Windows
Analysis Report
http://www.greendon.com/
Overview
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 2420 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 508 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2452,i ,104696265 8353439651 5,15961310 5525305224 55,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=2464 /prefetch :3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6772 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://www.gr eendon.com /" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 2 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.greendon.com | 95.211.219.66 | true | true | unknown | |
www.muscleandstrength.com | 104.22.7.178 | true | false | high | |
www.google.com | 142.251.40.228 | true | false | high | |
www.toroexoclk.com | 104.248.224.96 | true | false | high | |
saltandsalad.com | 184.94.215.122 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | high | ||
true |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
true |
| unknown | |
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
184.94.215.122 | saltandsalad.com | United States | 394896 | VXCHNGE-NC01US | false | |
104.22.7.178 | www.muscleandstrength.com | United States | 13335 | CLOUDFLARENETUS | false | |
104.248.224.96 | www.toroexoclk.com | United States | 14061 | DIGITALOCEAN-ASNUS | false | |
95.211.219.66 | www.greendon.com | Netherlands | 60781 | LEASEWEB-NL-AMS-01NetherlandsNL | true | |
142.251.40.228 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
192.168.2.6 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1649446 |
Start date and time: | 2025-03-26 19:33:39 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://www.greendon.com/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@23/2@14/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.72.110, 14 2.250.65.227, 172.253.122.84, 142.250.80.78, 142.250.176.195 , 23.9.183.29, 20.12.23.50 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, clients2.google.com, edged l.me.gvt1.com, accounts.google .com, redirector.gvt1.com, sls cr.update.microsoft.com, updat e.googleapis.com, clientservic es.googleapis.com, clients.l.g oogle.com, fe3cr.delivery.mp.m icrosoft.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: http:/
/www.greendon.com/
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 478 |
Entropy (8bit): | 5.831258948220251 |
Encrypted: | false |
SSDEEP: | 12:kxvsCk9cE3MJS/XUIfeyJ7cYpxpTWEUdN3ozVEZkYI:kbxs/kIfeEGd9+CI |
MD5: | 389A6D57D704002440495E20918828BF |
SHA1: | 778D12BAA52330F7F4048AC27E62DF8F739E00C1 |
SHA-256: | C321C18B384DB881BF43A73104EF11C59AF9A0A180504EE3291E1E4E2DEB405C |
SHA-512: | 8F32D02AE0C4041D125FEE7B95E7110981ABD885678FD438892EADDC51BFBC71BC87331B77D064549B18B5DE47AB6F54B5E3636FD570C325E19DED997D52F3CF |
Malicious: | false |
Reputation: | low |
URL: | https://www.greendon.com/ |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 132
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2025 19:34:30.696722031 CET | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 19:34:31.743761063 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 26, 2025 19:34:37.394124031 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:37.696707010 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:38.384227037 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:39.587342024 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:40.306132078 CET | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Mar 26, 2025 19:34:41.353032112 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 26, 2025 19:34:42.065778017 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:43.552155018 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:43.552189112 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:43.552450895 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:43.552614927 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:43.552628040 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:43.755786896 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:43.755894899 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:43.758584023 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:43.758596897 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:43.758938074 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:43.805591106 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:44.778178930 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:44.778239965 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:44.778357029 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:44.778564930 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:44.778580904 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:44.809261084 CET | 49731 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:44.809581041 CET | 49732 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:44.986217022 CET | 80 | 49732 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:44.986293077 CET | 49732 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:44.987207890 CET | 80 | 49731 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:44.988274097 CET | 49731 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.353410006 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.353491068 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.359601021 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.359612942 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.359857082 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.360186100 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.404278994 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.547665119 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.547741890 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.548006058 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.637115002 CET | 49730 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.637144089 CET | 443 | 49730 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.639842033 CET | 49735 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.639873981 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.639983892 CET | 49735 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.640511990 CET | 49735 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.640511990 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.640527010 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.640548944 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:45.640681028 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.640855074 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:45.640863895 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:46.012224913 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:46.012494087 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:46.012511015 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:46.012702942 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:46.012707949 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:46.017024994 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:46.017277956 CET | 49735 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:46.017297029 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:46.089732885 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:34:46.389100075 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:34:46.873917103 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:46.992994070 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:34:47.051981926 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:47.052057028 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:47.052107096 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:47.052726984 CET | 49736 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:47.052746058 CET | 443 | 49736 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:47.157150030 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.157191992 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.157274961 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.157618999 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.157629013 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.347750902 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.347846985 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.349001884 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.349011898 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.349328041 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.349550962 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.349559069 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.599247932 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.599325895 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.599419117 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.623358011 CET | 49738 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:47.623380899 CET | 443 | 49738 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:47.733633041 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:47.733681917 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:47.733968019 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:47.735766888 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:47.735783100 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.057631969 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.057763100 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.059073925 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.059083939 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.059323072 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.059669971 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.100275993 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.194760084 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:34:48.362581015 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.362656116 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.362699986 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.363126040 CET | 49739 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.363152027 CET | 443 | 49739 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.365298986 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.365331888 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.365396023 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.365510941 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.365518093 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.680566072 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.681061983 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.681082010 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:48.681555986 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:48.681562901 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:49.353501081 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:49.355716944 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:49.355778933 CET | 443 | 49740 | 184.94.215.122 | 192.168.2.4 |
Mar 26, 2025 19:34:49.355941057 CET | 49740 | 443 | 192.168.2.4 | 184.94.215.122 |
Mar 26, 2025 19:34:49.495043039 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.495076895 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.495316029 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.495316029 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.495343924 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.690954924 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.691049099 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.696912050 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.696934938 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.697171926 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.697757959 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.740264893 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.918617010 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.918723106 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.918761015 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.918776035 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.918788910 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.918800116 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.918839931 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.919178009 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919209003 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919225931 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.919241905 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919275999 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919291019 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.919300079 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919341087 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.919349909 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919363022 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.919406891 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.920171976 CET | 49741 | 443 | 192.168.2.4 | 104.22.7.178 |
Mar 26, 2025 19:34:49.920186996 CET | 443 | 49741 | 104.22.7.178 | 192.168.2.4 |
Mar 26, 2025 19:34:49.922828913 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:49.922863960 CET | 443 | 49742 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:49.922930002 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:49.923060894 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:49.923068047 CET | 443 | 49742 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.112955093 CET | 443 | 49742 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.113289118 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.113310099 CET | 443 | 49742 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.154047012 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.166637897 CET | 80 | 49732 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:50.166722059 CET | 49732 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:50.168934107 CET | 80 | 49731 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:50.168984890 CET | 49731 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:50.246033907 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.246118069 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.246387005 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.339374065 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.366473913 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.417011023 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.481975079 CET | 49732 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:50.482013941 CET | 49731 | 80 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:50.482146978 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.577991962 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.578752041 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:50.606841087 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:34:50.622225046 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:50.662687063 CET | 80 | 49732 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:50.662707090 CET | 80 | 49731 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:51.211442947 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:51.211517096 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:51.211699963 CET | 49735 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:51.340795994 CET | 49735 | 443 | 192.168.2.4 | 95.211.219.66 |
Mar 26, 2025 19:34:51.340831995 CET | 443 | 49735 | 95.211.219.66 | 192.168.2.4 |
Mar 26, 2025 19:34:53.783415079 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:53.783469915 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:53.783530951 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:55.338931084 CET | 49729 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:34:55.338970900 CET | 443 | 49729 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:34:55.415462017 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:34:56.477988958 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 26, 2025 19:34:56.578954935 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:34:56.579021931 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:57.338818073 CET | 49743 | 80 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:34:57.430485010 CET | 80 | 49743 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:35:05.027000904 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 26, 2025 19:35:23.572760105 CET | 49715 | 80 | 192.168.2.4 | 142.250.80.67 |
Mar 26, 2025 19:35:23.572966099 CET | 49714 | 80 | 192.168.2.4 | 23.210.73.5 |
Mar 26, 2025 19:35:23.573029041 CET | 49716 | 80 | 192.168.2.4 | 23.210.73.5 |
Mar 26, 2025 19:35:23.663353920 CET | 80 | 49715 | 142.250.80.67 | 192.168.2.4 |
Mar 26, 2025 19:35:23.663417101 CET | 49715 | 80 | 192.168.2.4 | 142.250.80.67 |
Mar 26, 2025 19:35:23.663878918 CET | 80 | 49714 | 23.210.73.5 | 192.168.2.4 |
Mar 26, 2025 19:35:23.663928986 CET | 49714 | 80 | 192.168.2.4 | 23.210.73.5 |
Mar 26, 2025 19:35:23.664175034 CET | 80 | 49716 | 23.210.73.5 | 192.168.2.4 |
Mar 26, 2025 19:35:23.664266109 CET | 49716 | 80 | 192.168.2.4 | 23.210.73.5 |
Mar 26, 2025 19:35:35.119354963 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:35:35.119364977 CET | 443 | 49742 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:35:43.526546001 CET | 49753 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:35:43.526592016 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:35:43.526665926 CET | 49753 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:35:43.526846886 CET | 49753 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:35:43.526863098 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:35:43.715437889 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:35:43.715975046 CET | 49753 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:35:43.716012955 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:35:51.340183020 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:35:51.340297937 CET | 443 | 49742 | 104.248.224.96 | 192.168.2.4 |
Mar 26, 2025 19:35:51.340383053 CET | 49742 | 443 | 192.168.2.4 | 104.248.224.96 |
Mar 26, 2025 19:35:53.734023094 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:35:53.734077930 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Mar 26, 2025 19:35:53.734143972 CET | 49753 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:35:55.340543032 CET | 49753 | 443 | 192.168.2.4 | 142.251.40.228 |
Mar 26, 2025 19:35:55.340569973 CET | 443 | 49753 | 142.251.40.228 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 26, 2025 19:34:39.646071911 CET | 53 | 54910 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:39.646389961 CET | 53 | 49784 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:39.867089987 CET | 53 | 50430 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:40.339107037 CET | 53 | 49749 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:43.462835073 CET | 55775 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:43.463005066 CET | 61093 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:43.550915956 CET | 53 | 55775 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:43.551023960 CET | 53 | 61093 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:44.586751938 CET | 51294 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:44.587084055 CET | 56301 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:44.600795984 CET | 55795 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:44.601058006 CET | 53040 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:44.754857063 CET | 53 | 53040 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:44.754873991 CET | 53 | 56301 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:44.777498960 CET | 53 | 55795 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:44.777546883 CET | 53 | 51294 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:47.060152054 CET | 59759 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:47.060321093 CET | 60994 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:47.152956009 CET | 53 | 59759 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:47.156748056 CET | 53 | 60994 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:47.626018047 CET | 52635 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:47.626364946 CET | 55489 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:47.718230963 CET | 53 | 55489 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:47.723885059 CET | 53 | 52635 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:49.355721951 CET | 53866 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:49.355824947 CET | 64725 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:49.489105940 CET | 53 | 53866 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:49.494411945 CET | 53 | 64725 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:50.064982891 CET | 62861 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:50.065174103 CET | 60659 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 26, 2025 19:34:50.153223991 CET | 53 | 62861 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:50.153357029 CET | 53 | 60659 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:34:57.426995039 CET | 53 | 59231 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:35:16.181325912 CET | 53 | 56803 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:35:17.583950996 CET | 53 | 58845 | 162.159.36.2 | 192.168.2.4 |
Mar 26, 2025 19:35:38.870840073 CET | 53 | 57054 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:35:39.021372080 CET | 53 | 53958 | 1.1.1.1 | 192.168.2.4 |
Mar 26, 2025 19:35:45.734808922 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 26, 2025 19:34:43.462835073 CET | 192.168.2.4 | 1.1.1.1 | 0x543f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:43.463005066 CET | 192.168.2.4 | 1.1.1.1 | 0xcd3c | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 19:34:44.586751938 CET | 192.168.2.4 | 1.1.1.1 | 0xc06e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:44.587084055 CET | 192.168.2.4 | 1.1.1.1 | 0x1795 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 19:34:44.600795984 CET | 192.168.2.4 | 1.1.1.1 | 0x8d0a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:44.601058006 CET | 192.168.2.4 | 1.1.1.1 | 0xd38d | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 19:34:47.060152054 CET | 192.168.2.4 | 1.1.1.1 | 0xabdf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:47.060321093 CET | 192.168.2.4 | 1.1.1.1 | 0x8a2e | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 19:34:47.626018047 CET | 192.168.2.4 | 1.1.1.1 | 0x7cfb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:47.626364946 CET | 192.168.2.4 | 1.1.1.1 | 0x1730 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 19:34:49.355721951 CET | 192.168.2.4 | 1.1.1.1 | 0xc890 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:49.355824947 CET | 192.168.2.4 | 1.1.1.1 | 0xcbc2 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 26, 2025 19:34:50.064982891 CET | 192.168.2.4 | 1.1.1.1 | 0xabac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 26, 2025 19:34:50.065174103 CET | 192.168.2.4 | 1.1.1.1 | 0xa474 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 26, 2025 19:34:43.550915956 CET | 1.1.1.1 | 192.168.2.4 | 0x543f | No error (0) | 142.251.40.228 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:43.551023960 CET | 1.1.1.1 | 192.168.2.4 | 0xcd3c | No error (0) | 65 | IN (0x0001) | false | |||
Mar 26, 2025 19:34:44.777498960 CET | 1.1.1.1 | 192.168.2.4 | 0x8d0a | No error (0) | 95.211.219.66 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:44.777546883 CET | 1.1.1.1 | 192.168.2.4 | 0xc06e | No error (0) | 95.211.219.66 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:47.152956009 CET | 1.1.1.1 | 192.168.2.4 | 0xabdf | No error (0) | 104.248.224.96 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:47.723885059 CET | 1.1.1.1 | 192.168.2.4 | 0x7cfb | No error (0) | 184.94.215.122 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:49.489105940 CET | 1.1.1.1 | 192.168.2.4 | 0xc890 | No error (0) | 104.22.7.178 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:49.489105940 CET | 1.1.1.1 | 192.168.2.4 | 0xc890 | No error (0) | 104.22.6.178 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:49.489105940 CET | 1.1.1.1 | 192.168.2.4 | 0xc890 | No error (0) | 172.67.41.162 | A (IP address) | IN (0x0001) | false | ||
Mar 26, 2025 19:34:49.494411945 CET | 1.1.1.1 | 192.168.2.4 | 0xcbc2 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 26, 2025 19:34:50.153223991 CET | 1.1.1.1 | 192.168.2.4 | 0xabac | No error (0) | 104.248.224.96 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49743 | 104.248.224.96 | 80 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 26, 2025 19:34:50.246387005 CET | 1258 | OUT | |
Mar 26, 2025 19:34:50.366473913 CET | 390 | IN | |
Mar 26, 2025 19:34:50.482146978 CET | 1205 | OUT | |
Mar 26, 2025 19:34:50.578752041 CET | 175 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 95.211.219.66 | 443 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 18:34:45 UTC | 666 | OUT | |
2025-03-26 18:34:45 UTC | 453 | IN | |
2025-03-26 18:34:45 UTC | 478 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49736 | 95.211.219.66 | 443 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 18:34:46 UTC | 1098 | OUT | |
2025-03-26 18:34:47 UTC | 1190 | IN | |
2025-03-26 18:34:47 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49738 | 104.248.224.96 | 443 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 18:34:47 UTC | 1479 | OUT | |
2025-03-26 18:34:47 UTC | 406 | IN | |
2025-03-26 18:34:47 UTC | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49739 | 184.94.215.122 | 443 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 18:34:48 UTC | 734 | OUT | |
2025-03-26 18:34:48 UTC | 292 | IN | |
2025-03-26 18:34:48 UTC | 332 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49740 | 184.94.215.122 | 443 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 18:34:48 UTC | 735 | OUT | |
2025-03-26 18:34:49 UTC | 620 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 104.22.7.178 | 443 | 508 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-26 18:34:49 UTC | 975 | OUT | |
2025-03-26 18:34:49 UTC | 1332 | IN | |
2025-03-26 18:34:49 UTC | 466 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 1369 | IN | |
2025-03-26 18:34:49 UTC | 331 | IN | |
2025-03-26 18:34:49 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 14:34:34 |
Start date: | 26/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 14:34:37 |
Start date: | 26/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 14:34:43 |
Start date: | 26/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |