Windows
Analysis Report
http://pub-3b43df3d08c6428eb75adaf661b4216f.r2.dev/docu/e_protocol.html
Overview
General Information
Detection
Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 2924 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 1848 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2144 --fi eld-trial- handle=202 0,i,121999 0260256689 793,552142 1119150629 212,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6536 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://pub-3b 43df3d08c6 428eb75ada f661b4216f .r2.dev/do cu/e_proto col.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_64 | Yara detected HtmlPhish_64 | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | Page Title: | ||
Source: | Page Title: |
Source: | File source: | ||
Source: | File source: |
Source: | File source: |
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Scripting | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
pub-3b43df3d08c6428eb75adaf661b4216f.r2.dev | 172.66.0.235 | true | true | unknown | |
www.google.com | 142.250.181.228 | true | false | high | |
www.continentalsports.co.uk | 95.154.228.177 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
95.154.228.177 | www.continentalsports.co.uk | United Kingdom | 20860 | IOMART-ASGB | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.181.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.66.0.235 | pub-3b43df3d08c6428eb75adaf661b4216f.r2.dev | United States | 13335 | CLOUDFLARENETUS | true |
IP |
---|
192.168.2.4 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591500 |
Start date and time: | 2025-01-15 01:41:02 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://pub-3b43df3d08c6428eb75adaf661b4216f.r2.dev/docu/e_protocol.html |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal92.phis.win@17/10@10/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.185.238, 142.251.168.84, 142.250.184.206, 142.250.186.46, 142.250.80.46, 74.125.0.102, 142.250.185.202, 142.250.184.234, 142.250.185.106, 216.58.206.42, 142.250.186.106, 142.250.185.170, 172.217.18.10, 142.250.184.202, 142.250.186.138, 142.250.186.42, 142.250.181.234, 142.250.185.234, 172.217.16.202, 142.250.186.74, 216.58.212.138, 142.250.186.170, 199.232.210.172, 2.23.77.188, 142.250.185.163, 2.23.242.162, 20.109.210.53, 13.107.246.45
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, otelrules.azureedge.net, ajax.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, r1---sn-t0aekn7e.gvt1.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: http://pub-3b43df3d08c6428eb75adaf661b4216f.r2.dev/docu/e_protocol.html
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | 3:HwT:QT |
MD5: | 344EB8D19F5C0A3435EF32FD9601F1FB |
SHA1: | E082EB1D89D91CC1A25A1D510268E576109DA07E |
SHA-256: | B44289B54959639FCA6A742F7CC2E2A5AF9C6E7B73C1B3E25227CA9790F3A587 |
SHA-512: | EB9F1CD4A566192160371F4B182EE00180F6912333FFB79C537BD80635A6AFE6379FBE7BB74043D635BA65C9F4F956D9E97E516E24E516F2591192A36F866EAE |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAmvkNS96nASHBIFDc5BTHo=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7494 |
Entropy (8bit): | 7.868668842804636 |
Encrypted: | false |
SSDEEP: | 192:ygdh+IXyP70WVRYaDpmW05te0t5WaEtyWU:yqh870CJDpU5wpU |
MD5: | E27D91CCCC9D333CE4E99262E368053D |
SHA1: | F59234771F6CD9D102FD50527CE1D684E305EDDD |
SHA-256: | 17A7F5E4C9165EF60EB0CBA29D6DC36F32F7FAB0306A6CDC898997141228C5FA |
SHA-512: | 069239A90A49B2848BAD2FE451C6E947E280BA4C93BF8E53C61D00765A532F636F1F733F6427E75ACCF76B432E55A0D5E1BECE8912C3C39F3E4915D2421A9E1F |
Malicious: | false |
Reputation: | low |
URL: | https://www.continentalsports.co.uk/media/catalog/product/cache/7fd38fa62b8fefd3d046b3795a3b5e36/b/l/blurred_invoice.jpg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85578 |
Entropy (8bit): | 5.366055229017455 |
Encrypted: | false |
SSDEEP: | 1536:EYE1JVoiB9JqZdXXe2pD3PgoIiulrUndZ6a4tfOR7WpfWBZ2BJda4w9W3qG9a986:v4J+OlfOhWppCW6G9a98Hr2 |
MD5: | 2F6B11A7E914718E0290410E85366FE9 |
SHA1: | 69BB69E25CA7D5EF0935317584E6153F3FD9A88C |
SHA-256: | 05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E |
SHA-512: | 0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 252205 |
Entropy (8bit): | 6.083975621579217 |
Encrypted: | false |
SSDEEP: | 6144:8ajpSYt72uB8zd3nuatHiuZ1aYxs7TA7V+se6LOt1Xf54:8a1SYtRc33CMaoQTA7V+se61 |
MD5: | AC9DBD4FD1FB0ADD29A1B8703BCE9406 |
SHA1: | D71E70C8AC03CF68134D5AB68DD2F05AD4B23002 |
SHA-256: | 6316CB80E53A87A277A3CF231119AC5BE5E8DEF905800F583841D36358EDB374 |
SHA-512: | FFDFE6A01976EB9CDF1E289CA03F938952058151440C62925CCC8D1BCFA8E48EEF7A72581461FC35B10AE02853116A27AE5C70D30AF166B10FEF6C3C9F53E5CF |
Malicious: | false |
Reputation: | low |
URL: | https://pub-3b43df3d08c6428eb75adaf661b4216f.r2.dev/docu/e_protocol.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7494 |
Entropy (8bit): | 7.868668842804636 |
Encrypted: | false |
SSDEEP: | 192:ygdh+IXyP70WVRYaDpmW05te0t5WaEtyWU:yqh870CJDpU5wpU |
MD5: | E27D91CCCC9D333CE4E99262E368053D |
SHA1: | F59234771F6CD9D102FD50527CE1D684E305EDDD |
SHA-256: | 17A7F5E4C9165EF60EB0CBA29D6DC36F32F7FAB0306A6CDC898997141228C5FA |
SHA-512: | 069239A90A49B2848BAD2FE451C6E947E280BA4C93BF8E53C61D00765A532F636F1F733F6427E75ACCF76B432E55A0D5E1BECE8912C3C39F3E4915D2421A9E1F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 85578 |
Entropy (8bit): | 5.366055229017455 |
Encrypted: | false |
SSDEEP: | 1536:EYE1JVoiB9JqZdXXe2pD3PgoIiulrUndZ6a4tfOR7WpfWBZ2BJda4w9W3qG9a986:v4J+OlfOhWppCW6G9a98Hr2 |
MD5: | 2F6B11A7E914718E0290410E85366FE9 |
SHA1: | 69BB69E25CA7D5EF0935317584E6153F3FD9A88C |
SHA-256: | 05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E |
SHA-512: | 0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB |
Malicious: | false |
Reputation: | low |
URL: | https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 01:41:57.992815018 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 15, 2025 01:42:00.488544941 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:00.488641024 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:00.488723040 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:00.489006042 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:00.489044905 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:01.167351961 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:01.167687893 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:01.167754889 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:01.169236898 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:01.169313908 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:01.170620918 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:01.170708895 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:01.211610079 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:01.211652040 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:01.258480072 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:02.360248089 CET | 54322 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:02.365267992 CET | 53 | 54322 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.366849899 CET | 54322 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:02.366883039 CET | 54322 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:02.371675014 CET | 53 | 54322 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.638036966 CET | 54324 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:02.638279915 CET | 54325 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:02.643098116 CET | 80 | 54324 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:02.643202066 CET | 54324 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:02.643342972 CET | 54324 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:02.643536091 CET | 80 | 54325 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:02.643591881 CET | 54325 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:02.648123980 CET | 80 | 54324 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:02.812196970 CET | 53 | 54322 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.813045979 CET | 54322 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:02.818413973 CET | 53 | 54322 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.818520069 CET | 54322 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:03.099009037 CET | 80 | 54324 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.111490965 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.111525059 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.111593962 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.111840010 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.111850977 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.152539015 CET | 54324 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.579489946 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.584594965 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.584616899 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.585560083 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.585639000 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.612504005 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.612592936 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.612699986 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.612713099 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.666213989 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.824743986 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.824790955 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.824834108 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.824840069 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.824852943 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.824882984 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.824887037 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.824892998 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.824913979 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.825279951 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.825305939 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.825313091 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.825320959 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.825356960 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.829399109 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.877309084 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.910604954 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.910665035 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.910698891 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.910715103 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.910725117 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.910758018 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.911214113 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.911257982 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.911259890 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.911267996 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.911384106 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.911807060 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.911859035 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.911890030 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.911895990 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.912676096 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.912708044 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.912710905 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.912718058 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.912755966 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.912759066 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.912765980 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.912801027 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.912806034 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.913567066 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.913592100 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.913606882 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.913613081 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.913650036 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.913654089 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.950988054 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.951019049 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.951035976 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.951049089 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.951078892 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.996751070 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.996815920 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.996855974 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.996866941 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.996911049 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.996944904 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.996951103 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.997468948 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.997519970 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.997529030 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.998135090 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.998167992 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.998171091 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.998178005 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.998198986 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.998994112 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.999025106 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.999032021 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.999037981 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:03.999063969 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.999078035 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:03.999989986 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.000022888 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.000029087 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.000035048 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.000060081 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.000914097 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.000946045 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.000957012 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.000962019 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.000988007 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.001904011 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.001944065 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.001975060 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.002026081 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.002037048 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.002054930 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.002768993 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.002815962 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.037344933 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.037404060 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083019018 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083064079 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083091974 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083137989 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083146095 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083178043 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083421946 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083461046 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083471060 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083475113 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083499908 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083836079 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083869934 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083878994 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.083884001 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.083908081 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.084526062 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.084568024 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.084584951 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.084614038 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.084620953 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.084624052 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.084640980 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.084641933 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.084676981 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.084681034 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.084711075 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.085433960 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.085474968 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.085484028 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.085486889 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.085508108 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.085527897 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.085530996 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.085544109 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.086242914 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.086282969 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.086282969 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.086292982 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.086321115 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.086332083 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.086359978 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.086361885 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.086369038 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.086396933 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.087291956 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.087341070 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.087344885 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.087354898 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.087387085 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.087387085 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.087395906 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.087405920 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.087435007 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.088177919 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088208914 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088232040 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.088236094 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088249922 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.088263035 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088265896 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.088273048 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088294029 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088313103 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.088316917 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.088340044 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.088972092 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.089011908 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.089015961 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.089065075 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.123740911 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.123795033 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.169625044 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.169706106 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.169723034 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.169729948 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.169766903 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.169770956 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.169802904 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.169806004 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.169831991 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.169833899 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.169848919 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.169873953 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.170576096 CET | 54327 | 443 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:04.170587063 CET | 443 | 54327 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:04.411067963 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:04.411112070 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:04.411186934 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:04.411731005 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:04.411741018 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.210690975 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.211343050 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.211375952 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.212887049 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.213076115 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.213924885 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.213999987 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.214102983 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.258158922 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.258188963 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.304095030 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.380045891 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.380079031 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.380089998 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.380115986 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.380139112 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.380167961 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.380191088 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.380194902 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.380393982 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.380850077 CET | 54330 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.380868912 CET | 443 | 54330 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.623259068 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.623379946 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:05.623461008 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.623709917 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:05.623733997 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.381213903 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.381510973 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.381541014 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.383021116 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.383090973 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.383491993 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.383651972 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.383662939 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.427335978 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.430186987 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.430205107 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.476468086 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.547064066 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.547100067 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.547111034 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.547132969 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.547149897 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.547183037 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.547200918 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.547207117 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:06.547245979 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.548238993 CET | 54335 | 443 | 192.168.2.4 | 95.154.228.177 |
Jan 15, 2025 01:42:06.548254967 CET | 443 | 54335 | 95.154.228.177 | 192.168.2.4 |
Jan 15, 2025 01:42:11.093378067 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:11.093449116 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:11.093693972 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:12.026181936 CET | 49738 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:42:12.026225090 CET | 443 | 49738 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:42:18.010118008 CET | 80 | 54325 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:18.010387897 CET | 54325 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:18.027193069 CET | 54325 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:18.032342911 CET | 80 | 54325 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:42:39.239629030 CET | 54343 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:39.245599985 CET | 53 | 54343 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:39.245698929 CET | 54343 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:39.245779991 CET | 54343 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:39.245794058 CET | 54343 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:39.250637054 CET | 53 | 54343 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:39.250647068 CET | 53 | 54343 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:39.748322964 CET | 53 | 54343 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:39.748702049 CET | 54343 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:39.754044056 CET | 53 | 54343 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:39.754112959 CET | 54343 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:48.103246927 CET | 54324 | 80 | 192.168.2.4 | 172.66.0.235 |
Jan 15, 2025 01:42:48.108249903 CET | 80 | 54324 | 172.66.0.235 | 192.168.2.4 |
Jan 15, 2025 01:43:00.541775942 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:00.541815996 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:00.541887999 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:00.542172909 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:00.542191029 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:01.198774099 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:01.199158907 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:01.199174881 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:01.199476957 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:01.199801922 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:01.199853897 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:01.249772072 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:11.164771080 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:11.164861917 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Jan 15, 2025 01:43:11.165040970 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:12.027152061 CET | 54398 | 443 | 192.168.2.4 | 142.250.181.228 |
Jan 15, 2025 01:43:12.027194023 CET | 443 | 54398 | 142.250.181.228 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 01:41:57.041404009 CET | 53 | 64736 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:41:57.322227001 CET | 53 | 54735 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:41:58.313842058 CET | 53 | 59848 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:00.480058908 CET | 52441 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:00.480315924 CET | 59892 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:00.487339020 CET | 53 | 59892 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:00.487469912 CET | 53 | 52441 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.359812021 CET | 53 | 60658 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.627939939 CET | 62724 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:02.628103971 CET | 51529 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:02.636398077 CET | 53 | 62724 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:02.637545109 CET | 53 | 51529 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:03.101820946 CET | 57148 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:03.102006912 CET | 55108 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:03.110838890 CET | 53 | 55108 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:03.110872030 CET | 53 | 57148 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:04.186604977 CET | 61076 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:04.186768055 CET | 53402 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:04.194597960 CET | 53 | 58795 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:04.299005985 CET | 53 | 53402 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:04.404825926 CET | 53 | 61076 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:05.373783112 CET | 53 | 52612 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:05.386485100 CET | 53 | 64249 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:05.406856060 CET | 51118 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:05.407080889 CET | 55422 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 01:42:05.521068096 CET | 53 | 55422 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:05.622531891 CET | 53 | 51118 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:14.983283043 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Jan 15, 2025 01:42:39.239077091 CET | 53 | 56928 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 01:42:56.318525076 CET | 53 | 64308 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 01:42:00.480058908 CET | 192.168.2.4 | 1.1.1.1 | 0x102 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 01:42:00.480315924 CET | 192.168.2.4 | 1.1.1.1 | 0x8eae | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 01:42:02.627939939 CET | 192.168.2.4 | 1.1.1.1 | 0xc22d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 01:42:02.628103971 CET | 192.168.2.4 | 1.1.1.1 | 0xd334 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 01:42:03.101820946 CET | 192.168.2.4 | 1.1.1.1 | 0x340b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 01:42:03.102006912 CET | 192.168.2.4 | 1.1.1.1 | 0xa33a | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 01:42:04.186604977 CET | 192.168.2.4 | 1.1.1.1 | 0x638d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 01:42:04.186768055 CET | 192.168.2.4 | 1.1.1.1 | 0x39e7 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 01:42:05.406856060 CET | 192.168.2.4 | 1.1.1.1 | 0xefd2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 01:42:05.407080889 CET | 192.168.2.4 | 1.1.1.1 | 0xc8 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 01:42:00.487339020 CET | 1.1.1.1 | 192.168.2.4 | 0x8eae | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 01:42:00.487469912 CET | 1.1.1.1 | 192.168.2.4 | 0x102 | No error (0) | 142.250.181.228 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 01:42:02.636398077 CET | 1.1.1.1 | 192.168.2.4 | 0xc22d | No error (0) | 172.66.0.235 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 01:42:02.636398077 CET | 1.1.1.1 | 192.168.2.4 | 0xc22d | No error (0) | 162.159.140.237 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 01:42:03.110872030 CET | 1.1.1.1 | 192.168.2.4 | 0x340b | No error (0) | 172.66.0.235 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 01:42:03.110872030 CET | 1.1.1.1 | 192.168.2.4 | 0x340b | No error (0) | 162.159.140.237 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 01:42:04.404825926 CET | 1.1.1.1 | 192.168.2.4 | 0x638d | No error (0) | 95.154.228.177 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 01:42:05.622531891 CET | 1.1.1.1 | 192.168.2.4 | 0xefd2 | No error (0) | 95.154.228.177 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 54324 | 172.66.0.235 | 80 | 1848 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 15, 2025 01:42:02.643342972 CET | 478 | OUT | |
Jan 15, 2025 01:42:03.099009037 CET | 534 | IN | |
Jan 15, 2025 01:42:48.103246927 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 54327 | 172.66.0.235 | 443 | 1848 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 00:42:03 UTC | 706 | OUT | |
2025-01-15 00:42:03 UTC | 284 | IN | |
2025-01-15 00:42:03 UTC | 1085 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN | |
2025-01-15 00:42:03 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 54330 | 95.154.228.177 | 443 | 1848 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 00:42:05 UTC | 635 | OUT | |
2025-01-15 00:42:05 UTC | 370 | IN | |
2025-01-15 00:42:05 UTC | 7494 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 54335 | 95.154.228.177 | 443 | 1848 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 00:42:06 UTC | 435 | OUT | |
2025-01-15 00:42:06 UTC | 370 | IN | |
2025-01-15 00:42:06 UTC | 7494 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 19:41:53 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 19:41:54 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 19:42:01 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |