Windows
Analysis Report
https://fonts.gstatic.com/s/roboto/v20/KFOmCnqEu92Fr1Mu72xKKTU1Kvnz.woff2)
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w11x64_office
chrome.exe (PID: 464 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: DBE43C1D0092437B88CFF7BD9ABC336C) chrome.exe (PID: 3612 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1844,i ,954997683 4094241246 ,912354160 3049460962 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion --vari ations-see d-version= 20250316-1 80048.7760 00 --mojo- platform-c hannel-han dle=2024 / prefetch:1 1 MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
chrome.exe (PID: 6088 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://fonts .gstatic.c om/s/robot o/v20/KFOm CnqEu92Fr1 Mu72xKKTU1 Kvnz.woff2 )" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
appidpolicyconverter.exe (PID: 6188 cmdline:
"C:\Window s\system32 \appidpoli cyconverte r.exe" MD5: 6567D9CF2545FAAC60974D9D682700D4) conhost.exe (PID: 6916 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 9698384842DA735D80D278A427A229AB)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 File Deletion | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.251.40.164 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.40.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.251.40.132 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.176.196 | unknown | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.25 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1654123 |
Start date and time: | 2025-04-02 00:57:52 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://fonts.gstatic.com/s/roboto/v20/KFOmCnqEu92Fr1Mu72xKKTU1Kvnz.woff2) |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@20/12@6/4 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, s ppsvc.exe, SIHClient.exe, appi dcertstorecheck.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.72.99, 142 .250.65.238, 142.250.65.206, 1 72.253.115.84, 142.250.80.78, 142.251.40.110, 142.250.80.14, 142.250.64.99, 142.251.35.174 , 199.232.214.172, 142.251.32. 110, 142.250.65.174, 142.250.8 0.10, 142.251.40.234, 142.250. 65.170, 142.250.64.106, 142.25 1.35.170, 142.251.41.10, 142.2 51.32.106, 142.251.40.106, 142 .250.65.234, 142.250.65.202, 1 42.251.40.138, 142.250.81.234, 142.251.40.170, 142.250.64.74 , 172.217.165.138, 142.250.72. 106, 142.251.40.131, 142.251.4 0.238, 142.250.64.110, 184.31. 69.3, 4.175.87.197 - Not all processes where analyz
ed, report is missing behavior information - VT rate limit hit for: https:
//fonts.gstatic.com/s/roboto/v 20/KFOmCnqEu92Fr1Mu72xKKTU1Kvn z.woff2)
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1609 |
Entropy (8bit): | 5.318250936261081 |
Encrypted: | false |
SSDEEP: | 24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xCREIS8f:3qD+2+pUAew85zsLA |
MD5: | F3E50A5D5CE568376BD48DBCD6451598 |
SHA1: | 2C74669BAB5C7D77E68FB47D6DD2643BB78C47B0 |
SHA-256: | 895DA0D71BA539C310F98B6D079A466E856234FCECBDFFC3EF2574297CC924E4 |
SHA-512: | D512566D7448D002DCC50243D52876C84D61AC1DD561DD4802C9EFB6AB4E87F2910D2261DD5407881201DC00FBEF99588C0160F5D781A22EE49675C1D74D707B |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/roboto/v20/KFOmCnqEu92Fr1Mu72xKKTU1Kvnz.woff2) |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/images/errors/robot.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 884 |
Entropy (8bit): | 5.170020420830404 |
Encrypted: | false |
SSDEEP: | 24:/ZRHZjgaMllIQwBHslgT1d1uawBATAmuoBN2t2t2t2t2t2t2tomffffffo:/HHHMl2QwKlgJXwBANuSNYYYYYYYomfg |
MD5: | 86D47275101ABF211BE19C48860D40E8 |
SHA1: | 8963282BD256CFE4B2EF77E05B7BEF3AE3874968 |
SHA-256: | 000032DBC7804AF2B70450EA340A514847907886FF1335A925936721E9F8E6B2 |
SHA-512: | ADD6D399558353F81012FCC0F3F61DBA9A9EECB88C8A145A0666773C4688FEC2720929A4A54064D4B1C2DE75D700F5A6E204C431BEA77B4A1CCE83F14C7ABE90 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1572 |
Entropy (8bit): | 5.2647442020070505 |
Encrypted: | false |
SSDEEP: | 24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xTOS8f:3qD+2+pUAew85zsT9A |
MD5: | 13FEC0C2FBF5C47C4608CE0C9405E5A7 |
SHA1: | DAFB6CA27CFD22E88A2D53150C4350FCA3D32A21 |
SHA-256: | 7F25FD0260C4EF8C26A87A5A126634E846BA539C75E5D508103F4D98831654A5 |
SHA-512: | 7B9C5B92CDB7C3CEA0B6B862EBE67F75D92C1F1A8D5AAFE771CA50A724E4AF7F3C1CA280CBC53BF3EA3FB6344C41D1BA06BC032FC9B408C3B30BD301239CD001 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 104
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 00:59:01.732610941 CEST | 49675 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:02.665385962 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:02.973038912 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:03.586766005 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:04.790644884 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:05.339545965 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:05.650031090 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:06.260216951 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:06.617847919 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:06.617896080 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:06.617984056 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:06.618159056 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:06.618175983 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:06.830400944 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:06.830895901 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:06.831789017 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:06.831796885 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:06.832055092 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:06.885220051 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:07.197731018 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:07.463363886 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:08.392005920 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.392035007 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.392116070 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.392324924 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.392369986 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.392879963 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.392894030 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.392923117 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.393290997 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.393307924 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.584449053 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.584569931 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.584608078 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.584683895 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.585073948 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.585098982 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.585427999 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.585437059 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.585441113 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.585700989 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.585752010 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.586111069 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.628278971 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.632272005 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772301912 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772363901 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772397995 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772459030 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.772469997 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772484064 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772537947 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.772558928 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.772610903 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.777437925 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.777488947 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.777545929 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.781713963 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.781774044 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.781809092 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.781842947 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.781869888 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.781927109 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.782056093 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.782056093 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.783834934 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.783870935 CEST | 443 | 49696 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:08.783895016 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.783934116 CEST | 49696 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.789089918 CEST | 49695 | 443 | 192.168.2.25 | 142.250.176.196 |
Apr 2, 2025 00:59:08.789104939 CEST | 443 | 49695 | 142.250.176.196 | 192.168.2.25 |
Apr 2, 2025 00:59:09.416589975 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.416637897 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.416721106 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.416785955 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.416826010 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.416892052 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.417227030 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.417244911 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.417339087 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.417351007 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.609122992 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.609267950 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.610054016 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.610060930 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.610253096 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.610332012 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.610383987 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.610912085 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.610924959 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.611177921 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.611480951 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.611552000 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.652276039 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.655536890 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:09.656270027 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.696285963 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:09.785177946 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:09.787132025 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:09.787185907 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:09.788197994 CEST | 49690 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 00:59:09.788214922 CEST | 443 | 49690 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793173075 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793253899 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793298960 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.793312073 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793365002 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793406010 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.793411016 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793459892 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.793612003 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.793617010 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.794466019 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.794543028 CEST | 443 | 49698 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.794606924 CEST | 49698 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.815515041 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.815567017 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.815601110 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.815637112 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.815669060 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.815707922 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.815716982 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.815732002 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.815768957 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.816584110 CEST | 49699 | 443 | 192.168.2.25 | 142.251.40.132 |
Apr 2, 2025 00:59:09.816597939 CEST | 443 | 49699 | 142.251.40.132 | 192.168.2.25 |
Apr 2, 2025 00:59:09.869168997 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:12.011656046 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:13.744839907 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:13.744988918 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:13.745153904 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:13.913364887 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:13.913413048 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:13.913451910 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.179790020 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.180000067 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.180821896 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.180896044 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.180967093 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.181081057 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.191941977 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.358751059 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.397054911 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.397197008 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.397418022 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.397547960 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.399353981 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.607137918 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.607223988 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.607965946 CEST | 443 | 49679 | 2.19.122.49 | 192.168.2.25 |
Apr 2, 2025 00:59:14.608057022 CEST | 49679 | 443 | 192.168.2.25 | 2.19.122.49 |
Apr 2, 2025 00:59:14.681799889 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:21.619514942 CEST | 49673 | 80 | 192.168.2.25 | 184.30.131.245 |
Apr 2, 2025 00:59:24.290678978 CEST | 49676 | 443 | 192.168.2.25 | 20.189.173.8 |
Apr 2, 2025 00:59:43.729268074 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 00:59:44.041656971 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 00:59:44.651030064 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 00:59:45.867656946 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 00:59:48.291363001 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 00:59:53.103687048 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 01:00:02.712685108 CEST | 49677 | 443 | 192.168.2.25 | 20.189.173.25 |
Apr 2, 2025 01:00:06.561547041 CEST | 49709 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 01:00:06.561584949 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 01:00:06.561666965 CEST | 49709 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 01:00:06.561773062 CEST | 49709 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 01:00:06.561779022 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 01:00:06.756016970 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 01:00:06.756345987 CEST | 49709 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 01:00:06.756360054 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 01:00:16.809799910 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 01:00:16.809871912 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Apr 2, 2025 01:00:16.809915066 CEST | 49709 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 01:00:16.811000109 CEST | 49711 | 80 | 192.168.2.25 | 142.250.176.195 |
Apr 2, 2025 01:00:16.905824900 CEST | 80 | 49711 | 142.250.176.195 | 192.168.2.25 |
Apr 2, 2025 01:00:16.905920982 CEST | 49711 | 80 | 192.168.2.25 | 142.250.176.195 |
Apr 2, 2025 01:00:16.906111002 CEST | 49711 | 80 | 192.168.2.25 | 142.250.176.195 |
Apr 2, 2025 01:00:17.004798889 CEST | 80 | 49711 | 142.250.176.195 | 192.168.2.25 |
Apr 2, 2025 01:00:17.005153894 CEST | 80 | 49711 | 142.250.176.195 | 192.168.2.25 |
Apr 2, 2025 01:00:17.010699987 CEST | 49711 | 80 | 192.168.2.25 | 142.250.176.195 |
Apr 2, 2025 01:00:17.106890917 CEST | 80 | 49711 | 142.250.176.195 | 192.168.2.25 |
Apr 2, 2025 01:00:17.150223017 CEST | 49711 | 80 | 192.168.2.25 | 142.250.176.195 |
Apr 2, 2025 01:00:18.558667898 CEST | 49709 | 443 | 192.168.2.25 | 142.251.40.164 |
Apr 2, 2025 01:00:18.558707952 CEST | 443 | 49709 | 142.251.40.164 | 192.168.2.25 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 2, 2025 00:59:02.429866076 CEST | 53 | 63938 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:02.455914974 CEST | 53 | 55216 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:03.046818972 CEST | 53 | 51949 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:03.192651033 CEST | 53 | 64728 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:05.123984098 CEST | 53 | 62947 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:05.504997969 CEST | 53 | 61860 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:06.511498928 CEST | 64466 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 2, 2025 00:59:06.511543036 CEST | 56440 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 2, 2025 00:59:06.616051912 CEST | 53 | 56440 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:06.616069078 CEST | 53 | 64466 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:08.293972969 CEST | 59426 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 2, 2025 00:59:08.294133902 CEST | 59282 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 2, 2025 00:59:08.391122103 CEST | 53 | 59426 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:08.391171932 CEST | 53 | 59282 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:09.317852020 CEST | 55357 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 2, 2025 00:59:09.318022966 CEST | 55211 | 53 | 192.168.2.25 | 1.1.1.1 |
Apr 2, 2025 00:59:09.415246010 CEST | 53 | 55211 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:09.415718079 CEST | 53 | 55357 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:22.468399048 CEST | 53 | 59211 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:31.580380917 CEST | 53 | 53840 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 00:59:41.538764000 CEST | 53 | 57097 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 01:00:02.035037994 CEST | 53 | 63183 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 01:00:03.938493013 CEST | 53 | 56732 | 1.1.1.1 | 192.168.2.25 |
Apr 2, 2025 01:00:07.846142054 CEST | 138 | 138 | 192.168.2.25 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 2, 2025 00:59:06.511498928 CEST | 192.168.2.25 | 1.1.1.1 | 0x25af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 00:59:06.511543036 CEST | 192.168.2.25 | 1.1.1.1 | 0x722e | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 2, 2025 00:59:08.293972969 CEST | 192.168.2.25 | 1.1.1.1 | 0x3d0b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 00:59:08.294133902 CEST | 192.168.2.25 | 1.1.1.1 | 0x135f | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 2, 2025 00:59:09.317852020 CEST | 192.168.2.25 | 1.1.1.1 | 0xc912 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 2, 2025 00:59:09.318022966 CEST | 192.168.2.25 | 1.1.1.1 | 0x4e2b | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 2, 2025 00:59:06.616051912 CEST | 1.1.1.1 | 192.168.2.25 | 0x722e | No error (0) | 65 | IN (0x0001) | false | |||
Apr 2, 2025 00:59:06.616069078 CEST | 1.1.1.1 | 192.168.2.25 | 0x25af | No error (0) | 142.251.40.164 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 00:59:08.391122103 CEST | 1.1.1.1 | 192.168.2.25 | 0x3d0b | No error (0) | 142.250.176.196 | A (IP address) | IN (0x0001) | false | ||
Apr 2, 2025 00:59:08.391171932 CEST | 1.1.1.1 | 192.168.2.25 | 0x135f | No error (0) | 65 | IN (0x0001) | false | |||
Apr 2, 2025 00:59:09.415246010 CEST | 1.1.1.1 | 192.168.2.25 | 0x4e2b | No error (0) | 65 | IN (0x0001) | false | |||
Apr 2, 2025 00:59:09.415718079 CEST | 1.1.1.1 | 192.168.2.25 | 0xc912 | No error (0) | 142.251.40.132 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.25 | 49711 | 142.250.176.195 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 2, 2025 01:00:16.906111002 CEST | 202 | OUT | |
Apr 2, 2025 01:00:17.005153894 CEST | 223 | IN | |
Apr 2, 2025 01:00:17.010699987 CEST | 200 | OUT | |
Apr 2, 2025 01:00:17.106890917 CEST | 223 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.25 | 49696 | 142.250.176.196 | 443 | 3612 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-01 22:59:08 UTC | 764 | OUT | |
2025-04-01 22:59:08 UTC | 683 | IN | |
2025-04-01 22:59:08 UTC | 537 | IN | |
2025-04-01 22:59:08 UTC | 1220 | IN | |
2025-04-01 22:59:08 UTC | 1220 | IN | |
2025-04-01 22:59:08 UTC | 1220 | IN | |
2025-04-01 22:59:08 UTC | 1220 | IN | |
2025-04-01 22:59:08 UTC | 910 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.25 | 49695 | 142.250.176.196 | 443 | 3612 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-01 22:59:08 UTC | 800 | OUT | |
2025-04-01 22:59:08 UTC | 671 | IN | |
2025-04-01 22:59:08 UTC | 549 | IN | |
2025-04-01 22:59:08 UTC | 1220 | IN | |
2025-04-01 22:59:08 UTC | 1220 | IN | |
2025-04-01 22:59:08 UTC | 181 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.25 | 49698 | 142.251.40.132 | 443 | 3612 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-01 22:59:09 UTC | 474 | OUT | |
2025-04-01 22:59:09 UTC | 683 | IN | |
2025-04-01 22:59:09 UTC | 537 | IN | |
2025-04-01 22:59:09 UTC | 1220 | IN | |
2025-04-01 22:59:09 UTC | 1220 | IN | |
2025-04-01 22:59:09 UTC | 1220 | IN | |
2025-04-01 22:59:09 UTC | 1220 | IN | |
2025-04-01 22:59:09 UTC | 910 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.25 | 49699 | 142.251.40.132 | 443 | 3612 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-01 22:59:09 UTC | 510 | OUT | |
2025-04-01 22:59:09 UTC | 671 | IN | |
2025-04-01 22:59:09 UTC | 549 | IN | |
2025-04-01 22:59:09 UTC | 1220 | IN | |
2025-04-01 22:59:09 UTC | 1220 | IN | |
2025-04-01 22:59:09 UTC | 181 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.25 | 49690 | 142.251.40.164 | 443 | 3612 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-01 22:59:09 UTC | 587 | OUT | |
2025-04-01 22:59:09 UTC | 1303 | IN | |
2025-04-01 22:59:09 UTC | 891 | IN | |
2025-04-01 22:59:09 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 18:58:59 |
Start date: | 01/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e40a0000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 18:59:00 |
Start date: | 01/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e40a0000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 18:59:06 |
Start date: | 01/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e40a0000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 18:59:07 |
Start date: | 01/04/2025 |
Path: | C:\Windows\System32\appidpolicyconverter.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff73ae70000 |
File size: | 155'648 bytes |
MD5 hash: | 6567D9CF2545FAAC60974D9D682700D4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 18:59:07 |
Start date: | 01/04/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff729690000 |
File size: | 1'040'384 bytes |
MD5 hash: | 9698384842DA735D80D278A427A229AB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |