Windows
Analysis Report
http://kra--31.cc/
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1004 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6036 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2220,i ,177337613 0311007936 6,88614352 4808119903 7,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2248 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6780 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://kra--3 1.cc/" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
kra--31.cc | 104.21.79.89 | true | false | unknown | |
www.google.com | 142.250.9.103 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.79.89 | kra--31.cc | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.9.103 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1664017 |
Start date and time: | 2025-04-13 09:00:17 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://kra--31.cc/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@22/10@6/3 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, sppsvc.exe, Runtim eBroker.exe, ShellExperienceHo st.exe, SIHClient.exe, SgrmBro ker.exe, backgroundTaskHost.ex e, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 74.125.136.102, 74 .125.136.101, 74.125.136.138, 74.125.136.113, 74.125.136.139 , 74.125.136.100, 64.233.185.9 4, 142.250.9.113, 142.250.9.13 9, 142.250.9.138, 142.250.9.10 0, 142.250.9.102, 142.250.9.10 1, 64.233.185.84, 108.177.122. 139, 108.177.122.102, 108.177. 122.100, 108.177.122.138, 108. 177.122.101, 108.177.122.113, 74.125.138.113, 74.125.138.139 , 74.125.138.138, 74.125.138.1 01, 74.125.138.102, 74.125.138 .100, 64.233.177.95, 108.177.1 22.94, 142.251.15.95, 74.125.1 36.95, 173.194.219.95, 142.250 .105.95, 64.233.176.95, 74.125 .21.95, 142.250.9.95, 172.217. 215.95, 108.177.122.95, 74.125 .138.95, 64.233.185.95, 172.25 3.124.95, 199.232.214.172, 23. 4.43.62, 64.233.185.138, 64.23 3.185.100, 64.233.185.139, 64. 233.185.101, 64.233.185.102, 6 4.233.185.113, 64.233.176.100, 64.233.176.113, 64.233.176.13 9, 64.233.176.102, 64.233.176. 101, 64.233.176.138, 142.251.1 5.94, 184.28.213.193, 20.12.23 .50 - Excluded domains from analysis
(whitelisted): fonts.googleap is.com, fs.microsoft.com, acco unts.google.com, content-autof ill.googleapis.com, slscr.upda te.microsoft.com, fonts.gstati c.com, ctldl.windowsupdate.com , clientservices.googleapis.co m, fe3cr.delivery.mp.microsoft .com, clients2.google.com, ocs p.digicert.com, edgedl.me.gvt1 .com, redirector.gvt1.com, upd ate.googleapis.com, clients.l. google.com, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data. - VT rate limit hit for: http:/
/kra--31.cc/
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 41845 |
Entropy (8bit): | 4.471834843648324 |
Encrypted: | false |
SSDEEP: | 384:I35RS71FYMknZII6TPHqZeeCD07bslnFerDY8qF6z6ngLNMjxCoXp4nXaSW:I3P6PZH5dD0AFerwFc6nONMHXp0m |
MD5: | DB5B32B816DDDCCDF7EF8EB0C7B2663D |
SHA1: | 9018DBCF63CF8ABEB4497F0C8F6EE0CD3525B3E8 |
SHA-256: | 1AC26E25A6FC725186F832F58E6F5951F2256EF4C0B8F5BB1FB8FB951135C493 |
SHA-512: | 3579CB5849BB90E5E1972D2106373C1197C7100A33488D1F1903491628DC63B594DF7B83AB40AC67A327806AB083684DD3CD40227A34E168192FE015C3B231B1 |
Malicious: | false |
Reputation: | low |
URL: | https://kra--31.cc/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9884 |
Entropy (8bit): | 5.476245200586647 |
Encrypted: | false |
SSDEEP: | 192:wAAGj73lOkiDAN/C734nkD8AO4x73/Ak8GAEif73RKkG5:BFrERPGRm |
MD5: | AEE824607990314C855A2D601BC0B09D |
SHA1: | 1F7907DBB5081FD3897AAAE58F6E2264DAEC9D91 |
SHA-256: | 13F2C0F493DE32018ABD6C456775DB4B79C1D2EE56118F42A07A19D882D6DC6F |
SHA-512: | 4B1C178C51FFA51D303EC1153BF4B7C827D7B93A5C3674E0E3C9105D58AC9A80A1A3662CEFD46B941FBCB249986692874907BA6B51EF9756CACA21F8656AA7F3 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.googleapis.com/css2?family=Inter:wght@300;400;500;700&display=swap |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18740 |
Entropy (8bit): | 7.9892288345233755 |
Encrypted: | false |
SSDEEP: | 384:AtbXebWepTmCSQiXLGg63eWz5WkPvRhc4Xci8yxpMNG:Adfeg9LGgHa3vRhj58yQNG |
MD5: | 06AB411342ACDBFE3E746EE904E12CC5 |
SHA1: | D83A47942575EEB80D30EBC7BF9A5B6F83C930FB |
SHA-256: | 62CC01DAEF72C3EA76A258445368D2F4AB8D05A91F91C53FD12F7C42E3325942 |
SHA-512: | 6DC7AE210DC6578115AC9A4B78431BE0F3F767684D3088FF5CD8094D1CE37756CE606571F325E6C97757DFFE012D491792EFAC56EFCE2FB7A4FCE9A7137CFC19 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/inter/v18/UcC73FwrK3iLTeHuS_nVMrMxCp50SjIa0ZL7SUc.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48444 |
Entropy (8bit): | 7.995593685409469 |
Encrypted: | true |
SSDEEP: | 768:dn0V9qZpy/4pR+9MzTCGXckDohHxCc/TfZQEh9UONYyPYcABoN/8rZujvB:dn0+rAmWUMooVrbZQE7NYyzABK8rQ1 |
MD5: | 8E433C0592F77BEB6DC527D7B90BE120 |
SHA1: | D7402416753AE1BB4CBD4B10D33A0C10517838BD |
SHA-256: | F052EE44C3728DFD23ABA8A4567150BC314D23903026FBB6AD089422C2DF56AF |
SHA-512: | 5E90F48B923BB95AEB49691D03DADE8825C119B2FA28977EA170C41548900F4E0165E2869F97C7A9380D7FF8FF331A1DA855500E5F7B0DFD2B9ABD77A386BBF3 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.gstatic.com/s/inter/v18/UcC73FwrK3iLTeHuS_nVMrMxCp50SjIa1ZL7.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | 3:HsqS1Y:Mp1Y |
MD5: | 5C5817DDFA72596CA976CA36E874EA95 |
SHA1: | 4491479472A5B053DE8967911670F25206244D71 |
SHA-256: | 2F317DE6216E423E81CC08AC342EA0ECD028D794E783D41CC46536ECCA8DC897 |
SHA-512: | 23E7764083C72130E745DC2A490DEAC90E99A02B00D318FE1B325C6BC16798C7FF3823FCC23346C811A66DE62656774D49C2E39F6E084B828033EA2C05773E3A |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCYRe5iLpGzJJEgUN0rme3CFNd0dOyEx5sw==?alt=proto |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 77
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 13, 2025 09:01:16.249401093 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:16.574907064 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:17.248811007 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:18.454730034 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:20.196976900 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:20.197065115 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:20.197181940 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:20.197477102 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:20.197534084 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:20.428278923 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:20.428564072 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:20.429565907 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:20.429616928 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:20.429953098 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:20.471585035 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:20.862204075 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:22.723836899 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:22.723927021 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:22.724195004 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:22.724195004 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:22.724349976 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.073074102 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.073292971 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.075387001 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.075413942 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.075859070 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.076186895 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.120277882 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600321054 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600415945 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600455999 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600495100 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600536108 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600565910 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600584984 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.600584984 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.600615025 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600630999 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.600639105 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.600670099 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.600697994 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601197004 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601231098 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601258039 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601257086 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.601324081 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601363897 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.601732969 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601780891 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601782084 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.601793051 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601835012 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.601845980 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601907015 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601938009 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.601953983 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.601970911 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.602039099 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.602052927 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.654215097 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716135025 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716211081 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716236115 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716272116 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716304064 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716350079 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716360092 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716428041 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716454983 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716463089 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716470957 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716502905 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716813087 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716859102 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716885090 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716891050 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716905117 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.716937065 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.716944933 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.717025995 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:23.717065096 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.719737053 CEST | 49725 | 443 | 192.168.2.4 | 104.21.79.89 |
Apr 13, 2025 09:01:23.719760895 CEST | 443 | 49725 | 104.21.79.89 | 192.168.2.4 |
Apr 13, 2025 09:01:24.518986940 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:24.833080053 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:25.442931890 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:25.677191973 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:26.642860889 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:27.962116003 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:01:28.267546892 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:01:28.288701057 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.288997889 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.289020061 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.409624100 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.409750938 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.409852028 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.410828114 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.410862923 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.410893917 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.410938025 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.411365032 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.413340092 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.413383961 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.413403988 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.413430929 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.416114092 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.532104969 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.536860943 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.539237022 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.539275885 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 13, 2025 09:01:28.539303064 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.539366007 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 13, 2025 09:01:28.876604080 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:01:29.047231913 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:30.079504967 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:01:30.412013054 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:30.412090063 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:30.412231922 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:31.127861977 CEST | 49723 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:01:31.127938032 CEST | 443 | 49723 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:01:32.488114119 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:01:33.846630096 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:35.291412115 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 13, 2025 09:01:37.299050093 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:01:43.461416006 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 13, 2025 09:01:46.908551931 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 13, 2025 09:02:20.137017012 CEST | 49743 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:02:20.137110949 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:02:20.137200117 CEST | 49743 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:02:20.137375116 CEST | 49743 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:02:20.137397051 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:02:20.357079983 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:02:20.357492924 CEST | 49743 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:02:20.357549906 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:02:30.358839035 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:02:30.358916998 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Apr 13, 2025 09:02:30.359005928 CEST | 49743 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:02:31.134594917 CEST | 49743 | 443 | 192.168.2.4 | 142.250.9.103 |
Apr 13, 2025 09:02:31.134656906 CEST | 443 | 49743 | 142.250.9.103 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 13, 2025 09:01:17.248730898 CEST | 53 | 61961 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:17.286031961 CEST | 53 | 50499 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:18.054100037 CEST | 53 | 63357 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:18.247726917 CEST | 53 | 61981 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:20.082108974 CEST | 55336 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 13, 2025 09:01:20.082281113 CEST | 62393 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 13, 2025 09:01:20.189059019 CEST | 53 | 55336 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:20.189433098 CEST | 53 | 62393 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:22.519064903 CEST | 55790 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 13, 2025 09:01:22.521344900 CEST | 59382 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 13, 2025 09:01:22.540363073 CEST | 59962 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 13, 2025 09:01:22.540719032 CEST | 61617 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 13, 2025 09:01:22.630214930 CEST | 53 | 55790 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:22.631272078 CEST | 53 | 59382 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:22.679928064 CEST | 53 | 59962 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:22.741554022 CEST | 53 | 61617 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:23.754749060 CEST | 53 | 50613 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:23.865832090 CEST | 53 | 57674 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:35.275190115 CEST | 53 | 56517 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:01:54.399981022 CEST | 53 | 57798 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:02:16.711863995 CEST | 53 | 61292 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:02:17.286020994 CEST | 53 | 63366 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:02:18.542278051 CEST | 53 | 54787 | 1.1.1.1 | 192.168.2.4 |
Apr 13, 2025 09:02:24.001190901 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Apr 13, 2025 09:01:22.741660118 CEST | 192.168.2.4 | 1.1.1.1 | c229 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 13, 2025 09:01:20.082108974 CEST | 192.168.2.4 | 1.1.1.1 | 0xc087 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 13, 2025 09:01:20.082281113 CEST | 192.168.2.4 | 1.1.1.1 | 0x9e84 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 13, 2025 09:01:22.519064903 CEST | 192.168.2.4 | 1.1.1.1 | 0x8def | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 13, 2025 09:01:22.521344900 CEST | 192.168.2.4 | 1.1.1.1 | 0x8196 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 13, 2025 09:01:22.540363073 CEST | 192.168.2.4 | 1.1.1.1 | 0xb3c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 13, 2025 09:01:22.540719032 CEST | 192.168.2.4 | 1.1.1.1 | 0xdb32 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 13, 2025 09:01:20.189059019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc087 | No error (0) | 142.250.9.103 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:20.189059019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc087 | No error (0) | 142.250.9.105 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:20.189059019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc087 | No error (0) | 142.250.9.99 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:20.189059019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc087 | No error (0) | 142.250.9.147 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:20.189059019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc087 | No error (0) | 142.250.9.106 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:20.189059019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc087 | No error (0) | 142.250.9.104 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:20.189433098 CEST | 1.1.1.1 | 192.168.2.4 | 0x9e84 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 13, 2025 09:01:22.630214930 CEST | 1.1.1.1 | 192.168.2.4 | 0x8def | No error (0) | 104.21.79.89 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:22.630214930 CEST | 1.1.1.1 | 192.168.2.4 | 0x8def | No error (0) | 172.67.169.109 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:22.631272078 CEST | 1.1.1.1 | 192.168.2.4 | 0x8196 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 13, 2025 09:01:22.679928064 CEST | 1.1.1.1 | 192.168.2.4 | 0xb3c0 | No error (0) | 104.21.79.89 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:22.679928064 CEST | 1.1.1.1 | 192.168.2.4 | 0xb3c0 | No error (0) | 172.67.169.109 | A (IP address) | IN (0x0001) | false | ||
Apr 13, 2025 09:01:22.741554022 CEST | 1.1.1.1 | 192.168.2.4 | 0xdb32 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49725 | 104.21.79.89 | 443 | 6036 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-13 07:01:23 UTC | 660 | OUT | |
2025-04-13 07:01:23 UTC | 807 | IN | |
2025-04-13 07:01:23 UTC | 562 | IN | |
2025-04-13 07:01:23 UTC | 264 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN | |
2025-04-13 07:01:23 UTC | 1369 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 03:01:11 |
Start date: | 13/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 03:01:15 |
Start date: | 13/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 03:01:21 |
Start date: | 13/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |