Windows
Analysis Report
https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1096 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 2788 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1940,i ,607508729 4735186206 ,160675516 3391876605 3,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version --mojo-pl atform-cha nnel-handl e=1972 /pr efetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6948 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://mindl abs.toplea ds.co/lt.p hp?x=3DZy~ GDFUqWh68K t0NtJgRWf~ nykj_Xvjhs 2jXDDJILL5 K3.y0y.0.d t1o2hidLvn uc3bHTDKni " MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 173.194.219.99 | true | false | high | |
sendgrid.production-us12.com | 31.172.83.250 | true | false | unknown | |
mindlabs.activehosted.com | 104.17.203.31 | true | false | unknown | |
mindlabs.topleads.co | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | unknown | ||
false | unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.17.203.31 | mindlabs.activehosted.com | United States | 13335 | CLOUDFLARENETUS | false | |
173.194.219.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
31.172.83.250 | sendgrid.production-us12.com | Germany | 44066 | DE-FIRSTCOLOwwwfirst-colonetDE | false |
IP |
---|
192.168.2.16 |
192.168.2.6 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1665629 |
Start date and time: | 2025-04-15 17:49:19 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://mindlabs.topleads.co/lt.php?x=3DZy~GDFUqWh68Kt0NtJgRWf~nykj_Xvjhs2jXDDJILL5K3.y0y.0.dt1o2hidLvnuc3bHTDKni |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@24/4@6/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 108.177.122.113, 1 08.177.122.100, 108.177.122.10 2, 108.177.122.101, 108.177.12 2.138, 108.177.122.139, 172.21 7.215.94, 172.217.215.138, 172 .217.215.100, 172.217.215.102, 172.217.215.113, 172.217.215. 139, 172.217.215.101, 74.125.2 1.84, 74.125.21.101, 74.125.21 .113, 74.125.21.102, 74.125.21 .138, 74.125.21.100, 74.125.21 .139, 74.125.138.138, 74.125.1 38.101, 74.125.138.100, 74.125 .138.139, 74.125.138.113, 74.1 25.138.102, 173.194.219.139, 1 73.194.219.101, 173.194.219.13 8, 173.194.219.100, 173.194.21 9.102, 173.194.219.113, 23.218 .145.76, 64.233.185.100, 64.23 3.185.113, 64.233.185.138, 64. 233.185.139, 64.233.185.102, 6 4.233.185.101, 74.125.136.94, 142.250.9.101, 142.250.9.100, 142.250.9.139, 142.250.9.113, 142.250.9.138, 142.250.9.102, 142.251.15.94, 23.79.17.61, 4. 245.163.56 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, clients2.google.com, edged l.me.gvt1.com, accounts.google .com, redirector.gvt1.com, sls cr.update.microsoft.com, updat e.googleapis.com, ctldl.window supdate.com, clientservices.go ogleapis.com, clients.l.google .com, c.pki.goog, fe3cr.delive ry.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//mindlabs.topleads.co/lt.php? x=3DZy~GDFUqWh68Kt0NtJgRWf~nyk j_Xvjhs2jXDDJILL5K3.y0y.0.dt1o 2hidLvnuc3bHTDKni
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 564 |
Entropy (8bit): | 4.775290370533887 |
Encrypted: | false |
SSDEEP: | 12:TjeRHVIdtklI5rRCNGlTF5TF5TF5TF5TF5TFK:neRH688lTPTPTPTPTPTc |
MD5: | 5DA4C1420F84EC727D1B6BDD0D46E62E |
SHA1: | 280D08D142F7386283F420444EC48E1CDBFD61BB |
SHA-256: | 3C8CC37A98346BD0123B35E5CCD87BD07D69914DAE04F8B49F61C150D96E9D1F |
SHA-512: | 7C51A628831D0236E8D314C71732B8A62E06334431D10F7C293C49B23665B2A6A1DDBC4772009010955B5228EA4A5CD97FB93581CE391EE1792E8A198B76111A |
Malicious: | false |
Reputation: | low |
URL: | https://sendgrid.production-us12.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 588 |
Entropy (8bit): | 4.727576914852944 |
Encrypted: | false |
SSDEEP: | 12:TiUDW5VIFUDWOlI5rRCNGlTF5TF5TF5TF5TF5TFK:eUDW5aUDWY8lTPTPTPTPTPTc |
MD5: | 1AFAC349CEA899675DE7D9F7F29EABA0 |
SHA1: | F924BE061A24E2E275E25193D4EB6FDAC4EEC9D6 |
SHA-256: | C48B71948160F9CC2AE1E8C93498E2C3EC4C3544D8FE7A4D2F85147444F862EC |
SHA-512: | CD3B7875AD23CF017CE25D49E7588B4BC4BB2E4A4D909CF2084CB0496E9378F00327EC4A55B93637E389AF66B8A3F9FB4133B868C505C8A4B0BAAA2E193C790E |
Malicious: | false |
Reputation: | low |
URL: | https://sendgrid.production-us12.com/?email=YiFzjIkJ5UJtEFDHdscrYLWB9GvfG8q%2BvCQGaktl3bPGz3YD%2Fs5yIf7SRA%2FvE1186MWgkVZ2Z2I5VKvsQx2OFnHLjmFBKE6Dfi74%2Fycgiz4Fuk1xu5IMzHVzzMVUXovJi8y7oUh4L3PpBqzt9Mmsf5BO%2FgTDKlV15Vky6GwmskaCUOeZYVd2WlOXetig92uFF0oyh4m1sgD9yOcwwrvexC86WIG5lLPBawa7R7SSK%2F9imDMZkIWxeYvY4TMPn38p2eUGQ%2BwF%2B9YpPfMYLzxH%2FdzwthFKMrFDS8jf3oDBC8NbkBzYgjGwr4mNz3s7TXmBGW7k8LFnU6YNTL4mnGMT6g%3D%3D |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 72
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 15, 2025 17:50:13.438204050 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:13.750277996 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:14.359585047 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:15.562845945 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:17.969014883 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:22.016918898 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:22.351763964 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:22.797606945 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:23.016180992 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:24.314064980 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:25.970483065 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:25.970530033 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:25.970611095 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:25.970817089 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:25.970834017 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:26.190947056 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:26.191080093 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:26.192420959 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:26.192429066 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:26.192617893 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:26.235220909 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:26.719549894 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:27.125461102 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.125500917 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.125932932 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.130057096 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.130083084 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.130230904 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.130603075 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.130619049 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.130765915 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.130784988 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.367285013 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.367425919 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.368360043 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.368560076 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.411461115 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.411469936 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.411684036 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.411782026 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.411806107 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.411966085 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:27.412055969 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.456273079 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:27.459259033 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:28.435064077 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:28.435185909 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:28.435234070 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:28.437992096 CEST | 49699 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:28.438000917 CEST | 443 | 49699 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:28.567990065 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:28.568079948 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:28.568173885 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:28.568429947 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:28.568466902 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:28.998305082 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:28.998421907 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:28.999763012 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:28.999793053 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.000025988 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.001539946 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:29.044301987 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.413908958 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.413969040 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.414038897 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:29.414891005 CEST | 49700 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:29.414932966 CEST | 443 | 49700 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.569874048 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:29.569924116 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.569992065 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:29.570296049 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:29.570312023 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:29.995178938 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:30.006212950 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:30.006253958 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:30.007961035 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:30.007972002 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:30.414458036 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:30.414537907 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:30.414647102 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:30.415508986 CEST | 49701 | 443 | 192.168.2.6 | 31.172.83.250 |
Apr 15, 2025 17:50:30.415528059 CEST | 443 | 49701 | 31.172.83.250 | 192.168.2.6 |
Apr 15, 2025 17:50:31.532373905 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:32.407346010 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 15, 2025 17:50:34.173113108 CEST | 49705 | 80 | 192.168.2.6 | 142.250.9.94 |
Apr 15, 2025 17:50:34.279966116 CEST | 80 | 49705 | 142.250.9.94 | 192.168.2.6 |
Apr 15, 2025 17:50:34.280067921 CEST | 49705 | 80 | 192.168.2.6 | 142.250.9.94 |
Apr 15, 2025 17:50:34.280260086 CEST | 49705 | 80 | 192.168.2.6 | 142.250.9.94 |
Apr 15, 2025 17:50:34.388299942 CEST | 80 | 49705 | 142.250.9.94 | 192.168.2.6 |
Apr 15, 2025 17:50:34.388828039 CEST | 80 | 49705 | 142.250.9.94 | 192.168.2.6 |
Apr 15, 2025 17:50:34.437997103 CEST | 49705 | 80 | 192.168.2.6 | 142.250.9.94 |
Apr 15, 2025 17:50:36.196408987 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:36.196485996 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:36.196569920 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:36.691071033 CEST | 49697 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:50:36.691095114 CEST | 443 | 49697 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:50:41.141829014 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 15, 2025 17:50:42.346218109 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:42.346422911 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:50:42.346559048 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:42.691010952 CEST | 49698 | 443 | 192.168.2.6 | 104.17.203.31 |
Apr 15, 2025 17:50:42.691025972 CEST | 443 | 49698 | 104.17.203.31 | 192.168.2.6 |
Apr 15, 2025 17:51:25.924350977 CEST | 49712 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:51:25.924407959 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:51:25.924513102 CEST | 49712 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:51:25.924854994 CEST | 49712 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:51:25.924864054 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:51:26.143320084 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:51:26.143832922 CEST | 49712 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:51:26.143848896 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:51:32.415795088 CEST | 443 | 49681 | 2.23.227.215 | 192.168.2.6 |
Apr 15, 2025 17:51:32.415821075 CEST | 443 | 49681 | 2.23.227.215 | 192.168.2.6 |
Apr 15, 2025 17:51:32.416063070 CEST | 49681 | 443 | 192.168.2.6 | 2.23.227.215 |
Apr 15, 2025 17:51:34.610897064 CEST | 49705 | 80 | 192.168.2.6 | 142.250.9.94 |
Apr 15, 2025 17:51:34.717360973 CEST | 80 | 49705 | 142.250.9.94 | 192.168.2.6 |
Apr 15, 2025 17:51:34.717430115 CEST | 49705 | 80 | 192.168.2.6 | 142.250.9.94 |
Apr 15, 2025 17:51:36.147458076 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:51:36.147500038 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Apr 15, 2025 17:51:36.147550106 CEST | 49712 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:51:36.691802025 CEST | 49712 | 443 | 192.168.2.6 | 173.194.219.99 |
Apr 15, 2025 17:51:36.691838980 CEST | 443 | 49712 | 173.194.219.99 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 15, 2025 17:50:21.496104002 CEST | 53 | 62772 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:21.499875069 CEST | 53 | 58092 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:22.384179115 CEST | 53 | 55172 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:22.537586927 CEST | 53 | 55689 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:25.861537933 CEST | 51147 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 15, 2025 17:50:25.861989975 CEST | 56516 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 15, 2025 17:50:25.968899965 CEST | 53 | 51147 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:25.968974113 CEST | 53 | 56516 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:26.960580111 CEST | 52775 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 15, 2025 17:50:26.960855007 CEST | 60622 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 15, 2025 17:50:27.105015039 CEST | 53 | 52775 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:27.117839098 CEST | 53 | 60622 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:28.439471006 CEST | 58861 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 15, 2025 17:50:28.439652920 CEST | 54321 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 15, 2025 17:50:28.564438105 CEST | 53 | 58861 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:28.566102982 CEST | 53 | 54321 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:39.564522982 CEST | 53 | 60336 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:50:58.345491886 CEST | 53 | 51847 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:51:20.102312088 CEST | 138 | 138 | 192.168.2.6 | 192.168.2.255 |
Apr 15, 2025 17:51:21.143721104 CEST | 53 | 61263 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:51:21.317380905 CEST | 53 | 63444 | 1.1.1.1 | 192.168.2.6 |
Apr 15, 2025 17:51:24.188086987 CEST | 53 | 61532 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 15, 2025 17:50:25.861537933 CEST | 192.168.2.6 | 1.1.1.1 | 0x7a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 15, 2025 17:50:25.861989975 CEST | 192.168.2.6 | 1.1.1.1 | 0x17f7 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 15, 2025 17:50:26.960580111 CEST | 192.168.2.6 | 1.1.1.1 | 0xd27 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 15, 2025 17:50:26.960855007 CEST | 192.168.2.6 | 1.1.1.1 | 0x29f | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 15, 2025 17:50:28.439471006 CEST | 192.168.2.6 | 1.1.1.1 | 0x17fe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 15, 2025 17:50:28.439652920 CEST | 192.168.2.6 | 1.1.1.1 | 0xa295 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 15, 2025 17:50:25.968899965 CEST | 1.1.1.1 | 192.168.2.6 | 0x7a0 | No error (0) | 173.194.219.99 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:25.968899965 CEST | 1.1.1.1 | 192.168.2.6 | 0x7a0 | No error (0) | 173.194.219.105 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:25.968899965 CEST | 1.1.1.1 | 192.168.2.6 | 0x7a0 | No error (0) | 173.194.219.104 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:25.968899965 CEST | 1.1.1.1 | 192.168.2.6 | 0x7a0 | No error (0) | 173.194.219.103 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:25.968899965 CEST | 1.1.1.1 | 192.168.2.6 | 0x7a0 | No error (0) | 173.194.219.147 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:25.968899965 CEST | 1.1.1.1 | 192.168.2.6 | 0x7a0 | No error (0) | 173.194.219.106 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:25.968974113 CEST | 1.1.1.1 | 192.168.2.6 | 0x17f7 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 15, 2025 17:50:27.105015039 CEST | 1.1.1.1 | 192.168.2.6 | 0xd27 | No error (0) | mindlabs.activehosted.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.105015039 CEST | 1.1.1.1 | 192.168.2.6 | 0xd27 | No error (0) | 104.17.203.31 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.105015039 CEST | 1.1.1.1 | 192.168.2.6 | 0xd27 | No error (0) | 104.17.206.31 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.105015039 CEST | 1.1.1.1 | 192.168.2.6 | 0xd27 | No error (0) | 104.17.204.31 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.105015039 CEST | 1.1.1.1 | 192.168.2.6 | 0xd27 | No error (0) | 104.17.205.31 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.105015039 CEST | 1.1.1.1 | 192.168.2.6 | 0xd27 | No error (0) | 104.17.202.31 | A (IP address) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.117839098 CEST | 1.1.1.1 | 192.168.2.6 | 0x29f | No error (0) | mindlabs.activehosted.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 15, 2025 17:50:27.117839098 CEST | 1.1.1.1 | 192.168.2.6 | 0x29f | No error (0) | 65 | IN (0x0001) | false | |||
Apr 15, 2025 17:50:28.564438105 CEST | 1.1.1.1 | 192.168.2.6 | 0x17fe | No error (0) | 31.172.83.250 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49705 | 142.250.9.94 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 15, 2025 17:50:34.280260086 CEST | 200 | OUT | |
Apr 15, 2025 17:50:34.388828039 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49699 | 104.17.203.31 | 443 | 2788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-15 15:50:27 UTC | 754 | OUT | |
2025-04-15 15:50:28 UTC | 1169 | IN | |
2025-04-15 15:50:28 UTC | 425 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49700 | 31.172.83.250 | 443 | 2788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-15 15:50:28 UTC | 1051 | OUT | |
2025-04-15 15:50:29 UTC | 171 | IN | |
2025-04-15 15:50:29 UTC | 588 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49701 | 31.172.83.250 | 443 | 2788 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-15 15:50:30 UTC | 992 | OUT | |
2025-04-15 15:50:30 UTC | 159 | IN | |
2025-04-15 15:50:30 UTC | 564 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 2 |
Start time: | 11:50:15 |
Start date: | 15/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 11:50:20 |
Start date: | 15/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 11 |
Start time: | 11:50:26 |
Start date: | 15/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |