:58:10.649909019 CET | 443 | 49703 | 104.17.24.14 | 192.168.2.18 |
Jan 7, 2025 14:58:13.124377966 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.124422073 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.124515057 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.124733925 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.124751091 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.766047955 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.766344070 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.766369104 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.767427921 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.767504930 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.768637896 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.768699884 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.817846060 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:13.817863941 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:13.865833998 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:20.909207106 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:21.212855101 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:21.818847895 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:23.018893957 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:23.614131927 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:23.614172935 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:23.619087934 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.619102955 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.619157076 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.619168043 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.619196892 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.693197966 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:23.693269968 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:23.693331957 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:23.979542017 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979561090 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979571104 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979581118 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979590893 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979612112 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:23.979651928 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:23.979861021 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979877949 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979892969 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979902029 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.979908943 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:23.979954958 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:23.980483055 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:58:23.980537891 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:58:24.582374096 CET | 49705 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:58:24.582402945 CET | 443 | 49705 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:58:24.603660107 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:24.603730917 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:24.603784084 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:25.427867889 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:26.387520075 CET | 49699 | 443 | 192.168.2.18 | 209.94.90.1 |
Jan 7, 2025 14:58:26.387548923 CET | 443 | 49699 | 209.94.90.1 | 192.168.2.18 |
Jan 7, 2025 14:58:28.033235073 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:28.334856987 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:28.941855907 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:30.153857946 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:30.233870983 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:32.566936970 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:37.375865936 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:39.834878922 CET | 49673 | 443 | 192.168.2.18 | 204.79.197.203 |
Jan 7, 2025 14:58:46.976880074 CET | 49679 | 443 | 192.168.2.18 | 52.182.141.63 |
Jan 7, 2025 14:58:55.092308998 CET | 49689 | 80 | 192.168.2.18 | 199.232.210.172 |
Jan 7, 2025 14:58:55.097652912 CET | 80 | 49689 | 199.232.210.172 | 192.168.2.18 |
Jan 7, 2025 14:58:55.097744942 CET | 49689 | 80 | 192.168.2.18 | 199.232.210.172 |
Jan 7, 2025 14:59:13.174968958 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:13.175009012 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:13.175098896 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:13.175316095 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:13.175328016 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:13.848959923 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:13.849265099 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:13.849303961 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:13.849653959 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:13.849994898 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:13.850059032 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:13.893901110 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:23.750305891 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:23.750391006 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:23.750471115 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:24.595168114 CET | 49712 | 443 | 192.168.2.18 | 142.250.186.132 |
Jan 7, 2025 14:59:24.595199108 CET | 443 | 49712 | 142.250.186.132 | 192.168.2.18 |
Jan 7, 2025 14:59:46.760099888 CET | 49691 | 80 | 192.168.2.18 | 192.229.221.95 |
Jan 7, 2025 14:59:46.760102034 CET | 49690 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:59:46.765223026 CET | 443 | 49690 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:59:46.765314102 CET | 49690 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:59:46.765558004 CET | 80 | 49691 | 192.229.221.95 | 192.168.2.18 |
Jan 7, 2025 14:59:46.765618086 CET | 49691 | 80 | 192.168.2.18 | 192.229.221.95 |
Jan 7, 2025 14:59:48.886976004 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Jan 7, 2025 14:59:48.892148018 CET | 443 | 49692 | 20.190.159.64 | 192.168.2.18 |
Jan 7, 2025 14:59:48.892215014 CET | 49692 | 443 | 192.168.2.18 | 20.190.159.64 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 7, 2025 14:58:08.376166105 CET | 53 | 53271 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:08.456521988 CET | 53 | 58910 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.206964016 CET | 63719 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:09.207120895 CET | 49379 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:09.213838100 CET | 53 | 63719 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.214409113 CET | 53 | 49379 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.453859091 CET | 53 | 58007 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.844181061 CET | 60763 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:09.844325066 CET | 56108 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:09.848751068 CET | 52664 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:09.848903894 CET | 60026 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:09.851105928 CET | 53 | 56108 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.855535984 CET | 53 | 60026 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:09.855546951 CET | 53 | 52664 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:13.116854906 CET | 50782 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:13.116985083 CET | 58159 | 53 | 192.168.2.18 | 1.1.1.1 |
Jan 7, 2025 14:58:13.123507977 CET | 53 | 50782 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:13.123644114 CET | 53 | 58159 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:26.395133018 CET | 53 | 50317 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:58:45.304984093 CET | 53 | 53816 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:59:08.147339106 CET | 53 | 62546 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:59:08.355134964 CET | 53 | 55367 | 1.1.1.1 | 192.168.2.18 |
Jan 7, 2025 14:59:28.240967989 CET | 138 | 138 | 192.168.2.18 | 192.168.2.255 |
Jan 7, 2025 14:59:38.427649021 CET | 53 | 49795 | 1.1.1.1 | 192.168.2.18 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 7, 2025 14:58:09.206964016 CET | 192.168.2.18 | 1.1.1.1 | 0x5412 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 14:58:09.207120895 CET | 192.168.2.18 | 1.1.1.1 | 0x21f9 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 7, 2025 14:58:09.844181061 CET | 192.168.2.18 | 1.1.1.1 | 0xe58c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 14:58:09.844325066 CET | 192.168.2.18 | 1.1.1.1 | 0x276c | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 7, 2025 14:58:09.848751068 CET | 192.168.2.18 | 1.1.1.1 | 0xaf61 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 14:58:09.848903894 CET | 192.168.2.18 | 1.1.1.1 | 0x4f34 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 7, 2025 14:58:13.116854906 CET | 192.168.2.18 | 1.1.1.1 | 0x195d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 14:58:13.116985083 CET | 192.168.2.18 | 1.1.1.1 | 0x17a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 7, 2025 14:58:09.213838100 CET | 1.1.1.1 | 192.168.2.18 | 0x5412 | No error (0) | 209.94.90.1 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 14:58:09.214409113 CET | 1.1.1.1 | 192.168.2.18 | 0x21f9 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 7, 2025 14:58:09.851105928 CET | 1.1.1.1 | 192.168.2.18 | 0x276c | No error (0) | cdn.jsdelivr.net.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 7, 2025 14:58:09.851159096 CET | 1.1.1.1 | 192.168.2.18 | 0xe58c | No error (0) | cdn.jsdelivr.net.cdn.cloudflare.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 7, 2025 14:58:09.855535984 CET | 1.1.1.1 | 192.168.2.18 | 0x4f34 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 7, 2025 14:58:09.855546951 CET | 1.1.1.1 | 192.168.2.18 | 0xaf61 | No error (0) | 104.17.24.14 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 14:58:09.855546951 CET | 1.1.1.1 | 192.168.2.18 | 0xaf61 | No error (0) | 104.17.25.14 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 14:58:13.123507977 CET | 1.1.1.1 | 192.168.2.18 | 0x195d | No error (0) | 142.250.186.132 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 14:58:13.123644114 CET | 1.1.1.1 | 192.168.2.18 | 0x17a | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.18 | 49698 | 209.94.90.1 | 443 | 3084 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 13:58:09 UTC | 797 | OUT | |
2025-01-07 13:58:09 UTC | 1142 | IN | |
2025-01-07 13:58:09 UTC | 227 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN | |
2025-01-07 13:58:09 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.18 | 49703 | 104.17.24.14 | 443 | 3084 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 13:58:10 UTC | 570 | OUT | |
2025-01-07 13:58:10 UTC | 947 | IN | |
2025-01-07 13:58:10 UTC | 422 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN | |
2025-01-07 13:58:10 UTC | 1369 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:58:06 |
Start date: | 07/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff728d30000 |
File size: | 3'242'272 bytes |
MD5 hash: | 83395EAB5B03DEA9720F8D7AC0D15CAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 08:58:07 |
Start date: | 07/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff728d30000 |
File size: | 3'242'272 bytes |
MD5 hash: | 83395EAB5B03DEA9720F8D7AC0D15CAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 08:58:08 |
Start date: | 07/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff728d30000 |
File size: | 3'242'272 bytes |
MD5 hash: | 83395EAB5B03DEA9720F8D7AC0D15CAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |