Windows
Analysis Report
http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 3952 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5504 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1732,i ,164550524 7163805367 0,16397329 1257132546 3,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2588 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7032 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://redrx7 .com/.rnur eo/7RZ0-PU ST0V-FIT3/ adelias@es trellagali cia.es" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Sample URL: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
redrx7.com | 203.170.84.9 | true | false | unknown | |
google.com | 142.250.65.206 | true | false | high | |
www.google.com | 142.251.35.164 | true | false | high | |
wfmrtebyt4.spitegagos.shop | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
203.170.84.9 | redrx7.com | Australia | 38719 | DREAMSCAPE-AS-APDreamscapeNetworksLimitedAU | false | |
142.251.35.164 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1652661 |
Start date and time: | 2025-03-31 11:18:31 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://redrx7.com/.rnureo/7RZ0-PUST0V-FIT3/adelias@estrellagalicia.es |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@27/2@37/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 23.203.176.221, 17 2.217.165.142, 142.250.65.163, 142.251.16.84, 142.251.40.174 , 142.251.40.99, 23.204.23.20, 131.253.33.254, 4.245.163.56 - Excluded domains from analysis
(whitelisted): a-ring-fallbac k.msedge.net, fs.microsoft.com , accounts.google.com, slscr.u pdate.microsoft.com, clientser vices.googleapis.com, fe3cr.de livery.mp.microsoft.com, clien ts2.google.com, edgedl.me.gvt1 .com, ocsp.digicert.com, redir ector.gvt1.com, update.googlea pis.com, crl3.digicert.com, cl ients.l.google.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: http:/
/redrx7.com/.rnureo/7RZ0-PUST0 V-FIT3/adelias@estrellagalicia .es
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 855 |
Entropy (8bit): | 5.1664619251976 |
Encrypted: | false |
SSDEEP: | 24:xmlwYr033SRO6bNDBHslgT1d1uawBATL8uoBN2t2t2t2t2t2t2tomffffffo:qdY3SRO2NDKlgJXwBAv8uSNYYYYYYYo9 |
MD5: | 6B8996F546719F210E9F61A8CDCEB060 |
SHA1: | 48EC16FC5FBE4C8597CC5C5711CD63543FF67B60 |
SHA-256: | 632B827B94B286BFFB6B09EED53AB977A6585317ECC95E94A7ED4F9F4C27C2A5 |
SHA-512: | 2C76D24513E895EF8B8567289DAA0FB8D881EA14E6166A10856FB1625B9DAFE3159724D5776B77A338B3F97C13F597189EF17E7A84119F46D727458487812D69 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 111
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 31, 2025 11:19:30.789489985 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:31.234090090 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:31.911529064 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:33.182312012 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:33.522922039 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.524972916 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.528126001 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.620557070 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.622788906 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.625319958 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.625349998 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.638931036 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.639131069 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.645977020 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.646030903 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.646085978 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.646197081 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.646223068 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.667188883 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.667203903 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:33.667257071 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:19:33.793800116 CEST | 443 | 49713 | 23.44.201.40 | 192.168.2.4 |
Mar 31, 2025 11:19:35.764574051 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:36.388272047 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:36.388326883 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:36.388397932 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:36.388571024 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:36.388592005 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:36.924562931 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:36.924645901 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:36.925826073 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:36.925839901 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:36.926265001 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:36.979190111 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:38.423049927 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:38.423155069 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:38.423245907 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:38.423954010 CEST | 49732 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:38.424156904 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:38.424448013 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:38.424484015 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:38.725542068 CEST | 80 | 49732 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:38.725604057 CEST | 80 | 49733 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:38.725649118 CEST | 49732 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:38.725696087 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:39.043839931 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:39.043929100 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:39.050287008 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:39.050327063 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:39.050817966 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:39.051213980 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:39.096271992 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:39.236044884 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:19:39.546055079 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:19:39.749629974 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:39.800635099 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:40.154645920 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:19:40.227646112 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:40.227875948 CEST | 443 | 49731 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:40.227972984 CEST | 49731 | 443 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:40.455459118 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:40.576297045 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:40.756907940 CEST | 80 | 49733 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:40.831043959 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:40.876275063 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:40.958142996 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:40.961998940 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:40.962064981 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:40.962903023 CEST | 49729 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:19:40.962918043 CEST | 443 | 49729 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:19:41.357824087 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:19:41.415966034 CEST | 80 | 49733 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:41.466763973 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:43.758177042 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:19:48.558285952 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:19:49.032856941 CEST | 80 | 49732 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:49.032946110 CEST | 49732 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:49.063177109 CEST | 49732 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:19:49.364753962 CEST | 80 | 49732 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:19:50.186342001 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 31, 2025 11:19:58.161813021 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 31, 2025 11:20:16.348886967 CEST | 80 | 49710 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:16.349097013 CEST | 49710 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:16.349194050 CEST | 49710 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:16.460896969 CEST | 80 | 49710 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:17.323456049 CEST | 80 | 49714 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:17.323652983 CEST | 49714 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:17.323760033 CEST | 49714 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:17.519320965 CEST | 80 | 49715 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:17.519458055 CEST | 49715 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:17.636296988 CEST | 49714 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:18.245590925 CEST | 49714 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:18.352807999 CEST | 80 | 49714 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:19.012643099 CEST | 80 | 49716 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:19.012793064 CEST | 49716 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:19.012862921 CEST | 49716 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:19.231106997 CEST | 49712 | 80 | 192.168.2.4 | 142.250.72.99 |
Mar 31, 2025 11:20:19.339832067 CEST | 49716 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:19.542841911 CEST | 49712 | 80 | 192.168.2.4 | 142.250.72.99 |
Mar 31, 2025 11:20:19.638108015 CEST | 80 | 49712 | 142.250.72.99 | 192.168.2.4 |
Mar 31, 2025 11:20:19.638185024 CEST | 49712 | 80 | 192.168.2.4 | 142.250.72.99 |
Mar 31, 2025 11:20:19.642168045 CEST | 80 | 49712 | 142.250.72.99 | 192.168.2.4 |
Mar 31, 2025 11:20:19.980366945 CEST | 49716 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:20.090744972 CEST | 80 | 49716 | 208.89.73.25 | 192.168.2.4 |
Mar 31, 2025 11:20:26.417124033 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:20:33.764926910 CEST | 49713 | 443 | 192.168.2.4 | 23.44.201.40 |
Mar 31, 2025 11:20:33.765288115 CEST | 49715 | 80 | 192.168.2.4 | 208.89.73.25 |
Mar 31, 2025 11:20:36.341309071 CEST | 49747 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:20:36.341346025 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:36.341415882 CEST | 49747 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:20:36.341789961 CEST | 49747 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:20:36.341806889 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:36.865864038 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:36.866416931 CEST | 49747 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:20:36.866441965 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:46.565713882 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:46.565854073 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:46.565937996 CEST | 49747 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:20:46.732189894 CEST | 49747 | 443 | 192.168.2.4 | 142.251.35.164 |
Mar 31, 2025 11:20:46.732218027 CEST | 443 | 49747 | 142.251.35.164 | 192.168.2.4 |
Mar 31, 2025 11:20:47.329703093 CEST | 80 | 49733 | 203.170.84.9 | 192.168.2.4 |
Mar 31, 2025 11:20:47.329777956 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:20:48.732325077 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:20:49.479661942 CEST | 49733 | 80 | 192.168.2.4 | 203.170.84.9 |
Mar 31, 2025 11:20:49.782718897 CEST | 80 | 49733 | 203.170.84.9 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 31, 2025 11:19:32.791944981 CEST | 53 | 57814 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:32.850830078 CEST | 53 | 56990 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:33.595520020 CEST | 53 | 52529 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:34.018439054 CEST | 53 | 59663 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:36.282603979 CEST | 63673 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:36.282763958 CEST | 51598 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:36.387284040 CEST | 53 | 63673 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:36.387348890 CEST | 53 | 51598 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:38.113285065 CEST | 56095 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:38.113650084 CEST | 53356 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:38.129694939 CEST | 49729 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:38.129862070 CEST | 52645 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:38.418957949 CEST | 53 | 52645 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:38.419002056 CEST | 53 | 53356 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:38.422233105 CEST | 53 | 49729 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:38.422492981 CEST | 53 | 56095 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:40.245007038 CEST | 60752 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:40.245265007 CEST | 62732 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:40.345900059 CEST | 53 | 60752 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:40.345972061 CEST | 53 | 62732 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:40.347088099 CEST | 63052 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:40.448678017 CEST | 53 | 63052 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:41.419228077 CEST | 51944 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:41.419486046 CEST | 57994 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:41.519582987 CEST | 53 | 51944 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:41.593321085 CEST | 52299 | 53 | 192.168.2.4 | 8.8.8.8 |
Mar 31, 2025 11:19:41.593746901 CEST | 54624 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:41.694921970 CEST | 53 | 54624 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:42.806129932 CEST | 51075 | 53 | 192.168.2.4 | 8.8.4.4 |
Mar 31, 2025 11:19:42.808810949 CEST | 56071 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:42.809223890 CEST | 61705 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:42.912919044 CEST | 53 | 61705 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:43.825365067 CEST | 59171 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:43.927109003 CEST | 53 | 59171 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:48.999901056 CEST | 62261 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:49.000134945 CEST | 56590 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:50.018580914 CEST | 53498 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:50.018830061 CEST | 55553 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:50.116702080 CEST | 53 | 53498 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:50.116750002 CEST | 53 | 55553 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:50.142298937 CEST | 58715 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:50.238575935 CEST | 53 | 58715 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:51.154006958 CEST | 53 | 59340 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:53.339807987 CEST | 63640 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:53.339963913 CEST | 54935 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:19:53.439709902 CEST | 53 | 63640 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:19:53.439758062 CEST | 53 | 54935 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:02.612945080 CEST | 57806 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:03.621052027 CEST | 57806 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:03.726308107 CEST | 53 | 57806 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:04.333745003 CEST | 65527 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:04.333899021 CEST | 55238 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:04.436491013 CEST | 53 | 65527 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:04.469183922 CEST | 64061 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:04.571888924 CEST | 53 | 64061 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:04.586893082 CEST | 64627 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:04.587158918 CEST | 53077 | 53 | 192.168.2.4 | 8.8.8.8 |
Mar 31, 2025 11:20:04.687808037 CEST | 53 | 64627 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:04.687856913 CEST | 53 | 53077 | 8.8.8.8 | 192.168.2.4 |
Mar 31, 2025 11:20:09.980784893 CEST | 53 | 53087 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:15.766005039 CEST | 53 | 62674 | 162.159.36.2 | 192.168.2.4 |
Mar 31, 2025 11:20:24.981647015 CEST | 53004 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:25.081602097 CEST | 53 | 53004 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:32.042572021 CEST | 53 | 56685 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:34.605057001 CEST | 49670 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:34.605307102 CEST | 60686 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:34.707441092 CEST | 53 | 49670 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:34.708518028 CEST | 53 | 60686 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:34.709362030 CEST | 56183 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:34.810210943 CEST | 53 | 56183 | 1.1.1.1 | 192.168.2.4 |
Mar 31, 2025 11:20:38.721108913 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Mar 31, 2025 11:20:47.402148962 CEST | 52057 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:48.417346954 CEST | 52057 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 31, 2025 11:20:48.516437054 CEST | 53 | 52057 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 31, 2025 11:19:36.282603979 CEST | 192.168.2.4 | 1.1.1.1 | 0xf710 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:36.282763958 CEST | 192.168.2.4 | 1.1.1.1 | 0x7f1d | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:38.113285065 CEST | 192.168.2.4 | 1.1.1.1 | 0x324b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:38.113650084 CEST | 192.168.2.4 | 1.1.1.1 | 0xf3eb | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:38.129694939 CEST | 192.168.2.4 | 1.1.1.1 | 0x9e83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:38.129862070 CEST | 192.168.2.4 | 1.1.1.1 | 0x3c73 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:40.245007038 CEST | 192.168.2.4 | 1.1.1.1 | 0xdec4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:40.245265007 CEST | 192.168.2.4 | 1.1.1.1 | 0xbfd3 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:40.347088099 CEST | 192.168.2.4 | 1.1.1.1 | 0xf437 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:41.419228077 CEST | 192.168.2.4 | 1.1.1.1 | 0xfd56 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:41.419486046 CEST | 192.168.2.4 | 1.1.1.1 | 0x64d5 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:41.593321085 CEST | 192.168.2.4 | 8.8.8.8 | 0x5689 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:41.593746901 CEST | 192.168.2.4 | 1.1.1.1 | 0xeef4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:42.806129932 CEST | 192.168.2.4 | 8.8.4.4 | 0x4ca6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:42.808810949 CEST | 192.168.2.4 | 1.1.1.1 | 0x48d4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:42.809223890 CEST | 192.168.2.4 | 1.1.1.1 | 0xe915 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:43.825365067 CEST | 192.168.2.4 | 1.1.1.1 | 0x4eaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:48.999901056 CEST | 192.168.2.4 | 1.1.1.1 | 0xaeb6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:49.000134945 CEST | 192.168.2.4 | 1.1.1.1 | 0xf78f | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:50.018580914 CEST | 192.168.2.4 | 1.1.1.1 | 0x7d5d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:50.018830061 CEST | 192.168.2.4 | 1.1.1.1 | 0x57ee | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:50.142298937 CEST | 192.168.2.4 | 1.1.1.1 | 0xc14d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:53.339807987 CEST | 192.168.2.4 | 1.1.1.1 | 0x813e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:53.339963913 CEST | 192.168.2.4 | 1.1.1.1 | 0xbe8a | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:20:02.612945080 CEST | 192.168.2.4 | 1.1.1.1 | 0xfc14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:03.621052027 CEST | 192.168.2.4 | 1.1.1.1 | 0xfc14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.333745003 CEST | 192.168.2.4 | 1.1.1.1 | 0x4ce1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.333899021 CEST | 192.168.2.4 | 1.1.1.1 | 0x1968 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.469183922 CEST | 192.168.2.4 | 1.1.1.1 | 0x6028 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.586893082 CEST | 192.168.2.4 | 1.1.1.1 | 0xa3a5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.587158918 CEST | 192.168.2.4 | 8.8.8.8 | 0x2a8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:24.981647015 CEST | 192.168.2.4 | 1.1.1.1 | 0x42fb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:34.605057001 CEST | 192.168.2.4 | 1.1.1.1 | 0xf58a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:34.605307102 CEST | 192.168.2.4 | 1.1.1.1 | 0xe176 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:20:34.709362030 CEST | 192.168.2.4 | 1.1.1.1 | 0xda87 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:47.402148962 CEST | 192.168.2.4 | 1.1.1.1 | 0xbb3a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:48.417346954 CEST | 192.168.2.4 | 1.1.1.1 | 0xbb3a | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 31, 2025 11:19:36.387284040 CEST | 1.1.1.1 | 192.168.2.4 | 0xf710 | No error (0) | 142.251.35.164 | A (IP address) | IN (0x0001) | false | ||
Mar 31, 2025 11:19:36.387348890 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f1d | No error (0) | 65 | IN (0x0001) | false | |||
Mar 31, 2025 11:19:38.422233105 CEST | 1.1.1.1 | 192.168.2.4 | 0x9e83 | No error (0) | 203.170.84.9 | A (IP address) | IN (0x0001) | false | ||
Mar 31, 2025 11:19:38.422492981 CEST | 1.1.1.1 | 192.168.2.4 | 0x324b | No error (0) | 203.170.84.9 | A (IP address) | IN (0x0001) | false | ||
Mar 31, 2025 11:19:40.345900059 CEST | 1.1.1.1 | 192.168.2.4 | 0xdec4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:40.345972061 CEST | 1.1.1.1 | 192.168.2.4 | 0xbfd3 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:40.448678017 CEST | 1.1.1.1 | 192.168.2.4 | 0xf437 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:41.519582987 CEST | 1.1.1.1 | 192.168.2.4 | 0xfd56 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:41.694921970 CEST | 1.1.1.1 | 192.168.2.4 | 0xeef4 | No error (0) | 142.250.65.206 | A (IP address) | IN (0x0001) | false | ||
Mar 31, 2025 11:19:42.912919044 CEST | 1.1.1.1 | 192.168.2.4 | 0xe915 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:43.927109003 CEST | 1.1.1.1 | 192.168.2.4 | 0x4eaf | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:50.116702080 CEST | 1.1.1.1 | 192.168.2.4 | 0x7d5d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:50.116750002 CEST | 1.1.1.1 | 192.168.2.4 | 0x57ee | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:19:50.238575935 CEST | 1.1.1.1 | 192.168.2.4 | 0xc14d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:53.439709902 CEST | 1.1.1.1 | 192.168.2.4 | 0x813e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:19:53.439758062 CEST | 1.1.1.1 | 192.168.2.4 | 0xbe8a | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:20:03.726308107 CEST | 1.1.1.1 | 192.168.2.4 | 0xfc14 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.436491013 CEST | 1.1.1.1 | 192.168.2.4 | 0x4ce1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.571888924 CEST | 1.1.1.1 | 192.168.2.4 | 0x6028 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:04.687808037 CEST | 1.1.1.1 | 192.168.2.4 | 0xa3a5 | No error (0) | 142.250.65.206 | A (IP address) | IN (0x0001) | false | ||
Mar 31, 2025 11:20:04.687856913 CEST | 8.8.8.8 | 192.168.2.4 | 0x2a8 | No error (0) | 142.250.65.206 | A (IP address) | IN (0x0001) | false | ||
Mar 31, 2025 11:20:25.081602097 CEST | 1.1.1.1 | 192.168.2.4 | 0x42fb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:34.707441092 CEST | 1.1.1.1 | 192.168.2.4 | 0xf58a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:34.708518028 CEST | 1.1.1.1 | 192.168.2.4 | 0xe176 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Mar 31, 2025 11:20:34.810210943 CEST | 1.1.1.1 | 192.168.2.4 | 0xda87 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Mar 31, 2025 11:20:48.516437054 CEST | 1.1.1.1 | 192.168.2.4 | 0xbb3a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49733 | 203.170.84.9 | 80 | 5504 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 31, 2025 11:19:40.455459118 CEST | 476 | OUT | |
Mar 31, 2025 11:19:41.415966034 CEST | 292 | IN | |
Mar 31, 2025 11:20:26.417124033 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49731 | 203.170.84.9 | 443 | 5504 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-31 09:19:39 UTC | 711 | OUT | |
2025-03-31 09:19:39 UTC | 297 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49729 | 142.251.35.164 | 443 | 5504 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-31 09:19:40 UTC | 595 | OUT | |
2025-03-31 09:19:40 UTC | 1303 | IN | |
2025-03-31 09:19:40 UTC | 862 | IN | |
2025-03-31 09:19:40 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 05:19:27 |
Start date: | 31/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 05:19:31 |
Start date: | 31/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 05:19:37 |
Start date: | 31/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |