Windows
Analysis Report
http://zwibbdq.trackbest.click/6/128767/262/1494/873186/403/9/4avg5x4ni5
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3348 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2428 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2268 --fi eld-trial- handle=215 6,i,157369 0947876139 1179,14924 7886424553 46770,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 5880 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://zwibbd q.trackbes t.click/6/ 128767/262 /1494/8731 86/403/9/4 avg5x4ni5" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
code.jquery.com | 151.101.66.137 | true | false | high | |
www.google.com | 142.250.181.228 | true | false | high | |
zwibbdq.trackbest.click | 23.228.85.252 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
true | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
216.58.212.132 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.181.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
23.228.85.252 | zwibbdq.trackbest.click | United States | 46573 | LAYER-HOSTUS | true | |
151.101.66.137 | code.jquery.com | United States | 54113 | FASTLYUS | false | |
151.101.194.137 | unknown | United States | 54113 | FASTLYUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1586743 |
Start date and time: | 2025-01-09 15:15:59 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://zwibbdq.trackbest.click/6/128767/262/1494/873186/403/9/4avg5x4ni5 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal60.win@16/17@10/7 |
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 216.58.206.35, 142.250.185.238, 142.251.5.84, 142.250.184.206, 172.217.18.110, 216.58.206.42, 172.217.18.106, 142.250.184.202, 142.250.185.74, 142.250.74.202, 172.217.16.202, 142.250.186.42, 172.217.18.10, 142.250.184.234, 142.250.185.138, 172.217.16.138, 142.250.185.106, 142.250.185.170, 216.58.212.170, 142.250.186.74, 216.58.206.74, 199.232.214.172, 192.229.221.95, 142.250.185.206, 142.250.74.206, 142.250.185.78, 172.217.16.206, 172.217.18.14, 199.232.210.172, 23.56.254.164, 23.1.237.91, 172.202.163.200, 23.1.237.16, 13.107.246.45
- Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, r.bing.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: http://zwibbdq.trackbest.click/6/128767/262/1494/873186/403/9/4avg5x4ni5
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9779566244569526 |
Encrypted: | false |
SSDEEP: | 48:8ddATk4OHUidAKZdA19ehwiZUklqehQy+3:8wfR/y |
MD5: | 3ABBBB96646015DB2A9B70597FCB1307 |
SHA1: | 2B536C3E9766F0AE5002C5C155288883CEAF9EFA |
SHA-256: | 2147B8FBF8C90A79EBEA7A2AD033FF52B233071D0702DD31FAF252CB1737EB79 |
SHA-512: | E036C1BE04C0ACD9FCE62238A2DAAE3EF5E9C7074B1EE080182AE3016AFC92E8A9A9C44A4D9E87A075CD54EE7CF6127307E3BD9E0523E9A7F288D9BC8E558672 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9904892115965174 |
Encrypted: | false |
SSDEEP: | 48:8jdATk4OHUidAKZdA1weh/iZUkAQkqehvy+2:8efj9QWy |
MD5: | DB9085C62DC2AE8929BF812E982C7A52 |
SHA1: | 09B3364AB7C586FFD46032B49354285AF7457B2B |
SHA-256: | F2A029563A55509732A02D96C002B19522A41581B5B29941D5F3A82F1F37A61D |
SHA-512: | 6CE24A709489D0D264DC1E2EDE198A6869D923BC7D84376D453A9468BC96559C0009A1C7244197A38F2FA7D62FEE2DFDCE08652CA66EBC2936B35E999A00E8CE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.004870552337598 |
Encrypted: | false |
SSDEEP: | 48:8xBdATk4sHUidAKZdA14tseh7sFiZUkmgqeh7sdy+BX:8xUfNnLy |
MD5: | 27FFD09EDEC0D03A77188D21EE7E82DB |
SHA1: | DE1F984D7BE3B945B8264A7D0AD87F1E4CDA322B |
SHA-256: | A927481DBACD8765F30AC20FA97F42DA8427E5517361A1C0929A00CFDBC7BB6B |
SHA-512: | D1BF78CEDE7B3A5495E781961D7C4C082BF27070AF5811A5BF8B854B3E63F672E85989B04F6359AB796EE52229ED8100BC0E64BF4A823294306F283E6F4F4A55 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.988846981941629 |
Encrypted: | false |
SSDEEP: | 48:8mdATk4OHUidAKZdA1vehDiZUkwqehjy+R:8JfAVy |
MD5: | C3E8C6BCE71EA8D65495543C1793A576 |
SHA1: | E820D628A5DABA0FD18CA9CFBE686D92CA87443C |
SHA-256: | ACA6C00F51BA709FA29501B9D71AE0A9922A157288D35C1857DCBFE24D836AFD |
SHA-512: | 679AB05A7FAEBFC81520BB4E7708162BCDB209660B7C97B57794588050040F00ADD66A048C1CA45C3BEB56A47148BA4BE0B35C74561AE2FDEF3CB0868A8B9EFE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9788897536105825 |
Encrypted: | false |
SSDEEP: | 48:8mdATk4OHUidAKZdA1hehBiZUk1W1qehJy+C:8Jfg9py |
MD5: | 73AC4ED5BC27EF94E3786E985E31990F |
SHA1: | D88AED8CAF56756BD99F0F6A3D84888EA3A81316 |
SHA-256: | 92BD93EEF87E1B4EDCF8520B3F8D1C15465D84B7610A04695CE56BBDB2163FD4 |
SHA-512: | 275CE745B8BD5DB8CF861B1D1D2FB6FF6634202FC79C045120C75B536110AE2751353E97E560C3B4361DECBCFCDAA14DED39739A7BB16AA23EA48D80324764A3 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.991675364902943 |
Encrypted: | false |
SSDEEP: | 48:8odATk4OHUidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:8bfuT/TbxWOvTbLy7T |
MD5: | 0E81DB473DE99FE0AAF4F2B16C9FE0FE |
SHA1: | 559E4EFE25953B294DC96B9D7ABC4A1126E90D66 |
SHA-256: | F8E398C9086127F3A2E596271A3CAB84CB7B14FCC5F8B6C00D6A7AAB4FF24C83 |
SHA-512: | F4AD7CDB870C8775C5EC3BFEC6CA4205AEDBF8322A4360EADA29AA3856ABC9E731C7E8F708A74728544EE418BB5264B1FAC33A7B4AD1966DD7EB6DE1E1794B6C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | 1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2696 |
Entropy (8bit): | 4.865640946455255 |
Encrypted: | false |
SSDEEP: | 48:IK0QVQkCEpkhzzgxvf/wQEH0vdkZMv9NK:JQkTR13reGdvi |
MD5: | 6BE633315EF9CFB35290CFDE5924EA7E |
SHA1: | B1AC364A9325BBB1DCCC6DF0B78355AB5DBBB98E |
SHA-256: | 515C78713BC1FB7F9F440661B0105D0A340D7CE01BFC615B3E3E71C1B6660C08 |
SHA-512: | 988274FCD9AB74BA161653302C3812217548355B1DAF78C73F3CD8B6E78C9FC372121D8C83C2C8AADB868CB2B64D5314977D3194416E06DDCD7B099700857D23 |
Malicious: | false |
Reputation: | low |
URL: | http://zwibbdq.trackbest.click/opt-out/t/6/128767/262/1494/873186/403/9/4avg5x4ni5 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1435 |
Entropy (8bit): | 4.7130828204283555 |
Encrypted: | false |
SSDEEP: | 24:UkvMuGRKe7+U6eSEMDSaGvMdufqGmnoSPfzS7pvMugQrYFv0CGSTYFUL9MtDY3Ss:Uk9w7x9sHGgufRNkz09fcFMCGJFUL9MO |
MD5: | 1FB5EDFEA0AF10D301EFCD56738BA30A |
SHA1: | 1AAC6EB08825AD63AC334CFF1F816CC9ECA71219 |
SHA-256: | 161D0961994DD86814FAFBA6EDD6FA7A75D17B19B2E60E1EE01ADAA9EA19DADC |
SHA-512: | A0C3F78B663E01D24DDD53AF6D0D1E3E9DD743C3E4CB6FC8F45588BCC37AB3923A2992505C4842D9E451692A7E7495155F58BFED056BCFE57E02204603F962DD |
Malicious: | false |
Reputation: | low |
URL: | http://zwibbdq.trackbest.click/assets/styles.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | 1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
Reputation: | low |
URL: | https://code.jquery.com/jquery-3.6.0.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.702819531114783 |
Encrypted: | false |
SSDEEP: | 3:H0RnhRn:U/R |
MD5: | E615BD19C7D9069406EBABB025E3F103 |
SHA1: | 00F1E1DEDC1AD40F1F721AC9F38C2CED5EE64FF9 |
SHA-256: | 8CE8BC6A60B5AE599DB9330EA7FBCB952754A3CA6E572C1C6019AEF0DAAFB89A |
SHA-512: | 8B986774DFF216B045C9570989D18D9563CD0D05D9983987443A899267DC37CDF4DEAF50B24F42C6086FAA58EE25D7F5E87E33DA68E4C8F91628579D9144547D |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAncl0f7U-C4HRIFDZfjqKA=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 458 |
Entropy (8bit): | 5.131460290374407 |
Encrypted: | false |
SSDEEP: | 12:8AaJ+dAW1FTWoK9xGixFoBwdNDJNZUSbZkXCABHRsqq+7p:8bJOAWYragNvZUSuzRsqZp |
MD5: | 0A3E69B8B37A6DF0ACD7E7F5D9D3B854 |
SHA1: | 680DE96CFE2AFF1B030BFBD4A7CFA2529993EA61 |
SHA-256: | 0F3A07F36D6BDDEE418F7D7548BC165B09817E10764A359D2773388CDEC9FF8A |
SHA-512: | 9C5C0679E082A5776536835110B90436CD6531E3B2C4FC7A15BDCE7F550D6647447C904E68D660FAF81E39C108E17198830E8B133E86D8559180FA6FB5CE25C7 |
Malicious: | false |
Reputation: | low |
URL: | http://zwibbdq.trackbest.click/6/128767/262/1494/873186/403/9/4avg5x4ni5 |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 15:16:56.075556993 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.075623035 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.075715065 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.075994968 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.076020956 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.717885017 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.718209982 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.718239069 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.720066071 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.720134020 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.721828938 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.721925020 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.767956018 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:56.767982006 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:16:56.814798117 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:16:59.141865969 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.142108917 CET | 49715 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.147073984 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:16:59.147110939 CET | 80 | 49715 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:16:59.147157907 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.147207975 CET | 49715 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.153150082 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.158040047 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:16:59.740030050 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:16:59.789206982 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.821288109 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:16:59.835577965 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:16:59.995115042 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:00.049376965 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:00.825759888 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:00.830764055 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:00.991343021 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:00.993767977 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:00.998703003 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.156229019 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.156256914 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.156270981 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.156369925 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:01.183403015 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:01.188471079 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.190649033 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.190694094 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.190772057 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.191046000 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.191061020 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.346923113 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.346941948 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:01.347105026 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:01.674036026 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.674557924 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.674587965 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.675467014 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.675535917 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.679593086 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.679657936 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.679877043 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.679889917 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.728813887 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.780026913 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780086040 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780117035 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780144930 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780158043 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.780177116 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780193090 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780220985 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.780237913 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.780337095 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780854940 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780885935 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780911922 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.780927896 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.780966997 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.784751892 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.796011925 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.796087980 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.796122074 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.836364031 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.872392893 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.872477055 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.872546911 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.872634888 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.872636080 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.872672081 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.872952938 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.872992039 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873044968 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.873054028 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873115063 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873166084 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.873173952 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873228073 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.873563051 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873761892 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873799086 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873815060 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.873821020 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873863935 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873876095 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.873882055 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.873929024 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.874486923 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.874557018 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.874603033 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.874608040 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.874672890 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.874711990 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.874758959 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.874768019 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.874820948 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.875405073 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.927689075 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.927710056 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.931859016 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.931931019 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.931957006 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965015888 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965070009 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965109110 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.965112925 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965135098 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965183973 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.965192080 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965329885 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965374947 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.965384960 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965395927 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.965574980 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.965641022 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.965646982 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967334986 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967350960 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967392921 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967403889 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967427015 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967452049 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967475891 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967490911 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967490911 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967502117 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967528105 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967561960 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967628956 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967636108 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967654943 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:01.967678070 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.967714071 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.968359947 CET | 49717 | 443 | 192.168.2.5 | 151.101.66.137 |
Jan 9, 2025 15:17:01.968377113 CET | 443 | 49717 | 151.101.66.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.001775980 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.001816034 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.002250910 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.002250910 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.002283096 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.454216003 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.455101967 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.455128908 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.456567049 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.456872940 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.458195925 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.458350897 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.459619999 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.459660053 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.502316952 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.564898968 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.580554008 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.580574989 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.580599070 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.580609083 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.580634117 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.580657959 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.580670118 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.580688000 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.626831055 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.654738903 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.654763937 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.654789925 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.654831886 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.654867887 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.654876947 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.654886961 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.656160116 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.656207085 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.656229019 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.656266928 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.656274080 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.656316042 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.656336069 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.741399050 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.741442919 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.741527081 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.741527081 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.741549969 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.741585970 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.742125034 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.742146969 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.742199898 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.742199898 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.742207050 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.742278099 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.742290974 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.742353916 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.742358923 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.742403030 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:02.742449045 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.890336037 CET | 49718 | 443 | 192.168.2.5 | 151.101.194.137 |
Jan 9, 2025 15:17:02.890361071 CET | 443 | 49718 | 151.101.194.137 | 192.168.2.5 |
Jan 9, 2025 15:17:06.618472099 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:17:06.618568897 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:17:06.618727922 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:17:07.771909952 CET | 49711 | 443 | 192.168.2.5 | 142.250.181.228 |
Jan 9, 2025 15:17:07.771945953 CET | 443 | 49711 | 142.250.181.228 | 192.168.2.5 |
Jan 9, 2025 15:17:44.158540964 CET | 49715 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:44.163393974 CET | 80 | 49715 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:46.362231016 CET | 49714 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:46.367085934 CET | 80 | 49714 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:56.199265003 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:17:56.199322939 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:17:56.199421883 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:17:56.202445030 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:17:56.202469110 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:17:56.882221937 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:17:56.885072947 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:17:56.885113001 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:17:56.885601997 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:17:56.886018991 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:17:56.886123896 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:17:56.939534903 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:17:59.769480944 CET | 49715 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:17:59.775762081 CET | 80 | 49715 | 23.228.85.252 | 192.168.2.5 |
Jan 9, 2025 15:17:59.775847912 CET | 49715 | 80 | 192.168.2.5 | 23.228.85.252 |
Jan 9, 2025 15:18:06.741115093 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:18:06.741271019 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 15:18:06.741337061 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:18:07.769830942 CET | 50041 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 15:18:07.769855022 CET | 443 | 50041 | 216.58.212.132 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 15:16:53.526424885 CET | 53 | 59338 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:16:53.555958986 CET | 53 | 54428 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:16:54.570753098 CET | 53 | 64281 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:16:56.066359997 CET | 49825 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:16:56.066360950 CET | 60798 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:16:56.072995901 CET | 53 | 49825 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:16:56.073666096 CET | 53 | 60798 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:16:59.125797033 CET | 62406 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:16:59.128922939 CET | 58879 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:16:59.136833906 CET | 53 | 62406 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:16:59.139837980 CET | 53 | 58879 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:01.181411982 CET | 60112 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:17:01.183268070 CET | 62732 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:17:01.188697100 CET | 53 | 60112 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:01.190249920 CET | 53 | 62732 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:01.991420031 CET | 56514 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:17:01.991633892 CET | 50674 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:17:01.998461008 CET | 53 | 56514 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:01.998543024 CET | 53 | 50674 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:02.008162022 CET | 53 | 53069 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:11.591434002 CET | 53 | 52549 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:30.604955912 CET | 53 | 63023 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:53.232099056 CET | 53 | 55884 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:53.575784922 CET | 53 | 57917 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:56.171447992 CET | 56501 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:17:56.171539068 CET | 52301 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 15:17:56.178117990 CET | 53 | 52301 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 15:17:56.178158045 CET | 53 | 56501 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 9, 2025 15:16:56.066359997 CET | 192.168.2.5 | 1.1.1.1 | 0xc707 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 15:16:56.066360950 CET | 192.168.2.5 | 1.1.1.1 | 0x8a4c | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 15:16:59.125797033 CET | 192.168.2.5 | 1.1.1.1 | 0x7280 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 15:16:59.128922939 CET | 192.168.2.5 | 1.1.1.1 | 0x39d4 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 15:17:01.181411982 CET | 192.168.2.5 | 1.1.1.1 | 0x1dd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 15:17:01.183268070 CET | 192.168.2.5 | 1.1.1.1 | 0x39de | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 15:17:01.991420031 CET | 192.168.2.5 | 1.1.1.1 | 0x604b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 15:17:01.991633892 CET | 192.168.2.5 | 1.1.1.1 | 0x1ced | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 15:17:56.171447992 CET | 192.168.2.5 | 1.1.1.1 | 0x9615 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 15:17:56.171539068 CET | 192.168.2.5 | 1.1.1.1 | 0x2d9c | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 9, 2025 15:16:56.072995901 CET | 1.1.1.1 | 192.168.2.5 | 0xc707 | No error (0) | 142.250.181.228 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:16:56.073666096 CET | 1.1.1.1 | 192.168.2.5 | 0x8a4c | No error (0) | 65 | IN (0x0001) | false | |||
Jan 9, 2025 15:16:59.136833906 CET | 1.1.1.1 | 192.168.2.5 | 0x7280 | No error (0) | 23.228.85.252 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.188697100 CET | 1.1.1.1 | 192.168.2.5 | 0x1dd8 | No error (0) | 151.101.66.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.188697100 CET | 1.1.1.1 | 192.168.2.5 | 0x1dd8 | No error (0) | 151.101.194.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.188697100 CET | 1.1.1.1 | 192.168.2.5 | 0x1dd8 | No error (0) | 151.101.130.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.188697100 CET | 1.1.1.1 | 192.168.2.5 | 0x1dd8 | No error (0) | 151.101.2.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.998461008 CET | 1.1.1.1 | 192.168.2.5 | 0x604b | No error (0) | 151.101.194.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.998461008 CET | 1.1.1.1 | 192.168.2.5 | 0x604b | No error (0) | 151.101.130.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.998461008 CET | 1.1.1.1 | 192.168.2.5 | 0x604b | No error (0) | 151.101.2.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:01.998461008 CET | 1.1.1.1 | 192.168.2.5 | 0x604b | No error (0) | 151.101.66.137 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 15:17:56.178117990 CET | 1.1.1.1 | 192.168.2.5 | 0x2d9c | No error (0) | 65 | IN (0x0001) | false | |||
Jan 9, 2025 15:17:56.178158045 CET | 1.1.1.1 | 192.168.2.5 | 0x9615 | No error (0) | 216.58.212.132 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49714 | 23.228.85.252 | 80 | 2428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 9, 2025 15:16:59.153150082 CET | 479 | OUT | |
Jan 9, 2025 15:16:59.740030050 CET | 710 | IN | |
Jan 9, 2025 15:16:59.821288109 CET | 431 | OUT | |
Jan 9, 2025 15:16:59.995115042 CET | 258 | IN | |
Jan 9, 2025 15:17:00.825759888 CET | 564 | OUT | |
Jan 9, 2025 15:17:00.991343021 CET | 393 | IN | |
Jan 9, 2025 15:17:00.993767977 CET | 572 | OUT | |
Jan 9, 2025 15:17:01.156229019 CET | 1236 | IN | |
Jan 9, 2025 15:17:01.156256914 CET | 1236 | IN | |
Jan 9, 2025 15:17:01.156270981 CET | 502 | IN | |
Jan 9, 2025 15:17:01.183403015 CET | 401 | OUT | |
Jan 9, 2025 15:17:01.346923113 CET | 1236 | IN | |
Jan 9, 2025 15:17:01.346941948 CET | 384 | IN | |
Jan 9, 2025 15:17:46.362231016 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49715 | 23.228.85.252 | 80 | 2428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 9, 2025 15:17:44.158540964 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49717 | 151.101.66.137 | 443 | 2428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 14:17:01 UTC | 577 | OUT | |
2025-01-09 14:17:01 UTC | 613 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN | |
2025-01-09 14:17:01 UTC | 1378 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49718 | 151.101.194.137 | 443 | 2428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 14:17:02 UTC | 358 | OUT | |
2025-01-09 14:17:02 UTC | 613 | IN | |
2025-01-09 14:17:02 UTC | 16384 | IN | |
2025-01-09 14:17:02 UTC | 16384 | IN | |
2025-01-09 14:17:02 UTC | 16384 | IN | |
2025-01-09 14:17:02 UTC | 16384 | IN | |
2025-01-09 14:17:02 UTC | 16384 | IN | |
2025-01-09 14:17:02 UTC | 7581 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 09:16:46 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 09:16:49 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 09:16:57 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |