Windows
Analysis Report
https://lap.gnoqwwhpwe.ru/3aeK/#Dmestevao@iif.com
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
- chrome.exe (PID: 1476 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 290DF23002E9B52249B5549F0C668A86) - chrome.exe (PID: 6876 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --string-a nnotations =is-enterp rise-manag ed=no --fi eld-trial- handle=189 6,i,559507 9606023361 514,168550 6593533632 6724,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction -- variations -seed-vers ion=202412 08-180523. 718000 --m ojo-platfo rm-channel -handle=22 12 /prefet ch:11 MD5: 290DF23002E9B52249B5549F0C668A86)
- chrome.exe (PID: 2292 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://lap.g noqwwhpwe. ru/3aeK/#D mestevao@i if.com" MD5: 290DF23002E9B52249B5549F0C668A86)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Sample URL: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
lap.gnoqwwhpwe.ru | 188.114.97.3 | true | false | high | |
www.google.com | 142.250.185.164 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
188.114.97.3 | lap.gnoqwwhpwe.ru | European Union | 13335 | CLOUDFLARENETUS | false | |
142.250.185.164 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.24 |
192.168.2.23 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1586435 |
Start date and time: | 2025-01-09 05:14:36 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://lap.gnoqwwhpwe.ru/3aeK/#Dmestevao@iif.com |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@17/4@4/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 104.18.38.233, 172.64.149.23, 142.250.184.227, 216.58.212.142, 64.233.166.84, 142.250.186.78, 142.250.185.110, 142.250.184.206, 216.58.206.78, 172.217.16.206, 172.217.18.14, 142.250.181.234, 142.250.74.202, 142.250.185.202, 142.250.185.170, 142.250.186.106, 142.250.186.42, 216.58.206.74, 142.250.186.138, 142.250.185.234, 142.250.185.138, 142.250.186.74, 142.250.185.74, 142.250.186.170, 142.250.184.202, 142.250.184.234, 172.217.16.202, 199.232.214.172, 142.250.186.163, 142.250.185.142, 142.250.186.46, 142.250.185.206, 52.149.20.212, 40.126.24.82
- Excluded domains from analysis (whitelisted): clients1.google.com, client.wns.windows.com, crt.comodoca.com.cdn.cloudflare.net, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.googleapis.com, crt.comodoca.com, x1.c.lencr.org, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, login.live.com, update.googleapis.com, clients.l.google.com, c.pki.goog
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- VT rate limit hit for: https://lap.gnoqwwhpwe.ru/3aeK/#Dmestevao@iif.com
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 553 |
Entropy (8bit): | 4.662821081936326 |
Encrypted: | false |
SSDEEP: | 12:TvgsoCVIogs01lI55aNGlTF5TF5TF5TF5TF5TFK:cEQtnstTPTPTPTPTPTc |
MD5: | 0127426BF3BA07FF7211399DDF5186C4 |
SHA1: | 221D89F3261F545AC58848EBA300E0134C76FF9A |
SHA-256: | 982B986BB578E137F062099427A8CAEC3C501C84A9E4B22369EBD2BADEC42FE7 |
SHA-512: | 6CEA4AB7D43A518A316120BF7AE340583E989A21FC3E142DDD71742D53A7AE6CFA276F232ACD6B6794444B28AA9A666C40171EE44341A7B9A3CA8453B61A371A |
Malicious: | false |
Reputation: | low |
URL: | https://lap.gnoqwwhpwe.ru/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 553 |
Entropy (8bit): | 4.662821081936326 |
Encrypted: | false |
SSDEEP: | 12:TvgsoCVIogs01lI55aNGlTF5TF5TF5TF5TF5TFK:cEQtnstTPTPTPTPTPTc |
MD5: | 0127426BF3BA07FF7211399DDF5186C4 |
SHA1: | 221D89F3261F545AC58848EBA300E0134C76FF9A |
SHA-256: | 982B986BB578E137F062099427A8CAEC3C501C84A9E4B22369EBD2BADEC42FE7 |
SHA-512: | 6CEA4AB7D43A518A316120BF7AE340583E989A21FC3E142DDD71742D53A7AE6CFA276F232ACD6B6794444B28AA9A666C40171EE44341A7B9A3CA8453B61A371A |
Malicious: | false |
Reputation: | low |
URL: | https://lap.gnoqwwhpwe.ru/3aeK/ |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 05:15:35.994632006 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:35.994663954 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:35.994772911 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:35.995151997 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:35.995201111 CET | 443 | 58553 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:35.995369911 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:35.996735096 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:35.996750116 CET | 443 | 58553 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:35.997107983 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:35.997123957 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.659086943 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.661717892 CET | 443 | 58553 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.663573980 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.663588047 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.664047003 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.664067030 CET | 443 | 58553 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.664716005 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.664769888 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.665127039 CET | 443 | 58553 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.665184975 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.682640076 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.682779074 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.685595036 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.685607910 CET | 443 | 58552 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.685664892 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.685691118 CET | 58552 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.686171055 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.686197996 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.686269999 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.687048912 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.687062979 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.687942982 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.687961102 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.688003063 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.688062906 CET | 443 | 58553 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.688143015 CET | 58553 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.688318968 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.688343048 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:36.688399076 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.688787937 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:36.688797951 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.341867924 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.344304085 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.344860077 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.344877005 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.345132113 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.345159054 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.345949888 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.346015930 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.346182108 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.346232891 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.351952076 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.352029085 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.352489948 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.352564096 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.352932930 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.352945089 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.394727945 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.394737005 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.394736052 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.442760944 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.474287033 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.474361897 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.474442959 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.477371931 CET | 58555 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.477391005 CET | 443 | 58555 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.571747065 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.619334936 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.666229963 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.666327953 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:37.666501045 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.667814016 CET | 58554 | 443 | 192.168.2.24 | 188.114.97.3 |
Jan 9, 2025 05:15:37.667835951 CET | 443 | 58554 | 188.114.97.3 | 192.168.2.24 |
Jan 9, 2025 05:15:39.421503067 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:39.421559095 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:39.421622038 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:39.421912909 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:39.421928883 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:40.266192913 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:40.266503096 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:40.266524076 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:40.267524004 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:40.267594099 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:40.271789074 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:40.271912098 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:40.325759888 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:40.325773001 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:40.373759985 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:50.178922892 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:50.179020882 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:15:50.179095984 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:51.394536972 CET | 58556 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:15:51.394562006 CET | 443 | 58556 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:17.473308086 CET | 49728 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 9, 2025 05:16:17.473385096 CET | 49727 | 443 | 192.168.2.24 | 98.64.238.3 |
Jan 9, 2025 05:16:17.473423004 CET | 58528 | 80 | 192.168.2.24 | 204.79.197.203 |
Jan 9, 2025 05:16:17.478429079 CET | 80 | 49728 | 192.229.221.95 | 192.168.2.24 |
Jan 9, 2025 05:16:17.478487968 CET | 49728 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 9, 2025 05:16:17.478769064 CET | 443 | 49727 | 98.64.238.3 | 192.168.2.24 |
Jan 9, 2025 05:16:17.478780985 CET | 80 | 58528 | 204.79.197.203 | 192.168.2.24 |
Jan 9, 2025 05:16:17.478822947 CET | 49727 | 443 | 192.168.2.24 | 98.64.238.3 |
Jan 9, 2025 05:16:17.478872061 CET | 58528 | 80 | 192.168.2.24 | 204.79.197.203 |
Jan 9, 2025 05:16:17.543051958 CET | 58560 | 80 | 192.168.2.24 | 142.250.185.131 |
Jan 9, 2025 05:16:17.547847986 CET | 80 | 58560 | 142.250.185.131 | 192.168.2.24 |
Jan 9, 2025 05:16:17.547919989 CET | 58560 | 80 | 192.168.2.24 | 142.250.185.131 |
Jan 9, 2025 05:16:17.547997952 CET | 58560 | 80 | 192.168.2.24 | 142.250.185.131 |
Jan 9, 2025 05:16:17.552797079 CET | 80 | 58560 | 142.250.185.131 | 192.168.2.24 |
Jan 9, 2025 05:16:18.170861006 CET | 80 | 58560 | 142.250.185.131 | 192.168.2.24 |
Jan 9, 2025 05:16:18.186794043 CET | 58561 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 9, 2025 05:16:18.191648006 CET | 80 | 58561 | 23.209.209.135 | 192.168.2.24 |
Jan 9, 2025 05:16:18.191735983 CET | 58561 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 9, 2025 05:16:18.191836119 CET | 58561 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 9, 2025 05:16:18.196564913 CET | 80 | 58561 | 23.209.209.135 | 192.168.2.24 |
Jan 9, 2025 05:16:18.220911026 CET | 58560 | 80 | 192.168.2.24 | 142.250.185.131 |
Jan 9, 2025 05:16:18.876586914 CET | 80 | 58561 | 23.209.209.135 | 192.168.2.24 |
Jan 9, 2025 05:16:18.883666992 CET | 58529 | 80 | 192.168.2.24 | 2.22.50.131 |
Jan 9, 2025 05:16:18.889079094 CET | 80 | 58529 | 2.22.50.131 | 192.168.2.24 |
Jan 9, 2025 05:16:18.889157057 CET | 58529 | 80 | 192.168.2.24 | 2.22.50.131 |
Jan 9, 2025 05:16:18.918380022 CET | 58561 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 9, 2025 05:16:19.388756037 CET | 58533 | 80 | 192.168.2.24 | 2.22.50.131 |
Jan 9, 2025 05:16:19.393915892 CET | 80 | 58533 | 2.22.50.131 | 192.168.2.24 |
Jan 9, 2025 05:16:19.393989086 CET | 58533 | 80 | 192.168.2.24 | 2.22.50.131 |
Jan 9, 2025 05:16:39.475126982 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:39.475167036 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:39.475263119 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:39.475589037 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:39.475605965 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:40.309340954 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:40.309669971 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:40.309701920 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:40.310103893 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:40.310524940 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:40.310589075 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:40.365953922 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:43.023221970 CET | 49673 | 443 | 192.168.2.24 | 20.198.118.190 |
Jan 9, 2025 05:16:43.023282051 CET | 443 | 49673 | 20.198.118.190 | 192.168.2.24 |
Jan 9, 2025 05:16:43.652349949 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:43.652390957 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:43.652513981 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:43.653584957 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:43.653599024 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:44.458965063 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:44.459044933 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:44.467351913 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:44.467370033 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:44.467580080 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:44.494342089 CET | 65034 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:16:44.499192953 CET | 53 | 65034 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:44.499283075 CET | 65034 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:16:44.504163027 CET | 53 | 65034 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:44.509972095 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:44.954212904 CET | 65034 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:16:44.959342957 CET | 53 | 65034 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:44.959400892 CET | 65034 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:16:45.713217974 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:45.713294983 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:45.713305950 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:45.713593960 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:45.755337954 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:45.887372017 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:45.887463093 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:45.887538910 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:45.887712955 CET | 58565 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:45.887734890 CET | 443 | 58565 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:46.512624025 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:46.512676954 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:46.512749910 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:46.513565063 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:46.513581038 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.317718983 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.317856073 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.320305109 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.320324898 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.320575953 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.324779034 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.324831009 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.324840069 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.324947119 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.367341995 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.499170065 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.499330044 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:47.499413013 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.499514103 CET | 65036 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:47.499537945 CET | 443 | 65036 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:50.237309933 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:50.237382889 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:50.237591028 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:50.869847059 CET | 443 | 49726 | 2.16.158.192 | 192.168.2.24 |
Jan 9, 2025 05:16:50.869987011 CET | 443 | 49726 | 2.16.158.192 | 192.168.2.24 |
Jan 9, 2025 05:16:50.870002031 CET | 49726 | 443 | 192.168.2.24 | 2.16.158.192 |
Jan 9, 2025 05:16:50.870039940 CET | 49726 | 443 | 192.168.2.24 | 2.16.158.192 |
Jan 9, 2025 05:16:51.390872002 CET | 58564 | 443 | 192.168.2.24 | 142.250.185.164 |
Jan 9, 2025 05:16:51.390912056 CET | 443 | 58564 | 142.250.185.164 | 192.168.2.24 |
Jan 9, 2025 05:16:55.697087049 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:55.697148085 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:55.697243929 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:55.699717999 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:55.699731112 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.498748064 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.498845100 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.501321077 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.501332045 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.501533031 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.505767107 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.505826950 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.505831957 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.505940914 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.551340103 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.679656029 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.679801941 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:16:56.679864883 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.680075884 CET | 65037 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:16:56.680093050 CET | 443 | 65037 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:09.473268986 CET | 58538 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 9, 2025 05:17:09.478362083 CET | 80 | 58538 | 192.229.221.95 | 192.168.2.24 |
Jan 9, 2025 05:17:09.478441954 CET | 58538 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 9, 2025 05:17:11.591456890 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:11.591517925 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:11.591654062 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:11.592518091 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:11.592533112 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.009319067 CET | 58540 | 443 | 192.168.2.24 | 184.28.90.27 |
Jan 9, 2025 05:17:12.014491081 CET | 443 | 58540 | 184.28.90.27 | 192.168.2.24 |
Jan 9, 2025 05:17:12.014559031 CET | 58540 | 443 | 192.168.2.24 | 184.28.90.27 |
Jan 9, 2025 05:17:12.169326067 CET | 58544 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 9, 2025 05:17:12.169327021 CET | 58542 | 443 | 192.168.2.24 | 40.126.31.67 |
Jan 9, 2025 05:17:12.174350977 CET | 443 | 58542 | 40.126.31.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.174417019 CET | 58542 | 443 | 192.168.2.24 | 40.126.31.67 |
Jan 9, 2025 05:17:12.174628973 CET | 80 | 58544 | 192.229.221.95 | 192.168.2.24 |
Jan 9, 2025 05:17:12.174685955 CET | 58544 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 9, 2025 05:17:12.376204967 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.376326084 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.379075050 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.379085064 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.379328012 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.382801056 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.382858992 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.382863045 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.382957935 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.423322916 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.552963018 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.553081036 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:12.553139925 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.553265095 CET | 65039 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:12.553280115 CET | 443 | 65039 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:13.088129044 CET | 58545 | 443 | 192.168.2.24 | 184.28.90.27 |
Jan 9, 2025 05:17:13.093293905 CET | 443 | 58545 | 184.28.90.27 | 192.168.2.24 |
Jan 9, 2025 05:17:13.093364954 CET | 58545 | 443 | 192.168.2.24 | 184.28.90.27 |
Jan 9, 2025 05:17:19.605181932 CET | 58561 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 9, 2025 05:17:19.605217934 CET | 58560 | 80 | 192.168.2.24 | 142.250.185.131 |
Jan 9, 2025 05:17:19.610318899 CET | 80 | 58561 | 23.209.209.135 | 192.168.2.24 |
Jan 9, 2025 05:17:19.610390902 CET | 58561 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 9, 2025 05:17:19.610640049 CET | 80 | 58560 | 142.250.185.131 | 192.168.2.24 |
Jan 9, 2025 05:17:19.610697985 CET | 58560 | 80 | 192.168.2.24 | 142.250.185.131 |
Jan 9, 2025 05:17:30.078634977 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.078691006 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:30.078820944 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.079760075 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.079777002 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:30.899961948 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:30.900094986 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.902654886 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.902667046 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:30.902873993 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:30.910855055 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.910913944 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.910918951 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:30.911056042 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:30.955326080 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:31.085356951 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:31.085428953 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Jan 9, 2025 05:17:31.085494995 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:31.086059093 CET | 65040 | 443 | 192.168.2.24 | 40.113.110.67 |
Jan 9, 2025 05:17:31.086077929 CET | 443 | 65040 | 40.113.110.67 | 192.168.2.24 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 05:15:35.175762892 CET | 53 | 56046 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:35.176563025 CET | 53 | 60185 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:35.849566936 CET | 60416 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:15:35.849741936 CET | 54284 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:15:35.901432991 CET | 53 | 54284 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:35.948386908 CET | 53 | 60416 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:36.712111950 CET | 53 | 61405 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:39.413682938 CET | 63953 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:15:39.414005995 CET | 62283 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 9, 2025 05:15:39.420460939 CET | 53 | 63953 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:39.420630932 CET | 53 | 62283 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:15:53.802376986 CET | 53 | 62478 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:04.409873009 CET | 53 | 55315 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:12.626971960 CET | 53 | 58029 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:34.725281000 CET | 53 | 53191 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:35.097383976 CET | 53 | 62086 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:16:44.493807077 CET | 53 | 54205 | 1.1.1.1 | 192.168.2.24 |
Jan 9, 2025 05:17:04.634185076 CET | 53 | 54797 | 1.1.1.1 | 192.168.2.24 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 9, 2025 05:15:35.849566936 CET | 192.168.2.24 | 1.1.1.1 | 0x224e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 05:15:35.849741936 CET | 192.168.2.24 | 1.1.1.1 | 0xb30c | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 05:15:39.413682938 CET | 192.168.2.24 | 1.1.1.1 | 0xb69a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 05:15:39.414005995 CET | 192.168.2.24 | 1.1.1.1 | 0xb795 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 9, 2025 05:15:35.901432991 CET | 1.1.1.1 | 192.168.2.24 | 0xb30c | No error (0) | 65 | IN (0x0001) | false | |||
Jan 9, 2025 05:15:35.948386908 CET | 1.1.1.1 | 192.168.2.24 | 0x224e | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 05:15:35.948386908 CET | 1.1.1.1 | 192.168.2.24 | 0x224e | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 05:15:39.420460939 CET | 1.1.1.1 | 192.168.2.24 | 0xb69a | No error (0) | 142.250.185.164 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 05:15:39.420630932 CET | 1.1.1.1 | 192.168.2.24 | 0xb795 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.24 | 58560 | 142.250.185.131 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 9, 2025 05:16:17.547997952 CET | 200 | OUT | |
Jan 9, 2025 05:16:18.170861006 CET | 223 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.24 | 58561 | 23.209.209.135 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 9, 2025 05:16:18.191836119 CET | 227 | OUT | |
Jan 9, 2025 05:16:18.876586914 CET | 1023 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.24 | 58555 | 188.114.97.3 | 443 | 6876 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:15:37 UTC | 672 | OUT | |
2025-01-09 04:15:37 UTC | 178 | IN | |
2025-01-09 04:15:37 UTC | 553 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 58554 | 188.114.97.3 | 443 | 6876 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:15:37 UTC | 602 | OUT | |
2025-01-09 04:15:37 UTC | 178 | IN | |
2025-01-09 04:15:37 UTC | 553 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.24 | 58565 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:16:45 UTC | 71 | OUT | |
2025-01-09 04:16:45 UTC | 260 | OUT | |
2025-01-09 04:16:45 UTC | 1084 | OUT | |
2025-01-09 04:16:45 UTC | 224 | OUT | |
2025-01-09 04:16:45 UTC | 14 | IN | |
2025-01-09 04:16:45 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.24 | 65036 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:16:47 UTC | 71 | OUT | |
2025-01-09 04:16:47 UTC | 260 | OUT | |
2025-01-09 04:16:47 UTC | 1084 | OUT | |
2025-01-09 04:16:47 UTC | 224 | OUT | |
2025-01-09 04:16:47 UTC | 14 | IN | |
2025-01-09 04:16:47 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.24 | 65037 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:16:56 UTC | 71 | OUT | |
2025-01-09 04:16:56 UTC | 260 | OUT | |
2025-01-09 04:16:56 UTC | 1084 | OUT | |
2025-01-09 04:16:56 UTC | 224 | OUT | |
2025-01-09 04:16:56 UTC | 14 | IN | |
2025-01-09 04:16:56 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
5 | 192.168.2.24 | 65039 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:17:12 UTC | 71 | OUT | |
2025-01-09 04:17:12 UTC | 260 | OUT | |
2025-01-09 04:17:12 UTC | 1084 | OUT | |
2025-01-09 04:17:12 UTC | 224 | OUT | |
2025-01-09 04:17:12 UTC | 14 | IN | |
2025-01-09 04:17:12 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
6 | 192.168.2.24 | 65040 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 04:17:30 UTC | 71 | OUT | |
2025-01-09 04:17:30 UTC | 260 | OUT | |
2025-01-09 04:17:30 UTC | 1084 | OUT | |
2025-01-09 04:17:30 UTC | 224 | OUT | |
2025-01-09 04:17:31 UTC | 14 | IN | |
2025-01-09 04:17:31 UTC | 58 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 23:15:32 |
Start date: | 08/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff701a30000 |
File size: | 3'001'952 bytes |
MD5 hash: | 290DF23002E9B52249B5549F0C668A86 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 23:15:33 |
Start date: | 08/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff701a30000 |
File size: | 3'001'952 bytes |
MD5 hash: | 290DF23002E9B52249B5549F0C668A86 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 23:15:35 |
Start date: | 08/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff701a30000 |
File size: | 3'001'952 bytes |
MD5 hash: | 290DF23002E9B52249B5549F0C668A86 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |