Windows
Analysis Report
https://varendot.com/lenCatch.txt
Overview
Detection
Score: | 20 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1844 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 4104 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --subpr oc-heap-pr ofiling -- field-tria l-handle=2 020,i,3426 2272178707 26310,1253 7377119968 816039,262 144 --disa ble-featur es=Optimiz ationGuide ModelDownl oading,Opt imizationH ints,Optim izationHin tsFetching ,Optimizat ionTargetP rediction --variatio ns-seed-ve rsion=2025 0306-18300 4.429000 - -mojo-plat form-chann el-handle= 2072 /pref etch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6848 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://varen dot.com/le nCatch.txt " MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
varendot.b-cdn.net | 185.152.66.243 | true | false | unknown | |
www.google.com | 74.125.136.104 | true | false | high | |
bunnyfonts.b-cdn.net | 185.152.66.243 | true | false | high | |
fonts.bunny.net | unknown | unknown | false | high | |
varendot.com | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
true | unknown | ||
true |
| unknown | |
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.152.66.243 | varendot.b-cdn.net | Slovakia (SLOVAK Republic) | 60068 | CDN77GB | false | |
74.125.136.104 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1666827 |
Start date and time: | 2025-04-17 00:50:27 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://varendot.com/lenCatch.txt |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.win@21/10@6/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.15.94, 64. 233.177.113, 64.233.177.139, 6 4.233.177.100, 64.233.177.101, 64.233.177.102, 64.233.177.13 8, 108.177.122.113, 108.177.12 2.139, 108.177.122.102, 108.17 7.122.101, 108.177.122.100, 10 8.177.122.138, 64.233.185.84, 142.250.9.139, 142.250.9.100, 142.250.9.101, 142.250.9.102, 142.250.9.138, 142.250.9.113, 173.194.219.101, 173.194.219.1 02, 173.194.219.138, 173.194.2 19.100, 173.194.219.139, 173.1 94.219.113, 64.233.176.139, 64 .233.176.138, 64.233.176.102, 64.233.176.113, 64.233.176.100 , 64.233.176.101, 23.4.43.62, 199.232.210.172, 74.125.136.10 0, 74.125.136.101, 74.125.136. 138, 74.125.136.139, 74.125.13 6.113, 74.125.136.102, 74.125. 138.139, 74.125.138.113, 74.12 5.138.101, 74.125.138.102, 74. 125.138.100, 74.125.138.138, 7 4.125.21.94, 172.217.215.94, 2 3.76.34.6, 20.12.23.50 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fe3cr.deliv ery.mp.microsoft.com, clients2 .google.com, edgedl.me.gvt1.co m, redirector.gvt1.com, ocsp.d igicert.com, update.googleapis .com, clients.l.google.com, c. pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//varendot.com/lenCatch.txt
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9075 |
Entropy (8bit): | 5.3725868105242895 |
Encrypted: | false |
SSDEEP: | 192:cS3aqkFbptPAqjxRP8SDQl03rOkFbptPAqjsJmVEDtum3IekFbptPAqjP9xutYNQ:B3kvdPbKkvdkf1kvdBoYe |
MD5: | 25D358C2F8ACD93C6A898A37C2FDD5EE |
SHA1: | 7F834241360EC76FAB72B3BF108B416CFF5E2135 |
SHA-256: | 17497B854752912CCFD39D98EB1984372AE7A42A9DC8C49F832644CD7FB50B2D |
SHA-512: | 09CE80C5B56D1D3BCDF2AC0057E7797DE7BE07FCA7CFC6B81D99CBD4758B4A71A0D959738A13BAD9E3268CA0582DED5CD4A8373C14EFAD8EA97751673D8E4F9C |
Malicious: | false |
Reputation: | low |
URL: | "https://fonts.bunny.net/css?family=Rubik:300,400,500" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 678 |
Entropy (8bit): | 5.1435496014689335 |
Encrypted: | false |
SSDEEP: | 12:kxRVrFjJRrZciWsGXmLFSHDSsz1X8lFamZ6k3hA1ZSZcsLvZ0mzegCoRwFjJUzk:kTlROi+WLojSw1MXlZ6M8QcslLCUzk |
MD5: | 0E3BDE19A08632F2E893BC2A835598BC |
SHA1: | 0BB50CBDED2D95B600B7437AD58AE8189C2A489B |
SHA-256: | F62504ABBB867B0D53B4D90D746313621819F2C5D39CEAB4695AC2B0EF8CF223 |
SHA-512: | 64048720AA563B780C491DA2C7C484D418DB508FB56B5D54A6AE9FD999308A96B75FD0149CE2E6459E7DF973F2535FE7D0CEAFDA79E5B48D96595999D575406D |
Malicious: | false |
Reputation: | low |
URL: | https://varendot.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 19140 |
Entropy (8bit): | 7.98695599617926 |
Encrypted: | false |
SSDEEP: | 384:oeibUjjYNnNrgPt2WA8klRZjFePRuJmd6Poy5MudXGA4heWhWYMnM9:o/gjMNrgPt2WAjlr8JaAy5MKXOeuW/o |
MD5: | 9D91C6D154DED95055BA9D8D8CD653C3 |
SHA1: | 9170307012D60109548247CE761FB5D71A45BEB2 |
SHA-256: | 7F9EA3A91849752F729CF003B4839B162DB15E3BCB57A4DD8FB2533FAB377AAD |
SHA-512: | 3411FE27CCC1E3F0F64307BEB9643A942530482ACFACB1F9ECC4EF27C23CB735024EAC0D5F87650CD8F18076C85362FF6FE2F8BE71B17516CF68B664BD55CC19 |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.bunny.net/rubik/files/rubik-latin-500-normal.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17556 |
Entropy (8bit): | 7.985973640781479 |
Encrypted: | false |
SSDEEP: | 384:IAWAX7otodyzgA8e1fZBmtpUaXovcAgVdXEIlO75sQHTkYmjxYPH+aVS:S64idB3Eu9EoK5lTkYoito |
MD5: | C26CC4BC55F4CC38E588B28BC6E8559D |
SHA1: | 662E36ABFDFA041420061CE216CE895E097655C1 |
SHA-256: | D447E3DDA790BF9638B928B14C0783BE54E5C8BB796E0F1D91DD6EE2E00351C0 |
SHA-512: | 7F7A5D84AC7740543A016D14ADFCBF2FDED8555B16C50782F47F7A9DF2E456EF73830101006C5330E235DF539A71758C11AEE34F8DAD398CDE69CB8CA55F2CFD |
Malicious: | false |
Reputation: | low |
URL: | https://fonts.bunny.net/rubik/files/rubik-latin-300-normal.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 678 |
Entropy (8bit): | 5.1435496014689335 |
Encrypted: | false |
SSDEEP: | 12:kxRVrFjJRrZciWsGXmLFSHDSsz1X8lFamZ6k3hA1ZSZcsLvZ0mzegCoRwFjJUzk:kTlROi+WLojSw1MXlZ6M8QcslLCUzk |
MD5: | 0E3BDE19A08632F2E893BC2A835598BC |
SHA1: | 0BB50CBDED2D95B600B7437AD58AE8189C2A489B |
SHA-256: | F62504ABBB867B0D53B4D90D746313621819F2C5D39CEAB4695AC2B0EF8CF223 |
SHA-512: | 64048720AA563B780C491DA2C7C484D418DB508FB56B5D54A6AE9FD999308A96B75FD0149CE2E6459E7DF973F2535FE7D0CEAFDA79E5B48D96595999D575406D |
Malicious: | false |
Reputation: | low |
URL: | https://varendot.com/lenCatch.txt |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 111
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 17, 2025 00:51:20.097090006 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 17, 2025 00:51:25.812915087 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:26.268976927 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:26.923047066 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:28.133686066 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:29.815500975 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 17, 2025 00:51:30.550040007 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:31.973433971 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:31.973481894 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:31.973726034 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:31.973859072 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:31.973865986 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:32.199954987 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:32.200022936 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:32.201153994 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:32.201164961 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:32.201399088 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:32.241276026 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:32.963757038 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:32.963820934 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:32.963907003 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:32.964132071 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:32.964257956 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:32.964272022 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:32.964277029 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:32.964358091 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:32.964478016 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:32.964519024 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.188491106 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.188594103 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.189593077 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.189625025 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.189896107 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.190326929 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.191035986 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.191104889 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.191972017 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.191982985 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.192343950 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.236280918 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.237415075 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.614526987 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.614667892 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.614722013 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.619023085 CEST | 49727 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.619050026 CEST | 443 | 49727 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.772877932 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.772888899 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.773072958 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.773175955 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.773189068 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.992733955 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.992799044 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.997214079 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:33.997221947 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.997473001 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:33.997720003 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.040275097 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.197829008 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.220051050 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.220112085 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.220132113 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.220143080 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.220185041 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.220247030 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.220419884 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.220592022 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.221896887 CEST | 49730 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.221905947 CEST | 443 | 49730 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.245913029 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.245954037 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.246052980 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.246397018 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.246404886 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.246484995 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.246840000 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.246855974 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.246995926 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.247008085 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.247137070 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.288311005 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.468468904 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.468533039 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.469306946 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.469316959 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.469521046 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.469532013 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.469575882 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.470046043 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.470050097 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.470155001 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.470361948 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.470643044 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.516273022 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.516288042 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.567684889 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.567858934 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.567909956 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.568460941 CEST | 49726 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.568476915 CEST | 443 | 49726 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.570368052 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:34.681969881 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.727705002 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.727726936 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.727797985 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.727823973 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.727869987 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.733545065 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.733573914 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.733593941 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.733630896 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.733644962 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.733664036 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.733702898 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.733710051 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.733720064 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.733767986 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.734889984 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.734972954 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.734977961 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.735019922 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.742877960 CEST | 49731 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.742891073 CEST | 443 | 49731 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.748081923 CEST | 49732 | 443 | 192.168.2.4 | 185.152.66.243 |
Apr 17, 2025 00:51:34.748089075 CEST | 443 | 49732 | 185.152.66.243 | 192.168.2.4 |
Apr 17, 2025 00:51:34.884490967 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:35.353276014 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:35.493863106 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:36.697007895 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:38.655090094 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.658293962 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.658334970 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.776895046 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.778146029 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.778160095 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.778215885 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.778835058 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.780427933 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.780440092 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.782437086 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.782449961 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.782494068 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.782516956 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.787044048 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.901521921 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.909869909 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.911997080 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.912010908 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 00:51:38.912058115 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 00:51:38.916083097 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:38.916351080 CEST | 49735 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:38.916393995 CEST | 443 | 49735 | 204.79.197.222 | 192.168.2.4 |
Apr 17, 2025 00:51:38.916491032 CEST | 49735 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:38.916727066 CEST | 49735 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:38.916740894 CEST | 443 | 49735 | 204.79.197.222 | 192.168.2.4 |
Apr 17, 2025 00:51:39.112293005 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:39.161897898 CEST | 49736 | 80 | 192.168.2.4 | 64.233.185.94 |
Apr 17, 2025 00:51:39.221709013 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:39.260453939 CEST | 443 | 49735 | 204.79.197.222 | 192.168.2.4 |
Apr 17, 2025 00:51:39.260528088 CEST | 49735 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:39.271667957 CEST | 80 | 49736 | 64.233.185.94 | 192.168.2.4 |
Apr 17, 2025 00:51:39.271735907 CEST | 49736 | 80 | 192.168.2.4 | 64.233.185.94 |
Apr 17, 2025 00:51:39.271889925 CEST | 49736 | 80 | 192.168.2.4 | 64.233.185.94 |
Apr 17, 2025 00:51:39.380477905 CEST | 80 | 49736 | 64.233.185.94 | 192.168.2.4 |
Apr 17, 2025 00:51:39.380880117 CEST | 80 | 49736 | 64.233.185.94 | 192.168.2.4 |
Apr 17, 2025 00:51:39.424810886 CEST | 49736 | 80 | 192.168.2.4 | 64.233.185.94 |
Apr 17, 2025 00:51:39.831075907 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:41.034672976 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:42.214823008 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:42.214890957 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:42.214948893 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:42.808988094 CEST | 49725 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:51:42.809034109 CEST | 443 | 49725 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:51:43.447344065 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:43.916106939 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:44.959625006 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 00:51:48.253985882 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:51:53.517925024 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 00:51:57.855324030 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 00:52:31.925987959 CEST | 49743 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:52:31.926042080 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:52:31.926147938 CEST | 49743 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:52:31.926279068 CEST | 49743 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:52:31.926287889 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:52:32.143585920 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:52:32.144207954 CEST | 49743 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:52:32.144259930 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:52:39.706371069 CEST | 49736 | 80 | 192.168.2.4 | 64.233.185.94 |
Apr 17, 2025 00:52:39.812654018 CEST | 80 | 49736 | 64.233.185.94 | 192.168.2.4 |
Apr 17, 2025 00:52:39.812699080 CEST | 49736 | 80 | 192.168.2.4 | 64.233.185.94 |
Apr 17, 2025 00:52:42.145988941 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:52:42.146056890 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Apr 17, 2025 00:52:42.146188974 CEST | 49743 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:52:42.802202940 CEST | 49743 | 443 | 192.168.2.4 | 74.125.136.104 |
Apr 17, 2025 00:52:42.802231073 CEST | 443 | 49743 | 74.125.136.104 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 17, 2025 00:51:27.585798979 CEST | 53 | 54804 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:27.684467077 CEST | 53 | 58126 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:28.508654118 CEST | 53 | 54351 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:28.685575008 CEST | 53 | 65075 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:31.863578081 CEST | 52260 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 00:51:31.863756895 CEST | 63236 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 00:51:31.972299099 CEST | 53 | 63236 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:31.972321987 CEST | 53 | 52260 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:32.847743988 CEST | 49468 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 00:51:32.848098993 CEST | 63193 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 00:51:32.960640907 CEST | 53 | 49468 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:32.963197947 CEST | 53 | 63193 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:33.664607048 CEST | 57456 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 00:51:33.664815903 CEST | 64754 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 00:51:33.772062063 CEST | 53 | 57456 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:33.772105932 CEST | 53 | 64754 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:51:45.762425900 CEST | 53 | 49753 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:52:04.471033096 CEST | 53 | 57125 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:52:27.277014971 CEST | 53 | 63824 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:52:27.439865112 CEST | 53 | 49594 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:52:30.361227036 CEST | 53 | 56106 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 00:52:34.119594097 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 17, 2025 00:51:31.863578081 CEST | 192.168.2.4 | 1.1.1.1 | 0x94c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 00:51:31.863756895 CEST | 192.168.2.4 | 1.1.1.1 | 0x8781 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 00:51:32.847743988 CEST | 192.168.2.4 | 1.1.1.1 | 0x9762 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 00:51:32.848098993 CEST | 192.168.2.4 | 1.1.1.1 | 0x5d7a | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 00:51:33.664607048 CEST | 192.168.2.4 | 1.1.1.1 | 0x4d89 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 00:51:33.664815903 CEST | 192.168.2.4 | 1.1.1.1 | 0xe64b | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 17, 2025 00:51:31.972299099 CEST | 1.1.1.1 | 192.168.2.4 | 0x8781 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 17, 2025 00:51:31.972321987 CEST | 1.1.1.1 | 192.168.2.4 | 0x94c7 | No error (0) | 74.125.136.104 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:31.972321987 CEST | 1.1.1.1 | 192.168.2.4 | 0x94c7 | No error (0) | 74.125.136.105 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:31.972321987 CEST | 1.1.1.1 | 192.168.2.4 | 0x94c7 | No error (0) | 74.125.136.147 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:31.972321987 CEST | 1.1.1.1 | 192.168.2.4 | 0x94c7 | No error (0) | 74.125.136.99 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:31.972321987 CEST | 1.1.1.1 | 192.168.2.4 | 0x94c7 | No error (0) | 74.125.136.106 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:31.972321987 CEST | 1.1.1.1 | 192.168.2.4 | 0x94c7 | No error (0) | 74.125.136.103 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:32.960640907 CEST | 1.1.1.1 | 192.168.2.4 | 0x9762 | No error (0) | varendot.b-cdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:32.960640907 CEST | 1.1.1.1 | 192.168.2.4 | 0x9762 | No error (0) | 185.152.66.243 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:32.963197947 CEST | 1.1.1.1 | 192.168.2.4 | 0x5d7a | No error (0) | varendot.b-cdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:33.772062063 CEST | 1.1.1.1 | 192.168.2.4 | 0x4d89 | No error (0) | bunnyfonts.b-cdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:33.772062063 CEST | 1.1.1.1 | 192.168.2.4 | 0x4d89 | No error (0) | 185.152.66.243 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 00:51:33.772105932 CEST | 1.1.1.1 | 192.168.2.4 | 0xe64b | No error (0) | bunnyfonts.b-cdn.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 64.233.185.94 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 17, 2025 00:51:39.271889925 CEST | 200 | OUT | |
Apr 17, 2025 00:51:39.380880117 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49727 | 185.152.66.243 | 443 | 4104 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-16 22:51:33 UTC | 674 | OUT | |
2025-04-16 22:51:33 UTC | 601 | IN | |
2025-04-16 22:51:33 UTC | 685 | IN | |
2025-04-16 22:51:33 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49730 | 185.152.66.243 | 443 | 4104 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-16 22:51:33 UTC | 594 | OUT | |
2025-04-16 22:51:34 UTC | 938 | IN | |
2025-04-16 22:51:34 UTC | 9083 | IN | |
2025-04-16 22:51:34 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49726 | 185.152.66.243 | 443 | 4104 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-16 22:51:34 UTC | 599 | OUT | |
2025-04-16 22:51:34 UTC | 602 | IN | |
2025-04-16 22:51:34 UTC | 685 | IN | |
2025-04-16 22:51:34 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49731 | 185.152.66.243 | 443 | 4104 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-16 22:51:34 UTC | 614 | OUT | |
2025-04-16 22:51:34 UTC | 990 | IN | |
2025-04-16 22:51:34 UTC | 16384 | IN | |
2025-04-16 22:51:34 UTC | 2756 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49732 | 185.152.66.243 | 443 | 4104 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-16 22:51:34 UTC | 614 | OUT | |
2025-04-16 22:51:34 UTC | 990 | IN | |
2025-04-16 22:51:34 UTC | 15394 | IN | |
2025-04-16 22:51:34 UTC | 2162 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 18:51:22 |
Start date: | 16/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 18:51:25 |
Start date: | 16/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 18:51:31 |
Start date: | 16/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |