Windows
Analysis Report
https://employerschoiceonline.instascreen.net/quickverify/release.taz?a=6aad0af695a81e45c40904d374f7153bb060e004&e=1744654543000&b=688506155&c=5
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6040 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5416 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2044,i ,121844596 2457043213 4,30791955 6991024024 6,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2076 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6324 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://emplo yerschoice online.ins tascreen.n et/quickve rify/relea se.taz?a=6 aad0af695a 81e45c4090 4d374f7153 bb060e004& e=17446545 43000&b=68 8506155&c= 5" MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 5652 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5760 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --metri cs-shmem-h andle=1936 ,i,1207253 7486879388 997,152790 1108579297 5354,52428 8 --field- trial-hand le=1756,i, 9776161172 668221715, 2789798183 340385106, 262144 --d isable-fea tures=Opti mizationGu ideModelDo wnloading, Optimizati onHints,Op timization HintsFetch ing,Optimi zationTarg etPredicti on --varia tions-seed -version=2 0250414-05 0123.76400 0 --mojo-p latform-ch annel-hand le=2064 /p refetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 704 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "C:\ Users\user \Downloads \Authoriza tion-Form- BENJAMIN-T HOMAS-BRAD LEY.html" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
fastly-tls12-bam.nr-data.net | 162.247.243.29 | true | false | high | |
b-group.instascreen.net | 54.188.253.192 | true | false | unknown | |
js-agent.newrelic.com | 162.247.243.39 | true | false | high | |
www.google.com | 64.233.185.106 | true | false | high | |
employerschoiceonline.instascreen.net | unknown | unknown | false | high | |
bam.nr-data.net | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
54.188.253.192 | b-group.instascreen.net | United States | 16509 | AMAZON-02US | false | |
162.247.243.29 | fastly-tls12-bam.nr-data.net | United States | 13335 | CLOUDFLARENETUS | false | |
162.247.243.39 | js-agent.newrelic.com | United States | 13335 | CLOUDFLARENETUS | false | |
64.233.185.106 | www.google.com | United States | 15169 | GOOGLEUS | false | |
108.177.122.147 | unknown | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.7 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1664836 |
Start date and time: | 2025-04-14 21:06:10 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 37s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://employerschoiceonline.instascreen.net/quickverify/release.taz?a=6aad0af695a81e45c40904d374f7153bb060e004&e=1744654543000&b=688506155&c=5 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@43/17@12/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, s ppsvc.exe, WMIADAP.exe, SIHCli ent.exe, SgrmBroker.exe, conho st.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 172.217.215.102, 1 72.217.215.101, 172.217.215.11 3, 172.217.215.138, 172.217.21 5.139, 172.217.215.100, 172.21 7.215.94, 172.253.124.84, 74.1 25.138.113, 74.125.138.100, 74 .125.138.139, 74.125.138.101, 74.125.138.102, 74.125.138.138 , 173.194.219.102, 173.194.219 .138, 173.194.219.100, 173.194 .219.101, 173.194.219.139, 173 .194.219.113, 108.177.122.100, 108.177.122.102, 108.177.122. 138, 108.177.122.113, 108.177. 122.139, 108.177.122.101, 64.2 33.176.95, 64.233.176.94, 23.2 18.145.145, 74.125.136.101, 74 .125.136.138, 74.125.136.113, 74.125.136.102, 74.125.136.139 , 74.125.136.100, 142.250.9.94 , 142.250.9.138, 142.250.9.101 , 142.250.9.113, 142.250.9.102 , 142.250.9.139, 142.250.9.100 , 64.233.185.94, 172.253.124.1 01, 172.253.124.139, 172.253.1 24.100, 172.253.124.138, 172.2 53.124.113, 172.253.124.102, 1 42.250.9.84, 74.125.21.100, 74 .125.21.101, 74.125.21.139, 74 .125.21.138, 74.125.21.102, 74 .125.21.113, 172.253.124.94, 7 4.125.138.94, 142.251.15.94, 4 .175.87.197, 23.79.17.61, 172. 202. - Excluded domains from analysis
(whitelisted): fonts.googleap is.com, fs.microsoft.com, acco unts.google.com, slscr.update. microsoft.com, fonts.gstatic.c om, ctldl.windowsupdate.com, c lientservices.googleapis.com, dns.msftncsi.com, fe3cr.delive ry.mp.microsoft.com, clients2. google.com, edgedl.me.gvt1.com , redirector.gvt1.com, update. googleapis.com, clients.l.goog le.com, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data. - VT rate limit hit for: https:
//employerschoiceonline.instas creen.net/quickverify/release. taz?a=6aad0af695a81e45c40904d3 74f7153bb060e004&e=1744654 543000&b=688506155&c=5
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32294 |
Entropy (8bit): | 5.425102287773794 |
Encrypted: | false |
SSDEEP: | 384:5bGmRhGjV+3ifEbSaGPc260350RqeJb/QJNhDOLNNZfGSDjnVXy85Dn3LFq:5b2+S8bml350IeJOhDGrto |
MD5: | 5C27CCCB81AC2D594D826A0F4F4C7D9D |
SHA1: | 8CA96E29D803868D6731FB388045BAEB148510A5 |
SHA-256: | 90517C924A29C2E37E17208037BEF51C194BFC3E4508D8BB6C2C3FEB3C5D2DAC |
SHA-512: | C16C59D292D874DD13E57B1AECBCB793B6E337B9B8960E31AFF4DD9F0347EDF133D7305FA6CEFF463B84BD34E6FA6FA01F3D835D17F339DA79435A685DD7D2DA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40394 |
Entropy (8bit): | 5.4155417064437845 |
Encrypted: | false |
SSDEEP: | 768:5b2+S8bml350IeJOhDGrt5IW0DE5KLv0Dq5KBX0DU5KlHMQMGE:c3JhTW0Q47024BX0A46QS |
MD5: | 77CDA4937A2722C2950062E30E362D39 |
SHA1: | 28EB59B8FBE915D9BA878D458F578E6F64A17178 |
SHA-256: | EC606D17CF9795F70E80B5F04A47A24A739E876A31BA648994DB330E8F378907 |
SHA-512: | 2E731F0E921BB7BB399F4B49D39AD4FECF8A74CBA884659B08FD89AF16A2261290BF4EB256B5B236A1242473250991DFCF72DFE1B30EE24B319A491DBD8C777B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40394 |
Entropy (8bit): | 5.4155417064437845 |
Encrypted: | false |
SSDEEP: | 768:5b2+S8bml350IeJOhDGrt5IW0DE5KLv0Dq5KBX0DU5KlHMQMGE:c3JhTW0Q47024BX0A46QS |
MD5: | 77CDA4937A2722C2950062E30E362D39 |
SHA1: | 28EB59B8FBE915D9BA878D458F578E6F64A17178 |
SHA-256: | EC606D17CF9795F70E80B5F04A47A24A739E876A31BA648994DB330E8F378907 |
SHA-512: | 2E731F0E921BB7BB399F4B49D39AD4FECF8A74CBA884659B08FD89AF16A2261290BF4EB256B5B236A1242473250991DFCF72DFE1B30EE24B319A491DBD8C777B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 87 |
Entropy (8bit): | 4.05298175485356 |
Encrypted: | false |
SSDEEP: | 3:U3KTDW3MiLLUHcjVXlVBT7PCcfn:H6NLgHWXZT7PCcfn |
MD5: | 5151B02BBED24D56CBE862FE7462084D |
SHA1: | 6ACAB31C3D18D3E61309E8B46338CF8BC4D67EEC |
SHA-256: | 300735AC477BB7E09CE2725F0031B085E5C86F09903D053AC8E44596731D8780 |
SHA-512: | BF09D8D9D0DFBE00FD38D3BEF695FA70CD9EB64BB629F475CB5BBF7889F866D1F9626DDBC84927020735F8FC0B4236206A7A5CA837368126D92C30ECDAED32C6 |
Malicious: | false |
Reputation: | low |
URL: | "https://bam.nr-data.net/1/0d2f6deff6?a=4275739&sa=1&v=1044.a6554e7&t=Unnamed%20Transaction&rst=283&ref=file:///C:/Users/user/Downloads/Authorization-Form-BENJAMIN-THOMAS-BRADLEY.html&be=78&fe=264&dc=217&af=err,xhr,stn,ins&perf=%7B%22timing%22:%7B%22of%22:1744657713925,%22n%22:0,%22f%22:9,%22dn%22:9,%22dne%22:9,%22c%22:9,%22ce%22:9,%22rq%22:9,%22rp%22:9,%22rpe%22:32,%22dl%22:45,%22di%22:213,%22ds%22:213,%22de%22:217,%22dc%22:263,%22l%22:263,%22le%22:264%7D,%22navigation%22:%7B%7D%7D&jsonp=NREUM.setToken" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 87 |
Entropy (8bit): | 4.05298175485356 |
Encrypted: | false |
SSDEEP: | 3:U3KTDW3MiLLUHcjVXlVBT7PCcfn:H6NLgHWXZT7PCcfn |
MD5: | 5151B02BBED24D56CBE862FE7462084D |
SHA1: | 6ACAB31C3D18D3E61309E8B46338CF8BC4D67EEC |
SHA-256: | 300735AC477BB7E09CE2725F0031B085E5C86F09903D053AC8E44596731D8780 |
SHA-512: | BF09D8D9D0DFBE00FD38D3BEF695FA70CD9EB64BB629F475CB5BBF7889F866D1F9626DDBC84927020735F8FC0B4236206A7A5CA837368126D92C30ECDAED32C6 |
Malicious: | false |
Reputation: | low |
URL: | "https://bam.nr-data.net/1/0d2f6deff6?a=4275739&sa=1&v=1044.a6554e7&t=Unnamed%20Transaction&rst=391&ref=file:///C:/Users/user/Downloads/Authorization-Form-BENJAMIN-THOMAS-BRADLEY.html&be=167&fe=235&dc=191&af=err,xhr,stn,ins&perf=%7B%22timing%22:%7B%22of%22:1744657722960,%22n%22:0,%22f%22:6,%22dn%22:6,%22dne%22:6,%22c%22:6,%22ce%22:6,%22rq%22:6,%22rp%22:6,%22rpe%22:9,%22dl%22:90,%22di%22:191,%22ds%22:191,%22de%22:191,%22dc%22:233,%22l%22:233,%22le%22:236%7D,%22navigation%22:%7B%7D%7D&jsonp=NREUM.setToken" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 87 |
Entropy (8bit): | 4.05298175485356 |
Encrypted: | false |
SSDEEP: | 3:U3KTDW3MiLLUHcjVXlVBT7PCcfn:H6NLgHWXZT7PCcfn |
MD5: | 5151B02BBED24D56CBE862FE7462084D |
SHA1: | 6ACAB31C3D18D3E61309E8B46338CF8BC4D67EEC |
SHA-256: | 300735AC477BB7E09CE2725F0031B085E5C86F09903D053AC8E44596731D8780 |
SHA-512: | BF09D8D9D0DFBE00FD38D3BEF695FA70CD9EB64BB629F475CB5BBF7889F866D1F9626DDBC84927020735F8FC0B4236206A7A5CA837368126D92C30ECDAED32C6 |
Malicious: | false |
Reputation: | low |
URL: | "https://bam.nr-data.net/1/0d2f6deff6?a=4275739&sa=1&v=1044.a6554e7&t=Unnamed%20Transaction&rst=1788&ref=file:///C:/Users/user/Downloads/Authorization-Form-BENJAMIN-THOMAS-BRADLEY.html&be=253&fe=1120&dc=1093&af=err,xhr,stn,ins&perf=%7B%22timing%22:%7B%22of%22:1744657636331,%22n%22:0,%22f%22:5,%22dn%22:5,%22dne%22:5,%22c%22:5,%22ce%22:5,%22rq%22:5,%22rp%22:5,%22rpe%22:118,%22dl%22:126,%22di%22:1089,%22ds%22:1092,%22de%22:1093,%22dc%22:1119,%22l%22:1119,%22le%22:1121%7D,%22navigation%22:%7B%7D%7D&jsonp=NREUM.setToken" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 22890 |
Entropy (8bit): | 5.299497896298777 |
Encrypted: | false |
SSDEEP: | 384:yWe9x8LHvWgIdGYwNRUyqK3zqdPEliwbiki5IYrQXFFPXXRbS7gQhs:yWzeg0GYwNHoprBQVBt/Qhs |
MD5: | 6442AAA45EC28F8B2C541026F3C24871 |
SHA1: | 32DC677BB3FA61736A35D30A809AA1C4A0A04976 |
SHA-256: | 574558BC99CBCC4C8A0E57519CB6A317A0A4E0B70094FBEC41946138D576486B |
SHA-512: | A158F255F94883CEA48CEE91A343946A5F1B04EC56764EAC0B9E4D478E48B34EBC24FC261E4A6D10F71928513E938CD9D8029A860187ADABAAAF19C4BD45834F |
Malicious: | false |
Reputation: | low |
URL: | https://js-agent.newrelic.com/nr-1044.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 14724 |
Entropy (8bit): | 5.49602855764709 |
Encrypted: | false |
SSDEEP: | 384:fihPi6ifiyyiUiAi7FhPF6FfFyyFUFAF7vhPv6vfvyyvUvAvhneVn9VnznQun4na:aU5a03DJnWdHkQj9gHdKGhy9VzF4zFVq |
MD5: | 519DFEEC1A1CDD1EEF8F2201090BE675 |
SHA1: | 22A84DBCB69DD399F3726B80858B38C264DFCBAD |
SHA-256: | 4ED63316CE7E7B844D78B0CB329A687CCEF90CB40E1E2A9AE093B2EB8A98E9FE |
SHA-512: | 83F63836370D0901C0E211540DBF9D321D32044BA0A7E8651D10A33010588512431316D6642ECB5532256478BD365511F8766903190FB57F84C1B1FD07A0B739 |
Malicious: | false |
Reputation: | low |
URL: | "https://fonts.googleapis.com/css?family=Roboto+Condensed:400,400italic,500,500italic,700,700italic" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32400 |
Entropy (8bit): | 5.274095985994467 |
Encrypted: | false |
SSDEEP: | 768:VTFGjLEN9RxxoaR4LfNSGm3SwXiL5No8c5NSpbJfai0Ydi9+QJEaNPDz4T06JOaH:uv7L2md |
MD5: | 9F8EC6F16D15D42A47DBF12A9CBDCC28 |
SHA1: | B5CC52FE2329E19B94EDEE8610F630A112711DD0 |
SHA-256: | 3B77B94E6A5AB4E9D345C74F10AAD3B6F057D7F777F91AC92273040F5B4639DF |
SHA-512: | 9AB82B5B4956FDDB01234F8B486B831CB5DA17712EEE3186B6A63238DBD191D672D324C9254A4EFC1C12DBB1D3C1269CA5A0FE9453D3A6EFC76C6F60EC82F9AA |
Malicious: | false |
Reputation: | low |
URL: | "https://fonts.googleapis.com/css?family=Roboto:400,400italic,500,500italic,700,700italic" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 40394 |
Entropy (8bit): | 5.4155417064437845 |
Encrypted: | false |
SSDEEP: | 768:5b2+S8bml350IeJOhDGrt5IW0DE5KLv0Dq5KBX0DU5KlHMQMGE:c3JhTW0Q47024BX0A46QS |
MD5: | 77CDA4937A2722C2950062E30E362D39 |
SHA1: | 28EB59B8FBE915D9BA878D458F578E6F64A17178 |
SHA-256: | EC606D17CF9795F70E80B5F04A47A24A739E876A31BA648994DB330E8F378907 |
SHA-512: | 2E731F0E921BB7BB399F4B49D39AD4FECF8A74CBA884659B08FD89AF16A2261290BF4EB256B5B236A1242473250991DFCF72DFE1B30EE24B319A491DBD8C777B |
Malicious: | false |
Reputation: | low |
URL: | https://employerschoiceonline.instascreen.net/quickverify/release.taz?a=6aad0af695a81e45c40904d374f7153bb060e004&e=1744654543000&b=688506155&c=5 |
Preview: |
Icon Hash: | 00b29a8e86828200 |
Download Network PCAP: filtered – full
- Total Packets: 145
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 14, 2025 21:07:06.684566021 CEST | 49675 | 443 | 192.168.2.7 | 2.23.227.208 |
Apr 14, 2025 21:07:06.684571981 CEST | 49673 | 443 | 192.168.2.7 | 2.23.227.208 |
Apr 14, 2025 21:07:06.684830904 CEST | 49674 | 443 | 192.168.2.7 | 2.23.227.208 |
Apr 14, 2025 21:07:08.559607029 CEST | 49676 | 80 | 192.168.2.7 | 23.199.215.203 |
Apr 14, 2025 21:07:08.559633970 CEST | 49677 | 443 | 192.168.2.7 | 2.18.98.62 |
Apr 14, 2025 21:07:13.436589003 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:13.436646938 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:13.436744928 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:13.436913013 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:13.436928034 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:13.658379078 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:13.658473015 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:13.659785986 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:13.659795046 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:13.660039902 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:13.702253103 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:14.873430014 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:14.873466015 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:14.873605967 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:14.873847961 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:14.873872042 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:14.874144077 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:14.874186993 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:14.874243975 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:14.874411106 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:14.874425888 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.398718119 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.398732901 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.398803949 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.398817062 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.400082111 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.400091887 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.400346994 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.400496960 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.400501966 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.400746107 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.400779963 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.448271036 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.453353882 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.792546988 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792599916 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792642117 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792680025 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.792701960 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792726994 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.792752028 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.792777061 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792886972 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792924881 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792954922 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.792964935 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.792994022 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.835500002 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.835623980 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.835638046 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.835654974 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:15.835700989 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.837848902 CEST | 49692 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:07:15.837869883 CEST | 443 | 49692 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:07:16.297678947 CEST | 49675 | 443 | 192.168.2.7 | 2.23.227.208 |
Apr 14, 2025 21:07:16.297698021 CEST | 49674 | 443 | 192.168.2.7 | 2.23.227.208 |
Apr 14, 2025 21:07:16.299949884 CEST | 49673 | 443 | 192.168.2.7 | 2.23.227.208 |
Apr 14, 2025 21:07:18.414048910 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.414098978 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.414211035 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.414372921 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.414388895 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.638545990 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.638880968 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.721211910 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.721235037 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.721596003 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.725111961 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.772279978 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844610929 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844682932 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844732046 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844772100 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844803095 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.844810963 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844827890 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.844878912 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.844878912 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.848057032 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.851581097 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.851619005 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.851768017 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.851784945 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.851923943 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.855129957 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.858705997 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.858767986 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.858783960 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.862214088 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.862312078 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.862421989 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.862435102 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.862485886 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.865777016 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.866019964 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:18.866103888 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.964979887 CEST | 49702 | 443 | 192.168.2.7 | 162.247.243.39 |
Apr 14, 2025 21:07:18.965003014 CEST | 443 | 49702 | 162.247.243.39 | 192.168.2.7 |
Apr 14, 2025 21:07:19.080976963 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.081042051 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.081171036 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.081374884 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.081391096 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.425316095 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.425375938 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.426553011 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.426563978 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.426796913 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.427021980 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.472276926 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.801842928 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.802002907 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:19.802078009 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.802927017 CEST | 49703 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:07:19.802942991 CEST | 443 | 49703 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:07:23.662071943 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:23.662132978 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:23.662220001 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:23.782200098 CEST | 49691 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:07:23.782224894 CEST | 443 | 49691 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:07:35.811039925 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:07:36.123166084 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:07:36.732557058 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:07:37.935688019 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:07:40.341871977 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:07:44.373079062 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:07:44.685070992 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:07:45.169538021 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:07:45.294543028 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:07:46.497673035 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:07:48.904062986 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:07:53.716389894 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:07:54.779031038 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Apr 14, 2025 21:08:00.403878927 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:08:00.403892994 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:08:03.325990915 CEST | 49678 | 443 | 192.168.2.7 | 20.189.173.15 |
Apr 14, 2025 21:08:13.391452074 CEST | 49718 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:08:13.391484976 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:13.391552925 CEST | 49718 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:08:13.391779900 CEST | 49718 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:08:13.391793013 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:13.614011049 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:13.614331961 CEST | 49718 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:08:13.614362955 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:15.796595097 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:08:15.796679020 CEST | 443 | 49693 | 54.188.253.192 | 192.168.2.7 |
Apr 14, 2025 21:08:15.796736956 CEST | 49693 | 443 | 192.168.2.7 | 54.188.253.192 |
Apr 14, 2025 21:08:18.984838963 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:18.984880924 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:18.984952927 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:18.985169888 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:18.985182047 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:19.201817036 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:19.202117920 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:19.202136040 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:19.202282906 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:19.202291012 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:19.451106071 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:19.451229095 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:19.451484919 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:19.451745987 CEST | 49721 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:19.451759100 CEST | 443 | 49721 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:23.624814987 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:23.624888897 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:23.625125885 CEST | 49718 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:08:23.797590017 CEST | 49718 | 443 | 192.168.2.7 | 64.233.185.106 |
Apr 14, 2025 21:08:23.797609091 CEST | 443 | 49718 | 64.233.185.106 | 192.168.2.7 |
Apr 14, 2025 21:08:32.028990030 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:32.029051065 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:32.029122114 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:32.029261112 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:32.029272079 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:32.245663881 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:32.245738983 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:32.247006893 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:32.247020006 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:32.247302055 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:32.295097113 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:35.172131062 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.172183037 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.172364950 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.172636032 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.172651052 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.507371902 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.507436037 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.556257963 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.556298018 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.556626081 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.557847023 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.600267887 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.958425045 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.958528996 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:35.958667994 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.960150003 CEST | 49731 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:35.960166931 CEST | 443 | 49731 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:42.244541883 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:42.244601965 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:42.244699955 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:43.930583954 CEST | 49729 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:08:43.930633068 CEST | 443 | 49729 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:08:44.214200974 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.214255095 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.214509964 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.215070009 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.215084076 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.550348997 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.558017015 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.558044910 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.558386087 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.558392048 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.944649935 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.944798946 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:08:44.944896936 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.946176052 CEST | 49735 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:08:44.946193933 CEST | 443 | 49735 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:31.984513044 CEST | 49739 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:09:31.984561920 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:31.985085011 CEST | 49739 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:09:31.985085011 CEST | 49739 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:09:31.985120058 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:32.201858997 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:32.202332973 CEST | 49739 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:09:32.202358961 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:35.064762115 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.064816952 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.064918041 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.065080881 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.065094948 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.281280041 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.281740904 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.281763077 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.282030106 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.282036066 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.528923988 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.529053926 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:35.529580116 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.529779911 CEST | 49741 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:35.529794931 CEST | 443 | 49741 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:42.200661898 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:42.200740099 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:42.200824022 CEST | 49739 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:09:44.021806955 CEST | 49739 | 443 | 192.168.2.7 | 108.177.122.147 |
Apr 14, 2025 21:09:44.021852016 CEST | 443 | 49739 | 108.177.122.147 | 192.168.2.7 |
Apr 14, 2025 21:09:45.125708103 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.125771046 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.125916004 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.126091003 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.126110077 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.344769955 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.345077038 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.345115900 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.345365047 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.345372915 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.604837894 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.604991913 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Apr 14, 2025 21:09:45.605040073 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.605557919 CEST | 49745 | 443 | 192.168.2.7 | 162.247.243.29 |
Apr 14, 2025 21:09:45.605575085 CEST | 443 | 49745 | 162.247.243.29 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 14, 2025 21:07:08.769221067 CEST | 53 | 61767 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:08.991539955 CEST | 53 | 65050 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:09.843553066 CEST | 53 | 51275 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:09.888768911 CEST | 53 | 55036 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:13.328639030 CEST | 62782 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:13.328958988 CEST | 61155 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:13.435421944 CEST | 53 | 61155 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:13.435569048 CEST | 53 | 62782 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:14.715353966 CEST | 52839 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:14.715631962 CEST | 61129 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:14.871109009 CEST | 53 | 61129 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:14.872678041 CEST | 53 | 52839 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:17.511733055 CEST | 53 | 61082 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:18.306637049 CEST | 50180 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:18.306934118 CEST | 53100 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:18.413413048 CEST | 53 | 53100 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:18.413434029 CEST | 53 | 50180 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:18.973704100 CEST | 57313 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:18.974118948 CEST | 62691 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:07:19.080231905 CEST | 53 | 62691 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:19.080323935 CEST | 53 | 57313 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:26.987896919 CEST | 53 | 54794 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:07:45.668445110 CEST | 53 | 64070 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:08.090332985 CEST | 53 | 53304 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:08.671926022 CEST | 53 | 54850 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:11.779267073 CEST | 53 | 51042 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:27.381901026 CEST | 53 | 52146 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:27.454116106 CEST | 53 | 55200 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:28.057846069 CEST | 53 | 60822 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:31.921524048 CEST | 54158 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:08:31.921750069 CEST | 55444 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:08:32.027864933 CEST | 53 | 54158 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:32.027893066 CEST | 53 | 55444 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:35.063652992 CEST | 59639 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:08:35.063950062 CEST | 53107 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 14, 2025 21:08:35.170418978 CEST | 53 | 59639 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:35.170514107 CEST | 53 | 53107 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:08:41.115115881 CEST | 138 | 138 | 192.168.2.7 | 192.168.2.255 |
Apr 14, 2025 21:08:45.048794031 CEST | 53 | 50141 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:09:03.920376062 CEST | 53 | 63139 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:09:26.700373888 CEST | 53 | 53974 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:09:27.219954014 CEST | 53 | 53228 | 1.1.1.1 | 192.168.2.7 |
Apr 14, 2025 21:09:30.372035027 CEST | 53 | 49709 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Apr 14, 2025 21:07:09.842083931 CEST | 192.168.2.7 | 1.1.1.1 | c24c | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 14, 2025 21:07:13.328639030 CEST | 192.168.2.7 | 1.1.1.1 | 0x6913 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 21:07:13.328958988 CEST | 192.168.2.7 | 1.1.1.1 | 0x219e | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 14, 2025 21:07:14.715353966 CEST | 192.168.2.7 | 1.1.1.1 | 0xa2e1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 21:07:14.715631962 CEST | 192.168.2.7 | 1.1.1.1 | 0x737d | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 14, 2025 21:07:18.306637049 CEST | 192.168.2.7 | 1.1.1.1 | 0x922c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 21:07:18.306934118 CEST | 192.168.2.7 | 1.1.1.1 | 0x6126 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 14, 2025 21:07:18.973704100 CEST | 192.168.2.7 | 1.1.1.1 | 0x622e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 21:07:18.974118948 CEST | 192.168.2.7 | 1.1.1.1 | 0x77a3 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 14, 2025 21:08:31.921524048 CEST | 192.168.2.7 | 1.1.1.1 | 0x4798 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 21:08:31.921750069 CEST | 192.168.2.7 | 1.1.1.1 | 0xe559 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 14, 2025 21:08:35.063652992 CEST | 192.168.2.7 | 1.1.1.1 | 0x7477 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 21:08:35.063950062 CEST | 192.168.2.7 | 1.1.1.1 | 0x3899 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 14, 2025 21:07:13.435421944 CEST | 1.1.1.1 | 192.168.2.7 | 0x219e | No error (0) | 65 | IN (0x0001) | false | |||
Apr 14, 2025 21:07:13.435569048 CEST | 1.1.1.1 | 192.168.2.7 | 0x6913 | No error (0) | 64.233.185.106 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:13.435569048 CEST | 1.1.1.1 | 192.168.2.7 | 0x6913 | No error (0) | 64.233.185.99 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:13.435569048 CEST | 1.1.1.1 | 192.168.2.7 | 0x6913 | No error (0) | 64.233.185.103 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:13.435569048 CEST | 1.1.1.1 | 192.168.2.7 | 0x6913 | No error (0) | 64.233.185.105 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:13.435569048 CEST | 1.1.1.1 | 192.168.2.7 | 0x6913 | No error (0) | 64.233.185.147 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:13.435569048 CEST | 1.1.1.1 | 192.168.2.7 | 0x6913 | No error (0) | 64.233.185.104 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:14.871109009 CEST | 1.1.1.1 | 192.168.2.7 | 0x737d | No error (0) | b-group.instascreen.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:14.872678041 CEST | 1.1.1.1 | 192.168.2.7 | 0xa2e1 | No error (0) | b-group.instascreen.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:14.872678041 CEST | 1.1.1.1 | 192.168.2.7 | 0xa2e1 | No error (0) | 54.188.253.192 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:14.872678041 CEST | 1.1.1.1 | 192.168.2.7 | 0xa2e1 | No error (0) | 44.240.253.46 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:14.872678041 CEST | 1.1.1.1 | 192.168.2.7 | 0xa2e1 | No error (0) | 54.186.209.228 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:18.413434029 CEST | 1.1.1.1 | 192.168.2.7 | 0x922c | No error (0) | 162.247.243.39 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:19.080231905 CEST | 1.1.1.1 | 192.168.2.7 | 0x77a3 | No error (0) | bam.cell.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:19.080231905 CEST | 1.1.1.1 | 192.168.2.7 | 0x77a3 | No error (0) | fastly-tls12-bam.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:19.080323935 CEST | 1.1.1.1 | 192.168.2.7 | 0x622e | No error (0) | bam.cell.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:19.080323935 CEST | 1.1.1.1 | 192.168.2.7 | 0x622e | No error (0) | fastly-tls12-bam.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:07:19.080323935 CEST | 1.1.1.1 | 192.168.2.7 | 0x622e | No error (0) | 162.247.243.29 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027864933 CEST | 1.1.1.1 | 192.168.2.7 | 0x4798 | No error (0) | 108.177.122.147 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027864933 CEST | 1.1.1.1 | 192.168.2.7 | 0x4798 | No error (0) | 108.177.122.105 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027864933 CEST | 1.1.1.1 | 192.168.2.7 | 0x4798 | No error (0) | 108.177.122.103 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027864933 CEST | 1.1.1.1 | 192.168.2.7 | 0x4798 | No error (0) | 108.177.122.99 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027864933 CEST | 1.1.1.1 | 192.168.2.7 | 0x4798 | No error (0) | 108.177.122.106 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027864933 CEST | 1.1.1.1 | 192.168.2.7 | 0x4798 | No error (0) | 108.177.122.104 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:32.027893066 CEST | 1.1.1.1 | 192.168.2.7 | 0xe559 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 14, 2025 21:08:35.170418978 CEST | 1.1.1.1 | 192.168.2.7 | 0x7477 | No error (0) | bam.cell.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:35.170418978 CEST | 1.1.1.1 | 192.168.2.7 | 0x7477 | No error (0) | fastly-tls12-bam.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:35.170418978 CEST | 1.1.1.1 | 192.168.2.7 | 0x7477 | No error (0) | 162.247.243.29 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:35.170514107 CEST | 1.1.1.1 | 192.168.2.7 | 0x3899 | No error (0) | bam.cell.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 14, 2025 21:08:35.170514107 CEST | 1.1.1.1 | 192.168.2.7 | 0x3899 | No error (0) | fastly-tls12-bam.nr-data.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49692 | 54.188.253.192 | 443 | 5416 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:07:15 UTC | 785 | OUT | |
2025-04-14 19:07:15 UTC | 884 | IN | |
2025-04-14 19:07:15 UTC | 15500 | IN | |
2025-04-14 19:07:15 UTC | 424 | IN | |
2025-04-14 19:07:15 UTC | 16384 | IN | |
2025-04-14 19:07:15 UTC | 8102 | IN | |
2025-04-14 19:07:15 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49702 | 162.247.243.39 | 443 | 5416 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:07:18 UTC | 540 | OUT | |
2025-04-14 19:07:18 UTC | 549 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN | |
2025-04-14 19:07:18 UTC | 1378 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49703 | 162.247.243.29 | 443 | 5416 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:07:19 UTC | 1020 | OUT | |
2025-04-14 19:07:19 UTC | 521 | IN | |
2025-04-14 19:07:19 UTC | 87 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49721 | 162.247.243.29 | 443 | 5416 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:08:19 UTC | 1676 | OUT | |
2025-04-14 19:08:19 UTC | 364 | IN | |
2025-04-14 19:08:19 UTC | 24 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49731 | 162.247.243.29 | 443 | 5760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:08:35 UTC | 1045 | OUT | |
2025-04-14 19:08:35 UTC | 521 | IN | |
2025-04-14 19:08:35 UTC | 87 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49735 | 162.247.243.29 | 443 | 5760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:08:44 UTC | 1045 | OUT | |
2025-04-14 19:08:44 UTC | 521 | IN | |
2025-04-14 19:08:44 UTC | 87 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49741 | 162.247.243.29 | 443 | 5760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:09:35 UTC | 1676 | OUT | |
2025-04-14 19:09:35 UTC | 364 | IN | |
2025-04-14 19:09:35 UTC | 24 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49745 | 162.247.243.29 | 443 | 5760 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 19:09:45 UTC | 1676 | OUT | |
2025-04-14 19:09:45 UTC | 364 | IN | |
2025-04-14 19:09:45 UTC | 24 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 15:07:06 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff778810000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 15:07:07 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff778810000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:07:13 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff778810000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 13 |
Start time: | 15:08:25 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff778810000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 14 |
Start time: | 15:08:26 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff778810000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 15 |
Start time: | 15:08:33 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff778810000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |