Windows
Analysis Report
https://rgpa3i8o6x1j.homes/?jf63wkd=U2FsdGVkX19qaUwcOlLYfSFLBfZWFppf1J9e8ekLOGqSUoNTcDmz 9BoCaIr 8Boe/S8JQ8WxAWIFgg9LsarJRJuiXCk7T1cRkNUVOhpcX2Ce1XGbCtH3DMJHU0hejczPkyUFuOp6hPFE5Zv1ed2fRB72sw6QQlf7J67Y2z4sIUViHc rZjD0KUFOYL70u7uAH7wHvkEF9kDrcLIHFac6yFNRruuSs1x8z/ptf9SJGtJv/pxVJtVKaCmAOD6xyj
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 352 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 4756 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2008,i ,215361516 7191505444 ,184074574 9737656171 0,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2036 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6816 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://rgpa3 i8o6x1j.ho mes/?jf63w kd=U2FsdGV kX19qaUwcO lLYfSFLBfZ WFppf1J9e8 ekLOGqSUoN TcDmz%209B oCaIr%20%2 08Boe/S8JQ 8WxAWIFgg9 LsarJRJuiX Ck7T1cRkNU VOhpcX2Ce1 XGbCtH3DMJ HU0hejczPk yUFuOp6hPF E5Zv1ed2fR B72sw6QQlf 7J67Y2z4sI UViHc%20rZ jD0KUFOYL7 0u7uAH7wHv kEF9kDrcLI HFac6yFNRr uuSs1x8z/p tf9SJGtJv/ pxVJtVKaCm AOD6xyjtec GAcjuZY7fn E0Aur1NDA= =" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
rgpa3i8o6x1j.homes | 3.224.79.245 | true | false | unknown | |
www.google.com | 74.125.136.105 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
74.125.136.105 | www.google.com | United States | 15169 | GOOGLEUS | false | |
3.224.79.245 | rgpa3i8o6x1j.homes | United States | 14618 | AMAZON-AESUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1664871 |
Start date and time: | 2025-04-14 22:01:53 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://rgpa3i8o6x1j.homes/?jf63wkd=U2FsdGVkX19qaUwcOlLYfSFLBfZWFppf1J9e8ekLOGqSUoNTcDmz 9BoCaIr 8Boe/S8JQ8WxAWIFgg9LsarJRJuiXCk7T1cRkNUVOhpcX2Ce1XGbCtH3DMJHU0hejczPkyUFuOp6hPFE5Zv1ed2fRB72sw6QQlf7J67Y2z4sIUViHc rZjD0KUFOYL70u7uAH7wHvkEF9kDrcLIHFac6yFNRruuSs1x8z/ptf9SJGtJv/pxVJtVKaCmAOD6xyjtecGAcjuZY7fnE0Aur1NDA== |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@21/0@4/3 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, sppsvc.exe, Runtim eBroker.exe, ShellExperienceHo st.exe, SIHClient.exe, SgrmBro ker.exe, backgroundTaskHost.ex e, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 172.217.215.138, 1 72.217.215.113, 172.217.215.10 1, 172.217.215.102, 172.217.21 5.100, 172.217.215.139, 64.233 .185.94, 142.250.9.84, 142.250 .9.101, 142.250.9.102, 142.250 .9.139, 142.250.9.138, 142.250 .9.100, 142.250.9.113, 74.125. 136.101, 74.125.136.139, 74.12 5.136.113, 74.125.136.138, 74. 125.136.102, 74.125.136.100, 1 73.194.219.138, 173.194.219.11 3, 173.194.219.101, 173.194.21 9.100, 173.194.219.102, 173.19 4.219.139, 23.4.43.62, 199.232 .210.172, 64.233.177.100, 64.2 33.177.138, 64.233.177.101, 64 .233.177.102, 64.233.177.139, 64.233.177.113, 64.233.185.113 , 64.233.185.102, 64.233.185.1 39, 64.233.185.101, 64.233.185 .100, 64.233.185.138, 74.125.1 38.101, 74.125.138.102, 74.125 .138.139, 74.125.138.138, 74.1 25.138.100, 74.125.138.113, 17 2.253.124.94, 108.177.122.94, 23.76.34.6, 20.12.23.50 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fe3cr.deliv ery.mp.microsoft.com, clients2 .google.com, edgedl.me.gvt1.co m, redirector.gvt1.com, ocsp.d igicert.com, update.googleapis .com, clients.l.google.com, c. pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//rgpa3i8o6x1j.homes/?jf63wkd= U2FsdGVkX19qaUwcOlLYfSFLBfZWFp pf1J9e8ekLOGqSUoNTcDmz%209BoCa Ir%20%208Boe/S8JQ8WxAWIFgg9Lsa rJRJuiXCk7T1cRkNUVOhpcX2Ce1XGb CtH3DMJHU0hejczPkyUFuOp6hPFE5Z v1ed2fRB72sw6QQlf7J67Y2z4sIUVi Hc%20rZjD0KUFOYL70u7uAH7wHvkEF 9kDrcLIHFac6yFNRruuSs1x8z/ptf9 SJGtJv/pxVJtVKaCmAOD6xyjtecGAc juZY7fnE0Aur1NDA==
Download Network PCAP: filtered – full
- Total Packets: 81
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 14, 2025 22:02:46.530498028 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 14, 2025 22:02:51.123764038 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:02:51.436604977 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:02:52.045993090 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:02:53.311721087 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:02:55.717156887 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:02:56.139024973 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 14, 2025 22:02:58.499336004 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:02:58.499433994 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:02:58.499691010 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:02:58.502017975 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:02:58.502054930 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:02:58.726943970 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:02:58.727016926 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:02:58.728318930 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:02:58.728332996 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:02:58.728627920 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:02:58.779988050 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:02:59.750715971 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:02:59.866908073 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:02:59.866950035 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:02:59.868084908 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:02:59.868232965 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:02:59.868238926 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:02:59.878884077 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:02:59.878909111 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:02:59.879029036 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:02:59.879194021 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:02:59.879208088 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.060758114 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:03:00.134944916 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.135029078 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.137793064 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.137859106 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.139698982 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.139705896 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.140182018 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.140908003 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.140918970 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.141071081 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.141796112 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.185823917 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.188281059 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.372486115 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.372658968 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.372715950 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.373106003 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.373128891 CEST | 443 | 49727 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:00.373140097 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.373177052 CEST | 49727 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:00.533174038 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:03:00.671921968 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:03:01.888448000 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:03:04.299381018 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:03:05.532213926 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.532972097 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.532972097 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.653094053 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.653706074 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.653790951 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.654247046 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.654301882 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.654402971 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.656012058 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.656526089 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.656565905 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.656630039 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.656630039 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.664035082 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.776894093 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.785027027 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.787178993 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.787221909 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 14, 2025 22:03:05.787319899 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 14, 2025 22:03:05.790323973 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:05.790328026 CEST | 49731 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:05.790450096 CEST | 443 | 49731 | 204.79.197.222 | 192.168.2.4 |
Apr 14, 2025 22:03:05.790612936 CEST | 49731 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:05.792020082 CEST | 49731 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:05.792058945 CEST | 443 | 49731 | 204.79.197.222 | 192.168.2.4 |
Apr 14, 2025 22:03:05.972095966 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:03:06.078424931 CEST | 80 | 49732 | 74.125.21.94 | 192.168.2.4 |
Apr 14, 2025 22:03:06.078561068 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:03:06.078634977 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:03:06.096308947 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:06.136719942 CEST | 443 | 49731 | 204.79.197.222 | 192.168.2.4 |
Apr 14, 2025 22:03:06.136831999 CEST | 49731 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:06.184839964 CEST | 80 | 49732 | 74.125.21.94 | 192.168.2.4 |
Apr 14, 2025 22:03:06.185442924 CEST | 80 | 49732 | 74.125.21.94 | 192.168.2.4 |
Apr 14, 2025 22:03:06.185482979 CEST | 80 | 49732 | 74.125.21.94 | 192.168.2.4 |
Apr 14, 2025 22:03:06.185841084 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:03:06.191936016 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:03:06.299015045 CEST | 80 | 49732 | 74.125.21.94 | 192.168.2.4 |
Apr 14, 2025 22:03:06.348011017 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:03:06.705702066 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:07.908755064 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:08.733700991 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:03:08.733831882 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:03:08.733941078 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:03:09.111855984 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:03:10.143093109 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 14, 2025 22:03:10.315094948 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:10.410861015 CEST | 49723 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:03:10.410934925 CEST | 443 | 49723 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:03:15.127484083 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:18.714556932 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 14, 2025 22:03:24.732450008 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 14, 2025 22:03:45.152667999 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:03:45.152702093 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:03:58.450773001 CEST | 49739 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:03:58.450869083 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:03:58.450982094 CEST | 49739 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:03:58.451381922 CEST | 49739 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:03:58.451466084 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:03:58.674375057 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:03:58.674696922 CEST | 49739 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:03:58.674776077 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:04:00.116518974 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:04:00.116741896 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:04:00.116838932 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:04:00.404316902 CEST | 49726 | 443 | 192.168.2.4 | 3.224.79.245 |
Apr 14, 2025 22:04:00.404340029 CEST | 443 | 49726 | 3.224.79.245 | 192.168.2.4 |
Apr 14, 2025 22:04:06.636925936 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:04:06.743350029 CEST | 80 | 49732 | 74.125.21.94 | 192.168.2.4 |
Apr 14, 2025 22:04:06.743411064 CEST | 49732 | 80 | 192.168.2.4 | 74.125.21.94 |
Apr 14, 2025 22:04:08.678812981 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:04:08.678874016 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Apr 14, 2025 22:04:08.679053068 CEST | 49739 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:04:10.408288002 CEST | 49739 | 443 | 192.168.2.4 | 74.125.136.105 |
Apr 14, 2025 22:04:10.408358097 CEST | 443 | 49739 | 74.125.136.105 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 14, 2025 22:02:54.445027113 CEST | 53 | 65254 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:54.502326012 CEST | 53 | 59749 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:55.264395952 CEST | 53 | 65202 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:55.538758039 CEST | 53 | 52186 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:58.390431881 CEST | 58358 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 14, 2025 22:02:58.390743971 CEST | 63261 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 14, 2025 22:02:58.497257948 CEST | 53 | 63261 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:58.497828960 CEST | 53 | 58358 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:59.731679916 CEST | 54458 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 14, 2025 22:02:59.734740973 CEST | 58918 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 14, 2025 22:02:59.842400074 CEST | 53 | 58918 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:02:59.864765882 CEST | 53 | 54458 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:03:12.517021894 CEST | 53 | 53046 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:03:31.246432066 CEST | 53 | 55412 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:03:53.936829090 CEST | 53 | 52192 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:03:54.077872038 CEST | 53 | 59224 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:03:56.807641983 CEST | 53 | 60994 | 1.1.1.1 | 192.168.2.4 |
Apr 14, 2025 22:03:59.145229101 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 14, 2025 22:02:58.390431881 CEST | 192.168.2.4 | 1.1.1.1 | 0x14f8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 22:02:58.390743971 CEST | 192.168.2.4 | 1.1.1.1 | 0x9500 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 14, 2025 22:02:59.731679916 CEST | 192.168.2.4 | 1.1.1.1 | 0xc96 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 14, 2025 22:02:59.734740973 CEST | 192.168.2.4 | 1.1.1.1 | 0x667a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 14, 2025 22:02:58.497257948 CEST | 1.1.1.1 | 192.168.2.4 | 0x9500 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 14, 2025 22:02:58.497828960 CEST | 1.1.1.1 | 192.168.2.4 | 0x14f8 | No error (0) | 74.125.136.105 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:58.497828960 CEST | 1.1.1.1 | 192.168.2.4 | 0x14f8 | No error (0) | 74.125.136.103 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:58.497828960 CEST | 1.1.1.1 | 192.168.2.4 | 0x14f8 | No error (0) | 74.125.136.147 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:58.497828960 CEST | 1.1.1.1 | 192.168.2.4 | 0x14f8 | No error (0) | 74.125.136.99 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:58.497828960 CEST | 1.1.1.1 | 192.168.2.4 | 0x14f8 | No error (0) | 74.125.136.104 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:58.497828960 CEST | 1.1.1.1 | 192.168.2.4 | 0x14f8 | No error (0) | 74.125.136.106 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:59.864765882 CEST | 1.1.1.1 | 192.168.2.4 | 0xc96 | No error (0) | 3.224.79.245 | A (IP address) | IN (0x0001) | false | ||
Apr 14, 2025 22:02:59.864765882 CEST | 1.1.1.1 | 192.168.2.4 | 0xc96 | No error (0) | 3.222.54.159 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49732 | 74.125.21.94 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 14, 2025 22:03:06.078634977 CEST | 202 | OUT | |
Apr 14, 2025 22:03:06.185442924 CEST | 1358 | IN | |
Apr 14, 2025 22:03:06.185482979 CEST | 1095 | IN | |
Apr 14, 2025 22:03:06.191936016 CEST | 200 | OUT | |
Apr 14, 2025 22:03:06.299015045 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49727 | 3.224.79.245 | 443 | 4756 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-14 20:03:00 UTC | 965 | OUT | |
2025-04-14 20:03:00 UTC | 83 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 16:02:49 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 16:02:52 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62fc20000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 16:02:58 |
Start date: | 14/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |