Windows
Analysis Report
https://customers.jam-software.de/downloadTrialProcess.php?article_no=671&
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- cmd.exe (PID: 2992 cmdline:
C:\Windows \system32\ cmd.exe /c wget -t 2 -v -T 60 -P "C:\Use rs\user\De sktop\down load" --no -check-cer tificate - -content-d isposition --user-ag ent="Mozil la/5.0 (Wi ndows NT 6 .1; WOW64; Trident/7 .0; AS; rv :11.0) lik e Gecko" " https://cu stomers.ja m-software .de/downlo adTrialPro cess.php?a rticle_no= 671&" > cm dline.out 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 4460 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - wget.exe (PID: 5728 cmdline:
wget -t 2 -v -T 60 - P "C:\User s\user\Des ktop\downl oad" --no- check-cert ificate -- content-di sposition --user-age nt="Mozill a/5.0 (Win dows NT 6. 1; WOW64; Trident/7. 0; AS; rv: 11.0) like Gecko" "h ttps://cus tomers.jam -software. de/downloa dTrialProc ess.php?ar ticle_no=6 71&" MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
- chrome.exe (PID: 4308 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t C:\Users \user\Desk top\downlo ad\downloa dTrial.php @.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 4296 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2152 --fi eld-trial- handle=176 4,i,107634 5560185830 0707,13392 0591239074 73353,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Last function: |
Source: | Binary or memory string: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Command and Scripting Interpreter | 1 DLL Side-Loading | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | 12 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
customers.jam-software.de | 116.202.5.43 | true | false | high | |
www.google.com | 216.58.212.132 | true | false | high | |
matomo.jam-software.de | 78.47.225.43 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false |
| unknown | |
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
116.202.5.43 | customers.jam-software.de | Germany | 24940 | HETZNER-ASDE | false | |
78.47.225.43 | matomo.jam-software.de | Germany | 24940 | HETZNER-ASDE | false | |
216.58.212.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false |
IP |
---|
192.168.2.6 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1586863 |
Start date and time: | 2025-01-09 17:36:29 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | urldownload.jbs |
Sample URL: | https://customers.jam-software.de/downloadTrialProcess.php?article_no=671& |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.phis.win@18/14@11/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.131, 64.233.167.84, 172.217.16.206, 216.58.212.174, 142.250.184.206, 199.232.214.172, 192.229.221.95, 142.250.185.238, 142.250.185.206, 142.250.186.78, 142.250.186.46, 142.250.186.163, 172.217.18.14, 142.250.65.206, 74.125.0.102, 142.250.184.238, 184.28.90.27, 4.175.87.197, 13.107.246.45, 23.1.237.91
- Excluded domains from analysis (whitelisted): clients1.google.com, www.bing.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, r1---sn-t0aekn7e.gvt1.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://customers.jam-software.de/downloadTrialProcess.php?article_no=671&
Time | Type | Description |
---|---|---|
17:37:13 | Task Scheduler |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9864163561477945 |
Encrypted: | false |
SSDEEP: | 48:8hdgTEUTH/cidAKZdA19ehwiZUklqehQy+3:8E/7q/y |
MD5: | 025F1375720043B88130F066C86EA10F |
SHA1: | 0BCA6EFB2A3215CD514FCBBEA7BE19908270F661 |
SHA-256: | 80D603BB10CF125F02270DE9DE28803F8697D48FCFE11C6940D2DF41141FC285 |
SHA-512: | 8DF6F1F0D0516B2C2BB6F3E54610C7561F50C41A54B12763187B156F19C58786029169B4D1914FEB8123A567BAAD8228218C3498E8871E24CF844FBFAD48A913 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9986589641686274 |
Encrypted: | false |
SSDEEP: | 48:8HddgTEUTH/cidAKZdA1weh/iZUkAQkqehvy+2:8HQ/7g9QWy |
MD5: | 251066E2FB4FE142C814FFDB83EDC8FA |
SHA1: | 78BAEBC086CE95BA1F10950A9DE6C77E6626FDCC |
SHA-256: | 72B652B704364963AE48BD7F5BD4068E972779C4A4FFD407100174DD0433F41D |
SHA-512: | 09B0E4FBE9B9B26325C42E09218724AA34C0FAE0FF89187A13DB582E8863C69DFCC71F024AE355C424ECB821E2EC14863151A801CC177F4869D827839A91F716 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.0118691242476645 |
Encrypted: | false |
SSDEEP: | 48:8x9dgTEUsH/cidAKZdA14tseh7sFiZUkmgqeh7sdy+BX:8xw/s4nLy |
MD5: | 35D60F2620B7258FD17D56905CB38AC1 |
SHA1: | F3316D6E01E1B6251E5D1D77DA3148FB60E7336B |
SHA-256: | 14246CDA7A475EC6AEFB97804AA9EBC89143952C5D26DB09191CB99C0AE57555 |
SHA-512: | 88708E02F73869E1FAAED850F94E1E9977BD24483E409ECFEF765EE2A38F5D9B4AE797A86992EAD3F242114A7A98D8E2190A71DB8E6B41D0F7BC3895D6398E83 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9998097559455004 |
Encrypted: | false |
SSDEEP: | 48:8fdgTEUTH/cidAKZdA1vehDiZUkwqehjy+R:86/7rVy |
MD5: | 139C13FAB09641858D054CF80CB7F1F5 |
SHA1: | 1FF81095AEECBF17C316FB9959EC2F86D9793265 |
SHA-256: | FF29C2FDB215110D4FCB4E04005031CB81C1CADFD17ECD550B231814D0481221 |
SHA-512: | 2AB15025C1F9B6EBE95183B83E50A648161427231C61C4DA884F6C2E0E99077541BED0C80B393EF5B974F161BB7CD328863A1CCEA220F776B0181650D1005514 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.990226113390623 |
Encrypted: | false |
SSDEEP: | 48:8jdgTEUTH/cidAKZdA1hehBiZUk1W1qehJy+C:8u/7r9py |
MD5: | 9DE345AFFC28D6BAB7BBB2A294067D80 |
SHA1: | 9EE224FD7EFDA2EEA0A31C29DD6AC31272ADE0E0 |
SHA-256: | BDC9A39920494051C2072B3E0BA85282B3FE33DF9619D093C3B6FCF9E1E17E37 |
SHA-512: | 6E1500734732BAE2D8D4F61FF9CF636438BDB533D6303053DFD29ECBCE8A68646A2024C24AF50C7D11E60DE1B4F0CC213FDCE4D4369985715157A5F72A8241BF |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 4.000997802569275 |
Encrypted: | false |
SSDEEP: | 48:84dgTEUTH/cidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbLy+yT+:8v/7LT/TbxWOvTbLy7T |
MD5: | 22587DD7B7CC9136553AAF968DDB4931 |
SHA1: | E30BB43CACD4D12DBA1D8A246F969D56DC2E06E6 |
SHA-256: | DC5EC4DF70F06A0B450194F083EFA99A706877EF63250653F7FA620D5083A566 |
SHA-512: | F31684E4D22EAC51A90E858801FBF474C2613FCE4A4264D072C82567A220C5796CE14C81277582785BF93685D5D3FF4A29CF6DF90FC15BC2C5399E6FB5D8BCE5 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\cmd.exe |
File Type: | |
Category: | modified |
Size (bytes): | 1027 |
Entropy (8bit): | 4.93913457288262 |
Encrypted: | false |
SSDEEP: | 24:3+OF15gMF7FUF7FwUxePncqov3BFdF7FwUxePgJ1NPb8Hh0CXAQPb89y:Z157hCh7bNDh7H15bEmUAybf |
MD5: | F95D3282FF186246D80AD01FD2F5A059 |
SHA1: | 3847B219268D3A2CAEF408A416E1896446EE5110 |
SHA-256: | A042FB66E4BE39EB26FEF14D93A68AB3351BE8C13AC1A46B8A74A85B89C579DC |
SHA-512: | E3B2B7B7DBEB56364A92B2575DB98D8B5ED4E1C0FA67B4DEBD33237B7D13716F74C313C048C95E7DDCBE1E0CD65AA95B7538BF8CAF1716938590852550E5D33A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\wget.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 129432 |
Entropy (8bit): | 5.255884149578655 |
Encrypted: | false |
SSDEEP: | 3072:ZYh8eip3huuf6IidlrvakdtQ47GKfHkDgJyZvvCywXE:Zi8eGRuufsr5zQ47GKfHkDguvvPwXE |
MD5: | 2A9703A574F377FBC35DAA496573B025 |
SHA1: | CF57223489638EC49082C1BB297764140B227CD8 |
SHA-256: | B33C262A55BD3BDFAABE58186128EE48E13273836922842E7134697D1D4DC1A4 |
SHA-512: | 722761F9F31A8DA15BD40CD036C55152CF8622553402DDE1EB568A4D9748506D2EFC487A8AC94865C1F0DD91349E607A13B9DE6933471340B35766902CB55C40 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 67460 |
Entropy (8bit): | 5.520131864209779 |
Encrypted: | false |
SSDEEP: | 1536:ATgnSINAJrRJqerEKlFXhuXEy+XzsyWbuds06Vdda8EbdAAOV4ITzvBCQaFLa:AT+Z2fuULzsyWbbVdda8EbdAA0XvBv5 |
MD5: | 97B41888A87C22615114D73C91CC70A3 |
SHA1: | A9E02FDB328A29BD8753E7000D0AFE6EF635AAD1 |
SHA-256: | F2E8975ED834C578C50D3923CEB26DE04D4FA44F74380F45F147585D909A874D |
SHA-512: | 0023E6FD1E095CB37FFD94393F583F9A1AD1FE18A03B72BD035D431401038B48CC9689E2BBF4B0BBEE5B6082E77DB6E2BDD55B4D5FFB1C45F86E0F330789C10F |
Malicious: | false |
Reputation: | low |
URL: | https://matomo.jam-software.de/matomo.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 67460 |
Entropy (8bit): | 5.520131864209779 |
Encrypted: | false |
SSDEEP: | 1536:ATgnSINAJrRJqerEKlFXhuXEy+XzsyWbuds06Vdda8EbdAAOV4ITzvBCQaFLa:AT+Z2fuULzsyWbbVdda8EbdAA0XvBv5 |
MD5: | 97B41888A87C22615114D73C91CC70A3 |
SHA1: | A9E02FDB328A29BD8753E7000D0AFE6EF635AAD1 |
SHA-256: | F2E8975ED834C578C50D3923CEB26DE04D4FA44F74380F45F147585D909A874D |
SHA-512: | 0023E6FD1E095CB37FFD94393F583F9A1AD1FE18A03B72BD035D431401038B48CC9689E2BBF4B0BBEE5B6082E77DB6E2BDD55B4D5FFB1C45F86E0F330789C10F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7406 |
Entropy (8bit): | 3.932825359837222 |
Encrypted: | false |
SSDEEP: | 48:2QGczkhtM+YraLKhXAzJeRVPiochtExBu5O2b/9bikWzZjYizRzsAx:2pRhu+xLKhXAdenWhtrOOOcizFsA |
MD5: | AB5871C9795879D3CAD68678BADE4E08 |
SHA1: | 1410E6E4D75628DAA11955500B811C23E6BDD58C |
SHA-256: | F0308EB3980A338D743E1F207A9FCECA2AC4D6815DEC3F5575E99E1312BBE3C0 |
SHA-512: | EBE557C7183B16AE1188B0AB50AC5B4991AFE0810BB605DF3C102D86CF1490D375B3578795BEC8BD7E021ABE56101165B03296B166123342A487A22FFB015D15 |
Malicious: | false |
Reputation: | low |
URL: | https://customers.jam-software.de/img/static/jam_logo_icons/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7406 |
Entropy (8bit): | 3.932825359837222 |
Encrypted: | false |
SSDEEP: | 48:2QGczkhtM+YraLKhXAzJeRVPiochtExBu5O2b/9bikWzZjYizRzsAx:2pRhu+xLKhXAdenWhtrOOOcizFsA |
MD5: | AB5871C9795879D3CAD68678BADE4E08 |
SHA1: | 1410E6E4D75628DAA11955500B811C23E6BDD58C |
SHA-256: | F0308EB3980A338D743E1F207A9FCECA2AC4D6815DEC3F5575E99E1312BBE3C0 |
SHA-512: | EBE557C7183B16AE1188B0AB50AC5B4991AFE0810BB605DF3C102D86CF1490D375B3578795BEC8BD7E021ABE56101165B03296B166123342A487A22FFB015D15 |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 17:37:23.414726019 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:23.414768934 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:23.414839029 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:23.417916059 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:23.417939901 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.082691908 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.082775116 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.084677935 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.084692955 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.085091114 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.086164951 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.127343893 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.521867990 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.524432898 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.524522066 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.528286934 CET | 49704 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.528307915 CET | 443 | 49704 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.552814960 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.552865982 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:24.552941084 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.554161072 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:24.554198027 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:25.349630117 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:25.349730968 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:25.351738930 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:25.351768970 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:25.352106094 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:25.353241920 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:25.395329952 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.437969923 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.438044071 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.438146114 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.438213110 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.483206034 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.536246061 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.536281109 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.536328077 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.536370039 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.536386967 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.536442041 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.536453962 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.538091898 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.538137913 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.538167000 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.538173914 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.538208961 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.538228989 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.633917093 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.633941889 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.634099960 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.634171009 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.634248972 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.635526896 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.635571957 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.635615110 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.635632038 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.635660887 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.635683060 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.636471033 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.636517048 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.636545897 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.636559010 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.636617899 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.636617899 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731059074 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731084108 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731158018 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731224060 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731247902 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731297016 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731333971 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731350899 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731363058 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731403112 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731422901 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731436968 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731470108 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731483936 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731496096 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731607914 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:26.731611013 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.731728077 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.751080036 CET | 49705 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:26.751111031 CET | 443 | 49705 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:31.774389982 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:31.774455070 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:31.774527073 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:31.776043892 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:31.776077032 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.525602102 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.525888920 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.525926113 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.526814938 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.526890993 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.528177977 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.528249025 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.528491974 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.528506994 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.580410957 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.906831026 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.906877995 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.906965971 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.906995058 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907013893 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907072067 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907109976 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.907113075 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907129049 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907188892 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.907210112 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907896042 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907921076 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.907964945 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.907983065 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:32.908024073 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:32.955574989 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.003093004 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.003117085 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.003199100 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.003233910 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.003295898 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.003570080 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.003585100 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.003643036 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.003660917 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.003715992 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.004303932 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.004373074 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.004385948 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.004415989 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.004479885 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.015984058 CET | 49711 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.016015053 CET | 443 | 49711 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.046940088 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.046982050 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.047070026 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.047262907 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.047271013 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.127238989 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.127288103 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.127373934 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.127615929 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.127624989 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.717559099 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.723293066 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.723315001 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.724796057 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.724883080 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.733218908 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.733311892 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.733889103 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.733903885 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.783503056 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:33.811961889 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.833344936 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.833381891 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.834280014 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.834381104 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.840558052 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.840636015 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.841172934 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:33.841191053 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:33.892946959 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.004775047 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.004842043 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.004863977 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.004883051 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.004955053 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:34.004986048 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.005044937 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.008882999 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:34.194871902 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.194931030 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.194951057 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.194969893 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.195008993 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.195028067 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.195061922 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.195100069 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.195126057 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.195180893 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.196366072 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.196413994 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.196464062 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.196482897 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.196515083 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.231755018 CET | 49715 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:34.231786013 CET | 443 | 49715 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.236649036 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.302124023 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.302139044 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.302211046 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.302215099 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.302243948 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.302306890 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.303400993 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.303421974 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.303478956 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.303495884 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.303534031 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.303591967 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.303781033 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.303854942 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.303869963 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.303895950 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.303965092 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.309957981 CET | 49716 | 443 | 192.168.2.5 | 78.47.225.43 |
Jan 9, 2025 17:37:34.309987068 CET | 443 | 49716 | 78.47.225.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.311216116 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:34.311321974 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.311408043 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:34.311651945 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:34.311675072 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:34.980042934 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:34.980149031 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:34.980263948 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:34.980428934 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:34.980448008 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:35.230858088 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.231303930 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.231374979 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.232842922 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.232954025 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.233412981 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.233501911 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.233652115 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.233669996 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.286892891 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.517538071 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.517615080 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.517635107 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.517652988 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.517719030 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.517800093 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.517837048 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.517838955 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.517901897 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.534101009 CET | 49718 | 443 | 192.168.2.5 | 116.202.5.43 |
Jan 9, 2025 17:37:35.534141064 CET | 443 | 49718 | 116.202.5.43 | 192.168.2.5 |
Jan 9, 2025 17:37:35.626979113 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:35.627218008 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:35.627283096 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:35.628307104 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:35.628390074 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:35.629544020 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:35.629612923 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:35.682307005 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:35.682378054 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:35.729052067 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:45.534560919 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:45.534648895 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:37:45.534742117 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:47.004515886 CET | 49719 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:37:47.004584074 CET | 443 | 49719 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:35.034498930 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:35.034596920 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:35.034794092 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:35.034998894 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:35.035037994 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:35.945605040 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:35.946603060 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:35.946624994 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:35.947088003 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:35.947541952 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:35.947623014 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:36.002021074 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:41.812624931 CET | 56600 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:38:41.817414999 CET | 53 | 56600 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:41.817480087 CET | 56600 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:38:41.817517996 CET | 56600 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:38:41.822302103 CET | 53 | 56600 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:42.381752014 CET | 53 | 56600 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:42.382755995 CET | 56600 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:38:42.387667894 CET | 53 | 56600 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:42.387764931 CET | 56600 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:38:45.630837917 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:45.630923033 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Jan 9, 2025 17:38:45.630990982 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:47.004368067 CET | 49998 | 443 | 192.168.2.5 | 216.58.212.132 |
Jan 9, 2025 17:38:47.004403114 CET | 443 | 49998 | 216.58.212.132 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 17:37:23.372416973 CET | 61665 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:23.394299030 CET | 53 | 61665 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:30.513885021 CET | 53 | 60807 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:30.607580900 CET | 53 | 55759 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:31.750524044 CET | 57004 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:31.750693083 CET | 59764 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:31.771034956 CET | 53 | 57004 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:31.771693945 CET | 53 | 59764 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:31.892205000 CET | 53 | 61658 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:33.032723904 CET | 57202 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:33.033046007 CET | 51438 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:33.046046972 CET | 53 | 57202 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:33.046093941 CET | 53 | 51438 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:33.103116035 CET | 49419 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:33.103312016 CET | 60232 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:33.116799116 CET | 53 | 49419 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:33.125580072 CET | 53 | 60232 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:34.286227942 CET | 54694 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:34.286596060 CET | 59966 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:34.301249027 CET | 53 | 59966 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:34.310136080 CET | 53 | 54694 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:34.972110987 CET | 55431 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:34.972328901 CET | 60771 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 9, 2025 17:37:34.978909969 CET | 53 | 60771 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:34.978991032 CET | 53 | 55431 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:37:49.070256948 CET | 53 | 49495 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:07.652316093 CET | 53 | 63001 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:30.324757099 CET | 53 | 62026 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:30.729331970 CET | 53 | 55699 | 1.1.1.1 | 192.168.2.5 |
Jan 9, 2025 17:38:41.808263063 CET | 53 | 63036 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 9, 2025 17:37:23.372416973 CET | 192.168.2.5 | 1.1.1.1 | 0x48f7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 17:37:31.750524044 CET | 192.168.2.5 | 1.1.1.1 | 0x522b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 17:37:31.750693083 CET | 192.168.2.5 | 1.1.1.1 | 0xae9f | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 17:37:33.032723904 CET | 192.168.2.5 | 1.1.1.1 | 0x928a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 17:37:33.033046007 CET | 192.168.2.5 | 1.1.1.1 | 0xa1fc | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 17:37:33.103116035 CET | 192.168.2.5 | 1.1.1.1 | 0xd7d7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 17:37:33.103312016 CET | 192.168.2.5 | 1.1.1.1 | 0x228f | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 17:37:34.286227942 CET | 192.168.2.5 | 1.1.1.1 | 0x6fc5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 17:37:34.286596060 CET | 192.168.2.5 | 1.1.1.1 | 0xaa7f | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 9, 2025 17:37:34.972110987 CET | 192.168.2.5 | 1.1.1.1 | 0xde24 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 17:37:34.972328901 CET | 192.168.2.5 | 1.1.1.1 | 0xa80c | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 9, 2025 17:37:23.394299030 CET | 1.1.1.1 | 192.168.2.5 | 0x48f7 | No error (0) | 116.202.5.43 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 17:37:31.771034956 CET | 1.1.1.1 | 192.168.2.5 | 0x522b | No error (0) | 78.47.225.43 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 17:37:33.046046972 CET | 1.1.1.1 | 192.168.2.5 | 0x928a | No error (0) | 116.202.5.43 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 17:37:33.116799116 CET | 1.1.1.1 | 192.168.2.5 | 0xd7d7 | No error (0) | 78.47.225.43 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 17:37:34.310136080 CET | 1.1.1.1 | 192.168.2.5 | 0x6fc5 | No error (0) | 116.202.5.43 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 17:37:34.978909969 CET | 1.1.1.1 | 192.168.2.5 | 0xa80c | No error (0) | 65 | IN (0x0001) | false | |||
Jan 9, 2025 17:37:34.978991032 CET | 1.1.1.1 | 192.168.2.5 | 0xde24 | No error (0) | 216.58.212.132 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49704 | 116.202.5.43 | 443 | 5728 | C:\Windows\SysWOW64\wget.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 16:37:24 UTC | 241 | OUT | |
2025-01-09 16:37:24 UTC | 614 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49705 | 116.202.5.43 | 443 | 5728 | C:\Windows\SysWOW64\wget.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 16:37:25 UTC | 265 | OUT | |
2025-01-09 16:37:26 UTC | 526 | IN | |
2025-01-09 16:37:26 UTC | 7666 | IN | |
2025-01-09 16:37:26 UTC | 16384 | IN | |
2025-01-09 16:37:26 UTC | 16384 | IN | |
2025-01-09 16:37:26 UTC | 16384 | IN | |
2025-01-09 16:37:26 UTC | 16384 | IN | |
2025-01-09 16:37:26 UTC | 16384 | IN | |
2025-01-09 16:37:26 UTC | 16384 | IN | |
2025-01-09 16:37:26 UTC | 8363 | IN | |
2025-01-09 16:37:26 UTC | 2 | IN | |
2025-01-09 16:37:26 UTC | 8192 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49711 | 78.47.225.43 | 443 | 4296 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 16:37:32 UTC | 495 | OUT | |
2025-01-09 16:37:32 UTC | 354 | IN | |
2025-01-09 16:37:32 UTC | 16030 | IN | |
2025-01-09 16:37:32 UTC | 16384 | IN | |
2025-01-09 16:37:32 UTC | 16384 | IN | |
2025-01-09 16:37:33 UTC | 16384 | IN | |
2025-01-09 16:37:33 UTC | 2278 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49715 | 116.202.5.43 | 443 | 4296 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 16:37:33 UTC | 586 | OUT | |
2025-01-09 16:37:34 UTC | 483 | IN | |
2025-01-09 16:37:34 UTC | 7406 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49716 | 78.47.225.43 | 443 | 4296 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 16:37:33 UTC | 355 | OUT | |
2025-01-09 16:37:34 UTC | 354 | IN | |
2025-01-09 16:37:34 UTC | 16030 | IN | |
2025-01-09 16:37:34 UTC | 16384 | IN | |
2025-01-09 16:37:34 UTC | 16384 | IN | |
2025-01-09 16:37:34 UTC | 16384 | IN | |
2025-01-09 16:37:34 UTC | 2278 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49718 | 116.202.5.43 | 443 | 4296 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-09 16:37:35 UTC | 386 | OUT | |
2025-01-09 16:37:35 UTC | 483 | IN | |
2025-01-09 16:37:35 UTC | 7406 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:37:22 |
Start date: | 09/01/2025 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x790000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 11:37:22 |
Start date: | 09/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:37:22 |
Start date: | 09/01/2025 |
Path: | C:\Windows\SysWOW64\wget.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 3'895'184 bytes |
MD5 hash: | 3DADB6E2ECE9C4B3E1E322E617658B60 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:37:27 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 6 |
Start time: | 11:37:29 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |