Windows
Analysis Report
https://cdn.trytraffics.com/rdr/YWE9MzUyODExMjgxJnNlaT0zMDM5ODczNCZ0az1LdmRFVldENjdLQW94U0FyQ2NQbCZ0PTUmYz05MGFzODc2ZmQ4OWFzNWZnOGEwOXM=
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 6660 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 4672 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2156 --fi eld-trial- handle=201 2,i,120003 1944337309 0438,15735 3141626680 19686,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 368 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://cdn.t rytraffics .com/rdr/Y WE9MzUyODE xMjgxJnNla T0zMDM5ODc zNCZ0az1Ld mRFVldENjd LQW94U0FyQ 2NQbCZ0PTU mYz05MGFzO Dc2ZmQ4OWF zNWZnOGEwO XM=" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
cdn.trytraffics.com | 188.114.97.3 | true | false | unknown | |
www.google.com | 142.250.185.196 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.196 | www.google.com | United States | 15169 | GOOGLEUS | false | |
188.114.97.3 | cdn.trytraffics.com | European Union | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.23 |
192.168.2.7 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591425 |
Start date and time: | 2025-01-15 00:31:24 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://cdn.trytraffics.com/rdr/YWE9MzUyODExMjgxJnNlaT0zMDM5ODczNCZ0az1LdmRFVldENjdLQW94U0FyQ2NQbCZ0PTUmYz05MGFzODc2ZmQ4OWFzNWZnOGEwOXM= |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@17/15@6/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.67, 142.251.168.84, 172.217.16.206, 142.250.184.206, 216.58.206.46, 199.232.214.172, 2.17.190.73, 142.250.185.238, 142.250.185.206, 142.250.186.174, 142.250.185.110, 142.250.186.78, 216.58.212.174, 34.104.35.123, 2.23.242.162, 4.245.163.56, 13.107.246.45
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://cdn.trytraffics.com/rdr/YWE9MzUyODExMjgxJnNlaT0zMDM5ODczNCZ0az1LdmRFVldENjdLQW94U0FyQ2NQbCZ0PTUmYz05MGFzODc2ZmQ4OWFzNWZnOGEwOXM=
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9717757879907847 |
Encrypted: | false |
SSDEEP: | 48:8VdWTALyiTHridAKZdA19ehwiZUklqehwtfy+3:8eTiZnfy |
MD5: | 2B02A1E82CB6154A507954FD9FD8E0EF |
SHA1: | E9580A4A47E0DF76927C00F39F6B51FE9E5C69A8 |
SHA-256: | E558D7F3304D6A880B4C74A548E0EA229AA07C88B9848D8486294F5AF26F26A2 |
SHA-512: | BF8B495024A0F409EACA31FCC82BDA2973E07DDAFF4E7051722BA5EC5425DCB56B0A38F764F53CCD9BE20AEE7B35B73040370A8CB2E884C3CBEDB424D1758D32 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9909121611047556 |
Encrypted: | false |
SSDEEP: | 48:8rdWTALyiTHridAKZdA1weh/iZUkAQkqehFtfy+2:8ITiL9QSfy |
MD5: | A420145817F9B6EB7431092FD8BC5887 |
SHA1: | 2B3D3228153526CE1ECBD67A23D2DEFDA15C0E6C |
SHA-256: | 30E9C4FA60DB30374327D80E18EC5E5130612EA574AC3E467FDCA1FBF62A4DFC |
SHA-512: | 347775BF1E7AD81912043E950D20DC9F51BED47107CA6E25058CDFB14444B1257F34A5CD6E42296AE79C62CEE2665DC69200A62BD8A9D60E161E32BBFFEDA74C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.0035329743657595 |
Encrypted: | false |
SSDEEP: | 48:8xDdWTALysHridAKZdA14tseh7sFiZUkmgqeh7s7tfy+BX:8xgTCnbfy |
MD5: | 78AD37959C5E9860F117E5377625102D |
SHA1: | FB00E88180E076CC7F6B3D331485990243886621 |
SHA-256: | 414A700EFA81ADA367CC4AC917E33640DEDD6B0CD1E793B168B20BF807CFDA4A |
SHA-512: | 984A773DC9968041F97918F50B94B7351C7F03A712AA9497D12D37BBB919D713307F84D77772DAAE209D0E1E269BC66CC67896D857E94AAF32F4A4196A60DDC5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9839489752712294 |
Encrypted: | false |
SSDEEP: | 48:8xdWTALyiTHridAKZdA1vehDiZUkwqehJtfy+R:8iTiIRfy |
MD5: | 290ED5CECE5E3385E65BE5C6D1A0F441 |
SHA1: | B3D972C30F2F15A11B74DC1B22FD8A461B4189AD |
SHA-256: | 3DA6A565567396CE13C20CE276171C8C8FF55A418FB1FA38076605752E88FDAE |
SHA-512: | 3B1D482BF24F68A5C728A8FDABF0EFA8E96596A127156AD88F99F1EDD311CC8057B0637F5A7D5765B4E62C1C644D8C7856C1EC1AE62926DF67BE666C66591F54 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9744709960330296 |
Encrypted: | false |
SSDEEP: | 48:8i/dWTALyiTHridAKZdA1hehBiZUk1W1qehHtfy+C:8i0TiY9tfy |
MD5: | 8F969C653043A79E3F4A67F7B5975F2A |
SHA1: | 15F1EF37F07ECD7465C0C6EE06C50019818A2264 |
SHA-256: | D9C2B239269B596BF89CA975FDDF1E9A5F85A2177649411DB70CCD5E6A0A04BB |
SHA-512: | D8464DA967A87E84100BCA6EB898BDD12700EED26DC00609D1FF39B0556D78B7CAAA8A7EA3625BE9BD545ADE5E14966AEAEE76F14FD7591E9082F322CFC961A9 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.984251993241678 |
Encrypted: | false |
SSDEEP: | 48:8rdWTALyiTHridAKZdA1duT+ehOuTbbiZUk5OjqehOuTbxtfy+yT+:8ITi2T/TbxWOvTbbfy7T |
MD5: | FE9B4020BB8EFFF6BDBEC0F42E6E22EA |
SHA1: | 2789369B03706240C12C339339BE2B6791E11B0B |
SHA-256: | 4AB3299B33D19E221DE9C29C9B0530BD1489D7C3429F177273D6E444C42C70C4 |
SHA-512: | CEACA98A05C7B5E42391250323C1F468CF10E1DBCFE3C73F7BB4A68BC4C614C15DF4C28B7B431FDF15FB0A2F557D529A112159A3D88E078D1C92F173EE98834F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6660_271153135\LICENSE
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1558 |
Entropy (8bit): | 5.11458514637545 |
Encrypted: | false |
SSDEEP: | 48:OBOCrYJ4rYJVwUCLHDy43HV713XEyMmZ3teTHn:LCrYJ4rYJVwUCHZ3Z13XtdUTH |
MD5: | EE002CB9E51BB8DFA89640A406A1090A |
SHA1: | 49EE3AD535947D8821FFDEB67FFC9BC37D1EBBB2 |
SHA-256: | 3DBD2C90050B652D63656481C3E5871C52261575292DB77D4EA63419F187A55B |
SHA-512: | D1FDCC436B8CA8C68D4DC7077F84F803A535BF2CE31D9EB5D0C466B62D6567B2C59974995060403ED757E92245DB07E70C6BDDBF1C3519FED300CC5B9BF9177C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6660_271153135\_metadata\verified_contents.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 6.018989605004616 |
Encrypted: | false |
SSDEEP: | 48:p/hUI1OwEU3AdIq7ak68O40E2szOxxUJ8BPFkf31U4PrHfqY3J5D:RnOwtQIq7aZ40E2sYUJAYRr/qYZ5D |
MD5: | C4709C1D483C9233A3A66A7E157624EA |
SHA1: | 99A000EB5FE5CC1E94E3155EE075CD6E43DC7582 |
SHA-256: | 225243DC75352D63B0B9B2F48C8AAA09D55F3FB9E385741B12A1956A941880D9 |
SHA-512: | B45E1FD999D1340CC5EB5A49A4CD967DC736EA3F4EC8B02227577CC3D1E903341BE3217FBB0B74765C72085AC51C63EEF6DCB169D137BBAF3CC49E21EA6468D7 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6660_271153135\manifest.fingerprint
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.820000180714897 |
Encrypted: | false |
SSDEEP: | 3:SVzHL3phUmWRDNKydvgHVz:SBHLLUmWRbCp |
MD5: | BBEC7670A2519FEB0627F17D0C0B5276 |
SHA1: | 9C30B996F1B069F86EF7C0136DFAF7E614674DEA |
SHA-256: | 670A6F6BBADAB2C2BE63898525FCAF72E7454739E77C04D120BC1A46B6694CAC |
SHA-512: | 1ED4ED6AE2A2CBE86F9E8C6C7A2672EBB2F37DBE83D2BF09D875DB435ED63BF5F5CF60CA846865166F9A498095F6D61BD51B0A092E097430439E8A5A3A14CB15 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6660_271153135\manifest.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85 |
Entropy (8bit): | 4.462192586591686 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifFCmMARWHJqS1kULJVPY:F6VlM8aRWpqS1kSJVg |
MD5: | 084E339C0C9FE898102815EAC9A7CDEA |
SHA1: | 6ABF7EAAA407D2EAB8706361E5A2E5F776D6C644 |
SHA-256: | 52CD62F4AC1F9E7D7C4944EE111F84A42337D16D5DE7BE296E945146D6D7DC15 |
SHA-512: | 0B67A89F3EBFF6FEC3796F481EC2AFBAC233CF64FDC618EC6BA1C12AE125F28B27EE09E8CD0FADB8F6C8785C83929EA6F751E0DDF592DD072AB2CF439BD28534 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6660_271153135\sets.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9817 |
Entropy (8bit): | 4.629347296880043 |
Encrypted: | false |
SSDEEP: | 96:Mon4mvC4qX19s1blbw/BNKLcxbdmf56MFJtRTGXvcxN43uP+8qJl:v5C4ql7BkIVmtRTGXvcxBsl |
MD5: | 8C702C686B703020BC0290BAFC90D7A0 |
SHA1: | EB08FF7885B4C1DE3EF3D61E40697C0C71903E27 |
SHA-256: | 97D9E39021512305820F27B9662F0351E45639124F5BD29F0466E9072A9D0C62 |
SHA-512: | 6137D0ED10E6A27924ED3AB6A0C5F9B21EB0E16A876447DADABD88338198F31BB9D89EF8F0630F4573EA34A24FB3FD3365D7EA78A97BA10028A0758E0A550739 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 315 |
Entropy (8bit): | 5.0572271090563765 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR |
MD5: | A34AC19F4AFAE63ADC5D2F7BC970C07F |
SHA1: | A82190FC530C265AA40A045C21770D967F4767B8 |
SHA-256: | D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3 |
SHA-512: | 42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765 |
Malicious: | false |
Reputation: | low |
URL: | https://cdn.trytraffics.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 861 |
Entropy (8bit): | 5.265155464912692 |
Encrypted: | false |
SSDEEP: | 24:hMNmlBHkspKZHxfHW+chXErd9HxfHW+chXEvptK:Im3/pKX/W+cyx/W+cutK |
MD5: | ECB6ACD75071ADF12B2AB8301480ED67 |
SHA1: | CB5AF240F2D9402B2E1DA564582A47CF635E2B14 |
SHA-256: | B1C609F77291DDF13645E8BEDF7E50A1054C44D659F014FA727E0F36A5B680C0 |
SHA-512: | A019EB7BE3FB8D6053A46DC1A9B6FC67DB22301B0E6C78709AE96AD18171D5F090E0C8E3DF6CEAB0E64A6D2F619F0D0D9D321577B0C9B6BE4D46DFAF4B3B943E |
Malicious: | false |
Reputation: | low |
URL: | https://cdn.trytraffics.com/rdr/YWE9MzUyODExMjgxJnNlaT0zMDM5ODczNCZ0az1LdmRFVldENjdLQW94U0FyQ2NQbCZ0PTUmYz05MGFzODc2ZmQ4OWFzNWZnOGEwOXM= |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 00:32:09.267271996 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:09.267455101 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:09.376749992 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:18.867345095 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:18.867360115 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:18.992342949 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:20.314234972 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:20.314273119 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:20.314362049 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:20.314601898 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:20.314610958 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:20.610852957 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 15, 2025 00:32:20.610943079 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 00:32:20.963360071 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:20.963655949 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:20.963680983 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:20.964667082 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:20.964716911 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:20.966037035 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:20.966095924 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:21.007023096 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:21.007049084 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:21.053899050 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:21.176230907 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.176275969 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.176333904 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.176373959 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.176423073 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.176466942 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.187777042 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.187786102 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.188049078 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.188060045 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.708048105 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.708515882 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.708538055 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.710164070 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.710242033 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.717418909 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.721743107 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.721893072 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.722290993 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.722320080 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.723346949 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.723412991 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.724865913 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.724879026 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.728269100 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.728415012 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.775784969 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.775789022 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:21.775798082 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:21.820637941 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:22.312175035 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.313671112 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.313812971 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:22.316914082 CET | 49713 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:22.316939116 CET | 443 | 49713 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.364011049 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:22.407341003 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.865253925 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.865340948 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.865411997 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:22.871634960 CET | 49714 | 443 | 192.168.2.5 | 188.114.97.3 |
Jan 15, 2025 00:32:22.871655941 CET | 443 | 49714 | 188.114.97.3 | 192.168.2.5 |
Jan 15, 2025 00:32:22.875425100 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:22.875466108 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:22.875735998 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:22.875999928 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:22.876018047 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.346390963 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.346647024 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.346664906 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.347588062 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.347644091 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.348787069 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.348856926 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.348938942 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.391325951 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.397699118 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.397706985 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.444562912 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.475152016 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.475208998 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.475280046 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.475447893 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.475470066 CET | 443 | 49716 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.475482941 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.475568056 CET | 49716 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.476512909 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.476608992 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.476716995 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.476962090 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.476998091 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.942725897 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.986278057 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.986311913 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.986833096 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.987659931 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:23.987730980 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:23.987799883 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:24.031373024 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:24.039258957 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:24.118886948 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:24.119282961 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:24.119370937 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:24.119550943 CET | 49717 | 443 | 192.168.2.5 | 35.190.80.1 |
Jan 15, 2025 00:32:24.119566917 CET | 443 | 49717 | 35.190.80.1 | 192.168.2.5 |
Jan 15, 2025 00:32:30.859457016 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:30.859524012 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:32:30.859571934 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:32.071819067 CET | 49711 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:32:32.071871996 CET | 443 | 49711 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:18.501981020 CET | 54572 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:33:18.509309053 CET | 53 | 54572 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:33:18.509439945 CET | 54572 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:33:18.516752958 CET | 53 | 54572 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:33:18.964060068 CET | 54572 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:33:18.971580029 CET | 53 | 54572 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:33:18.971681118 CET | 54572 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:33:20.367737055 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:20.367779016 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:20.367882013 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:20.368098021 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:20.368113995 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:21.001506090 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:21.001924992 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:21.001940966 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:21.002382040 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:21.002810001 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:21.002882957 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:21.054174900 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:30.938407898 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:30.938463926 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Jan 15, 2025 00:33:30.938555002 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:32.072033882 CET | 54574 | 443 | 192.168.2.5 | 142.250.185.196 |
Jan 15, 2025 00:33:32.072067022 CET | 443 | 54574 | 142.250.185.196 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 00:32:15.858376026 CET | 53 | 53967 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:15.957830906 CET | 53 | 61812 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:17.091830969 CET | 53 | 52611 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:20.304940939 CET | 64326 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:32:20.305080891 CET | 50105 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:32:20.313210964 CET | 53 | 50105 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:20.313252926 CET | 53 | 64326 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:21.111443043 CET | 54829 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:32:21.111665964 CET | 59560 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:32:21.122672081 CET | 53 | 54829 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:21.273293018 CET | 53 | 59560 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:22.866372108 CET | 56432 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:32:22.866646051 CET | 57351 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 00:32:22.874737978 CET | 53 | 56432 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:22.874896049 CET | 53 | 57351 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:34.096574068 CET | 53 | 59348 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:32:53.111814976 CET | 53 | 63567 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:33:15.504262924 CET | 53 | 52591 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:33:15.703154087 CET | 53 | 57110 | 1.1.1.1 | 192.168.2.5 |
Jan 15, 2025 00:33:18.501318932 CET | 53 | 63260 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 15, 2025 00:32:21.273382902 CET | 192.168.2.5 | 1.1.1.1 | c27e | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 00:32:20.304940939 CET | 192.168.2.5 | 1.1.1.1 | 0xec13 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 00:32:20.305080891 CET | 192.168.2.5 | 1.1.1.1 | 0x2917 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 00:32:21.111443043 CET | 192.168.2.5 | 1.1.1.1 | 0x9e0e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 00:32:21.111665964 CET | 192.168.2.5 | 1.1.1.1 | 0xf80b | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 00:32:22.866372108 CET | 192.168.2.5 | 1.1.1.1 | 0x4d9a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 00:32:22.866646051 CET | 192.168.2.5 | 1.1.1.1 | 0xcc6a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 00:32:20.313210964 CET | 1.1.1.1 | 192.168.2.5 | 0x2917 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 00:32:20.313252926 CET | 1.1.1.1 | 192.168.2.5 | 0xec13 | No error (0) | 142.250.185.196 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 00:32:21.122672081 CET | 1.1.1.1 | 192.168.2.5 | 0x9e0e | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 00:32:21.122672081 CET | 1.1.1.1 | 192.168.2.5 | 0x9e0e | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 00:32:21.273293018 CET | 1.1.1.1 | 192.168.2.5 | 0xf80b | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 00:32:22.874737978 CET | 1.1.1.1 | 192.168.2.5 | 0x4d9a | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49713 | 188.114.97.3 | 443 | 4672 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 23:32:21 UTC | 770 | OUT | |
2025-01-14 23:32:22 UTC | 795 | IN | |
2025-01-14 23:32:22 UTC | 574 | IN | |
2025-01-14 23:32:22 UTC | 294 | IN | |
2025-01-14 23:32:22 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49714 | 188.114.97.3 | 443 | 4672 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 23:32:22 UTC | 702 | OUT | |
2025-01-14 23:32:22 UTC | 834 | IN | |
2025-01-14 23:32:22 UTC | 322 | IN | |
2025-01-14 23:32:22 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49716 | 35.190.80.1 | 443 | 4672 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 23:32:23 UTC | 542 | OUT | |
2025-01-14 23:32:23 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49717 | 35.190.80.1 | 443 | 4672 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 23:32:23 UTC | 480 | OUT | |
2025-01-14 23:32:23 UTC | 535 | OUT | |
2025-01-14 23:32:24 UTC | 168 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 18:32:11 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 18:32:14 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 18:32:19 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |