Windows
Analysis Report
https://click.convertkit-mail3.com/p9up9gom8kb9h226rgmtqhpn5o333hr/l2hehmhl56p999b6/zlFhiaJ8BbBSEcPFc3ACzWUXL68bravVsl61ZdxQNjnUhzShEZyq224==#dDBQWGNXNGYzMHd4ZHpCMEtqcm5LTE5zb0YzVlQzR1BiMG43QVA3aUNLRUszekhxdDlWVUMzWFhldlJlMGppK21UY0NZcXpGS2QxMjdPS2VuTnRzWU9FUXovZ2RzZXJhK0VLRDNLMkViNHM9
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 2660 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 2556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1968,i ,493449850 3610984479 ,299934614 537164840, 262144 --d isable-fea tures=Opti mizationGu ideModelDo wnloading, Optimizati onHints,Op timization HintsFetch ing,Optimi zationTarg etPredicti on --varia tions-seed -version=2 0250306-18 3004.42900 0 --mojo-p latform-ch annel-hand le=2012 /p refetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6396 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://click .convertki t-mail3.co m/p9up9gom 8kb9h226rg mtqhpn5o33 3hr/l2hehm hl56p999b6 /zlFhiaJ8B bBSEcPFc3A CzWUXL68br avVsl61Zdx QNjnUhzShE Zyq224==#d DBQWGNXNGY zMHd4ZHpCM Etqcm5LTE5 zb0YzVlQzR 1BiMG43QVA 3aUNLRUsze khxdDlWVUM zWFhldlJlM GppK21UY0N ZcXpGS2QxM jdPS2VuTnR zWU9FUXovZ 2RzZXJhK0V LRDNLMkViN HM9" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • AV Detection
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: | ||
Source: | HTTP traffic: | ||
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.dpvyw6trk.com | 35.190.6.55 | true | false | unknown | |
alexandermoss-yy.com | 103.100.38.23 | true | false | unknown | |
xmu.freshreliablelink.com | 190.10.8.2 | true | false | high | |
www.google.com | 142.250.80.68 | true | false | high | |
www.streamoptimum.com | 216.244.86.218 | true | false | unknown | |
xmu.topnewlink.com | 190.10.8.2 | true | false | high | |
click.convertkit-mail3.com | 3.137.134.154 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.80.68 | www.google.com | United States | 15169 | GOOGLEUS | false | |
3.137.134.154 | click.convertkit-mail3.com | United States | 16509 | AMAZON-02US | false | |
190.10.8.2 | xmu.freshreliablelink.com | Costa Rica | 3790 | RADIOGRAFICACOSTARRICENSECR | false | |
216.244.86.218 | www.streamoptimum.com | United States | 23033 | WOWUS | false | |
103.100.38.23 | alexandermoss-yy.com | India | 136956 | ANATPL-AS-APAssistiveNetworksandtechnologiesPvtLtdIN | false | |
35.190.6.55 | www.dpvyw6trk.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.10 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1644452 |
Start date and time: | 2025-03-20 15:25:00 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 55s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://click.convertkit-mail3.com/p9up9gom8kb9h226rgmtqhpn5o333hr/l2hehmhl56p999b6/zlFhiaJ8BbBSEcPFc3ACzWUXL68bravVsl61ZdxQNjnUhzShEZyq224==#dDBQWGNXNGYzMHd4ZHpCMEtqcm5LTE5zb0YzVlQzR1BiMG43QVA3aUNLRUszekhxdDlWVUMzWFhldlJlMGppK21UY0NZcXpGS2QxMjdPS2VuTnRzWU9FUXovZ2RzZXJhK0VLRDNLMkViNHM9 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@22/2@17/7 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, s ppsvc.exe, SIHClient.exe, Sgrm userer.exe, conhost.exe, TextI nputHost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.35.163, 14 2.250.80.46, 142.250.65.238, 1 72.253.115.84, 142.250.65.206, 172.253.122.84, 142.251.40.20 6, 142.251.40.174, 142.250.80. 78, 199.232.214.172, 142.251.4 1.14, 142.251.32.110, 142.250. 80.35, 142.251.40.110, 142.251 .40.142, 142.251.40.99, 172.20 2.163.200, 184.30.55.36 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, clients2.google.com, edged l.me.gvt1.com, accounts.google .com, redirector.gvt1.com, sls cr.update.microsoft.com, updat e.googleapis.com, ctldl.window supdate.com, clientservices.go ogleapis.com, clients.l.google .com, c.pki.goog, fe3cr.delive ry.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//click.convertkit-mail3.com/p 9up9gom8kb9h226rgmtqhpn5o333hr /l2hehmhl56p999b6/zlFhiaJ8BbBS EcPFc3ACzWUXL68bravVsl61ZdxQNj nUhzShEZyq224==#dDBQWGNXNGYzMH d4ZHpCMEtqcm5LTE5zb0YzVlQzR1Bi MG43QVA3aUNLRUszekhxdDlWVUMzWF hldlJlMGppK21UY0NZcXpGS2QxMjdP S2VuTnRzWU9FUXovZ2RzZXJhK0VLRD NLMkViNHM9
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 577 |
Entropy (8bit): | 7.636286762385051 |
Encrypted: | false |
SSDEEP: | 12:X35Bp2PN07P8P0DzRJ6CoRUyWUxPgO/bOtshYTkU2fJ7:X3pON0LO0JJ6CoRUyWKb7YTX2V |
MD5: | 2C8AB6CCF49FBC48B083881E8B6328CB |
SHA1: | F2D9ECC6DDE0C2D7E30F59D8349C7F5F8F6A583D |
SHA-256: | B8EFBF3285E723EB18E161E4BDBAF64075E91A2EF1D6AE730B573E751CA2B81D |
SHA-512: | 324722F83218D2E42B5F7D45CF10C6AE7145B6E65671B9E72FA4F5F1817F48DB4A4C4DE2236FB3BC7593D37442DCB0EA378C3CEB41EE936472814F867CD7903C |
Malicious: | false |
Reputation: | low |
URL: | http://alexandermoss-yy.com/ |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 138
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 20, 2025 15:25:54.234708071 CET | 49677 | 443 | 192.168.2.10 | 2.23.227.208 |
Mar 20, 2025 15:25:54.234728098 CET | 49676 | 443 | 192.168.2.10 | 2.23.227.208 |
Mar 20, 2025 15:25:54.234848022 CET | 49675 | 443 | 192.168.2.10 | 2.23.227.208 |
Mar 20, 2025 15:26:01.565783978 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:01.565830946 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:01.566083908 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:01.566083908 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:01.566116095 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:01.786657095 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:01.786792994 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:01.787977934 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:01.787990093 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:01.788408995 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:01.841440916 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:02.870739937 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:02.870781898 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:02.871109962 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:02.871321917 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:02.871361971 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:02.871428967 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:02.871500969 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:02.871516943 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:02.871638060 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:02.871645927 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.194508076 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.194582939 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.195859909 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.195871115 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.196127892 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.196455002 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.197206974 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.197273016 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.198225021 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.198246956 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.198649883 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.240334988 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.249388933 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.316474915 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.316569090 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.316824913 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.317020893 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.317045927 CET | 443 | 49689 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:03.317055941 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.317193031 CET | 49689 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:03.469811916 CET | 49691 | 443 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:03.469857931 CET | 443 | 49691 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:03.469964027 CET | 49691 | 443 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:03.470124960 CET | 49691 | 443 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:03.470134020 CET | 443 | 49691 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:03.775348902 CET | 443 | 49691 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:03.776058912 CET | 49692 | 443 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:03.776110888 CET | 443 | 49692 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:03.776329994 CET | 49692 | 443 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:03.776329994 CET | 49692 | 443 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:03.776369095 CET | 443 | 49692 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:03.843630075 CET | 49677 | 443 | 192.168.2.10 | 2.23.227.208 |
Mar 20, 2025 15:26:03.843630075 CET | 49676 | 443 | 192.168.2.10 | 2.23.227.208 |
Mar 20, 2025 15:26:03.843643904 CET | 49675 | 443 | 192.168.2.10 | 2.23.227.208 |
Mar 20, 2025 15:26:04.094996929 CET | 443 | 49692 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:04.277347088 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:04.363253117 CET | 49694 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:04.583913088 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:04.586020947 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:04.613571882 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:04.682387114 CET | 80 | 49694 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:04.682563066 CET | 49694 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:04.919709921 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:04.920604944 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:04.971579075 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:05.037452936 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:05.388252020 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:06.792052031 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:06.841299057 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:08.094969988 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.095021963 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.095097065 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.095333099 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.095345974 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.421618938 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.421729088 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.422995090 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.423007965 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.423254013 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.423819065 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.464324951 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.903175116 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.903248072 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.903465033 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.905117035 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.905137062 CET | 443 | 49697 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.905148029 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.905186892 CET | 49697 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.907896996 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.907944918 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:08.908027887 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.908189058 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:08.908205032 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:09.280561924 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:09.280854940 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:09.280879021 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:09.281336069 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:09.281361103 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:09.328039885 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:09.641274929 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:09.801019907 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:09.801095963 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:09.801161051 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:09.801620007 CET | 49698 | 443 | 192.168.2.10 | 216.244.86.218 |
Mar 20, 2025 15:26:09.801642895 CET | 443 | 49698 | 216.244.86.218 | 192.168.2.10 |
Mar 20, 2025 15:26:10.079417944 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:10.079469919 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:10.079600096 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:10.079827070 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:10.079833984 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:10.246575117 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:10.467999935 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:10.468128920 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:10.469436884 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:10.469451904 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:10.469783068 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:10.470144987 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:10.516335011 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.065248013 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.065351009 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.065408945 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.065927029 CET | 49699 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.065952063 CET | 443 | 49699 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.330235958 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.330281019 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.330332994 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.330540895 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.330550909 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.452524900 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:11.700922966 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.701081038 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.704564095 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.704579115 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.704834938 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.708017111 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:11.752321959 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:11.810237885 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:11.810308933 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:11.810353994 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:11.817545891 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:11.817991018 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:12.409199953 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:12.409308910 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:12.409439087 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:12.410022020 CET | 49700 | 443 | 192.168.2.10 | 190.10.8.2 |
Mar 20, 2025 15:26:12.410037041 CET | 443 | 49700 | 190.10.8.2 | 192.168.2.10 |
Mar 20, 2025 15:26:12.411952019 CET | 49688 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:26:12.411979914 CET | 443 | 49688 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:26:12.412034988 CET | 49693 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:12.722398043 CET | 80 | 49693 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:12.727236032 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:12.727344036 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:12.727438927 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:12.727582932 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:12.727615118 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:12.930761099 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:12.930897951 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:12.931974888 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:12.932007074 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:12.932300091 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:12.932571888 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:12.976329088 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:13.163892031 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:13.163970947 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:13.164028883 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:13.164499044 CET | 49703 | 443 | 192.168.2.10 | 35.190.6.55 |
Mar 20, 2025 15:26:13.164518118 CET | 443 | 49703 | 35.190.6.55 | 192.168.2.10 |
Mar 20, 2025 15:26:13.856652021 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:14.169219017 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Mar 20, 2025 15:26:14.266114950 CET | 80 | 49707 | 142.251.32.99 | 192.168.2.10 |
Mar 20, 2025 15:26:14.266205072 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Mar 20, 2025 15:26:14.266385078 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Mar 20, 2025 15:26:14.363843918 CET | 80 | 49707 | 142.251.32.99 | 192.168.2.10 |
Mar 20, 2025 15:26:14.364423990 CET | 80 | 49707 | 142.251.32.99 | 192.168.2.10 |
Mar 20, 2025 15:26:14.370286942 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Mar 20, 2025 15:26:14.467006922 CET | 80 | 49707 | 142.251.32.99 | 192.168.2.10 |
Mar 20, 2025 15:26:14.513292074 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Mar 20, 2025 15:26:17.841818094 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:18.153784990 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:18.669677019 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:18.764810085 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:19.967473984 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:22.372790098 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:27.186634064 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:28.278795958 CET | 49672 | 443 | 192.168.2.10 | 204.79.197.203 |
Mar 20, 2025 15:26:36.121881008 CET | 80 | 49694 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:36.122035980 CET | 49694 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:36.796329021 CET | 49678 | 443 | 192.168.2.10 | 20.189.173.26 |
Mar 20, 2025 15:26:48.200817108 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:26:48.200845957 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:26:49.685112000 CET | 49694 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:49.988940954 CET | 80 | 49694 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:56.446307898 CET | 80 | 49694 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:26:56.446398020 CET | 49694 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:56.811952114 CET | 49694 | 80 | 192.168.2.10 | 103.100.38.23 |
Mar 20, 2025 15:26:57.135148048 CET | 80 | 49694 | 103.100.38.23 | 192.168.2.10 |
Mar 20, 2025 15:27:01.484175920 CET | 49716 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:27:01.484224081 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:01.484293938 CET | 49716 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:27:01.484591007 CET | 49716 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:27:01.484602928 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:01.682899952 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:01.683387995 CET | 49716 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:27:01.683408022 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:03.196602106 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:27:03.196675062 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:27:03.196742058 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:27:03.390201092 CET | 49690 | 443 | 192.168.2.10 | 3.137.134.154 |
Mar 20, 2025 15:27:03.390235901 CET | 443 | 49690 | 3.137.134.154 | 192.168.2.10 |
Mar 20, 2025 15:27:11.682720900 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:11.682794094 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:11.682843924 CET | 49716 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:27:13.393107891 CET | 49716 | 443 | 192.168.2.10 | 142.250.80.68 |
Mar 20, 2025 15:27:13.393151045 CET | 443 | 49716 | 142.250.80.68 | 192.168.2.10 |
Mar 20, 2025 15:27:14.670562983 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Mar 20, 2025 15:27:14.803591967 CET | 80 | 49707 | 142.251.32.99 | 192.168.2.10 |
Mar 20, 2025 15:27:14.803886890 CET | 49707 | 80 | 192.168.2.10 | 142.251.32.99 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 20, 2025 15:25:57.005536079 CET | 53 | 56750 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:25:57.421503067 CET | 53 | 58228 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:25:57.515650988 CET | 53 | 65263 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:25:58.186470032 CET | 53 | 64417 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:01.420402050 CET | 60243 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:01.420576096 CET | 59466 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:01.533005953 CET | 53 | 59466 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:01.564762115 CET | 53 | 60243 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:02.742484093 CET | 51173 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:02.744654894 CET | 50946 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:02.847415924 CET | 53 | 50946 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:02.869951010 CET | 53 | 51173 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:03.322218895 CET | 61294 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:03.322582006 CET | 62641 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:03.437474966 CET | 53 | 61294 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:03.476687908 CET | 53 | 62641 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:04.098401070 CET | 63092 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:04.098762035 CET | 50842 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:04.252360106 CET | 53 | 63092 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:04.276834965 CET | 53 | 50842 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:06.802881956 CET | 52006 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:06.803041935 CET | 57840 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:06.979427099 CET | 53 | 57840 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:07.826797962 CET | 60272 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:08.094393969 CET | 53 | 60272 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:09.803993940 CET | 49578 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:09.804177046 CET | 49867 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:10.062480927 CET | 53 | 49867 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:10.078068018 CET | 53 | 49578 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:11.068389893 CET | 64753 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:11.068645954 CET | 51049 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:11.316073895 CET | 53 | 64753 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:11.329721928 CET | 53 | 51049 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:12.412328005 CET | 49673 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:12.412477970 CET | 55988 | 53 | 192.168.2.10 | 1.1.1.1 |
Mar 20, 2025 15:26:12.644701004 CET | 53 | 55988 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:12.726608038 CET | 53 | 49673 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:15.155695915 CET | 53 | 56499 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:34.280849934 CET | 53 | 61147 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:56.821136951 CET | 53 | 58054 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:56.951287985 CET | 53 | 65470 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:26:59.879765987 CET | 53 | 57990 | 1.1.1.1 | 192.168.2.10 |
Mar 20, 2025 15:27:16.489485979 CET | 138 | 138 | 192.168.2.10 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Mar 20, 2025 15:25:57.418183088 CET | 192.168.2.10 | 1.1.1.1 | c239 | (Port unreachable) | Destination Unreachable |
Mar 20, 2025 15:26:03.476784945 CET | 192.168.2.10 | 1.1.1.1 | c236 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 20, 2025 15:26:01.420402050 CET | 192.168.2.10 | 1.1.1.1 | 0xad91 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:01.420576096 CET | 192.168.2.10 | 1.1.1.1 | 0x9eea | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:02.742484093 CET | 192.168.2.10 | 1.1.1.1 | 0x9dc3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:02.744654894 CET | 192.168.2.10 | 1.1.1.1 | 0x6435 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:03.322218895 CET | 192.168.2.10 | 1.1.1.1 | 0xf08e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:03.322582006 CET | 192.168.2.10 | 1.1.1.1 | 0xd3c0 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:04.098401070 CET | 192.168.2.10 | 1.1.1.1 | 0xb5be | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:04.098762035 CET | 192.168.2.10 | 1.1.1.1 | 0x52a0 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:06.802881956 CET | 192.168.2.10 | 1.1.1.1 | 0xbee7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:06.803041935 CET | 192.168.2.10 | 1.1.1.1 | 0x16f5 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:07.826797962 CET | 192.168.2.10 | 1.1.1.1 | 0x4ca1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:09.803993940 CET | 192.168.2.10 | 1.1.1.1 | 0xee7c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:09.804177046 CET | 192.168.2.10 | 1.1.1.1 | 0x7e91 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:11.068389893 CET | 192.168.2.10 | 1.1.1.1 | 0x73e0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:11.068645954 CET | 192.168.2.10 | 1.1.1.1 | 0x3772 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 20, 2025 15:26:12.412328005 CET | 192.168.2.10 | 1.1.1.1 | 0xaadf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 20, 2025 15:26:12.412477970 CET | 192.168.2.10 | 1.1.1.1 | 0xa58a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 20, 2025 15:26:01.533005953 CET | 1.1.1.1 | 192.168.2.10 | 0x9eea | No error (0) | 65 | IN (0x0001) | false | |||
Mar 20, 2025 15:26:01.564762115 CET | 1.1.1.1 | 192.168.2.10 | 0xad91 | No error (0) | 142.250.80.68 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:02.869951010 CET | 1.1.1.1 | 192.168.2.10 | 0x9dc3 | No error (0) | 3.137.134.154 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:02.869951010 CET | 1.1.1.1 | 192.168.2.10 | 0x9dc3 | No error (0) | 3.141.235.236 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:02.869951010 CET | 1.1.1.1 | 192.168.2.10 | 0x9dc3 | No error (0) | 3.20.113.100 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:03.437474966 CET | 1.1.1.1 | 192.168.2.10 | 0xf08e | No error (0) | 103.100.38.23 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:04.252360106 CET | 1.1.1.1 | 192.168.2.10 | 0xb5be | No error (0) | 103.100.38.23 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:08.094393969 CET | 1.1.1.1 | 192.168.2.10 | 0x4ca1 | No error (0) | 216.244.86.218 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:10.078068018 CET | 1.1.1.1 | 192.168.2.10 | 0xee7c | No error (0) | 190.10.8.2 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:11.316073895 CET | 1.1.1.1 | 192.168.2.10 | 0x73e0 | No error (0) | 190.10.8.2 | A (IP address) | IN (0x0001) | false | ||
Mar 20, 2025 15:26:12.726608038 CET | 1.1.1.1 | 192.168.2.10 | 0xaadf | No error (0) | 35.190.6.55 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49693 | 103.100.38.23 | 80 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 20, 2025 15:26:04.613571882 CET | 435 | OUT | |
Mar 20, 2025 15:26:04.920604944 CET | 829 | IN | |
Mar 20, 2025 15:26:05.037452936 CET | 618 | OUT | |
Mar 20, 2025 15:26:06.792052031 CET | 488 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.10 | 49707 | 142.251.32.99 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 20, 2025 15:26:14.266385078 CET | 202 | OUT | |
Mar 20, 2025 15:26:14.364423990 CET | 223 | IN | |
Mar 20, 2025 15:26:14.370286942 CET | 200 | OUT | |
Mar 20, 2025 15:26:14.467006922 CET | 223 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.10 | 49694 | 103.100.38.23 | 80 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 20, 2025 15:26:49.685112000 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49689 | 3.137.134.154 | 443 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-20 14:26:03 UTC | 782 | OUT | |
2025-03-20 14:26:03 UTC | 471 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.10 | 49697 | 216.244.86.218 | 443 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-20 14:26:08 UTC | 771 | OUT | |
2025-03-20 14:26:08 UTC | 646 | IN | |
2025-03-20 14:26:08 UTC | 276 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.10 | 49698 | 216.244.86.218 | 443 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-20 14:26:09 UTC | 934 | OUT | |
2025-03-20 14:26:09 UTC | 629 | IN | |
2025-03-20 14:26:09 UTC | 98 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.10 | 49699 | 190.10.8.2 | 443 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-20 14:26:10 UTC | 737 | OUT | |
2025-03-20 14:26:11 UTC | 833 | IN | |
2025-03-20 14:26:11 UTC | 718 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.10 | 49700 | 190.10.8.2 | 443 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-20 14:26:11 UTC | 784 | OUT | |
2025-03-20 14:26:12 UTC | 811 | IN | |
2025-03-20 14:26:12 UTC | 662 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.10 | 49703 | 35.190.6.55 | 443 | 2556 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-20 14:26:12 UTC | 762 | OUT | |
2025-03-20 14:26:13 UTC | 299 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 10:25:55 |
Start date: | 20/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ea9f0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 10:25:55 |
Start date: | 20/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ea9f0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 10:26:02 |
Start date: | 20/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ea9f0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |