Windows
Analysis Report
https://www.mediafire.com/file/aeiurtz1j2ru8jw/Dowody i dowody potwierdzające w dochodzeniach karnych.zip/file
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5272 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5896 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2448,i ,642445977 7877152407 ,170152120 9794457529 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion --vari ations-see d-version= 20250306-1 83004.4290 00 --mojo- platform-c hannel-han dle=2480 / prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6780 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://www.m ediafire.c om/file/ae iurtz1j2ru 8jw/Dowody %20i%20dow ody%20potw ierdzaj%C4 %85ce%20w% 20dochodze niach%20ka rnych.zip/ file" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.mediafire.com | 104.17.150.117 | true | false | high | |
download2289.mediafire.com | 199.91.155.30 | true | false | high | |
www.google.com | 74.125.138.103 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
74.125.138.103 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.17.150.117 | www.mediafire.com | United States | 13335 | CLOUDFLARENETUS | false | |
199.91.155.30 | download2289.mediafire.com | United States | 46179 | MEDIAFIREUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1665570 |
Start date and time: | 2025-04-15 17:06:53 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://www.mediafire.com/file/aeiurtz1j2ru8jw/Dowody i dowody potwierdzające w dochodzeniach karnych.zip/file |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@21/2@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, sppsvc.exe, Runtim eBroker.exe, ShellExperienceHo st.exe, SIHClient.exe, SgrmBro ker.exe, backgroundTaskHost.ex e, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 172.253.124.94, 10 8.177.122.100, 108.177.122.102 , 108.177.122.139, 108.177.122 .113, 108.177.122.138, 108.177 .122.101, 74.125.138.100, 74.1 25.138.139, 74.125.138.101, 74 .125.138.102, 74.125.138.113, 74.125.138.138, 64.233.177.84, 64.233.185.101, 64.233.185.13 9, 64.233.185.100, 64.233.185. 102, 64.233.185.113, 64.233.18 5.138, 74.125.21.101, 74.125.2 1.138, 74.125.21.113, 74.125.2 1.139, 74.125.21.100, 74.125.2 1.102, 199.232.214.172, 23.4.4 3.62, 199.232.210.172, 142.250 .9.113, 142.250.9.100, 142.250 .9.138, 142.250.9.139, 142.250 .9.102, 142.250.9.101, 173.194 .219.138, 173.194.219.101, 173 .194.219.139, 173.194.219.102, 173.194.219.113, 173.194.219. 100, 74.125.21.94, 74.125.136. 113, 74.125.136.139, 74.125.13 6.100, 74.125.136.138, 74.125. 136.101, 74.125.136.102, 64.23 3.185.94, 23.76.34.6, 20.12.23 .50 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fe3cr.deliv ery.mp.microsoft.com, clients2 .google.com, ocsp.digicert.com , edgedl.me.gvt1.com, redirect or.gvt1.com, update.googleapis .com, clients.l.google.com, c. pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//www.mediafire.com/file/aeiur tz1j2ru8jw/Dowody%20i%20dowody %20potwierdzaj%C4%85ce%20w%20d ochodzeniach%20karnych.zip/fil e
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 7.9787141423441925 |
Encrypted: | false |
SSDEEP: | 384:gwOnuSmpIsu042WvGnAqmGSf2JZ8v15xLs3ZON:l8LfZ2+GnAnoE15JspQ |
MD5: | F0985F76B57D6709B686EF1CF98774BD |
SHA1: | 3F792EE6AF88E3896039324E74EF82BE39751111 |
SHA-256: | ACED56120206CC4CE5762019BED1BC36950F70E31D4E55CC906143ADF7805B55 |
SHA-512: | 5D8DF39A21B79E86F4041CF184B32BF133E0A975461331BD887460177AACD0A3AF66B4A3C7D0E67BFD10E8D6F2D4D3751446E6EC31D5BA2E019E183297FAA8BC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 7.9787141423441925 |
Encrypted: | false |
SSDEEP: | 384:gwOnuSmpIsu042WvGnAqmGSf2JZ8v15xLs3ZON:l8LfZ2+GnAnoE15JspQ |
MD5: | F0985F76B57D6709B686EF1CF98774BD |
SHA1: | 3F792EE6AF88E3896039324E74EF82BE39751111 |
SHA-256: | ACED56120206CC4CE5762019BED1BC36950F70E31D4E55CC906143ADF7805B55 |
SHA-512: | 5D8DF39A21B79E86F4041CF184B32BF133E0A975461331BD887460177AACD0A3AF66B4A3C7D0E67BFD10E8D6F2D4D3751446E6EC31D5BA2E019E183297FAA8BC |
Malicious: | false |
Reputation: | low |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 85
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 15, 2025 17:07:44.053508997 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:07:51.217895985 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:07:51.611134052 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:07:52.410897017 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:07:53.615648031 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:07:53.662501097 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:07:54.889153004 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:07:54.889219999 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:07:54.889290094 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:07:54.889435053 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:07:54.889446974 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:07:55.117158890 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:07:55.117235899 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:07:55.118434906 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:07:55.118444920 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:07:55.118720055 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:07:55.162880898 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:07:56.021358967 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:07:56.916857004 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:56.916903019 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:56.917061090 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:56.917299032 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:56.917416096 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:56.917529106 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:56.917649984 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:56.917678118 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:56.917771101 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:56.917788029 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.251779079 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.251916885 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.253056049 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.253072023 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.253349066 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.253629923 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.255964041 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.256035089 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.260160923 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.260179996 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.260503054 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.296282053 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.305150986 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.484143972 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.484236002 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.484324932 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.485177994 CEST | 49725 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:07:57.485194921 CEST | 443 | 49725 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:07:57.635102987 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:57.635163069 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:57.635312080 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:57.635639906 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:57.635653019 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:57.913410902 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:57.913489103 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:57.915179968 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:57.915193081 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:57.915416956 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:57.915941000 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:57.956271887 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:58.350667000 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:58.351521015 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:58.351537943 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:58.351571083 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:58.351592064 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:58.351613045 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:58.351633072 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:58.392483950 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:58.392579079 CEST | 443 | 49727 | 199.91.155.30 | 192.168.2.4 |
Apr 15, 2025 17:07:58.392638922 CEST | 49727 | 443 | 192.168.2.4 | 199.91.155.30 |
Apr 15, 2025 17:07:59.819499969 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:00.147542000 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:00.756582022 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:00.834709883 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:08:01.959702015 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:03.128099918 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:03.428442955 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:03.457714081 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.459882975 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.459978104 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.563694954 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.564837933 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.564851999 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.564896107 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.564927101 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.565645933 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.565679073 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.565881014 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.565890074 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.567358017 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.567445993 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.567462921 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.567496061 CEST | 49710 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 15, 2025 17:08:03.671715021 CEST | 443 | 49710 | 204.79.197.222 | 192.168.2.4 |
Apr 15, 2025 17:08:03.930501938 CEST | 49732 | 80 | 192.168.2.4 | 74.125.136.94 |
Apr 15, 2025 17:08:04.036694050 CEST | 80 | 49732 | 74.125.136.94 | 192.168.2.4 |
Apr 15, 2025 17:08:04.036782980 CEST | 49732 | 80 | 192.168.2.4 | 74.125.136.94 |
Apr 15, 2025 17:08:04.036911011 CEST | 49732 | 80 | 192.168.2.4 | 74.125.136.94 |
Apr 15, 2025 17:08:04.037658930 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:04.142978907 CEST | 80 | 49732 | 74.125.136.94 | 192.168.2.4 |
Apr 15, 2025 17:08:04.143409014 CEST | 80 | 49732 | 74.125.136.94 | 192.168.2.4 |
Apr 15, 2025 17:08:04.194487095 CEST | 49732 | 80 | 192.168.2.4 | 74.125.136.94 |
Apr 15, 2025 17:08:04.368436098 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:05.117737055 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:08:05.117887020 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:08:05.117930889 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:08:05.252991915 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:05.754792929 CEST | 49723 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:08:05.754865885 CEST | 443 | 49723 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:08:07.662993908 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:09.178045988 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:10.443516016 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 15, 2025 17:08:12.131814003 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:08:12.131903887 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:08:12.131957054 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:08:12.476028919 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:12.775177002 CEST | 49726 | 443 | 192.168.2.4 | 104.17.150.117 |
Apr 15, 2025 17:08:12.775213957 CEST | 443 | 49726 | 104.17.150.117 | 192.168.2.4 |
Apr 15, 2025 17:08:18.780231953 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 15, 2025 17:08:22.089848042 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 15, 2025 17:08:54.820079088 CEST | 49740 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:08:54.820178032 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:08:54.820297956 CEST | 49740 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:08:54.820441961 CEST | 49740 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:08:54.820462942 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:08:55.040065050 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:08:55.040431023 CEST | 49740 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:08:55.040502071 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:09:04.491338968 CEST | 49732 | 80 | 192.168.2.4 | 74.125.136.94 |
Apr 15, 2025 17:09:04.597876072 CEST | 80 | 49732 | 74.125.136.94 | 192.168.2.4 |
Apr 15, 2025 17:09:04.597929001 CEST | 49732 | 80 | 192.168.2.4 | 74.125.136.94 |
Apr 15, 2025 17:09:05.040437937 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:09:05.040518999 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Apr 15, 2025 17:09:05.040616035 CEST | 49740 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:09:05.760694027 CEST | 49740 | 443 | 192.168.2.4 | 74.125.138.103 |
Apr 15, 2025 17:09:05.760765076 CEST | 443 | 49740 | 74.125.138.103 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 15, 2025 17:07:51.806562901 CEST | 53 | 63186 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:51.813827991 CEST | 53 | 53902 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:52.630095959 CEST | 53 | 52552 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:52.803749084 CEST | 53 | 62922 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:54.757846117 CEST | 58391 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 15, 2025 17:07:54.758225918 CEST | 64359 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 15, 2025 17:07:54.865885973 CEST | 53 | 64359 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:54.865914106 CEST | 53 | 58391 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:56.807298899 CEST | 65110 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 15, 2025 17:07:56.807840109 CEST | 53064 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 15, 2025 17:07:56.915184021 CEST | 53 | 65110 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:56.916017056 CEST | 53 | 53064 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:57.488414049 CEST | 61737 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 15, 2025 17:07:57.488689899 CEST | 61466 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 15, 2025 17:07:57.599833965 CEST | 53 | 61466 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:07:57.629483938 CEST | 53 | 61737 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:08:09.709309101 CEST | 53 | 61046 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:08:28.641238928 CEST | 53 | 61853 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:08:51.053494930 CEST | 53 | 54604 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:08:51.123390913 CEST | 53 | 55736 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:08:52.975791931 CEST | 53 | 49652 | 1.1.1.1 | 192.168.2.4 |
Apr 15, 2025 17:08:59.294486046 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 15, 2025 17:07:54.757846117 CEST | 192.168.2.4 | 1.1.1.1 | 0xafb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 15, 2025 17:07:54.758225918 CEST | 192.168.2.4 | 1.1.1.1 | 0x7058 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 15, 2025 17:07:56.807298899 CEST | 192.168.2.4 | 1.1.1.1 | 0x251d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 15, 2025 17:07:56.807840109 CEST | 192.168.2.4 | 1.1.1.1 | 0x848a | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 15, 2025 17:07:57.488414049 CEST | 192.168.2.4 | 1.1.1.1 | 0x3c30 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 15, 2025 17:07:57.488689899 CEST | 192.168.2.4 | 1.1.1.1 | 0x6066 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 15, 2025 17:07:54.865885973 CEST | 1.1.1.1 | 192.168.2.4 | 0x7058 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 15, 2025 17:07:54.865914106 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb | No error (0) | 74.125.138.103 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:54.865914106 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb | No error (0) | 74.125.138.147 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:54.865914106 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb | No error (0) | 74.125.138.99 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:54.865914106 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb | No error (0) | 74.125.138.106 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:54.865914106 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb | No error (0) | 74.125.138.104 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:54.865914106 CEST | 1.1.1.1 | 192.168.2.4 | 0xafb | No error (0) | 74.125.138.105 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:56.915184021 CEST | 1.1.1.1 | 192.168.2.4 | 0x251d | No error (0) | 104.17.150.117 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:56.915184021 CEST | 1.1.1.1 | 192.168.2.4 | 0x251d | No error (0) | 104.17.151.117 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:07:56.916017056 CEST | 1.1.1.1 | 192.168.2.4 | 0x848a | No error (0) | 65 | IN (0x0001) | false | |||
Apr 15, 2025 17:07:57.629483938 CEST | 1.1.1.1 | 192.168.2.4 | 0x3c30 | No error (0) | 199.91.155.30 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49732 | 74.125.136.94 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 15, 2025 17:08:04.036911011 CEST | 200 | OUT | |
Apr 15, 2025 17:08:04.143409014 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49725 | 104.17.150.117 | 443 | 5896 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-15 15:07:57 UTC | 768 | OUT | |
2025-04-15 15:07:57 UTC | 1218 | IN | |
2025-04-15 15:07:57 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49727 | 199.91.155.30 | 443 | 5896 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-15 15:07:57 UTC | 1157 | OUT | |
2025-04-15 15:07:58 UTC | 337 | IN | |
2025-04-15 15:07:58 UTC | 16384 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 11:07:46 |
Start date: | 15/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 11:07:50 |
Start date: | 15/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 11:07:55 |
Start date: | 15/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |