Windows
Analysis Report
https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 2804 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 4320 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2292,i ,173524361 6567819914 2,10092777 1887104257 98,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=2492 /prefetch :3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6648 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://usg02 .safelinks .protectio n.office36 5.us/?url= https%3A%2 F%2Flinks. daily.inve stingskeep er.com%2Ft rack%3Fuid %3Da3279f8 b-b292-438 c-a320-cc2 0f4c87589% 26txnid%3D 4d4792a7-4 bc3-4505-9 78b-f20945 0cd9a8%26e id%3D4c4e8 593-ace9-4 767-8b41-8 513ad59743 8%26mid%3D 3362ae60-5 88c-49ab-b 09c-80f1ed 79d17b%26b sft_ek%3D2 025-03-24T 22%253A00% 253A12Z%26 bsft_mime_ type%3Dhtm l%26bsft_t v%3D198%26 bsft_lx%3D 6%26bsft_a aid%3Da1f6 e90e-30b3- 4e74-bc2b- d28e46c02c 74%26a%3Dc lick%26red ir%3Dhttps %253A%252F %252Fclick .tracking. investings keeper.com %252F67c98 43e0f3b707 c79a6b65c% 253Femail% 253Dlinden .blue%2525 40ga.com%2 526domain% 253D035IK% 2526type%2 53DB%2526p roduct%253 DAYGT3JS2% 2526utm_ca mpaign%253 Dik_r-24-3 -aygt3js2- yahoo_all% 2526utm_so urce%253Db lueshift%2 526utm_med ium%253Dem ail%2526ut m_content% 253Dik_r-t emplate-2& data=05%7C 02%7Clinde n.blue%40g a.com%7Cb4 00af556efd 4c2a03ac08 dd6b24dfdb %7C05e5388 7e4b345958 7f73ae79f0 e723e%7C0% 7C0%7C6387 8452830894 9376%7CUnk nown%7CTWF pbGZsb3d8e yJFbXB0eU1 hcGkiOnRyd WUsIlYiOiI wLjAuMDAwM CIsIlAiOiJ XaW4zMiIsI kFOIjoiTWF pbCIsIldUI joyfQ%3D%3 D%7C0%7C%7 C%7C&sdata =tjEqsrgVw LWIuwClGr3 H%2FpLKdZ7 vzNH6qyW1Z OS1SBA%3D& reserved=0 " MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_BlockedWebSite | Yara detected BlockedWebSite | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_BlockedWebSite | Yara detected BlockedWebSite | Joe Security |
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Phishing |
---|
Source: | File source: | ||
Source: | File source: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
usg02.safelinks.protection.office365.us | 23.103.208.28 | true | false | high | |
www.google.com | 142.251.40.196 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.103.209.28 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
23.103.208.28 | usg02.safelinks.protection.office365.us | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.251.40.196 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1648609 |
Start date and time: | 2025-03-26 01:56:42 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%3A00%3A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%3A%2F%2Fclick.tracking.investingskeeper.com%2F67c9843e0f3b707c79a6b65c%3Femail%3Dlinden.blue%2540ga.com%26domain%3D035IK%26type%3DB%26product%3DAYGT3JS2%26utm_campaign%3Dik_r-24-3-aygt3js2-yahoo_all%26utm_source%3Dblueshift%26utm_medium%3Demail%26utm_content%3Dik_r-template-2&data=05|02|linden.blue%40ga.com|b400af556efd4c2a03ac08dd6b24dfdb|05e53887e4b3459587f73ae79f0e723e|0|0|638784528308949376|Unknown|TWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D|0|||&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.phis.win@21/9@6/4 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.41.3, 142. 251.40.110, 142.251.40.238, 64 .233.180.84, 142.250.81.238, 1 42.250.176.206, 23.203.176.221 , 199.232.214.172, 142.250.72. 110, 142.250.80.110, 142.251.3 2.110, 142.250.80.78, 142.250. 176.195, 142.251.40.206, 142.2 50.72.99, 184.31.69.3, 4.245.1 63.56 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fe3cr.deliv ery.mp.microsoft.com, clients2 .google.com, edgedl.me.gvt1.co m, redirector.gvt1.com, ocsp.d igicert.com, update.googleapis .com, clients.l.google.com, c. pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//usg02.safelinks.protection.o ffice365.us/?url=https%3A%2F%2 Flinks.daily.investingskeeper. com%2Ftrack%3Fuid%3Da3279f8b-b 292-438c-a320-cc20f4c87589%26t xnid%3D4d4792a7-4bc3-4505-978b -f209450cd9a8%26eid%3D4c4e8593 -ace9-4767-8b41-8513ad597438%2 6mid%3D3362ae60-588c-49ab-b09c -80f1ed79d17b%26bsft_ek%3D2025 -03-24T22%253A00%253A12Z%26bsf t_mime_type%3Dhtml%26bsft_tv%3 D198%26bsft_lx%3D6%26bsft_aaid %3Da1f6e90e-30b3-4e74-bc2b-d28 e46c02c74%26a%3Dclick%26redir% 3Dhttps%253A%252F%252Fclick.tr acking.investingskeeper.com%25 2F67c9843e0f3b707c79a6b65c%253 Femail%253Dlinden.blue%252540g a.com%2526domain%253D035IK%252 6type%253DB%2526product%253DAY GT3JS2%2526utm_campaign%253Dik _r-24-3-aygt3js2-yahoo_all%252 6utm_source%253Dblueshift%2526 utm_medium%253Demail%2526utm_c ontent%253Dik_r-template-2& ;data=05%7C02%7Clinden.blue%40 ga.com%7Cb400af556efd4c2a03ac0 8dd6b24dfdb%7C05e53887e4b34595 87f73ae79f0e723e%7C0%7C0%7C638 784528308949376%7CUnknown%7CTW FpbGZsb3d8eyJFbXB0eU1hcGkiOnRy dWUsIlYiOiIwLjAuMDAwMCIsIlAiOi JXaW4zMi
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6481 |
Entropy (8bit): | 5.9837161374056524 |
Encrypted: | false |
SSDEEP: | 96:qE6+WMS85j6dEKE7WzVDEJ3cG3pJjzpekmGbsMJpZmu7VvC68d4gC4vr:V6ZMSJ+7SzWJ3D5Nzpekdb1Jn1ZqR2Ir |
MD5: | 9D0D75CBB0196F64A50E88E68DCF5FF2 |
SHA1: | 7F56EE90FC68F9621610BA182F5C0A614B343EAD |
SHA-256: | E52A742B837BF9DC8127AC9BE5B04A72037834E031D2EE224E3092DAA98D08EE |
SHA-512: | 2059BD2D3787214E59E95438586565F887489560E32D2D1C2E562F5DAC510BBCEC84B83658DB0A13A4AA6409A5036DDDF8DBEAE2A91FBCEDF3F807528521E662 |
Malicious: | false |
Reputation: | low |
URL: | https://usg02.safelinks.protection.office365.us/?url=https%3A%2F%2Flinks.daily.investingskeeper.com%2Ftrack%3Fuid%3Da3279f8b-b292-438c-a320-cc20f4c87589%26txnid%3D4d4792a7-4bc3-4505-978b-f209450cd9a8%26eid%3D4c4e8593-ace9-4767-8b41-8513ad597438%26mid%3D3362ae60-588c-49ab-b09c-80f1ed79d17b%26bsft_ek%3D2025-03-24T22%253A00%253A12Z%26bsft_mime_type%3Dhtml%26bsft_tv%3D198%26bsft_lx%3D6%26bsft_aaid%3Da1f6e90e-30b3-4e74-bc2b-d28e46c02c74%26a%3Dclick%26redir%3Dhttps%253A%252F%252Fclick.tracking.investingskeeper.com%252F67c9843e0f3b707c79a6b65c%253Femail%253Dlinden.blue%252540ga.com%2526domain%253D035IK%2526type%253DB%2526product%253DAYGT3JS2%2526utm_campaign%253Dik_r-24-3-aygt3js2-yahoo_all%2526utm_source%253Dblueshift%2526utm_medium%253Demail%2526utm_content%253Dik_r-template-2&data=05%7C02%7Clinden.blue%40ga.com%7Cb400af556efd4c2a03ac08dd6b24dfdb%7C05e53887e4b3459587f73ae79f0e723e%7C0%7C0%7C638784528308949376%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tjEqsrgVwLWIuwClGr3H%2FpLKdZ7vzNH6qyW1ZOS1SBA%3D&reserved=0 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 25664 |
Entropy (8bit): | 4.972505404550475 |
Encrypted: | false |
SSDEEP: | 384:OXE05KiOBf35OPGJulcJBzzdtKUmpZKfWve:E35Ki7PGJNJBZOpZKeve |
MD5: | FF4FEDB556605288FEC259EE6B8D5981 |
SHA1: | BBC525AB65E54999044F14FF8F31CF25EEDB7754 |
SHA-256: | 2809B6F62DC341D238F02C33C7347A7BA714F10B6F075BDD39A1CD7C68CE9807 |
SHA-512: | 9EAE6F8D1822A1EF91B909B0D6A8826BFB323BD34FA76FBF0A2DCA99B5F580BA09173ECD2068F393979EBAE248BF5FF1FC592C5D43D5EEB33E0EC6DDE93E8349 |
Malicious: | false |
Reputation: | low |
URL: | https://usg02.safelinks.protection.office365.us/Content/images/cross.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25664 |
Entropy (8bit): | 4.972505404550475 |
Encrypted: | false |
SSDEEP: | 384:OXE05KiOBf35OPGJulcJBzzdtKUmpZKfWve:E35Ki7PGJNJBZOpZKeve |
MD5: | FF4FEDB556605288FEC259EE6B8D5981 |
SHA1: | BBC525AB65E54999044F14FF8F31CF25EEDB7754 |
SHA-256: | 2809B6F62DC341D238F02C33C7347A7BA714F10B6F075BDD39A1CD7C68CE9807 |
SHA-512: | 9EAE6F8D1822A1EF91B909B0D6A8826BFB323BD34FA76FBF0A2DCA99B5F580BA09173ECD2068F393979EBAE248BF5FF1FC592C5D43D5EEB33E0EC6DDE93E8349 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3932 |
Entropy (8bit): | 5.202197618496175 |
Encrypted: | false |
SSDEEP: | 96:W1nWD5QBnuxm32TPv1YyZvtcpcJcLCmzYzMz4ChX5xQFMXpSgfsHjrAwn:MmmqvWCiLfxpSgfsHjrAwn |
MD5: | BBAD95C4A0BE4E5775B7D5B409FBF602 |
SHA1: | FAD598750B15C207DFEF6E1FEA3C072BAEAC2B66 |
SHA-256: | 41F78D15AE18C36B84C819D9AF3511C342C180F0ABA8F91DC1CCF4046B56B308 |
SHA-512: | 4006994F240E4DAB7134F1B716E51E4FFC0DD495EAF3269165FB0C27D89B2F19063AF17086553B39507199D62DBCD8BA6F07F34770BCAF15C40CF5EF06419631 |
Malicious: | false |
Reputation: | low |
URL: | https://usg02.safelinks.protection.office365.us/Content/Scripts/safelinksv2.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1588 |
Entropy (8bit): | 5.174121809218917 |
Encrypted: | false |
SSDEEP: | 48:9pZigAOvzbYdvG2AumPBqykF1KdpwGFKcjeA5mkxofP:piFVmPBq/OI9GGP |
MD5: | 3AF1FDB9A3F664A6683D212F4787733A |
SHA1: | 59063D49B723A1988236C8D39C2804C6EBC5FF95 |
SHA-256: | A9CE4840FF0D613B456081DEA64E46EB717A1F8BFA5AFB05D3BD058F294E416C |
SHA-512: | F8872E0C875BE6037C14480630E461FC1ADFA2049DB03BAE5D8CB6B320A2C084D4B266AEB02E24009B4BA84821E216690CA875B165164447FE8329B48C9E261F |
Malicious: | false |
Reputation: | low |
URL: | https://usg02.safelinks.protection.office365.us/Content/Scripts/site.js |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 104
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2025 01:57:37.284415007 CET | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:37.799932003 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 26, 2025 01:57:40.912554979 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:41.221775055 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:41.831270933 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:43.034399986 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:45.505126953 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:46.893248081 CET | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:47.408875942 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 26, 2025 01:57:49.674515963 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:57:49.806052923 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:57:49.806122065 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:49.806195021 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:57:49.806338072 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:57:49.806355953 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:49.987024069 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:57:50.010118008 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:50.010195971 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:57:50.011363029 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:57:50.011380911 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:50.011642933 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:50.065140009 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:57:50.315160990 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:50.596415043 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:57:51.802324057 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:57:51.818700075 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:51.818734884 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:51.818799019 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:51.819020033 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:51.819036961 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:51.819386005 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:51.819469929 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:51.819614887 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:51.819722891 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:51.819746971 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.155713081 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.155786037 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:52.155991077 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.156070948 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:52.157617092 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:52.157632113 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.158128977 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.158433914 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:52.158478975 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.160222054 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:52.160228968 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.160629034 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:52.208394051 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:54.210784912 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:57:55.763952017 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.767137051 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.767184973 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.854223013 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.855232954 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.855310917 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.855837107 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.856218100 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.856236935 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.856298923 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.856347084 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.856405020 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.859385967 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.859424114 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:55.859462976 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.859482050 CET | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 01:57:55.945647955 CET | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Mar 26, 2025 01:57:57.313010931 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.313066959 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.313152075 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.313183069 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.313235998 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.313241005 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.313292027 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.314929008 CET | 49727 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.314941883 CET | 443 | 49727 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.354618073 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.354650021 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.354724884 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.354851007 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.354968071 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.355129957 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.355148077 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.471575022 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.471601963 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.471709967 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.471746922 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.471913099 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.475681067 CET | 49726 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.475699902 CET | 443 | 49726 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.478243113 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.478274107 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.478751898 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.478794098 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.478799105 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.676625013 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.678967953 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.679008007 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.682390928 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.682405949 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.796504021 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.796526909 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.796629906 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.796629906 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.796746969 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.800978899 CET | 49732 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.801001072 CET | 443 | 49732 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.802578926 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.844333887 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.909935951 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.909948111 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:57.918060064 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:57.918109894 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148669958 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148734093 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148756981 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148798943 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148814917 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.148833036 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148842096 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148855925 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.148953915 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.148953915 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.148953915 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.148988008 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.149014950 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.149024010 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.149144888 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.149152040 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.149199009 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.149322987 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.149518967 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.153381109 CET | 49735 | 443 | 192.168.2.4 | 23.103.208.28 |
Mar 26, 2025 01:57:58.153403997 CET | 443 | 49735 | 23.103.208.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.446722031 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:58.446794033 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.446937084 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:58.447051048 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:58.447068930 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.900587082 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.900679111 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:58.901236057 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:58.901254892 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.902009964 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:58.902367115 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:58.948276043 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.018646002 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:57:59.206824064 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.206871033 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.206914902 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.206935883 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.206979036 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207010031 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.207050085 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.207056046 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207083941 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207117081 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207117081 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.207148075 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.207163095 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207211971 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.207226038 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207279921 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.207324028 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.208969116 CET | 49737 | 443 | 192.168.2.4 | 23.103.209.28 |
Mar 26, 2025 01:57:59.208993912 CET | 443 | 49737 | 23.103.209.28 | 192.168.2.4 |
Mar 26, 2025 01:57:59.925076962 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 01:57:59.993982077 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:59.994038105 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:57:59.994203091 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:58:01.849370956 CET | 49723 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:58:01.849400997 CET | 443 | 49723 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:08.618676901 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 01:58:49.759231091 CET | 49743 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:58:49.759336948 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:49.759463072 CET | 49743 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:58:49.759614944 CET | 49743 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:58:49.759638071 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:49.949270964 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:49.949539900 CET | 49743 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:58:49.949590921 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:59.949956894 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:59.950015068 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Mar 26, 2025 01:58:59.950203896 CET | 49743 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:59:01.848155022 CET | 49743 | 443 | 192.168.2.4 | 142.251.40.196 |
Mar 26, 2025 01:59:01.848217010 CET | 443 | 49743 | 142.251.40.196 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2025 01:57:45.886795998 CET | 53 | 54269 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:45.902930021 CET | 53 | 56807 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:46.491627932 CET | 53 | 57756 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:46.575021982 CET | 53 | 52922 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:49.706882000 CET | 53919 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 01:57:49.707182884 CET | 60784 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 01:57:49.804002047 CET | 53 | 60784 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:49.805320978 CET | 53 | 53919 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:51.663768053 CET | 58886 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 01:57:51.663862944 CET | 61152 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 01:57:51.815254927 CET | 53 | 61152 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:51.816668034 CET | 53 | 58886 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:58.241349936 CET | 60309 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 01:57:58.241584063 CET | 49734 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 01:57:58.412461996 CET | 53 | 60309 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:57:58.446156025 CET | 53 | 49734 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:58:03.481544971 CET | 53 | 52853 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:58:22.340908051 CET | 53 | 49594 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:58:44.790582895 CET | 53 | 51411 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:58:45.379599094 CET | 53 | 55305 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:58:48.117305994 CET | 53 | 61777 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 01:58:49.103167057 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Mar 26, 2025 01:57:46.487552881 CET | 192.168.2.4 | 1.1.1.1 | c1f9 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 26, 2025 01:57:49.706882000 CET | 192.168.2.4 | 1.1.1.1 | 0x1117 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 01:57:49.707182884 CET | 192.168.2.4 | 1.1.1.1 | 0xb89d | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 01:57:51.663768053 CET | 192.168.2.4 | 1.1.1.1 | 0xc8ee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 01:57:51.663862944 CET | 192.168.2.4 | 1.1.1.1 | 0xa534 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 01:57:58.241349936 CET | 192.168.2.4 | 1.1.1.1 | 0xa387 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 01:57:58.241584063 CET | 192.168.2.4 | 1.1.1.1 | 0xefe2 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 26, 2025 01:57:49.804002047 CET | 1.1.1.1 | 192.168.2.4 | 0xb89d | No error (0) | 65 | IN (0x0001) | false | |||
Mar 26, 2025 01:57:49.805320978 CET | 1.1.1.1 | 192.168.2.4 | 0x1117 | No error (0) | 142.251.40.196 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 01:57:51.816668034 CET | 1.1.1.1 | 192.168.2.4 | 0xc8ee | No error (0) | 23.103.208.28 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 01:57:51.816668034 CET | 1.1.1.1 | 192.168.2.4 | 0xc8ee | No error (0) | 23.103.209.28 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 01:57:58.412461996 CET | 1.1.1.1 | 192.168.2.4 | 0xa387 | No error (0) | 23.103.209.28 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 01:57:58.412461996 CET | 1.1.1.1 | 192.168.2.4 | 0xa387 | No error (0) | 23.103.208.28 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49727 | 23.103.208.28 | 443 | 4320 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 00:57:52 UTC | 1754 | OUT | |
2025-03-26 00:57:57 UTC | 612 | IN | |
2025-03-26 00:57:57 UTC | 6481 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49726 | 23.103.208.28 | 443 | 4320 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 00:57:57 UTC | 1680 | OUT | |
2025-03-26 00:57:57 UTC | 539 | IN | |
2025-03-26 00:57:57 UTC | 3932 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49732 | 23.103.208.28 | 443 | 4320 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 00:57:57 UTC | 1658 | OUT | |
2025-03-26 00:57:57 UTC | 553 | IN | |
2025-03-26 00:57:57 UTC | 1588 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49735 | 23.103.208.28 | 443 | 4320 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 00:57:57 UTC | 1719 | OUT | |
2025-03-26 00:57:58 UTC | 540 | IN | |
2025-03-26 00:57:58 UTC | 15844 | IN | |
2025-03-26 00:57:58 UTC | 9820 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49737 | 23.103.209.28 | 443 | 4320 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 00:57:58 UTC | 427 | OUT | |
2025-03-26 00:57:59 UTC | 541 | IN | |
2025-03-26 00:57:59 UTC | 15843 | IN | |
2025-03-26 00:57:59 UTC | 9821 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 20:57:40 |
Start date: | 25/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 20:57:43 |
Start date: | 25/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:57:50 |
Start date: | 25/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |