Windows
Analysis Report
https://dl.edge-aicdn.net/assets/init-a.js
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6228 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6760 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1932,i ,122940070 6743884773 9,41086311 7654221673 0,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2124 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 2900 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= printing.m ojom.Unsan dboxedPrin tBackendHo st --lang= en-US --se rvice-sand box-type=n one --no-p re-read-ma in-dll --f ield-trial -handle=19 32,i,12294 0070674388 47739,4108 6311765422 16730,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction - -variation s-seed-ver sion=20250 306-183004 .429000 -- mojo-platf orm-channe l-handle=4 972 /prefe tch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6600 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://dl.ed ge-aicdn.n et/assets/ init-a.js" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
dl.edge-aicdn.net | 104.21.16.1 | true | false | high | |
www.google.com | 142.251.40.164 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | unknown | ||
false |
| unknown | |
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.40.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.21.16.1 | dl.edge-aicdn.net | United States | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1661430 |
Start date and time: | 2025-04-10 05:20:53 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 58s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://dl.edge-aicdn.net/assets/init-a.js |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@23/2@6/4 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, conhost.exe, svc host.exe - Excluded IPs from analysis (wh
itelisted): 184.31.69.3, 199.2 32.214.172, 142.250.65.174, 14 2.251.41.3, 142.250.31.84, 142 .250.65.238, 142.251.32.110, 1 42.250.65.206, 142.251.40.238, 142.250.176.206, 142.250.81.2 38, 142.250.65.227, 142.250.80 .78, 142.251.40.195, 172.202.1 63.200 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fs-wildcard .microsoft.com.edgekey.net, fs -wildcard.microsoft.com.edgeke y.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe 3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2 686.clo.footprintdns.com, ax-r ing.msedge.net, clients2.googl e.com, edgedl.me.gvt1.com, red irector.gvt1.com, update.googl eapis.com, clients.l.google.co m, prod.fs.microsoft.com.akadn s.net, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//dl.edge-aicdn.net/assets/ini t-a.js
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 111 |
Entropy (8bit): | 4.62062991365628 |
Encrypted: | false |
SSDEEP: | 3:vFWWMNCmXyKgCC6beXqZj+PBMkmKqWWU667wtKPU9KgqLn:TM3i0b9ZjZvKtWRbtmBg6n |
MD5: | E7A9350210B4DBA641F6020447C96045 |
SHA1: | 581ACCEF4A8B7FBED97291FE7DD4E113F794EC80 |
SHA-256: | 08142330655DEB1526DCC56795C92EB5C13012F75B599D5AC68DB4027953ED80 |
SHA-512: | 2DCB8AD4EAC1B103DA4F806A49D7A0EFCC64D362865A18EFB257B45059BC1453D053136073009929415200F48F47B03F8E19E52A8AF7CB846AD081E0318586A2 |
Malicious: | false |
Reputation: | low |
URL: | https://dl.edge-aicdn.net/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 74
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 10, 2025 05:21:43.131386995 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:21:43.443434954 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:21:44.052861929 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:21:44.091269970 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 10, 2025 05:21:45.255925894 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:21:47.311867952 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:21:47.405554056 CEST | 80 | 49691 | 142.251.40.131 | 192.168.2.5 |
Apr 10, 2025 05:21:47.405639887 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:21:47.430227995 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:21:47.524321079 CEST | 80 | 49691 | 142.251.40.131 | 192.168.2.5 |
Apr 10, 2025 05:21:47.524511099 CEST | 80 | 49691 | 142.251.40.131 | 192.168.2.5 |
Apr 10, 2025 05:21:47.524560928 CEST | 80 | 49691 | 142.251.40.131 | 192.168.2.5 |
Apr 10, 2025 05:21:47.524629116 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:21:47.662164927 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:21:48.116282940 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:21:48.213232994 CEST | 80 | 49691 | 142.251.40.131 | 192.168.2.5 |
Apr 10, 2025 05:21:48.255891085 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:21:52.631459951 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:21:53.708731890 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 10, 2025 05:21:55.842133045 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:21:55.842179060 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:21:55.842402935 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:21:55.842528105 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:21:55.842544079 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:21:56.052948952 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:21:56.053175926 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:21:56.055139065 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:21:56.055150032 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:21:56.055635929 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:21:56.101116896 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:21:57.438692093 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.438729048 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.438812971 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.439282894 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.439333916 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.439430952 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.439486027 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.439497948 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.439636946 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.439644098 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.653336048 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.653413057 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.653940916 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.654184103 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.654489994 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.654495001 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.654978037 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.655385971 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.655391932 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.655775070 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.655859947 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.695769072 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.696299076 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.891721010 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.891912937 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.891974926 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.892956972 CEST | 49703 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:57.892975092 CEST | 443 | 49703 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.973093033 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:58.016303062 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.128483057 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.128571987 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.128657103 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:58.130369902 CEST | 49702 | 443 | 192.168.2.5 | 104.21.16.1 |
Apr 10, 2025 05:21:58.130384922 CEST | 443 | 49702 | 104.21.16.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.227118969 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.227220058 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.227300882 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.227483988 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.227508068 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.432962894 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.433053970 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.434155941 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.434180975 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.434727907 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.435077906 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.476295948 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.640937090 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.641135931 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.641222000 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.641526937 CEST | 49705 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.641563892 CEST | 443 | 49705 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.642513037 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.642564058 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.642633915 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.642800093 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.642819881 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.842889071 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.844949961 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.844971895 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.845190048 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:58.845199108 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:59.063479900 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:59.063692093 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:21:59.063751936 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:59.064146996 CEST | 49706 | 443 | 192.168.2.5 | 35.190.80.1 |
Apr 10, 2025 05:21:59.064162016 CEST | 443 | 49706 | 35.190.80.1 | 192.168.2.5 |
Apr 10, 2025 05:22:02.241308928 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 10, 2025 05:22:05.449666977 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 10, 2025 05:22:05.449706078 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 10, 2025 05:22:05.680001020 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 10, 2025 05:22:05.680103064 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 10, 2025 05:22:05.680207014 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 10, 2025 05:22:05.680607080 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 10, 2025 05:22:05.680641890 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 10, 2025 05:22:05.993812084 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 10, 2025 05:22:05.993925095 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 10, 2025 05:22:06.046499968 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:22:06.046581030 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:22:06.046649933 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:22:07.555229902 CEST | 49701 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:22:07.555272102 CEST | 443 | 49701 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:22:50.366056919 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:22:50.459285975 CEST | 80 | 49691 | 142.251.40.131 | 192.168.2.5 |
Apr 10, 2025 05:22:50.459389925 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.131 |
Apr 10, 2025 05:22:55.804691076 CEST | 49713 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:22:55.804737091 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:22:55.804905891 CEST | 49713 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:22:55.805130005 CEST | 49713 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:22:55.805139065 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:22:56.007580996 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:22:56.008057117 CEST | 49713 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:22:56.008090019 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:23:06.016172886 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:23:06.016330957 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Apr 10, 2025 05:23:06.016603947 CEST | 49713 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:23:07.555160046 CEST | 49713 | 443 | 192.168.2.5 | 142.251.40.164 |
Apr 10, 2025 05:23:07.555233955 CEST | 443 | 49713 | 142.251.40.164 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 10, 2025 05:21:51.298928976 CEST | 53 | 62558 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:51.506489992 CEST | 53 | 57182 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:52.321898937 CEST | 53 | 59439 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:55.743633032 CEST | 50353 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 10, 2025 05:21:55.743983984 CEST | 52624 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 10, 2025 05:21:55.840692043 CEST | 53 | 50353 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:55.840876102 CEST | 53 | 52624 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.338711023 CEST | 60376 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 10, 2025 05:21:57.338963985 CEST | 57066 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 10, 2025 05:21:57.437741041 CEST | 53 | 57066 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:57.438102961 CEST | 53 | 60376 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.129702091 CEST | 64287 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 10, 2025 05:21:58.129877090 CEST | 53177 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 10, 2025 05:21:58.226104975 CEST | 53 | 64287 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:21:58.226325989 CEST | 53 | 53177 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:22:09.326023102 CEST | 53 | 58316 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:22:28.405482054 CEST | 53 | 55013 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:22:46.404113054 CEST | 138 | 138 | 192.168.2.5 | 192.168.2.255 |
Apr 10, 2025 05:22:51.108880997 CEST | 53 | 62531 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:22:51.116099119 CEST | 53 | 53128 | 1.1.1.1 | 192.168.2.5 |
Apr 10, 2025 05:22:54.168248892 CEST | 53 | 55088 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 10, 2025 05:21:55.743633032 CEST | 192.168.2.5 | 1.1.1.1 | 0xf9cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 10, 2025 05:21:55.743983984 CEST | 192.168.2.5 | 1.1.1.1 | 0xbfff | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 10, 2025 05:21:57.338711023 CEST | 192.168.2.5 | 1.1.1.1 | 0x4153 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 10, 2025 05:21:57.338963985 CEST | 192.168.2.5 | 1.1.1.1 | 0xba37 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 10, 2025 05:21:58.129702091 CEST | 192.168.2.5 | 1.1.1.1 | 0xf292 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 10, 2025 05:21:58.129877090 CEST | 192.168.2.5 | 1.1.1.1 | 0x86e3 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 10, 2025 05:21:55.840692043 CEST | 1.1.1.1 | 192.168.2.5 | 0xf9cb | No error (0) | 142.251.40.164 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:55.840876102 CEST | 1.1.1.1 | 192.168.2.5 | 0xbfff | No error (0) | 65 | IN (0x0001) | false | |||
Apr 10, 2025 05:21:57.437741041 CEST | 1.1.1.1 | 192.168.2.5 | 0xba37 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:57.438102961 CEST | 1.1.1.1 | 192.168.2.5 | 0x4153 | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Apr 10, 2025 05:21:58.226104975 CEST | 1.1.1.1 | 192.168.2.5 | 0xf292 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.5 | 49691 | 142.251.40.131 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 10, 2025 05:21:47.430227995 CEST | 202 | OUT | |
Apr 10, 2025 05:21:47.524511099 CEST | 1254 | IN | |
Apr 10, 2025 05:21:47.524560928 CEST | 1198 | IN | |
Apr 10, 2025 05:21:48.116282940 CEST | 200 | OUT | |
Apr 10, 2025 05:21:48.213232994 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49703 | 104.21.16.1 | 443 | 6760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-10 03:21:57 UTC | 683 | OUT | |
2025-04-10 03:21:57 UTC | 1354 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49702 | 104.21.16.1 | 443 | 6760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-10 03:21:57 UTC | 613 | OUT | |
2025-04-10 03:21:58 UTC | 975 | IN | |
2025-04-10 03:21:58 UTC | 111 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49705 | 35.190.80.1 | 443 | 6760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-10 03:21:58 UTC | 546 | OUT | |
2025-04-10 03:21:58 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49706 | 35.190.80.1 | 443 | 6760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-10 03:21:58 UTC | 521 | OUT | |
2025-04-10 03:21:58 UTC | 438 | OUT | |
2025-04-10 03:21:59 UTC | 214 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 23:21:45 |
Start date: | 09/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fa0a0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 23:21:49 |
Start date: | 09/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fa0a0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 23:21:51 |
Start date: | 09/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fa0a0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 6 |
Start time: | 23:21:55 |
Start date: | 09/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff65bd60000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |