Windows
Analysis Report
http://storage.ml-cachehost.net/lib/config-a.js
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5928 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 2592 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2016,i ,106978222 7070808781 3,16803609 7298034472 03,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=2120 /prefetch :3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6872 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://storag e.ml-cache host.net/l ib/config- a.js" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
storage.ml-cachehost.net | 172.67.175.195 | true | false | high | |
www.google.com | 142.251.15.99 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.15.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.21.17.111 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1663590 |
Start date and time: | 2025-04-12 00:42:27 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 54s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://storage.ml-cachehost.net/lib/config-a.js |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@22/2@8/4 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 64.233.185.94, 74. 125.21.113, 74.125.21.101, 74. 125.21.102, 74.125.21.138, 74. 125.21.139, 74.125.21.100, 173 .194.219.139, 173.194.219.100, 173.194.219.102, 173.194.219. 138, 173.194.219.113, 173.194. 219.101, 64.233.185.84, 74.125 .136.100, 74.125.136.113, 74.1 25.136.101, 74.125.136.102, 74 .125.136.138, 74.125.136.139, 64.233.176.139, 64.233.176.101 , 64.233.176.113, 64.233.176.1 02, 64.233.176.138, 64.233.176 .100, 74.125.138.100, 74.125.1 38.138, 74.125.138.102, 74.125 .138.139, 74.125.138.101, 74.1 25.138.113, 23.13.145.132, 23. 218.145.145, 108.177.122.102, 108.177.122.101, 108.177.122.1 38, 108.177.122.113, 108.177.1 22.139, 108.177.122.100, 142.2 50.9.139, 142.250.9.102, 142.2 50.9.113, 142.250.9.100, 142.2 50.9.101, 142.250.9.138, 74.12 5.138.94, 23.79.17.61, 4.245.1 63.56 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fe3cr.deliv ery.mp.microsoft.com, clients2 .google.com, ocsp.digicert.com , edgedl.me.gvt1.com, redirect or.gvt1.com, update.googleapis .com, clients.l.google.com, c. pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: http:/
/storage.ml-cachehost.net/lib/ config-a.js
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 111 |
Entropy (8bit): | 4.62062991365628 |
Encrypted: | false |
SSDEEP: | 3:vFWWMNCmXyKgCC6beXqZj+PBMkmKqWWU667wtKPU9KgqLn:TM3i0b9ZjZvKtWRbtmBg6n |
MD5: | E7A9350210B4DBA641F6020447C96045 |
SHA1: | 581ACCEF4A8B7FBED97291FE7DD4E113F794EC80 |
SHA-256: | 08142330655DEB1526DCC56795C92EB5C13012F75B599D5AC68DB4027953ED80 |
SHA-512: | 2DCB8AD4EAC1B103DA4F806A49D7A0EFCC64D362865A18EFB257B45059BC1453D053136073009929415200F48F47B03F8E19E52A8AF7CB846AD081E0318586A2 |
Malicious: | false |
Reputation: | low |
URL: | https://storage.ml-cachehost.net/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 87
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 12, 2025 00:43:19.097172976 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:25.252866030 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:25.554990053 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:26.159884930 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:27.362838030 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:28.384222031 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:28.384325981 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:28.384408951 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:28.384569883 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:28.384592056 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:28.617815018 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:28.618005037 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:28.619036913 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:28.619087934 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:28.619858980 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:28.674618959 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:28.705979109 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:29.768381119 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:30.064481020 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.064521074 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.064593077 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.064723015 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.064734936 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.296408892 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.296518087 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.297544003 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.297558069 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.297930002 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.298258066 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.307915926 CEST | 80 | 49711 | 217.20.48.20 | 192.168.2.4 |
Apr 12, 2025 00:43:30.308027983 CEST | 49711 | 80 | 192.168.2.4 | 217.20.48.20 |
Apr 12, 2025 00:43:30.340310097 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.571073055 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.571216106 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.571398020 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.696463108 CEST | 49726 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.696532965 CEST | 443 | 49726 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.723651886 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.723752022 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.723831892 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.724037886 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.724066973 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.950330019 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.956950903 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.957041979 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:30.963004112 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:30.963058949 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:31.279164076 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:31.279315948 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:31.279393911 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:31.287734032 CEST | 49727 | 443 | 192.168.2.4 | 104.21.17.111 |
Apr 12, 2025 00:43:31.287779093 CEST | 443 | 49727 | 104.21.17.111 | 192.168.2.4 |
Apr 12, 2025 00:43:31.390041113 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.390067101 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.390122890 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.390244007 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.390254021 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.626157999 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.626306057 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.627754927 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.627763987 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.628104925 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.628437042 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.676276922 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.860157013 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.860372066 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.860569954 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.860631943 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.860651970 CEST | 443 | 49729 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.860661983 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.860702038 CEST | 49729 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.861468077 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.861562014 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.861650944 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.861766100 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:31.861793041 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.085206985 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.085571051 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:32.085633039 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.085696936 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:32.085719109 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.324670076 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.324750900 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.325097084 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:32.325097084 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:32.325167894 CEST | 443 | 49730 | 35.190.80.1 | 192.168.2.4 |
Apr 12, 2025 00:43:32.325231075 CEST | 49730 | 443 | 192.168.2.4 | 35.190.80.1 |
Apr 12, 2025 00:43:34.021826982 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:34.330785036 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:34.580738068 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:34.941941023 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:36.145057917 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:38.372167110 CEST | 49711 | 80 | 192.168.2.4 | 217.20.48.20 |
Apr 12, 2025 00:43:38.381907940 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:43:38.478343010 CEST | 80 | 49711 | 217.20.48.20 | 192.168.2.4 |
Apr 12, 2025 00:43:38.550476074 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:38.609970093 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:38.610032082 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:38.610441923 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:38.690962076 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:43:38.708184958 CEST | 49724 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:43:38.708245993 CEST | 443 | 49724 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:43:38.740854025 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.741553068 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.741592884 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.846874952 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.847500086 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.847557068 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.848139048 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.848181009 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.848258972 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.848328114 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.848885059 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.849777937 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.849798918 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:38.849848986 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 12, 2025 00:43:38.954762936 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 12, 2025 00:43:39.300487995 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:43:40.503575087 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:43:42.909929991 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:43:43.363070965 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:44.190582037 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 12, 2025 00:43:47.720808029 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:43:52.966629982 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 12, 2025 00:43:57.323173046 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 12, 2025 00:44:28.332983017 CEST | 49742 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:44:28.333070993 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:44:28.333173990 CEST | 49742 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:44:28.333352089 CEST | 49742 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:44:28.333388090 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:44:28.555896044 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:44:28.556436062 CEST | 49742 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:44:28.556492090 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:44:38.569329023 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:44:38.569399118 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Apr 12, 2025 00:44:38.569566965 CEST | 49742 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:44:38.708471060 CEST | 49742 | 443 | 192.168.2.4 | 142.251.15.99 |
Apr 12, 2025 00:44:38.708504915 CEST | 443 | 49742 | 142.251.15.99 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 12, 2025 00:43:24.722714901 CEST | 53 | 56697 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:24.725739956 CEST | 53 | 58862 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:25.669807911 CEST | 53 | 59476 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:25.857006073 CEST | 53 | 64388 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:28.271564960 CEST | 60601 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:28.271564960 CEST | 61881 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:28.380261898 CEST | 53 | 60601 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:28.383424044 CEST | 53 | 61881 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:29.938505888 CEST | 63365 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:29.938505888 CEST | 49935 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:29.955585957 CEST | 62502 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:29.956082106 CEST | 57607 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:30.045631886 CEST | 53 | 63365 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:30.046000004 CEST | 53 | 49935 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:30.062899113 CEST | 53 | 57607 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:30.064034939 CEST | 53 | 62502 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.280375957 CEST | 58419 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:31.280458927 CEST | 51800 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 12, 2025 00:43:31.388853073 CEST | 53 | 51800 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:31.389641047 CEST | 53 | 58419 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:43:42.878786087 CEST | 53 | 62080 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:44:01.816864967 CEST | 53 | 55251 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:44:23.989916086 CEST | 53 | 49550 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:44:24.476025105 CEST | 53 | 51606 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:44:26.785655975 CEST | 53 | 62423 | 1.1.1.1 | 192.168.2.4 |
Apr 12, 2025 00:44:33.510577917 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 12, 2025 00:43:28.271564960 CEST | 192.168.2.4 | 1.1.1.1 | 0xe493 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 12, 2025 00:43:28.271564960 CEST | 192.168.2.4 | 1.1.1.1 | 0x26bd | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 12, 2025 00:43:29.938505888 CEST | 192.168.2.4 | 1.1.1.1 | 0x8a6b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 12, 2025 00:43:29.938505888 CEST | 192.168.2.4 | 1.1.1.1 | 0xa241 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 12, 2025 00:43:29.955585957 CEST | 192.168.2.4 | 1.1.1.1 | 0xd24b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 12, 2025 00:43:29.956082106 CEST | 192.168.2.4 | 1.1.1.1 | 0x7531 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 12, 2025 00:43:31.280375957 CEST | 192.168.2.4 | 1.1.1.1 | 0xa5dd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 12, 2025 00:43:31.280458927 CEST | 192.168.2.4 | 1.1.1.1 | 0xf7e9 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 12, 2025 00:43:28.380261898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe493 | No error (0) | 142.251.15.99 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:28.380261898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe493 | No error (0) | 142.251.15.105 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:28.380261898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe493 | No error (0) | 142.251.15.104 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:28.380261898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe493 | No error (0) | 142.251.15.106 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:28.380261898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe493 | No error (0) | 142.251.15.103 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:28.380261898 CEST | 1.1.1.1 | 192.168.2.4 | 0xe493 | No error (0) | 142.251.15.147 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:28.383424044 CEST | 1.1.1.1 | 192.168.2.4 | 0x26bd | No error (0) | 65 | IN (0x0001) | false | |||
Apr 12, 2025 00:43:30.045631886 CEST | 1.1.1.1 | 192.168.2.4 | 0x8a6b | No error (0) | 172.67.175.195 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:30.045631886 CEST | 1.1.1.1 | 192.168.2.4 | 0x8a6b | No error (0) | 104.21.17.111 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:30.046000004 CEST | 1.1.1.1 | 192.168.2.4 | 0xa241 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 12, 2025 00:43:30.062899113 CEST | 1.1.1.1 | 192.168.2.4 | 0x7531 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 12, 2025 00:43:30.064034939 CEST | 1.1.1.1 | 192.168.2.4 | 0xd24b | No error (0) | 104.21.17.111 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:30.064034939 CEST | 1.1.1.1 | 192.168.2.4 | 0xd24b | No error (0) | 172.67.175.195 | A (IP address) | IN (0x0001) | false | ||
Apr 12, 2025 00:43:31.389641047 CEST | 1.1.1.1 | 192.168.2.4 | 0xa5dd | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49726 | 104.21.17.111 | 443 | 2592 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-11 22:43:30 UTC | 689 | OUT | |
2025-04-11 22:43:30 UTC | 1365 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49727 | 104.21.17.111 | 443 | 2592 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-11 22:43:30 UTC | 626 | OUT | |
2025-04-11 22:43:31 UTC | 989 | IN | |
2025-04-11 22:43:31 UTC | 111 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49729 | 35.190.80.1 | 443 | 2592 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-11 22:43:31 UTC | 565 | OUT | |
2025-04-11 22:43:31 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49730 | 35.190.80.1 | 443 | 2592 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-11 22:43:32 UTC | 540 | OUT | |
2025-04-11 22:43:32 UTC | 453 | OUT | |
2025-04-11 22:43:32 UTC | 214 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 18:43:21 |
Start date: | 11/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 18:43:22 |
Start date: | 11/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 18:43:28 |
Start date: | 11/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |