Windows
Analysis Report
https://ipfs.io/ipfs/bafkreidfpb2invnj4i76skys5sfmk3hycbkxhquyb7d6uhnbls3gwf4a5q#support@sealevel.com
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6240 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6924 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2156 --fi eld-trial- handle=197 2,i,146275 6303481655 8379,10217 7967722596 5790,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6616 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://ipfs. io/ipfs/ba fkreidfpb2 invnj4i76s kys5sfmk3h ycbkxhquyb 7d6uhnbls3 gwf4a5q#su pport@seal evel.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security | ||
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | Sample URL: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Drive-by Compromise | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
www.google.com | 142.250.185.100 | true | false | high | |
www.sealevel.com | 104.21.64.1 | true | false | unknown | |
webhook.site | 178.63.67.106 | true | false | high | |
ipfs.io | 209.94.90.1 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false |
| unknown | |
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.64.1 | www.sealevel.com | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.185.100 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
178.63.67.106 | webhook.site | Germany | 24940 | HETZNER-ASDE | false | |
172.217.16.196 | unknown | United States | 15169 | GOOGLEUS | false | |
209.94.90.1 | ipfs.io | United States | 40680 | PROTOCOLUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591857 |
Start date and time: | 2025-01-15 14:57:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 39s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://ipfs.io/ipfs/bafkreidfpb2invnj4i76skys5sfmk3hycbkxhquyb7d6uhnbls3gwf4a5q#support@sealevel.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal60.phis.win@18/22@14/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.186.78, 142.251.168.84, 142.250.181.238, 142.250.181.234, 142.250.186.106, 216.58.212.170, 142.250.186.138, 172.217.23.106, 142.250.184.234, 172.217.16.138, 172.217.16.202, 142.250.185.106, 142.250.184.202, 142.250.185.138, 216.58.206.42, 172.217.18.10, 142.250.186.170, 216.58.206.74, 142.250.185.74, 142.250.186.174, 142.250.186.42, 142.250.185.202, 142.250.185.234, 172.217.18.106, 216.58.212.138, 142.250.186.74, 142.250.185.170, 142.250.185.238, 172.217.23.100, 142.250.185.68, 216.58.206.46, 142.250.74.206, 142.250.185.142, 216.58.212.163, 142.250.186.142, 184.28.90.27, 52.149.20.212
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ajax.googleapis.com, clientservices.googleapis.com, t1.gstatic.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, firebasestorage.googleapis.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://ipfs.io/ipfs/bafkreidfpb2invnj4i76skys5sfmk3hycbkxhquyb7d6uhnbls3gwf4a5q#support@sealevel.com
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9698765617602207 |
Encrypted: | false |
SSDEEP: | 48:8FOdVT9BEHCidAKZdA1FehwiZUklqehuy+3:8qvNFy |
MD5: | BED807EB9801AE8D0E8D5E64AEE4168E |
SHA1: | 227BCE049E068178B89BAD0DBE4A95ADF9479EC6 |
SHA-256: | 80ED2BD994C81335518712FD877FC26B55BEF5E88FC743545387C31701EBE17E |
SHA-512: | F94088B444C8E141A57CC214D74964A41C69C69ECA9294355ACAE1997C4A9B9272E68E5DFC49E147B3289FFAFBDB14E7975ED1CB7E91D556640FCC09F71439DE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9904541393343913 |
Encrypted: | false |
SSDEEP: | 48:8wOdVT9BEHCidAKZdA1seh/iZUkAQkqeh1y+2:8dvj9Q8y |
MD5: | 58EB6A15741A7226B2A5B26FE9910F52 |
SHA1: | 413E0C9403E0BBFD0831B3AB045909FE6F0B3E09 |
SHA-256: | 1F7F058D0F1C143977C861D09612AFB7001C7AF38B09292D80239F686588CEA1 |
SHA-512: | 5FFA08D48CB9BB0036B7E5CF47460885B6FB6AB18DEF037FD93464C793A4D5352F81363792E576EE42B702EE7D4D114FCA2C926F4A60AD0006CDF0044D599173 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.002427052266544 |
Encrypted: | false |
SSDEEP: | 48:85OdVT9BAHCidAKZdA14meh7sFiZUkmgqeh7sLy+BX:8uvjnZy |
MD5: | 2EC5AADD9D81850B1F231748F68DC8BB |
SHA1: | 556C410D83012753552BF1391F695867C2DCC0B9 |
SHA-256: | 19796775906778501790053C27D7664CB5D66A9700B973046B37E932F4EE58E0 |
SHA-512: | FA456E114203092B2BA012AACCE17B8D6BFE5A3F07A8E488C64FA68E38C58709751DA921AAD37B1EC4D6A8EDCB45635177F71698AA878530FF77E56741CB9BC2 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9828196215838867 |
Encrypted: | false |
SSDEEP: | 48:8vOdVT9BEHCidAKZdA1TehDiZUkwqehBy+R:8MvQTy |
MD5: | 88E05A1E3FB8403EEFC8F3612F04F044 |
SHA1: | 9372D41A8B639A8BA83B78844202CCA8E51D61AC |
SHA-256: | 5D86E6BC6AAE27BC1A5854CB5E2C1E1B7C0C78C8637AF6A689DFDB7DF8F7371C |
SHA-512: | 52BA26E2DAFA7EA07F711179806F723C843A448962DFB454F24775527E7D4FED84BF4DFDFD572816F02766879AEFCCCDC3F082B691C50B120AB8F5487E1C5322 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.974524159406328 |
Encrypted: | false |
SSDEEP: | 48:8WYOdVT9BEHCidAKZdA1dehBiZUk1W1qehPy+C:8Evw9vy |
MD5: | 40D5CFEB9C9057CD077FD9E3E67521B5 |
SHA1: | EEC3A9FFACB9EAD3B3CDD039CD2AE26EBFD7088B |
SHA-256: | BECD701829155AD75BA221C89AFB3E0E1D3A3BEEB2842B224210DB78CEF2CADB |
SHA-512: | 8C02D4EF73FA0B4A084EE97531CB506F8C9D8076B6C5A8E5C0E36D909AB7979C5295396EA3853B83619A7E0D07FD081E614B13DFA07558087A3F5D5C6246D165 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9851800188696194 |
Encrypted: | false |
SSDEEP: | 48:8nOdVT9BEHCidAKZdA1duTeehOuTbbiZUk5OjqehOuTbZy+yT+:8EviTfTbxWOvTbZy7T |
MD5: | 852DD81336B6B3586D13530A3AB0B632 |
SHA1: | E68433C25E9430466C99912E3DD871F531AB083D |
SHA-256: | F98FA2BFF9FDC46BCBD733DED40507AF73809D6B564C0F2D89173CE8E808A540 |
SHA-512: | 5ECE0A8E3DE6BB51502E9B3981C40B0A92DE40007E977431F57143AEEE08DFE1CF394E5FF90218DF95E354320FD378A84F3CE080B5184FAFE2E3A7070F69F65F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32 |
Entropy (8bit): | 4.413909765557392 |
Encrypted: | false |
SSDEEP: | 3:2T5CZZ8mek:0CZZ8m7 |
MD5: | A5ED4BAF1E3EA02E3E8303106EBB791A |
SHA1: | C583088EC025B992C59C4AA4B9543B38B3EB1FF5 |
SHA-256: | 1403C7DC4D943C3C944027680B720C798AF62BF7B6D36B6CC2FD0C5F8E9EFC41 |
SHA-512: | D2072CD2BB901223A3B34AD98668CA6B2143286A56450B90C2984FF07AB446783AD72FEC3E5296CA773E5DC84A6240EA667C880C5D4B22A2AFF55C454619D5D1 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwnafXqpG7OCbBIFDbq_44ASBQ1MSZGY?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 56109 |
Entropy (8bit): | 7.973537367126651 |
Encrypted: | false |
SSDEEP: | 768:K2IH1Jqp3G6W3cZZq0PtaJg01kv+HnSKDS+Mj4wjRHQV2w/BCnhdKGNqvzgkH0O1:ArqpXH3RlCgLFjj4mRHs2w0n6IstzQq |
MD5: | CE793AC1E75B3F60908CC6E3D63379E5 |
SHA1: | 3BF1BAD607D899BB91DECB1BB0B32A0D82C233A8 |
SHA-256: | 42171D76548498998DA88F032ABA50A028B9481FD7004A9A3B5D3B8D98FE48A2 |
SHA-512: | 025C6474A68618D59ABD019B1821C5ACBDA6958FF7FC9D97DBBECA02C0BCBE2C5329603AE61EC89B00DBA1F09525F76D04B54BC6D9B5B8D230609282E78CC1FC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 274 |
Entropy (8bit): | 6.732985317875807 |
Encrypted: | false |
SSDEEP: | 6:6v/lhPfah08/kKvMIoRNqe6zProGR9nsA+/VUftMNCv8j24VwK/DgJA/8Wgp:6v/76rv2NaDzrsPVUmCqEU5EWq |
MD5: | 21A42A57BC0B13BBAE707196837C5EC3 |
SHA1: | F58514B1CDB45B009548BA5C504A4AB536D348A0 |
SHA-256: | 663FBBB2E70A843DA32D00D5EC403BD87B280351958BC537C09B84B31BC391C6 |
SHA-512: | 1D815C66C6B03CA81139848343B0241837F3D54EF3B91797F260DC97CA2D907C1D34162E8E8B4A0893C5E13F5AABFA14C11B03C8D512A8C75F06525F40825AED |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 274 |
Entropy (8bit): | 6.732985317875807 |
Encrypted: | false |
SSDEEP: | 6:6v/lhPfah08/kKvMIoRNqe6zProGR9nsA+/VUftMNCv8j24VwK/DgJA/8Wgp:6v/76rv2NaDzrsPVUmCqEU5EWq |
MD5: | 21A42A57BC0B13BBAE707196837C5EC3 |
SHA1: | F58514B1CDB45B009548BA5C504A4AB536D348A0 |
SHA-256: | 663FBBB2E70A843DA32D00D5EC403BD87B280351958BC537C09B84B31BC391C6 |
SHA-512: | 1D815C66C6B03CA81139848343B0241837F3D54EF3B91797F260DC97CA2D907C1D34162E8E8B4A0893C5E13F5AABFA14C11B03C8D512A8C75F06525F40825AED |
Malicious: | false |
Reputation: | low |
URL: | "https://t1.gstatic.com/faviconV2?client=SOCIAL&type=FAVICON&fallback_opts=TYPE,SIZE,URL&url=http://sealevel.com&size=16" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 492 |
Entropy (8bit): | 7.443140866786406 |
Encrypted: | false |
SSDEEP: | 12:6v/7w9xBoc7dfbmXwR54uPABdsBCRGE03H76f79ysL5w:t9/1dfbV5pIssN03H7kpyW5w |
MD5: | 3CA64F83FDCF25135D87E08AF65E68C9 |
SHA1: | B82D0979D555BD137B33C15021129E06CBEEA59A |
SHA-256: | 2E30FF33270FD8687B0EB4D12652BFD967F23975F158BF8DA93BECE2BA4AB947 |
SHA-512: | 7675A8C4E6146E62DDA019340EF95E477AA3D14364B5A773114EA1110C38233F5D8D9B08F6C83BF7664B33695AAC7254B25D727A15EA6A9DED2EC9D1EA07DC0E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 56109 |
Entropy (8bit): | 7.973537367126651 |
Encrypted: | false |
SSDEEP: | 768:K2IH1Jqp3G6W3cZZq0PtaJg01kv+HnSKDS+Mj4wjRHQV2w/BCnhdKGNqvzgkH0O1:ArqpXH3RlCgLFjj4mRHs2w0n6IstzQq |
MD5: | CE793AC1E75B3F60908CC6E3D63379E5 |
SHA1: | 3BF1BAD607D899BB91DECB1BB0B32A0D82C233A8 |
SHA-256: | 42171D76548498998DA88F032ABA50A028B9481FD7004A9A3B5D3B8D98FE48A2 |
SHA-512: | 025C6474A68618D59ABD019B1821C5ACBDA6958FF7FC9D97DBBECA02C0BCBE2C5329603AE61EC89B00DBA1F09525F76D04B54BC6D9B5B8D230609282E78CC1FC |
Malicious: | false |
Reputation: | low |
URL: | https://firebasestorage.googleapis.com/v0/b/portal-aa363.appspot.com/o/26-269507_arbys-logo-transparent-norton-secured-logo-png-png.png?alt=media&token=270a0942-12e5-423b-8855-04615084dca8 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 492 |
Entropy (8bit): | 7.443140866786406 |
Encrypted: | false |
SSDEEP: | 12:6v/7w9xBoc7dfbmXwR54uPABdsBCRGE03H76f79ysL5w:t9/1dfbV5pIssN03H7kpyW5w |
MD5: | 3CA64F83FDCF25135D87E08AF65E68C9 |
SHA1: | B82D0979D555BD137B33C15021129E06CBEEA59A |
SHA-256: | 2E30FF33270FD8687B0EB4D12652BFD967F23975F158BF8DA93BECE2BA4AB947 |
SHA-512: | 7675A8C4E6146E62DDA019340EF95E477AA3D14364B5A773114EA1110C38233F5D8D9B08F6C83BF7664B33695AAC7254B25D727A15EA6A9DED2EC9D1EA07DC0E |
Malicious: | false |
Reputation: | low |
URL: | https://firebasestorage.googleapis.com/v0/b/portal-aa363.appspot.com/o/favicons.png?alt=media&token=805fb0ef-a2d9-4a7f-85e6-d68384e166e3 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | 1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 55407 |
Entropy (8bit): | 5.481899219948928 |
Encrypted: | false |
SSDEEP: | 384:/VfMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDnMXDn9:/jJBaA6 |
MD5: | D0EB7045E8185F39786D730EC4797FA9 |
SHA1: | 8C990E122CE9AE5ACAB54FF2E85C5F7D38B2F42B |
SHA-256: | 65787486D5A9E23FE92B12EC8AC56CF8105573C2980FC7EA1DA15CB66B1780EC |
SHA-512: | 4C43EA7804C29A4585BAADC286AD4378D16CFB55FB526F6A75D305A53BA789FC9BBC66A8C0A88F463A6A962AC356337A914C88CCD43E7550073F2C6884CC3331 |
Malicious: | false |
Reputation: | low |
URL: | https://ipfs.io/ipfs/bafkreidfpb2invnj4i76skys5sfmk3hycbkxhquyb7d6uhnbls3gwf4a5q |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | 1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
Reputation: | low |
URL: | https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 14:57:42.629472017 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:57:42.932024002 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:57:43.538969994 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:57:44.427371979 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.427405119 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.427455902 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.427917957 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.428020954 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.428024054 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.428033113 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.428102016 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.428299904 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.428344011 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.742072105 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:57:44.893742085 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.893748999 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.894033909 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.894057035 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.894248962 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.894320011 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.895728111 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.895797968 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.895848989 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.895921946 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.896925926 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.897011042 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.897083044 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.897089005 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.897165060 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.897254944 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.947994947 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.948121071 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:44.948189020 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.996021032 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.058799982 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.058845997 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.058877945 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.058906078 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.058939934 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.058953047 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.058981895 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.058995008 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.059046984 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.059052944 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.059461117 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.059487104 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.059521914 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.059528112 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.059585094 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.063472033 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.063517094 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.063582897 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.063589096 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.107019901 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.145482063 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.145529032 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.145553112 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.145582914 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.145617962 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.145643950 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.145657063 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.145998001 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146048069 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146054029 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.146060944 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146097898 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.146104097 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146644115 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146680117 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146713972 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146750927 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146795988 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146820068 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.146827936 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.146852016 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.147567987 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.147602081 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.147638083 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.147659063 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.147665024 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.147686958 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.147696972 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.147742987 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.147748947 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.148483992 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.148533106 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.148534060 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.148542881 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.148590088 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.232652903 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.232887983 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.232923985 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.232959032 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.232986927 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.233021975 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.233042002 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.233381987 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.233428955 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.237543106 CET | 49708 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:45.237564087 CET | 443 | 49708 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.274044037 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:57:47.148055077 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:57:48.028635979 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.028681040 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.028768063 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.029112101 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.029131889 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.066917896 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.066982031 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.067074060 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.067555904 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.067590952 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.289706945 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:48.289752007 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:48.289861917 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:48.290098906 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:48.290118933 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:48.554013968 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.554335117 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.554404020 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.555913925 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.555995941 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.557080030 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.557183027 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.557262897 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.557280064 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.612993956 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:48.666991949 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.667284966 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.667299986 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.668179989 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.668241978 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.669656038 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.669725895 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.670088053 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.670099020 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.722978115 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.941452980 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.941652060 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.941714048 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.942162991 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.942183971 CET | 443 | 49720 | 142.250.185.100 | 192.168.2.16 |
Jan 15, 2025 14:57:48.942193031 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.942239046 CET | 49720 | 443 | 192.168.2.16 | 142.250.185.100 |
Jan 15, 2025 14:57:48.952857018 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:48.953126907 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:48.953140020 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:48.954152107 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:48.954212904 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:48.954530001 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:48.954607964 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:49.008981943 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:49.008997917 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:49.056994915 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:49.111248016 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111500025 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111566067 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.111591101 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111676931 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111721039 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.111732006 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111829042 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111876011 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.111885071 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.111975908 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.112021923 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.112030029 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.115827084 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.115888119 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.115900993 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.115986109 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.116030931 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.116039991 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.127118111 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.127269983 CET | 443 | 49721 | 104.21.64.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.127337933 CET | 49721 | 443 | 192.168.2.16 | 104.21.64.1 |
Jan 15, 2025 14:57:49.136560917 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.136595011 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.136667967 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.136914015 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.136928082 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.630136967 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.630347967 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.630357981 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.631589890 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.631666899 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.632564068 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.632630110 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.632715940 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.679008007 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.679016113 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.724986076 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.759506941 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.759573936 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.759629011 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.759803057 CET | 49725 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.759816885 CET | 443 | 49725 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.760953903 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.761002064 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.761198997 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.761430979 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:49.761444092 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.236922979 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.237381935 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.237406015 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.237906933 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.239176035 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.239290953 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.240895987 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.283370972 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.368539095 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.368737936 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.368818998 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.368983984 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.369009972 CET | 443 | 49726 | 35.190.80.1 | 192.168.2.16 |
Jan 15, 2025 14:57:50.369024038 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.369066954 CET | 49726 | 443 | 192.168.2.16 | 35.190.80.1 |
Jan 15, 2025 14:57:50.794486046 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:57:51.098030090 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:57:51.700416088 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:57:51.955005884 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:57:52.905354023 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:57:55.263354063 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:57:55.311050892 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:57:55.566080093 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:57:56.173055887 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:57:57.387171984 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:57:58.860161066 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:58.860311985 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:58.860512972 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:59.699614048 CET | 49722 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:57:59.699692011 CET | 443 | 49722 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:57:59.793530941 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:59.793608904 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:57:59.793791056 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:57:59.794135094 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:58:00.126051903 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:58:01.453780890 CET | 49709 | 443 | 192.168.2.16 | 209.94.90.1 |
Jan 15, 2025 14:58:01.453856945 CET | 443 | 49709 | 209.94.90.1 | 192.168.2.16 |
Jan 15, 2025 14:58:01.564081907 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 14:58:04.594141006 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:58:09.727271080 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 14:58:14.201158047 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 14:58:26.331120968 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:26.331192017 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:26.331301928 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:26.331480980 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:26.331505060 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.013196945 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.013655901 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.013719082 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.015883923 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.016005039 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.017190933 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.017311096 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.017380953 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.059406042 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.066453934 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.066514015 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.114209890 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.312446117 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.312529087 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:27.312633991 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.313168049 CET | 49730 | 443 | 192.168.2.16 | 178.63.67.106 |
Jan 15, 2025 14:58:27.313208103 CET | 443 | 49730 | 178.63.67.106 | 192.168.2.16 |
Jan 15, 2025 14:58:30.704426050 CET | 49698 | 80 | 192.168.2.16 | 2.22.50.144 |
Jan 15, 2025 14:58:30.704607010 CET | 49699 | 80 | 192.168.2.16 | 2.22.50.144 |
Jan 15, 2025 14:58:30.709533930 CET | 80 | 49698 | 2.22.50.144 | 192.168.2.16 |
Jan 15, 2025 14:58:30.709619045 CET | 49698 | 80 | 192.168.2.16 | 2.22.50.144 |
Jan 15, 2025 14:58:30.709947109 CET | 80 | 49699 | 2.22.50.144 | 192.168.2.16 |
Jan 15, 2025 14:58:30.710002899 CET | 49699 | 80 | 192.168.2.16 | 2.22.50.144 |
Jan 15, 2025 14:58:48.340646029 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:48.340722084 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:48.340817928 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:48.341087103 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:48.341109037 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:49.009887934 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:49.010410070 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:49.010456085 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:49.011599064 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:49.012000084 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:49.012186050 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:49.056422949 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:58.890100002 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:58.890280008 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:58:58.890360117 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:59.712307930 CET | 49733 | 443 | 192.168.2.16 | 172.217.16.196 |
Jan 15, 2025 14:58:59.712390900 CET | 443 | 49733 | 172.217.16.196 | 192.168.2.16 |
Jan 15, 2025 14:59:21.100697041 CET | 49701 | 80 | 192.168.2.16 | 2.23.77.188 |
Jan 15, 2025 14:59:21.100698948 CET | 49700 | 443 | 192.168.2.16 | 20.190.160.22 |
Jan 15, 2025 14:59:21.105895042 CET | 80 | 49701 | 2.23.77.188 | 192.168.2.16 |
Jan 15, 2025 14:59:21.105986118 CET | 49701 | 80 | 192.168.2.16 | 2.23.77.188 |
Jan 15, 2025 14:59:21.106411934 CET | 443 | 49700 | 20.190.160.22 | 192.168.2.16 |
Jan 15, 2025 14:59:21.106461048 CET | 49700 | 443 | 192.168.2.16 | 20.190.160.22 |
Jan 15, 2025 14:59:23.450917959 CET | 49702 | 443 | 192.168.2.16 | 20.190.160.22 |
Jan 15, 2025 14:59:23.456094980 CET | 443 | 49702 | 20.190.160.22 | 192.168.2.16 |
Jan 15, 2025 14:59:23.456211090 CET | 49702 | 443 | 192.168.2.16 | 20.190.160.22 |
Jan 15, 2025 14:59:48.411153078 CET | 49735 | 443 | 192.168.2.16 | 142.250.185.196 |
Jan 15, 2025 14:59:48.411181927 CET | 443 | 49735 | 142.250.185.196 | 192.168.2.16 |
Jan 15, 2025 14:59:48.411318064 CET | 49735 | 443 | 192.168.2.16 | 142.250.185.196 |
Jan 15, 2025 14:59:48.411598921 CET | 49735 | 443 | 192.168.2.16 | 142.250.185.196 |
Jan 15, 2025 14:59:48.411613941 CET | 443 | 49735 | 142.250.185.196 | 192.168.2.16 |
Jan 15, 2025 14:59:49.067292929 CET | 443 | 49735 | 142.250.185.196 | 192.168.2.16 |
Jan 15, 2025 14:59:49.067981958 CET | 49735 | 443 | 192.168.2.16 | 142.250.185.196 |
Jan 15, 2025 14:59:49.067996979 CET | 443 | 49735 | 142.250.185.196 | 192.168.2.16 |
Jan 15, 2025 14:59:49.068455935 CET | 443 | 49735 | 142.250.185.196 | 192.168.2.16 |
Jan 15, 2025 14:59:49.068923950 CET | 49735 | 443 | 192.168.2.16 | 142.250.185.196 |
Jan 15, 2025 14:59:49.069010973 CET | 443 | 49735 | 142.250.185.196 | 192.168.2.16 |
Jan 15, 2025 14:59:49.116672039 CET | 49735 | 443 | 192.168.2.16 | 142.250.185.196 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 14:57:43.455904007 CET | 53 | 56364 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:43.505564928 CET | 53 | 53387 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.418514967 CET | 64082 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:44.419014931 CET | 63870 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:44.425057888 CET | 53 | 64082 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.426829100 CET | 53 | 63870 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:44.533152103 CET | 53 | 54391 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.173799038 CET | 53 | 55304 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:45.262469053 CET | 53 | 59575 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:46.325562954 CET | 53 | 56080 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:46.397471905 CET | 53 | 56021 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:46.671319008 CET | 53 | 52107 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.020912886 CET | 54054 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:48.021136999 CET | 52867 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:48.021785021 CET | 58794 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:48.022075891 CET | 58840 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:48.027671099 CET | 53 | 52867 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.027884960 CET | 53 | 54054 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.055109978 CET | 53 | 58794 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.185657978 CET | 53 | 58840 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.280703068 CET | 60179 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:48.280915976 CET | 60394 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:48.288597107 CET | 53 | 60394 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.288614988 CET | 53 | 60179 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:48.951143980 CET | 53 | 60851 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.128684998 CET | 51943 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:49.128892899 CET | 56011 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:57:49.135535955 CET | 53 | 51943 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.136188030 CET | 53 | 56011 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:57:49.906971931 CET | 53 | 60976 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:01.461950064 CET | 53 | 54457 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:20.512196064 CET | 53 | 59433 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:26.321968079 CET | 64732 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:58:26.322180986 CET | 49826 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:58:26.329401970 CET | 53 | 64732 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:26.330595970 CET | 53 | 49826 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:43.243693113 CET | 53 | 51622 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:43.453785896 CET | 53 | 57224 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:58:46.959796906 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Jan 15, 2025 14:59:13.568681955 CET | 53 | 58301 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:59:48.403007030 CET | 62768 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:59:48.403158903 CET | 55152 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 14:59:48.409857988 CET | 53 | 55152 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 14:59:48.410310030 CET | 53 | 62768 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 15, 2025 14:57:48.185810089 CET | 192.168.2.16 | 1.1.1.1 | c2ea | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 14:57:44.418514967 CET | 192.168.2.16 | 1.1.1.1 | 0xfca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:57:44.419014931 CET | 192.168.2.16 | 1.1.1.1 | 0x4867 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 14:57:48.020912886 CET | 192.168.2.16 | 1.1.1.1 | 0xb5af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:57:48.021136999 CET | 192.168.2.16 | 1.1.1.1 | 0x2f48 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 14:57:48.021785021 CET | 192.168.2.16 | 1.1.1.1 | 0xda64 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:57:48.022075891 CET | 192.168.2.16 | 1.1.1.1 | 0xbc62 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 14:57:48.280703068 CET | 192.168.2.16 | 1.1.1.1 | 0xb730 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:57:48.280915976 CET | 192.168.2.16 | 1.1.1.1 | 0x399b | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 14:57:49.128684998 CET | 192.168.2.16 | 1.1.1.1 | 0x75a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:57:49.128892899 CET | 192.168.2.16 | 1.1.1.1 | 0x5693 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 14:58:26.321968079 CET | 192.168.2.16 | 1.1.1.1 | 0x3e49 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:58:26.322180986 CET | 192.168.2.16 | 1.1.1.1 | 0x29ad | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 14:59:48.403007030 CET | 192.168.2.16 | 1.1.1.1 | 0xf840 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 14:59:48.403158903 CET | 192.168.2.16 | 1.1.1.1 | 0xd147 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 14:57:44.425057888 CET | 1.1.1.1 | 192.168.2.16 | 0xfca | No error (0) | 209.94.90.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:44.426829100 CET | 1.1.1.1 | 192.168.2.16 | 0x4867 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 14:57:48.027671099 CET | 1.1.1.1 | 192.168.2.16 | 0x2f48 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 14:57:48.027884960 CET | 1.1.1.1 | 192.168.2.16 | 0xb5af | No error (0) | 142.250.185.100 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.055109978 CET | 1.1.1.1 | 192.168.2.16 | 0xda64 | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:48.185657978 CET | 1.1.1.1 | 192.168.2.16 | 0xbc62 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 14:57:48.288597107 CET | 1.1.1.1 | 192.168.2.16 | 0x399b | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 14:57:48.288614988 CET | 1.1.1.1 | 192.168.2.16 | 0xb730 | No error (0) | 172.217.16.196 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:57:49.135535955 CET | 1.1.1.1 | 192.168.2.16 | 0x75a | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:58:26.329401970 CET | 1.1.1.1 | 192.168.2.16 | 0x3e49 | No error (0) | 178.63.67.106 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:58:26.329401970 CET | 1.1.1.1 | 192.168.2.16 | 0x3e49 | No error (0) | 178.63.67.153 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 14:59:48.409857988 CET | 1.1.1.1 | 192.168.2.16 | 0xd147 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 14:59:48.410310030 CET | 1.1.1.1 | 192.168.2.16 | 0xf840 | No error (0) | 142.250.185.196 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49708 | 209.94.90.1 | 443 | 6924 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 13:57:44 UTC | 714 | OUT | |
2025-01-15 13:57:45 UTC | 1069 | IN | |
2025-01-15 13:57:45 UTC | 300 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN | |
2025-01-15 13:57:45 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49721 | 104.21.64.1 | 443 | 6924 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 13:57:48 UTC | 670 | OUT | |
2025-01-15 13:57:49 UTC | 1281 | IN | |
2025-01-15 13:57:49 UTC | 1253 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN | |
2025-01-15 13:57:49 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49720 | 142.250.185.100 | 443 | 6924 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 13:57:48 UTC | 689 | OUT | |
2025-01-15 13:57:48 UTC | 484 | IN | |
2025-01-15 13:57:48 UTC | 332 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49725 | 35.190.80.1 | 443 | 6924 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 13:57:49 UTC | 537 | OUT | |
2025-01-15 13:57:49 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49726 | 35.190.80.1 | 443 | 6924 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 13:57:50 UTC | 478 | OUT | |
2025-01-15 13:57:50 UTC | 400 | OUT | |
2025-01-15 13:57:50 UTC | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49730 | 178.63.67.106 | 443 | 6924 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 13:58:27 UTC | 688 | OUT | |
2025-01-15 13:58:27 UTC | 58 | OUT | |
2025-01-15 13:58:27 UTC | 191 | IN | |
2025-01-15 13:58:27 UTC | 115 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:57:42 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 08:57:42 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:57:43 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |