Windows
Analysis Report
http://aicenterr.vercel.app/asd.com.html
Overview
Detection
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3012 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3792 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2356 --fi eld-trial- handle=220 4,i,103135 3341998486 9242,43540 4894641529 6629,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6052 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://aicent err.vercel .app/asd.c om.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
scontent.xx.fbcdn.net | 157.240.251.9 | true | false | high | |
aicenterr.vercel.app | 216.198.79.129 | true | true | unknown | |
www.google.com | 142.250.186.100 | true | false | high | |
upload.wikimedia.org | 185.15.59.240 | true | false | high | |
static.xx.fbcdn.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
false |
| unknown | |
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
157.240.251.9 | scontent.xx.fbcdn.net | United States | 32934 | FACEBOOKUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
216.198.79.129 | aicenterr.vercel.app | United States | 11696 | NBS11696US | true | |
185.15.59.240 | upload.wikimedia.org | Netherlands | 14907 | WIKIMEDIAUS | false | |
157.240.253.1 | unknown | United States | 32934 | FACEBOOKUS | false | |
142.250.186.100 | www.google.com | United States | 15169 | GOOGLEUS | false | |
64.29.17.129 | unknown | Canada | 13768 | COGECO-PEER1CA | false |
IP |
---|
192.168.2.6 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1590442 |
Start date and time: | 2025-01-14 01:49:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://aicenterr.vercel.app/asd.com.html |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal80.phis.win@17/18@14/9 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.185.238, 142.251.168.84, 142.250.184.206, 142.250.186.174, 172.217.16.206, 142.250.186.170, 216.58.206.74, 172.217.16.138, 142.250.181.234, 142.250.185.74, 216.58.212.138, 142.250.185.138, 142.250.185.170, 142.250.185.234, 142.250.186.42, 216.58.212.170, 142.250.186.106, 142.250.184.202, 216.58.206.42, 142.250.186.74, 142.250.185.202, 199.232.214.172, 2.17.190.73, 172.217.18.14, 216.58.206.78, 172.217.23.110, 142.250.186.67, 2.23.242.162, 20.109.210.53, 13.107.246.45
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: http://aicenterr.vercel.app/asd.com.html
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9761875218546114 |
Encrypted: | false |
SSDEEP: | 48:8LdVT9Ni0H4idAKZdA19ehwiZUklqehr1ny+3:8nXizS5y |
MD5: | C65FD84C972634CA655391C8DC8F23B2 |
SHA1: | 95CA8CCC26400878AA05CCDDBE81378CC4873650 |
SHA-256: | 4A2F22B7A9513AE814E082F235FD8FF87C6382F7A5339382350697FD0F7553CB |
SHA-512: | 694B9847D61E71CF3B08672B4279824C16A7DF1F47F40C04E463B5F96D05A7D57B8F75E08438F02AB481FE5FA58F71FE6844D47CCB6311EDB95D719D0DF64388 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9884733719259233 |
Encrypted: | false |
SSDEEP: | 48:8udVT9Ni0H4idAKZdA1weh/iZUkAQkqehC1ny+2:8EXiB9Ql5y |
MD5: | 3878D470DB0F653845913B2333BB301C |
SHA1: | E9C2C45DC1661FB6DAB7851155BA583621597564 |
SHA-256: | 74C414902192B0AB49FB44E4B1563D0C5BC5B25C423FB6C90255F0D956B7E5C2 |
SHA-512: | D36EEC7A9D0B68DE03966FEE49BA02EB486A7105E366FADC844394805CA0CFEE934ECC0A3730D719E59D0B20599183E4F40E67A262AA50593216C29B4BE839DA |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.00285272656886 |
Encrypted: | false |
SSDEEP: | 48:8x2dVT9NsH4idAKZdA14tseh7sFiZUkmgqeh7sc1ny+BX:8xcXpnW5y |
MD5: | BE24DC4E6C66DB9EE759A7D51DC76F37 |
SHA1: | A30847F2AB77187ADE0827E227A1347EDB930236 |
SHA-256: | ADCEB357F49C0A831B5C1962BFE391B725A59FFB03E396CA43548CB0F3BF4ECE |
SHA-512: | E6AF014B14CBF168BAEE01F5188981DD917102DBF47F668C7D382E7C4F7B2B385C6EE276813BED7F187848F64B4533303C4D9073C5A7F17DD75C7769828FA45A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9881973330798046 |
Encrypted: | false |
SSDEEP: | 48:8kdVT9Ni0H4idAKZdA1vehDiZUkwqeh+1ny+R:82XiiE5y |
MD5: | 0BC3A47ADBF7D925EE4DB6D1588F861D |
SHA1: | 000C62FAB68E56C05D5DF8BC15A1F9DA5CC9FE58 |
SHA-256: | DE0799B3A96E5D3E2F998CF68930C3BB12F3C6F96B178E137ADE95FA4E39105E |
SHA-512: | 42BC6F412ACA358245BBC77A401697071033A8421796E51A055FEBBE91F6A6FDD5760B8E851701D49493A968E09B5C8B1E86E152860619957118B14847B186DF |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.978648669475043 |
Encrypted: | false |
SSDEEP: | 48:8GdVT9Ni0H4idAKZdA1hehBiZUk1W1qehw1ny+C:8MXiS9Q5y |
MD5: | 4E4EC373BBB2608AB765C45A7613B9D7 |
SHA1: | A2691E05271DB76605E261B4CED1A9121B9D2311 |
SHA-256: | E9079B0FB091EF502E13D8A180947B796481796A8D65647B130891B949D364FD |
SHA-512: | BB91E1E82A2D64F9BB67FF92FB64EACA8CD157C99A89B9F3323B9238B4FA77ABA00F6586D2B4E770977643C4400702C825463E4E72E47B65C281DB1EFB6CBAF8 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.990028349379411 |
Encrypted: | false |
SSDEEP: | 48:8QdVT9Ni0H4idAKZdA1duT+ehOuTbbiZUk5OjqehOuTbW1ny+yT+:8CXiMT/TbxWOvTbW5y7T |
MD5: | 8738C4A3A8CC2ACA98188FC526DF0B94 |
SHA1: | D16EA4E33EA0F3AF07078F65AA66F8EBA0E8E1CB |
SHA-256: | 8F115118F1340C6BAD6E71C1A0F44BA9D4AF3FA77878FF4457885355BDAC9CEB |
SHA-512: | 5D535E66EFA1013FF59E1B68EF4338A9E438D4DEE8C991B0F64892B1DA8A517ED427AA7980E38E14C04B1D8FFE27054F45E69490A3CD6D39A5690FE380C17D09 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 10125 |
Entropy (8bit): | 5.039298920818719 |
Encrypted: | false |
SSDEEP: | 192:vd+SzvEQU19GSGq+y3hly8iV9+ymRdwNwkP1cFGur9plWQ07sbsDmnJHy6iPT:vdFP1Zur9pE7sbsDMJO |
MD5: | D0160795EFA02C90CA63C23DB2662EBC |
SHA1: | 19F274692A4043B02A781CBDB7D3CBC0DA47BDC8 |
SHA-256: | B30189E7B24DA8AC6DD6EA08F2938AC40D1202A89565E042D1DB5D3CAFF5FFB6 |
SHA-512: | 6936537F7F5C5667318D657E6EF5E77CD73DEBA2B693F6DDD2B7A96917527CD721D1AFD2539BAF804E7D6112DD202ED5DC76EDE519F2EE97267D70303C09E1C2 |
Malicious: | false |
Reputation: | low |
URL: | https://aicenterr.vercel.app/asd.com.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 35332 |
Entropy (8bit): | 7.989281588330394 |
Encrypted: | false |
SSDEEP: | 384:CgtIW3e78QqBfbMdm8e9+mYK9bdTx1ixaIevOqUJP+jyeeXzNKy3uDGjl1c2+RyZ:CgWSTBfbMA5+FTaIevic+52cwsOggMxh |
MD5: | 4C0C8BA1CC2B390BED2FC53450B088A9 |
SHA1: | 22F168B4B75680C9F8D2E82CC09CE4B07072DDFC |
SHA-256: | 41F549936E8EFED12B9402B78C4216FE46C6F66312A6BCDE8727EDB01232EEDC |
SHA-512: | F7A1D16DF823717DE3D758364F490A6FFE111E52CD6B41115C82ED8FE5446A60CADB56ACB8D7DE96C299C6430024466DA46F76EE185BB37486117413537F7606 |
Malicious: | false |
Reputation: | low |
URL: | https://static.xx.fbcdn.net/rsrc.php/v4/y4/r/N3dO4_SJQPQ.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 44 |
Entropy (8bit): | 4.578638720860854 |
Encrypted: | false |
SSDEEP: | 3:QQinPbDKtht:+Pbqn |
MD5: | 2C0DC3161885C7BE37A936C5D44BB73C |
SHA1: | 60DD2E10E35E765E926856CDFC541295070896FE |
SHA-256: | DB5D63E1A995DE35569B6B4CA657C36261E8EA21818A1932B2E754C31D38BE39 |
SHA-512: | 162CCEC776146B3E071FA753D9AF21C206A7492E81F86E5FD6AF09A97FDE4ECE82E27E96584B8E52F896F5AE47233356A1586A13EF20AA916C7C1D1B5927C17F |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwn-Ts8F-oULoRIFDXhvEhkSBQ3OQUx6EhAJFtJDHZ_mSccSBQ0GH--0?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 39 |
Entropy (8bit): | 4.31426624499232 |
Encrypted: | false |
SSDEEP: | 3:ErAbcBxYAFDJvzqxgl:1wBxYA7vzqxg |
MD5: | D4AC7F1BBA70BA87C56E6D93092B7CCA |
SHA1: | 96492A95A7F9153EED58A3598C4CCE56EDC6F8D1 |
SHA-256: | 91218093A08027E8F69C8051F9DEEF1FE6C22B278B3F6BDF761E7587CB272774 |
SHA-512: | AFDE5B08290C83B95037CACE1B4625457690C824E21615A01413CE8A1040F8C86CD6ABD873DDD57D31C053F835C0F05EB5CDA2B102A17EF558240E73A1AFD1F4 |
Malicious: | false |
Reputation: | low |
URL: | https://aicenterr.vercel.app/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1354 |
Entropy (8bit): | 5.411294788208795 |
Encrypted: | false |
SSDEEP: | 24:2dUxGvTXdwpAyYtV1itfUafYY2MVVIvbAIYWDHFvJAAeUzrSB:cUQRb1u8aiQIvbAI1lxAAeEC |
MD5: | 17B573894ED72C1303E934D6BF56CF2F |
SHA1: | 6A6396AC2D75ED26E2A0E85C71938156F9BDE39B |
SHA-256: | 82BC3244A4458DEB1FE7B096B0DC65C7F1F6A0D5627A1733A0FDCC9430612D46 |
SHA-512: | 11BEA26BEBC3DC6959F99343DA31CA9E33EAAD354D24328222ED285CB94AABC5A3A1C76B02FC8A89BEC985F6FFAED08BCEC7B4A73F01E698B7B9130B85242E1A |
Malicious: | false |
Reputation: | low |
URL: | https://upload.wikimedia.org/wikipedia/commons/5/51/Facebook_f_logo_%282019%29.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1354 |
Entropy (8bit): | 5.411294788208795 |
Encrypted: | false |
SSDEEP: | 24:2dUxGvTXdwpAyYtV1itfUafYY2MVVIvbAIYWDHFvJAAeUzrSB:cUQRb1u8aiQIvbAI1lxAAeEC |
MD5: | 17B573894ED72C1303E934D6BF56CF2F |
SHA1: | 6A6396AC2D75ED26E2A0E85C71938156F9BDE39B |
SHA-256: | 82BC3244A4458DEB1FE7B096B0DC65C7F1F6A0D5627A1733A0FDCC9430612D46 |
SHA-512: | 11BEA26BEBC3DC6959F99343DA31CA9E33EAAD354D24328222ED285CB94AABC5A3A1C76B02FC8A89BEC985F6FFAED08BCEC7B4A73F01E698B7B9130B85242E1A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35332 |
Entropy (8bit): | 7.989281588330394 |
Encrypted: | false |
SSDEEP: | 384:CgtIW3e78QqBfbMdm8e9+mYK9bdTx1ixaIevOqUJP+jyeeXzNKy3uDGjl1c2+RyZ:CgWSTBfbMA5+FTaIevic+52cwsOggMxh |
MD5: | 4C0C8BA1CC2B390BED2FC53450B088A9 |
SHA1: | 22F168B4B75680C9F8D2E82CC09CE4B07072DDFC |
SHA-256: | 41F549936E8EFED12B9402B78C4216FE46C6F66312A6BCDE8727EDB01232EEDC |
SHA-512: | F7A1D16DF823717DE3D758364F490A6FFE111E52CD6B41115C82ED8FE5446A60CADB56ACB8D7DE96C299C6430024466DA46F76EE185BB37486117413537F7606 |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 01:49:56.323561907 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:49:56.323616028 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:49:56.417323112 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:50:05.518695116 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:05.518718958 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:05.518802881 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:05.518980026 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:05.518989086 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:05.931946039 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:50:05.931957006 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:50:06.025645971 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:50:06.173893929 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:06.174153090 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:06.174170017 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:06.175823927 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:06.175883055 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:06.176883936 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:06.176986933 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:06.228645086 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:06.228655100 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:06.275521040 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:06.340073109 CET | 49714 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.340107918 CET | 49715 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.345027924 CET | 80 | 49714 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.345040083 CET | 80 | 49715 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.345103979 CET | 49714 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.345128059 CET | 49715 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.345252991 CET | 49714 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.350137949 CET | 80 | 49714 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.835206985 CET | 80 | 49714 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.835400105 CET | 80 | 49714 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.835422039 CET | 80 | 49714 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.835438967 CET | 49714 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.835459948 CET | 49714 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.835819960 CET | 49714 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:06.840718985 CET | 80 | 49714 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.857187033 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:06.857247114 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:06.857319117 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:06.857513905 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:06.857528925 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.335838079 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.336127996 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.336154938 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.337150097 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.337244034 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.344403028 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.344587088 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.344616890 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.344651937 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.387721062 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.387751102 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.434443951 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.483983994 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484029055 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484057903 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484219074 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.484245062 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484353065 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.484641075 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484649897 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484720945 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.484730005 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484744072 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.484798908 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.484798908 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.494219065 CET | 49717 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:07.494240046 CET | 443 | 49717 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:07.547945023 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:07.548053980 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:07.548769951 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:07.548799038 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:07.548836946 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:07.549134016 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:07.549134016 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:07.549165964 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:07.549411058 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:07.549448967 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:07.746375084 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 14, 2025 01:50:07.748027086 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 14, 2025 01:50:08.183609962 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.184015989 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.184084892 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.185750961 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.185887098 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.185906887 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.187130928 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.187380075 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.187380075 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.187412024 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.187478065 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.238445044 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.238512039 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.284617901 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.288042068 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.288274050 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.288281918 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.289469957 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.289561987 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.290668964 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.290668964 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.290677071 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.290724039 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.346978903 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.346991062 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.400994062 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.422720909 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.422785997 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.422853947 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.422920942 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.422960997 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.423013926 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.424695015 CET | 49718 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.424726963 CET | 443 | 49718 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.437365055 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.437396049 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.437459946 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.437937975 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:08.437952995 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:08.559182882 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.559326887 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.559340000 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.599603891 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.649847984 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.649877071 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.649894953 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.649931908 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.649938107 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.649956942 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.649982929 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.649982929 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.650005102 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.650008917 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.650048018 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.681870937 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.681894064 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.681936026 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.681937933 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.681962967 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.681972980 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.681983948 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.681992054 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.682028055 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.688576937 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.688644886 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.688656092 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.688719034 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.688747883 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.688805103 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.689081907 CET | 49719 | 443 | 192.168.2.5 | 157.240.251.9 |
Jan 14, 2025 01:50:08.689094067 CET | 443 | 49719 | 157.240.251.9 | 192.168.2.5 |
Jan 14, 2025 01:50:08.698185921 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:08.698239088 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:08.698313951 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:08.699306011 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:08.699337006 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:08.710573912 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:08.710592985 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:08.710680008 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:08.710954905 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:08.710971117 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.133872032 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.134233952 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.134248018 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.137850046 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.137932062 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.137939930 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.137994051 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.138523102 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.138600111 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.138808966 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.138814926 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.169167042 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.169650078 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:09.169666052 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.170011044 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.170583963 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:09.170640945 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.170880079 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:09.181446075 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.215328932 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.324529886 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.324794054 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.324867964 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:09.325691938 CET | 49722 | 443 | 192.168.2.5 | 64.29.17.129 |
Jan 14, 2025 01:50:09.325736046 CET | 443 | 49722 | 64.29.17.129 | 192.168.2.5 |
Jan 14, 2025 01:50:09.338221073 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.338612080 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.338661909 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.339550972 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.339623928 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.340343952 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.340410948 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.340523005 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.340540886 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.377001047 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.377067089 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.377118111 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.377135038 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.377221107 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.377273083 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.382812977 CET | 49721 | 443 | 192.168.2.5 | 185.15.59.240 |
Jan 14, 2025 01:50:09.382823944 CET | 443 | 49721 | 185.15.59.240 | 192.168.2.5 |
Jan 14, 2025 01:50:09.386884928 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.620975971 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.621081114 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.621105909 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.667366028 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.699171066 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.699181080 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.699369907 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.699379921 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.699420929 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.699474096 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.699496984 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.699521065 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.699533939 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.734028101 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.734044075 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.734128952 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.734150887 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.734215975 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.734215975 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.734221935 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.741246939 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.741307974 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:09.741338015 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.741545916 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.742216110 CET | 49723 | 443 | 192.168.2.5 | 157.240.253.1 |
Jan 14, 2025 01:50:09.742230892 CET | 443 | 49723 | 157.240.253.1 | 192.168.2.5 |
Jan 14, 2025 01:50:16.096487045 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:16.096656084 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:16.096766949 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:17.465037107 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:50:17.465070963 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:50:36.742995977 CET | 80 | 49715 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:50:36.743087053 CET | 49715 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:37.474728107 CET | 49715 | 80 | 192.168.2.5 | 216.198.79.129 |
Jan 14, 2025 01:50:37.480865002 CET | 80 | 49715 | 216.198.79.129 | 192.168.2.5 |
Jan 14, 2025 01:51:05.576697111 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:05.576735020 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:05.576816082 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:05.577038050 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:05.577052116 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:06.225210905 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:06.225501060 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:06.225513935 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:06.225747108 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:06.226264954 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:06.226304054 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:06.276249886 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:16.148622036 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:16.148755074 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Jan 14, 2025 01:51:16.148828030 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:17.474239111 CET | 49987 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 14, 2025 01:51:17.474257946 CET | 443 | 49987 | 142.250.186.100 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 01:50:01.045109987 CET | 53 | 52530 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:01.102279902 CET | 53 | 51945 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:02.091310978 CET | 53 | 61784 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:05.510726929 CET | 49464 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:05.510833979 CET | 57907 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:05.517258883 CET | 53 | 49464 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:05.517944098 CET | 53 | 57907 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:06.329090118 CET | 64368 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:06.329421997 CET | 62998 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:06.338202953 CET | 53 | 64368 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:06.338493109 CET | 53 | 62998 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:06.847661018 CET | 53876 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:06.847996950 CET | 51787 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:06.855580091 CET | 53 | 51787 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:06.856779099 CET | 53 | 53876 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:07.534554005 CET | 53756 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:07.534554005 CET | 55610 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:07.535156965 CET | 60740 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:07.535156965 CET | 63715 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:07.541233063 CET | 53 | 53756 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:07.541543007 CET | 53 | 55610 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:07.541940928 CET | 53 | 63715 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:07.542242050 CET | 53 | 60740 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:07.567338943 CET | 53 | 59096 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:08.429617882 CET | 60195 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:08.429866076 CET | 52954 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:08.436745882 CET | 53 | 52954 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:08.436783075 CET | 53 | 60195 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:08.702344894 CET | 59987 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:08.702503920 CET | 58929 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 14, 2025 01:50:08.709101915 CET | 53 | 59987 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:08.710015059 CET | 53 | 58929 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:19.190841913 CET | 53 | 64298 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:50:38.090060949 CET | 53 | 58176 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:51:00.835630894 CET | 53 | 53645 | 1.1.1.1 | 192.168.2.5 |
Jan 14, 2025 01:51:01.110974073 CET | 53 | 58701 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 14, 2025 01:50:05.510726929 CET | 192.168.2.5 | 1.1.1.1 | 0xd460 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:05.510833979 CET | 192.168.2.5 | 1.1.1.1 | 0xad46 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 14, 2025 01:50:06.329090118 CET | 192.168.2.5 | 1.1.1.1 | 0x214b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:06.329421997 CET | 192.168.2.5 | 1.1.1.1 | 0xcb8b | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 14, 2025 01:50:06.847661018 CET | 192.168.2.5 | 1.1.1.1 | 0x6153 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:06.847996950 CET | 192.168.2.5 | 1.1.1.1 | 0x117a | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 14, 2025 01:50:07.534554005 CET | 192.168.2.5 | 1.1.1.1 | 0x851 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:07.534554005 CET | 192.168.2.5 | 1.1.1.1 | 0x6966 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 14, 2025 01:50:07.535156965 CET | 192.168.2.5 | 1.1.1.1 | 0xe1ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:07.535156965 CET | 192.168.2.5 | 1.1.1.1 | 0x4a75 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 14, 2025 01:50:08.429617882 CET | 192.168.2.5 | 1.1.1.1 | 0x24f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:08.429866076 CET | 192.168.2.5 | 1.1.1.1 | 0xde10 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 14, 2025 01:50:08.702344894 CET | 192.168.2.5 | 1.1.1.1 | 0xe3f6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 01:50:08.702503920 CET | 192.168.2.5 | 1.1.1.1 | 0x1be5 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 14, 2025 01:50:05.517258883 CET | 1.1.1.1 | 192.168.2.5 | 0xd460 | No error (0) | 142.250.186.100 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:05.517944098 CET | 1.1.1.1 | 192.168.2.5 | 0xad46 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 14, 2025 01:50:06.338202953 CET | 1.1.1.1 | 192.168.2.5 | 0x214b | No error (0) | 216.198.79.129 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:06.338202953 CET | 1.1.1.1 | 192.168.2.5 | 0x214b | No error (0) | 64.29.17.129 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:06.856779099 CET | 1.1.1.1 | 192.168.2.5 | 0x6153 | No error (0) | 64.29.17.129 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:06.856779099 CET | 1.1.1.1 | 192.168.2.5 | 0x6153 | No error (0) | 216.198.79.129 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:07.541233063 CET | 1.1.1.1 | 192.168.2.5 | 0x851 | No error (0) | 185.15.59.240 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:07.541940928 CET | 1.1.1.1 | 192.168.2.5 | 0x4a75 | No error (0) | scontent.xx.fbcdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:07.541940928 CET | 1.1.1.1 | 192.168.2.5 | 0x4a75 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 14, 2025 01:50:07.541940928 CET | 1.1.1.1 | 192.168.2.5 | 0x4a75 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 14, 2025 01:50:07.542242050 CET | 1.1.1.1 | 192.168.2.5 | 0xe1ae | No error (0) | scontent.xx.fbcdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:07.542242050 CET | 1.1.1.1 | 192.168.2.5 | 0xe1ae | No error (0) | 157.240.251.9 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:08.436783075 CET | 1.1.1.1 | 192.168.2.5 | 0x24f | No error (0) | 185.15.59.240 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:08.709101915 CET | 1.1.1.1 | 192.168.2.5 | 0xe3f6 | No error (0) | scontent.xx.fbcdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:08.709101915 CET | 1.1.1.1 | 192.168.2.5 | 0xe3f6 | No error (0) | 157.240.253.1 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:08.710015059 CET | 1.1.1.1 | 192.168.2.5 | 0x1be5 | No error (0) | scontent.xx.fbcdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 14, 2025 01:50:08.710015059 CET | 1.1.1.1 | 192.168.2.5 | 0x1be5 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 14, 2025 01:50:08.710015059 CET | 1.1.1.1 | 192.168.2.5 | 0x1be5 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49714 | 216.198.79.129 | 80 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 01:50:06.345252991 CET | 447 | OUT | |
Jan 14, 2025 01:50:06.835206985 CET | 59 | IN | |
Jan 14, 2025 01:50:06.835400105 CET | 143 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49717 | 64.29.17.129 | 443 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 00:50:07 UTC | 675 | OUT | |
2025-01-14 00:50:07 UTC | 561 | IN | |
2025-01-14 00:50:07 UTC | 2372 | IN | |
2025-01-14 00:50:07 UTC | 992 | IN | |
2025-01-14 00:50:07 UTC | 4744 | IN | |
2025-01-14 00:50:07 UTC | 2017 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49718 | 185.15.59.240 | 443 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 00:50:08 UTC | 637 | OUT | |
2025-01-14 00:50:08 UTC | 1079 | IN | |
2025-01-14 00:50:08 UTC | 1354 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49719 | 157.240.251.9 | 443 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 00:50:08 UTC | 615 | OUT | |
2025-01-14 00:50:08 UTC | 1877 | IN | |
2025-01-14 00:50:08 UTC | 1 | IN | |
2025-01-14 00:50:08 UTC | 15925 | IN | |
2025-01-14 00:50:08 UTC | 16384 | IN | |
2025-01-14 00:50:08 UTC | 3022 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49721 | 185.15.59.240 | 443 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 00:50:09 UTC | 397 | OUT | |
2025-01-14 00:50:09 UTC | 1079 | IN | |
2025-01-14 00:50:09 UTC | 1354 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49722 | 64.29.17.129 | 443 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 00:50:09 UTC | 608 | OUT | |
2025-01-14 00:50:09 UTC | 363 | IN | |
2025-01-14 00:50:09 UTC | 39 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49723 | 157.240.253.1 | 443 | 3792 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 00:50:09 UTC | 375 | OUT | |
2025-01-14 00:50:09 UTC | 1896 | IN | |
2025-01-14 00:50:09 UTC | 1 | IN | |
2025-01-14 00:50:09 UTC | 15843 | IN | |
2025-01-14 00:50:09 UTC | 16384 | IN | |
2025-01-14 00:50:09 UTC | 3104 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 19:49:57 |
Start date: | 13/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 19:49:59 |
Start date: | 13/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 19:50:05 |
Start date: | 13/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |