Windows
Analysis Report
https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX4
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 6912 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 7100 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1280,i ,160460242 3417790561 6,12265871 9700178373 79,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n --mojo-p latform-ch annel-hand le=2188 /p refetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 5732 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://lx-sa gittarius- star-mail. qiye.163.c om/unsubsc ribe_en.ht ml?host=wa imao-north -star-mail .qiye.163. com&sign=V 2.AxFoZzgy Gz1_yBD6EP fKZmMfZmJx 6fN7367rVW jF5G-yqkg0 m602Dujylu 7nMyG9uycP ujqEldyydq 4V3CCrDGrz VExEMmkjhr ofGHmY5NiP DFz4k9IuMk tqmVI595yP MYX6XETKsd oIGT8PY9AK JW6IbnN4zz ZsrrWz_vAK AKYzXo6gc9 969aSX478F hEr3&from= fanny@lisi homeware.c om" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Sample URL: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
lx-sagittarius-star-mail.qiye.163.com | 8.218.184.24 | true | false | high | |
www.google.com | 142.250.65.228 | true | false | high | |
waimao-north-star-mail.qiye.163.com | 8.210.52.23 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.65.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
8.210.52.23 | waimao-north-star-mail.qiye.163.com | Singapore | 45102 | CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC | false | |
8.218.184.24 | lx-sagittarius-star-mail.qiye.163.com | Singapore | 45102 | CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1650125 |
Start date and time: | 2025-03-27 13:51:20 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://lx-sagittarius-star-mail.qiye.163.com/unsubscribe_en.html?host=waimao-north-star-mail.qiye.163.com&sign=V2.AxFoZzgyGz1_yBD6EPfKZmMfZmJx6fN7367rVWjF5G-yqkg0m602Dujylu7nMyG9uycPujqEldyydq4V3CCrDGrzVExEMmkjhrofGHmY5NiPDFz4k9IuMktqmVI595yPMYX6XETKsdoIGT8PY9AKJW6IbnN4zzZsrrWz_vAKAKYzXo6gc9969aSX478FhEr3&from=fanny@lisihomeware.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@22/2@10/4 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, s ppsvc.exe, SIHClient.exe, Sgrm Broker.exe, backgroundTaskHost .exe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.40.238, 14 2.251.40.227, 172.253.62.84, 1 42.250.65.238, 142.250.65.234, 142.250.81.234, 142.251.32.10 6, 142.251.35.170, 142.251.40. 106, 142.251.40.138, 142.251.4 0.170, 142.250.64.106, 142.250 .72.106, 142.250.176.202, 142. 251.40.202, 142.251.40.234, 14 2.251.41.10, 172.217.165.138, 142.250.65.170, 142.250.65.202 , 142.250.65.195, 4.175.87.197 , 23.204.23.20, 20.190.151.133 , 23.57.90.150 - Excluded domains from analysis
(whitelisted): www.bing.com, clients1.google.com, fs.micros oft.com, accounts.google.com, content-autofill.googleapis.co m, slscr.update.microsoft.com, clientservices.googleapis.com , fe3cr.delivery.mp.microsoft. com, clients2.google.com, edge dl.me.gvt1.com, redirector.gvt 1.com, login.live.com, update. googleapis.com, clients.l.goog le.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//lx-sagittarius-star-mail.qiy e.163.com/unsubscribe_en.html? host=waimao-north-star-mail.qi ye.163.com&sign=V2.AxFoZzg yGz1_yBD6EPfKZmMfZmJx6fN7367rV WjF5G-yqkg0m602Dujylu7nMyG9uyc PujqEldyydq4V3CCrDGrzVExEMmkjh rofGHmY5NiPDFz4k9IuMktqmVI595y PMYX6XETKsdoIGT8PY9AKJW6IbnN4z zZsrrWz_vAKAKYzXo6gc9969aSX478 FhEr3&from=fanny@lisihomew are.com
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.625 |
Encrypted: | false |
SSDEEP: | 3:HFn:l |
MD5: | 418FBC40DEEBD999D02A91F3BC9850B9 |
SHA1: | A04AB7C83CB2CDF175711BF34C27A0C32F801DC2 |
SHA-256: | E85E233CE28065F9DE8A6429A42B6BFC4752340EDB2F66AF1B79F1B805549771 |
SHA-512: | 74599CE0567379C67882DCC387D869C2F5340D5F814789A65740C378A85949822118A4C8B842241D297087907CF646271DAB0866E3754291F729C3253185986D |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCbwisDGAAlFsEgUNZecJJiHrxEi0VrAAAw==?alt=proto |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 85
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 27, 2025 13:51:50.445832968 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:50.445868969 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:50.445955992 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:50.446439028 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:50.446485043 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:50.446542978 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:50.446605921 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:50.446616888 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:50.446696997 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:50.446715117 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.322860956 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.323049068 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:51.324278116 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:51.324286938 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.324676037 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.325345993 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:51.355520010 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.355652094 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:51.356193066 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:51.356205940 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.356976032 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.368272066 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:51.401544094 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.004798889 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.004873037 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.004972935 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.004991055 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.005037069 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.005110025 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.005656958 CET | 49703 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.005675077 CET | 443 | 49703 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.103070021 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.144275904 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.461046934 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.461216927 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.461383104 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.461905956 CET | 49704 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.461947918 CET | 443 | 49704 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.553996086 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.554084063 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:52.554177999 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.554315090 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:52.554337025 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.480534077 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.480699062 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:53.481213093 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:53.481239080 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.482067108 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.482373953 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:53.524302959 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.848201990 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.848436117 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:53.848515034 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:53.849257946 CET | 49711 | 443 | 192.168.2.16 | 8.218.184.24 |
Mar 27, 2025 13:51:53.849292994 CET | 443 | 49711 | 8.218.184.24 | 192.168.2.16 |
Mar 27, 2025 13:51:54.189620972 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:51:54.189682961 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:51:54.189810038 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:51:54.189960957 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:51:54.189985037 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:51:54.389193058 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:51:54.389309883 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:51:54.390583992 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:51:54.390603065 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:51:54.391016006 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:51:54.431583881 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:03.229419947 CET | 49673 | 443 | 192.168.2.16 | 2.23.227.208 |
Mar 27, 2025 13:52:03.229477882 CET | 443 | 49673 | 2.23.227.208 | 192.168.2.16 |
Mar 27, 2025 13:52:04.410691023 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:52:04.410835981 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:52:04.411005974 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:05.524571896 CET | 49712 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:05.524645090 CET | 443 | 49712 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:52:06.608072042 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:06.913801908 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:07.519838095 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:08.734695911 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:11.142740965 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:15.052216053 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:15.355789900 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:15.943839073 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:15.959628105 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:17.169800997 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:19.575912952 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:24.376925945 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:25.556905985 CET | 49671 | 443 | 192.168.2.16 | 204.79.197.203 |
Mar 27, 2025 13:52:33.986982107 CET | 49679 | 443 | 192.168.2.16 | 52.182.143.211 |
Mar 27, 2025 13:52:36.078174114 CET | 49692 | 80 | 192.168.2.16 | 142.251.41.3 |
Mar 27, 2025 13:52:36.078258038 CET | 49693 | 80 | 192.168.2.16 | 23.210.73.5 |
Mar 27, 2025 13:52:36.167175055 CET | 80 | 49692 | 142.251.41.3 | 192.168.2.16 |
Mar 27, 2025 13:52:36.167257071 CET | 49692 | 80 | 192.168.2.16 | 142.251.41.3 |
Mar 27, 2025 13:52:36.167578936 CET | 80 | 49693 | 23.210.73.5 | 192.168.2.16 |
Mar 27, 2025 13:52:36.167651892 CET | 49693 | 80 | 192.168.2.16 | 23.210.73.5 |
Mar 27, 2025 13:52:37.468445063 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:37.468522072 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:37.468650103 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:37.468843937 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:37.468867064 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.356950998 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.357072115 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.361057043 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.361088037 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.361673117 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.362036943 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.404304981 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.851929903 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.852102041 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.852181911 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.853147984 CET | 49722 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.853183031 CET | 443 | 49722 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.944825888 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.944925070 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:38.945034027 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.945184946 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:38.945207119 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:39.881089926 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:39.881210089 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:39.881702900 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:39.881733894 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:39.881953955 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:39.882241011 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:39.924288988 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:40.252849102 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:40.253026962 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:40.253117085 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:40.255155087 CET | 49723 | 443 | 192.168.2.16 | 8.210.52.23 |
Mar 27, 2025 13:52:40.255196095 CET | 443 | 49723 | 8.210.52.23 | 192.168.2.16 |
Mar 27, 2025 13:52:54.153444052 CET | 49727 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:54.153539896 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:52:54.153661966 CET | 49727 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:54.153836966 CET | 49727 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:54.153872967 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:52:54.342205048 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:52:54.342740059 CET | 49727 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:52:54.342824936 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:53:04.347996950 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:53:04.348051071 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Mar 27, 2025 13:53:04.348189116 CET | 49727 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:53:05.516385078 CET | 49727 | 443 | 192.168.2.16 | 142.250.65.228 |
Mar 27, 2025 13:53:05.516446114 CET | 443 | 49727 | 142.250.65.228 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 27, 2025 13:51:49.432512045 CET | 53 | 52923 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:49.447033882 CET | 53 | 51744 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:50.018435955 CET | 64184 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:51:50.020973921 CET | 58458 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:51:50.171655893 CET | 53 | 62671 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:50.328039885 CET | 53 | 52590 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:50.389765978 CET | 53 | 64184 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:50.470571995 CET | 53 | 58458 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:52.165514946 CET | 53 | 52347 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:52.464922905 CET | 62252 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:51:52.465085983 CET | 56724 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:51:52.553121090 CET | 53 | 62252 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:52.553167105 CET | 53 | 56724 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:54.099731922 CET | 52733 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:51:54.100086927 CET | 56609 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:51:54.188024998 CET | 53 | 52733 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:51:54.188177109 CET | 53 | 56609 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:07.274394989 CET | 53 | 55392 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:25.662650108 CET | 53 | 60180 | 162.159.36.2 | 192.168.2.16 |
Mar 27, 2025 13:52:26.270138979 CET | 53 | 49318 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:37.254220963 CET | 54212 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:52:37.254362106 CET | 51840 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:52:37.430146933 CET | 53 | 54212 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:37.869633913 CET | 53 | 51840 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:38.855988979 CET | 57209 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:52:38.856138945 CET | 49815 | 53 | 192.168.2.16 | 1.1.1.1 |
Mar 27, 2025 13:52:38.944087029 CET | 53 | 57209 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:38.944149017 CET | 53 | 49815 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:49.261348009 CET | 53 | 61834 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:52:49.359231949 CET | 53 | 62487 | 1.1.1.1 | 192.168.2.16 |
Mar 27, 2025 13:53:12.661035061 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Mar 27, 2025 13:53:19.997567892 CET | 53 | 49354 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Mar 27, 2025 13:51:50.470668077 CET | 192.168.2.16 | 1.1.1.1 | c23e | (Port unreachable) | Destination Unreachable |
Mar 27, 2025 13:52:37.869734049 CET | 192.168.2.16 | 1.1.1.1 | c23c | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 27, 2025 13:51:50.018435955 CET | 192.168.2.16 | 1.1.1.1 | 0xe52f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2025 13:51:50.020973921 CET | 192.168.2.16 | 1.1.1.1 | 0x74d5 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2025 13:51:52.464922905 CET | 192.168.2.16 | 1.1.1.1 | 0xdaf3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2025 13:51:52.465085983 CET | 192.168.2.16 | 1.1.1.1 | 0x7aa0 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2025 13:51:54.099731922 CET | 192.168.2.16 | 1.1.1.1 | 0x81d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2025 13:51:54.100086927 CET | 192.168.2.16 | 1.1.1.1 | 0xb825 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2025 13:52:37.254220963 CET | 192.168.2.16 | 1.1.1.1 | 0x2b6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2025 13:52:37.254362106 CET | 192.168.2.16 | 1.1.1.1 | 0xb395 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 27, 2025 13:52:38.855988979 CET | 192.168.2.16 | 1.1.1.1 | 0x2ab3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 27, 2025 13:52:38.856138945 CET | 192.168.2.16 | 1.1.1.1 | 0x94fd | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 27, 2025 13:51:50.389765978 CET | 1.1.1.1 | 192.168.2.16 | 0xe52f | No error (0) | 8.218.184.24 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2025 13:51:52.553121090 CET | 1.1.1.1 | 192.168.2.16 | 0xdaf3 | No error (0) | 8.218.184.24 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2025 13:51:54.188024998 CET | 1.1.1.1 | 192.168.2.16 | 0x81d5 | No error (0) | 142.250.65.228 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2025 13:51:54.188177109 CET | 1.1.1.1 | 192.168.2.16 | 0xb825 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 27, 2025 13:52:37.430146933 CET | 1.1.1.1 | 192.168.2.16 | 0x2b6f | No error (0) | 8.210.52.23 | A (IP address) | IN (0x0001) | false | ||
Mar 27, 2025 13:52:38.944087029 CET | 1.1.1.1 | 192.168.2.16 | 0x2ab3 | No error (0) | 8.210.52.23 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49703 | 8.218.184.24 | 443 | 7100 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-27 12:51:51 UTC | 976 | OUT | |
2025-03-27 12:51:52 UTC | 493 | IN | |
2025-03-27 12:51:52 UTC | 8415 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49704 | 8.218.184.24 | 443 | 7100 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-27 12:51:52 UTC | 926 | OUT | |
2025-03-27 12:51:52 UTC | 472 | IN | |
2025-03-27 12:51:52 UTC | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49711 | 8.218.184.24 | 443 | 7100 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-27 12:51:53 UTC | 412 | OUT | |
2025-03-27 12:51:53 UTC | 472 | IN | |
2025-03-27 12:51:53 UTC | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49722 | 8.210.52.23 | 443 | 7100 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-27 12:52:38 UTC | 850 | OUT | |
2025-03-27 12:52:38 UTC | 645 | IN | |
2025-03-27 12:52:38 UTC | 63 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49723 | 8.210.52.23 | 443 | 7100 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-27 12:52:39 UTC | 636 | OUT | |
2025-03-27 12:52:40 UTC | 452 | IN | |
2025-03-27 12:52:40 UTC | 77 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:51:47 |
Start date: | 27/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77eaf0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 08:51:48 |
Start date: | 27/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77eaf0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:51:49 |
Start date: | 27/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77eaf0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |