Windows
Analysis Report
https://mickhall.co.uk/owa-auth-logon.aspx/index.html
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 1908 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 4928 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2256 --fi eld-trial- handle=220 4,i,179880 9654745935 4591,22575 0987574231 0024,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6600 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://mickh all.co.uk/ owa-auth-l ogon.aspx/ index.html " MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Obfuscated Files or Information | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
mickhall.co.uk | 149.255.62.140 | true | true | unknown | |
www.google.com | 142.250.185.132 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true | unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
149.255.62.140 | mickhall.co.uk | United Kingdom | 34931 | AWARESOFTGB | true |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1585898 |
Start date and time: | 2025-01-08 13:34:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 58s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://mickhall.co.uk/owa-auth-logon.aspx/index.html |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.phis.win@16/10@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.181.238, 142.250.110.84, 172.217.18.14, 142.250.185.174, 142.250.185.110, 142.250.185.202, 142.250.185.106, 142.250.185.234, 142.250.186.42, 142.250.186.138, 142.250.185.138, 142.250.185.170, 216.58.212.170, 216.58.206.74, 142.250.186.74, 142.250.184.234, 142.250.186.106, 142.250.74.202, 172.217.18.10, 172.217.16.202, 142.250.185.74, 142.250.185.78, 199.232.214.172, 192.229.221.95, 142.250.186.78, 142.250.186.174, 216.58.206.78, 142.250.186.163, 184.28.90.27, 20.109.210.53, 13.107.253.45
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://mickhall.co.uk/owa-auth-logon.aspx/index.html
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 44 |
Entropy (8bit): | 4.5077429145253145 |
Encrypted: | false |
SSDEEP: | 3:sLei3Xa8LDaGqJ:sRn5LDNqJ |
MD5: | E136EDEEEF6EF9664E8A32591220ACDE |
SHA1: | 5EF9885CE46D548EE8A3329E2DB59828A19154B8 |
SHA-256: | 28987AB581BF8E488474FCE077C4CEBF78F16915107D9F34E2AF64E53BEFA4E3 |
SHA-512: | F4583448A1146B61405BBB524284213F56B9ACAAB7552E3A8B8230C04B2B3EE5B3A08561536C19A9B58076D2D17B5512B903B424713DFCE5206B42B80B08DD13 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHglgBkYPbypYzhIFDXhvEhkSBQ2e7oKCEgUNzkFMeg==?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 67163 |
Entropy (8bit): | 7.965220156452789 |
Encrypted: | false |
SSDEEP: | 1536:z0OFsomr/6f87Ke93+VAyUfDZvYXCn6vn2B7:z0OFsbr/607d931VeC0nI |
MD5: | 1D1797586EB441DA3E3E237C56717206 |
SHA1: | F614DAC31228EF93C826FD4DEE5E6D1622AEEE9B |
SHA-256: | AC3E6457B3B51A35DAA8140DC38F863E27DC92CC45EACBF5DA3E2C7CD4E7EE67 |
SHA-512: | 88192FA6AC61D5DED23AE73DB468FF419BF8552AE9923EB23C388D222DE17D8F111B8E03C71BF68B9CEE9A65A929DA8ADFF305A3076198BB5BF1333A545ABE40 |
Malicious: | false |
Reputation: | low |
URL: | https://mickhall.co.uk/owa-auth-logon.aspx/image.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7886 |
Entropy (8bit): | 3.5472733281483655 |
Encrypted: | false |
SSDEEP: | 48:g8KokgDQoxTP0Vh0jV/H2kPxL6GUEtcrCOmgfzQumtGCzYoITin0iarrWtwVWsiw:97DdTGhGW6yS7Kvs/WjiUKqWmNQOWY |
MD5: | 759FADE9033AA298629E4B000DCD6DDE |
SHA1: | 34A1ADF5C7326D7BDE5B5735471B5D81E611C189 |
SHA-256: | CF0808A61EC571E0C4975663903B288009D55502AC0445D9948983B339A5CF6E |
SHA-512: | E96E93B13D70420D4D509D89A6337651440AE049B2A23D57C6250987003C46512C40C85C41BFA1C473A704801C961FFBE421522B89A1C34BA3B9E82A6D0769ED |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 67163 |
Entropy (8bit): | 7.965220156452789 |
Encrypted: | false |
SSDEEP: | 1536:z0OFsomr/6f87Ke93+VAyUfDZvYXCn6vn2B7:z0OFsbr/607d931VeC0nI |
MD5: | 1D1797586EB441DA3E3E237C56717206 |
SHA1: | F614DAC31228EF93C826FD4DEE5E6D1622AEEE9B |
SHA-256: | AC3E6457B3B51A35DAA8140DC38F863E27DC92CC45EACBF5DA3E2C7CD4E7EE67 |
SHA-512: | 88192FA6AC61D5DED23AE73DB468FF419BF8552AE9923EB23C388D222DE17D8F111B8E03C71BF68B9CEE9A65A929DA8ADFF305A3076198BB5BF1333A545ABE40 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4528 |
Entropy (8bit): | 4.425452399299421 |
Encrypted: | false |
SSDEEP: | 48:tkOZ9PYDX6PAEjrDcsC+DGtB3HxBqKTANo9SX0GFVfgFljHuK:Gi9jJjrDcsv6jRTIC |
MD5: | FEBF3D757C83E76EC5ED0E65AC060054 |
SHA1: | 5AC544D2B31936CC10B1214D2AE6EB170BC214CB |
SHA-256: | E43CBDCF6A82A2D29F2D96DF05CE11B68C81ED85F96CA1DD74EA1CA9874624ED |
SHA-512: | 153CD179713796F5A9B81247E728D25B00D7A6740E4DEA2420E635D9EFBF1CE56929F0F330D31B222287286AC4D670E7A4ADE685AABB924221994ECFA4A4B091 |
Malicious: | false |
Reputation: | low |
URL: | https://mickhall.co.uk/owa-auth-logon.aspx/index.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7886 |
Entropy (8bit): | 3.5472733281483655 |
Encrypted: | false |
SSDEEP: | 48:g8KokgDQoxTP0Vh0jV/H2kPxL6GUEtcrCOmgfzQumtGCzYoITin0iarrWtwVWsiw:97DdTGhGW6yS7Kvs/WjiUKqWmNQOWY |
MD5: | 759FADE9033AA298629E4B000DCD6DDE |
SHA1: | 34A1ADF5C7326D7BDE5B5735471B5D81E611C189 |
SHA-256: | CF0808A61EC571E0C4975663903B288009D55502AC0445D9948983B339A5CF6E |
SHA-512: | E96E93B13D70420D4D509D89A6337651440AE049B2A23D57C6250987003C46512C40C85C41BFA1C473A704801C961FFBE421522B89A1C34BA3B9E82A6D0769ED |
Malicious: | false |
Reputation: | low |
URL: | https://mickhall.co.uk/owa-auth-logon.aspx/favicon.ico |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 8, 2025 13:34:56.973453045 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 8, 2025 13:35:06.582357883 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 8, 2025 13:35:09.137464046 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.137501955 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.137573004 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.137785912 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.137800932 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.870126009 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.871783018 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.871804953 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.872790098 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.872867107 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.874063969 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.874141932 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.930030107 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:09.930048943 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:09.972740889 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:10.538258076 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:10.538288116 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:10.538355112 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:10.538664103 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:10.538677931 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:10.547250032 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:10.547292948 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:10.547354937 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:10.547566891 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:10.547581911 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.244169950 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.246356010 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.265264988 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.265286922 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.265739918 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.265757084 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.266161919 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.266222954 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.266639948 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.266700029 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.286880016 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.286956072 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.287408113 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.287430048 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.289083958 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.289158106 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.338104963 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.338140011 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.338149071 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.383764029 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.582268953 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.582289934 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.582298040 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.582343102 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.582369089 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.582405090 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.596515894 CET | 49741 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.596539021 CET | 443 | 49741 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.607501030 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.651328087 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869616032 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869636059 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869647026 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869669914 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869682074 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869688988 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869708061 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.869725943 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869757891 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.869760036 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.869775057 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.877007961 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.877023935 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.877041101 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.877062082 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.877069950 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.877090931 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.877118111 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.919131041 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.959330082 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.959338903 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.959367990 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.959398985 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.959418058 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.959431887 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.959480047 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.959501028 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.966384888 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.966402054 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.966470957 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.966476917 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.966803074 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.966847897 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.966852903 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.966861010 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.966895103 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.976216078 CET | 49740 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.976227045 CET | 443 | 49740 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.983875036 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.983910084 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:11.984087944 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.984289885 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:11.984303951 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.022727966 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.022762060 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.022825003 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.023027897 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.023041964 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.711401939 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.711739063 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.711754084 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.712044001 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.712555885 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.712606907 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.712977886 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.755328894 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.855503082 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.855732918 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.855761051 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.856631041 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.856682062 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.857012033 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.857069016 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.857157946 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:12.857165098 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:12.910078049 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.000869989 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.000891924 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.000941992 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.000951052 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.000989914 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.002465963 CET | 49744 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.002481937 CET | 443 | 49744 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.006562948 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.006578922 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.006633043 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.006989002 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.007000923 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308659077 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308671951 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308680058 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308708906 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308716059 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308722019 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308896065 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.308896065 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.308933020 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.308984041 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.325743914 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.325759888 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.325828075 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.325845957 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.370744944 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.412761927 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.412770987 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.412818909 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.412827969 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.412980080 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.412980080 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.412995100 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.415558100 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.447634935 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.447664976 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.447702885 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.447757959 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.447832108 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.447832108 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.459348917 CET | 49745 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.459366083 CET | 443 | 49745 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.816405058 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.816704988 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.816725016 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.817029953 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.817450047 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.817508936 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:13.817625999 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:13.863318920 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:14.113236904 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:14.113255024 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:14.113307953 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:14.113339901 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:14.113383055 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:14.115597010 CET | 49746 | 443 | 192.168.2.4 | 149.255.62.140 |
Jan 8, 2025 13:35:14.115608931 CET | 443 | 49746 | 149.255.62.140 | 192.168.2.4 |
Jan 8, 2025 13:35:19.771843910 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:19.771905899 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:35:19.772027969 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:21.506731987 CET | 49738 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:35:21.506745100 CET | 443 | 49738 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.186563969 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:09.186575890 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.186640024 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:09.186877012 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:09.186887026 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.833390951 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.875839949 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:09.875866890 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.876302958 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.876969099 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:09.877042055 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:09.919428110 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:14.426882029 CET | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Jan 8, 2025 13:36:14.426942110 CET | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Jan 8, 2025 13:36:14.431879044 CET | 80 | 49723 | 199.232.210.172 | 192.168.2.4 |
Jan 8, 2025 13:36:14.431953907 CET | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Jan 8, 2025 13:36:14.432284117 CET | 80 | 49724 | 199.232.210.172 | 192.168.2.4 |
Jan 8, 2025 13:36:14.432336092 CET | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Jan 8, 2025 13:36:19.740052938 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:19.740124941 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Jan 8, 2025 13:36:19.740180016 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:21.546312094 CET | 49796 | 443 | 192.168.2.4 | 142.250.185.132 |
Jan 8, 2025 13:36:21.546344042 CET | 443 | 49796 | 142.250.185.132 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 8, 2025 13:35:05.287344933 CET | 53 | 59331 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:05.330305099 CET | 53 | 58813 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:06.591134071 CET | 53 | 61422 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:09.129853010 CET | 50117 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 8, 2025 13:35:09.129966021 CET | 49455 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 8, 2025 13:35:09.136610031 CET | 53 | 49455 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:09.136624098 CET | 53 | 50117 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:10.486804962 CET | 63349 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 8, 2025 13:35:10.487020969 CET | 50394 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 8, 2025 13:35:10.519623041 CET | 53 | 63349 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:10.537832975 CET | 53 | 50394 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:11.681082010 CET | 53 | 55847 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:11.987232924 CET | 49520 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 8, 2025 13:35:11.987552881 CET | 52693 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 8, 2025 13:35:11.994429111 CET | 53 | 52693 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:12.022181988 CET | 53 | 49520 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:23.621944904 CET | 53 | 53955 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:35:25.994853020 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Jan 8, 2025 13:35:42.443726063 CET | 53 | 62647 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:36:04.794411898 CET | 53 | 52317 | 1.1.1.1 | 192.168.2.4 |
Jan 8, 2025 13:36:05.356209993 CET | 53 | 57610 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 8, 2025 13:35:09.129853010 CET | 192.168.2.4 | 1.1.1.1 | 0x51b5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 8, 2025 13:35:09.129966021 CET | 192.168.2.4 | 1.1.1.1 | 0x8d14 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 8, 2025 13:35:10.486804962 CET | 192.168.2.4 | 1.1.1.1 | 0x3f8a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 8, 2025 13:35:10.487020969 CET | 192.168.2.4 | 1.1.1.1 | 0xa380 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 8, 2025 13:35:11.987232924 CET | 192.168.2.4 | 1.1.1.1 | 0x6f6e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 8, 2025 13:35:11.987552881 CET | 192.168.2.4 | 1.1.1.1 | 0x617 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 8, 2025 13:35:09.136610031 CET | 1.1.1.1 | 192.168.2.4 | 0x8d14 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 8, 2025 13:35:09.136624098 CET | 1.1.1.1 | 192.168.2.4 | 0x51b5 | No error (0) | 142.250.185.132 | A (IP address) | IN (0x0001) | false | ||
Jan 8, 2025 13:35:10.519623041 CET | 1.1.1.1 | 192.168.2.4 | 0x3f8a | No error (0) | 149.255.62.140 | A (IP address) | IN (0x0001) | false | ||
Jan 8, 2025 13:35:12.022181988 CET | 1.1.1.1 | 192.168.2.4 | 0x6f6e | No error (0) | 149.255.62.140 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49741 | 149.255.62.140 | 443 | 4928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-08 12:35:11 UTC | 687 | OUT | |
2025-01-08 12:35:11 UTC | 251 | IN | |
2025-01-08 12:35:11 UTC | 4528 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49740 | 149.255.62.140 | 443 | 4928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-08 12:35:11 UTC | 632 | OUT | |
2025-01-08 12:35:11 UTC | 206 | IN | |
2025-01-08 12:35:11 UTC | 16178 | IN | |
2025-01-08 12:35:11 UTC | 16384 | IN | |
2025-01-08 12:35:11 UTC | 16384 | IN | |
2025-01-08 12:35:11 UTC | 16384 | IN | |
2025-01-08 12:35:11 UTC | 1833 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49744 | 149.255.62.140 | 443 | 4928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-08 12:35:12 UTC | 634 | OUT | |
2025-01-08 12:35:12 UTC | 254 | IN | |
2025-01-08 12:35:12 UTC | 7886 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49745 | 149.255.62.140 | 443 | 4928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-08 12:35:12 UTC | 367 | OUT | |
2025-01-08 12:35:13 UTC | 206 | IN | |
2025-01-08 12:35:13 UTC | 16178 | IN | |
2025-01-08 12:35:13 UTC | 16384 | IN | |
2025-01-08 12:35:13 UTC | 16384 | IN | |
2025-01-08 12:35:13 UTC | 16384 | IN | |
2025-01-08 12:35:13 UTC | 1833 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49746 | 149.255.62.140 | 443 | 4928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-08 12:35:13 UTC | 369 | OUT | |
2025-01-08 12:35:14 UTC | 254 | IN | |
2025-01-08 12:35:14 UTC | 7886 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 07:35:00 |
Start date: | 08/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 07:35:03 |
Start date: | 08/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 07:35:09 |
Start date: | 08/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |