Windows
Analysis Report
https://ddei5-0-ctp.trendmicro.com/wis/clicktime/v1/query?url=https%3a%2f%2fsq0uq.mjt.lu%2flnk%2fAbsAACej50gAAAAAAAAAA9sYsioAAYKJnZIAAAAAAC8AFgBn_tm3AcQFOuePTgG1NwZJ7SjTGAArHGw%2f1%2fE90PwWou8HNiapWtPKPg0A%2faHR0cHM6Ly91cmxkZWZlbnNlLnByb29mcG9pbnQuY29tL3YyL3VybD91PWh0dHBzLTNBX19zaXRlLnRpbWhlaW5yaW
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5452 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5944 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2192,i ,134054060 0467155085 4,89170970 9620560858 2,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2312 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7036 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://ddei5 -0-ctp.tre ndmicro.co m/wis/clic ktime/v1/q uery?url=h ttps%3a%2f %2fsq0uq.m jt.lu%2fln k%2fAbsAAC ej50gAAAAA AAAAA9sYsi oAAYKJnZIA AAAAAC8AFg Bn%5ftm3Ac QFOuePTgG1 NwZJ7SjTGA ArHGw%2f1% 2fE90PwWou 8HNiapWtPK Pg0A%2faHR 0cHM6Ly91c mxkZWZlbnN lLnByb29mc G9pbnQuY29 tL3YyL3Vyb D91PWh0dHB zLTNBX19za XRlLnRpbWh laW5yaWNob GF3LmNvbSZ kPUR3TUZBd yZjPWV1R1p zdGNhVERsb HZpbUVOOGI 3alhyd3FPZ i12NUFfQ2R wZ25WZmlpT U0mcj1VVnR weTVUX3F6R 2xBLW12N0N iaWVXV1Q4b kZWZG5Bdmk xeVJESlZ1Y m5zdDdZak0 4NDItN1paL TVsQUFWV0V IJm09ci1xa E5BU1FvLXh sQXV2MnFvZ 0FHdWRIVzc 0d25EMVktT FB1Mm1mRUt mTHEyM0JGN UFLVHdJRXR YRWpYdU9WV SZzPWJScmx oeVBvMkhiU UdpbUlrRVp ZdFYyaW9JT 29xYUVTZFd xMHFIZS10b zQmZT0&umi d=0E76A6CD -32D9-6C06 -B3DF-BE1D 7AF13E80&a uth=9bbf93 0103c38bc7 dcedd0dacc 9bedf6609c 7415-23057 d803de858b 3113fecf5a cbefbb3578 b4d1c" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: | ||
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ctp-proxy.prod.wrs.trendmicro.com | 35.163.45.223 | true | false | high | |
site.timheinrichlaw.com | 172.233.49.32 | true | false | unknown | |
tesla.com | 2.18.50.207 | true | false | high | |
urldefense.com | 52.204.90.22 | true | false | high | |
www.google.com | 74.125.21.103 | true | false | high | |
sq0uq.mjt.lu | 35.241.186.140 | true | false | high | |
urldefense.proofpoint.com | unknown | unknown | false | high | |
ddei5-0-ctp.trendmicro.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false |
| unknown | |
false | unknown | ||
false |
| unknown | |
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.233.49.32 | site.timheinrichlaw.com | United States | 20940 | AKAMAI-ASN1EU | false | |
74.125.21.103 | www.google.com | United States | 15169 | GOOGLEUS | false | |
35.241.186.140 | sq0uq.mjt.lu | United States | 15169 | GOOGLEUS | false | |
2.18.50.207 | tesla.com | European Union | 33905 | AKAMAI-AMSEU | false | |
52.204.90.22 | urldefense.com | United States | 14618 | AMAZON-AESUS | false | |
35.163.45.223 | ctp-proxy.prod.wrs.trendmicro.com | United States | 16509 | AMAZON-02US | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1667161 |
Start date and time: | 2025-04-17 08:12:31 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 33s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://ddei5-0-ctp.trendmicro.com/wis/clicktime/v1/query?url=https%3a%2f%2fsq0uq.mjt.lu%2flnk%2fAbsAACej50gAAAAAAAAAA9sYsioAAYKJnZIAAAAAAC8AFgBn_tm3AcQFOuePTgG1NwZJ7SjTGAArHGw%2f1%2fE90PwWou8HNiapWtPKPg0A%2faHR0cHM6Ly91cmxkZWZlbnNlLnByb29mcG9pbnQuY29tL3YyL3VybD91PWh0dHBzLTNBX19zaXRlLnRpbWhlaW5yaWNobGF3LmNvbSZkPUR3TUZBdyZjPWV1R1pzdGNhVERsbHZpbUVOOGI3alhyd3FPZi12NUFfQ2RwZ25WZmlpTU0mcj1VVnRweTVUX3F6R2xBLW12N0NiaWVXV1Q4bkZWZG5BdmkxeVJESlZ1Ym5zdDdZak04NDItN1paLTVsQUFWV0VIJm09ci1xaE5BU1FvLXhsQXV2MnFvZ0FHdWRIVzc0d25EMVktTFB1Mm1mRUtmTHEyM0JGNUFLVHdJRXRYRWpYdU9WVSZzPWJScmxoeVBvMkhiUUdpbUlrRVpZdFYyaW9JT29xYUVTZFdxMHFIZS10bzQmZT0&umid=0E76A6CD-32D9-6C06-B3DF-BE1D7AF13E80&auth=9bbf930103c38bc7dcedd0dacc9bedf6609c7415-23057d803de858b3113fecf5acbefbb3578b4d1c |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@21/0@12/7 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 74.125.136.139, 74 .125.136.100, 74.125.136.101, 74.125.136.138, 74.125.136.113 , 74.125.136.102, 64.233.185.8 4, 64.233.185.139, 64.233.185. 102, 64.233.185.113, 64.233.18 5.100, 64.233.185.101, 64.233. 185.138, 108.177.122.94, 142.2 50.105.100, 142.250.105.138, 1 42.250.105.139, 142.250.105.11 3, 142.250.105.101, 142.250.10 5.102, 64.233.177.102, 64.233. 177.139, 64.233.177.101, 64.23 3.177.100, 64.233.177.138, 64. 233.177.113, 74.125.138.100, 7 4.125.138.102, 74.125.138.138, 74.125.138.113, 74.125.138.10 1, 74.125.138.139, 23.4.43.62, 199.232.214.172, 173.194.219. 139, 173.194.219.138, 173.194. 219.102, 173.194.219.113, 173. 194.219.100, 173.194.219.101, 74.125.21.139, 74.125.21.100, 74.125.21.101, 74.125.21.102, 74.125.21.113, 74.125.21.138, 172.253.124.102, 172.253.124.1 39, 172.253.124.100, 172.253.1 24.101, 172.253.124.138, 172.2 53.124.113, 64.233.185.94, 142 .251.15.102, 142.251.15.100, 1 42.251.15.139, 142.251.15.101, 142.251.15.138, 142.251.15.11 3, 142.250.9.102, 142.250.9.10 1, 1 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fs.microsoft.com, accou nts.google.com, slscr.update.m icrosoft.com, ctldl.windowsupd ate.com, clientservices.google apis.com, fe3cr.delivery.mp.mi crosoft.com, clients2.google.c om, edgedl.me.gvt1.com, redire ctor.gvt1.com, ocsp.digicert.c om, update.googleapis.com, cli ents.l.google.com, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//ddei5-0-ctp.trendmicro.com/w is/clicktime/v1/query?url=http s%3a%2f%2fsq0uq.mjt.lu%2flnk%2 fAbsAACej50gAAAAAAAAAA9sYsioAA YKJnZIAAAAAAC8AFgBn%5ftm3AcQFO uePTgG1NwZJ7SjTGAArHGw%2f1%2fE 90PwWou8HNiapWtPKPg0A%2faHR0cH M6Ly91cmxkZWZlbnNlLnByb29mcG9p bnQuY29tL3YyL3VybD91PWh0dHBzLT NBX19zaXRlLnRpbWhlaW5yaWNobGF3 LmNvbSZkPUR3TUZBdyZjPWV1R1pzdG NhVERsbHZpbUVOOGI3alhyd3FPZi12 NUFfQ2RwZ25WZmlpTU0mcj1VVnRweT VUX3F6R2xBLW12N0NiaWVXV1Q4bkZW ZG5BdmkxeVJESlZ1Ym5zdDdZak04ND ItN1paLTVsQUFWV0VIJm09ci1xaE5B U1FvLXhsQXV2MnFvZ0FHdWRIVzc0d2 5EMVktTFB1Mm1mRUtmTHEyM0JGNUFL VHdJRXRYRWpYdU9WVSZzPWJScmxoeV BvMkhiUUdpbUlrRVpZdFYyaW9JT29x YUVTZFdxMHFIZS10bzQmZT0&um id=0E76A6CD-32D9-6C06-B3DF-BE1 D7AF13E80&auth=9bbf930103c 38bc7dcedd0dacc9bedf6609c7415- 23057d803de858b3113fecf5acbefb b3578b4d1c
Download Network PCAP: filtered – full
- Total Packets: 124
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 17, 2025 08:13:25.541838884 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 17, 2025 08:13:30.303730965 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:30.604353905 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:31.213722944 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:32.448132038 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:34.949018002 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:35.152107000 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 17, 2025 08:13:37.417501926 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:37.417542934 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:37.417653084 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:37.417871952 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:37.417884111 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:37.640060902 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:37.640151024 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:37.641423941 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:37.641441107 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:37.641740084 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:37.682306051 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:38.448681116 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:13:38.751666069 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:13:38.887342930 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:38.887403965 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:38.887528896 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:38.887691975 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:38.887712955 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:38.921600103 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:38.921665907 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:38.921793938 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:38.923351049 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:38.923367023 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.237684011 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.237848043 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:39.274569035 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:39.274601936 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.274887085 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.275055885 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.275120020 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:39.275564909 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:39.275579929 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.275835991 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.276330948 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:39.324270010 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:39.338469982 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:39.354100943 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:13:39.758764982 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:40.557529926 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:13:42.965574026 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:13:43.691164017 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.691540956 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.691540956 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.812299013 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.812796116 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.812834024 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.813555956 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.813594103 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.813911915 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.814490080 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.815722942 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.815761089 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.815793037 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.818980932 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.819072008 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.935230970 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.940041065 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.942301989 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.942313910 CEST | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Apr 17, 2025 08:13:43.942404985 CEST | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 17, 2025 08:13:43.945362091 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:43.945369959 CEST | 49732 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:43.945427895 CEST | 443 | 49732 | 204.79.197.222 | 192.168.2.4 |
Apr 17, 2025 08:13:43.945555925 CEST | 49732 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:43.951502085 CEST | 49732 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:43.951539040 CEST | 443 | 49732 | 204.79.197.222 | 192.168.2.4 |
Apr 17, 2025 08:13:44.155891895 CEST | 49733 | 80 | 192.168.2.4 | 172.253.124.94 |
Apr 17, 2025 08:13:44.245759010 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:44.262089968 CEST | 80 | 49733 | 172.253.124.94 | 192.168.2.4 |
Apr 17, 2025 08:13:44.262290001 CEST | 49733 | 80 | 192.168.2.4 | 172.253.124.94 |
Apr 17, 2025 08:13:44.262365103 CEST | 49733 | 80 | 192.168.2.4 | 172.253.124.94 |
Apr 17, 2025 08:13:44.282481909 CEST | 443 | 49732 | 204.79.197.222 | 192.168.2.4 |
Apr 17, 2025 08:13:44.282565117 CEST | 49732 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:44.368563890 CEST | 80 | 49733 | 172.253.124.94 | 192.168.2.4 |
Apr 17, 2025 08:13:44.369836092 CEST | 80 | 49733 | 172.253.124.94 | 192.168.2.4 |
Apr 17, 2025 08:13:44.420079947 CEST | 49733 | 80 | 192.168.2.4 | 172.253.124.94 |
Apr 17, 2025 08:13:44.575630903 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:44.575853109 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:44.575912952 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:44.576461077 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:44.576483011 CEST | 443 | 49728 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:13:44.576497078 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:44.576529980 CEST | 49728 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:13:44.778856993 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:44.778893948 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:44.778949022 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:44.779155016 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:44.779160976 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:44.857845068 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:45.205490112 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.205550909 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:45.206789017 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:45.206800938 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.207036972 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.207314014 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:45.248265028 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.618050098 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.618226051 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.619474888 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:45.619493008 CEST | 443 | 49735 | 35.241.186.140 | 192.168.2.4 |
Apr 17, 2025 08:13:45.619523048 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:45.619656086 CEST | 49735 | 443 | 192.168.2.4 | 35.241.186.140 |
Apr 17, 2025 08:13:45.732666969 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:45.732717037 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:45.732812881 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:45.733668089 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:45.733690023 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.065319061 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:46.125276089 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.125349998 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:46.126379967 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:46.126394033 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.126686096 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.127237082 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:46.168271065 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.252454996 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.252605915 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.253999949 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:46.254025936 CEST | 443 | 49736 | 52.204.90.22 | 192.168.2.4 |
Apr 17, 2025 08:13:46.254054070 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:46.254964113 CEST | 49736 | 443 | 192.168.2.4 | 52.204.90.22 |
Apr 17, 2025 08:13:46.405807018 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:46.405930996 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:46.406060934 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:46.406266928 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:46.406316996 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:46.826200008 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:46.826277018 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:46.827804089 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:46.827832937 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:46.828078032 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:46.828396082 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:46.876276016 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:47.251396894 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:47.251595974 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:47.251658916 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:47.252933979 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:47.252983093 CEST | 443 | 49738 | 172.233.49.32 | 192.168.2.4 |
Apr 17, 2025 08:13:47.253011942 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:47.253038883 CEST | 49738 | 443 | 192.168.2.4 | 172.233.49.32 |
Apr 17, 2025 08:13:47.377243996 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:13:47.377338886 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:13:47.377473116 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:13:47.377626896 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:13:47.377665997 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:13:47.655313015 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:47.655383110 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:47.655558109 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:47.780286074 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:13:48.135747910 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:13:48.135974884 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:13:48.136883974 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:13:48.136917114 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:13:48.137285948 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:13:48.137866974 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:13:48.184279919 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:13:48.477916002 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:48.597692966 CEST | 49724 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:13:48.597723007 CEST | 443 | 49724 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:13:49.358984947 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 17, 2025 08:13:53.292606115 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:13:57.388047934 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 17, 2025 08:14:02.896945000 CEST | 49680 | 443 | 192.168.2.4 | 204.79.197.222 |
Apr 17, 2025 08:14:24.290663004 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:14:24.290720940 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:14:33.186139107 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:14:33.186177015 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Apr 17, 2025 08:14:37.359755039 CEST | 49744 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:14:37.359812975 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:14:37.359919071 CEST | 49744 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:14:37.360097885 CEST | 49744 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:14:37.360114098 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:14:37.577405930 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:14:37.577760935 CEST | 49744 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:14:37.577835083 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:14:39.276026964 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:14:39.276114941 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:14:39.276216030 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:14:39.600483894 CEST | 49729 | 443 | 192.168.2.4 | 35.163.45.223 |
Apr 17, 2025 08:14:39.600548983 CEST | 443 | 49729 | 35.163.45.223 | 192.168.2.4 |
Apr 17, 2025 08:14:44.716902018 CEST | 49733 | 80 | 192.168.2.4 | 172.253.124.94 |
Apr 17, 2025 08:14:44.823046923 CEST | 80 | 49733 | 172.253.124.94 | 192.168.2.4 |
Apr 17, 2025 08:14:44.823103905 CEST | 49733 | 80 | 192.168.2.4 | 172.253.124.94 |
Apr 17, 2025 08:14:47.583731890 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:14:47.583810091 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:14:47.583893061 CEST | 49744 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:14:47.605226994 CEST | 49744 | 443 | 192.168.2.4 | 74.125.21.103 |
Apr 17, 2025 08:14:47.605272055 CEST | 443 | 49744 | 74.125.21.103 | 192.168.2.4 |
Apr 17, 2025 08:15:15.554852009 CEST | 49708 | 443 | 192.168.2.4 | 52.113.196.254 |
Apr 17, 2025 08:15:18.198369980 CEST | 49739 | 443 | 192.168.2.4 | 2.18.50.207 |
Apr 17, 2025 08:15:18.198394060 CEST | 443 | 49739 | 2.18.50.207 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 17, 2025 08:13:33.706557035 CEST | 53 | 53927 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:33.709846973 CEST | 53 | 63638 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:34.535759926 CEST | 53 | 65331 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:34.738208055 CEST | 53 | 60367 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:37.309441090 CEST | 60936 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:37.310094118 CEST | 57340 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:37.415976048 CEST | 53 | 60936 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:37.416505098 CEST | 53 | 57340 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:38.774641037 CEST | 55917 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:38.774964094 CEST | 58428 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:38.886326075 CEST | 53 | 58428 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:38.886667013 CEST | 53 | 55917 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:44.579756021 CEST | 61773 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:44.580121040 CEST | 53374 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:44.729465008 CEST | 53 | 53374 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:44.778219938 CEST | 53 | 61773 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:45.620708942 CEST | 64577 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:45.620708942 CEST | 54113 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:45.729579926 CEST | 53 | 54113 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:45.731033087 CEST | 53 | 64577 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:46.254807949 CEST | 64602 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:46.254961967 CEST | 50681 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:46.401128054 CEST | 53 | 64602 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:46.405311108 CEST | 53 | 50681 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:47.253757954 CEST | 52925 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:47.253971100 CEST | 57684 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 17, 2025 08:13:47.361462116 CEST | 53 | 52925 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:47.376720905 CEST | 53 | 57684 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:13:51.666939974 CEST | 53 | 62457 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:14:10.549137115 CEST | 53 | 63828 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:14:33.047179937 CEST | 53 | 55446 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:14:33.479281902 CEST | 53 | 52511 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:14:34.275676966 CEST | 53 | 50189 | 1.1.1.1 | 192.168.2.4 |
Apr 17, 2025 08:14:38.143837929 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Apr 17, 2025 08:15:03.149775982 CEST | 53 | 63298 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 17, 2025 08:13:37.309441090 CEST | 192.168.2.4 | 1.1.1.1 | 0xb84b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 08:13:37.310094118 CEST | 192.168.2.4 | 1.1.1.1 | 0x8573 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 08:13:38.774641037 CEST | 192.168.2.4 | 1.1.1.1 | 0x7853 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 08:13:38.774964094 CEST | 192.168.2.4 | 1.1.1.1 | 0x5d26 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 08:13:44.579756021 CEST | 192.168.2.4 | 1.1.1.1 | 0x9edd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 08:13:44.580121040 CEST | 192.168.2.4 | 1.1.1.1 | 0xbc54 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 08:13:45.620708942 CEST | 192.168.2.4 | 1.1.1.1 | 0x4745 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 08:13:45.620708942 CEST | 192.168.2.4 | 1.1.1.1 | 0x5a14 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 08:13:46.254807949 CEST | 192.168.2.4 | 1.1.1.1 | 0xd9b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 08:13:46.254961967 CEST | 192.168.2.4 | 1.1.1.1 | 0xb76a | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 17, 2025 08:13:47.253757954 CEST | 192.168.2.4 | 1.1.1.1 | 0x7f38 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 17, 2025 08:13:47.253971100 CEST | 192.168.2.4 | 1.1.1.1 | 0x1744 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 17, 2025 08:13:37.415976048 CEST | 1.1.1.1 | 192.168.2.4 | 0xb84b | No error (0) | 74.125.21.103 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:37.415976048 CEST | 1.1.1.1 | 192.168.2.4 | 0xb84b | No error (0) | 74.125.21.147 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:37.415976048 CEST | 1.1.1.1 | 192.168.2.4 | 0xb84b | No error (0) | 74.125.21.99 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:37.415976048 CEST | 1.1.1.1 | 192.168.2.4 | 0xb84b | No error (0) | 74.125.21.104 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:37.415976048 CEST | 1.1.1.1 | 192.168.2.4 | 0xb84b | No error (0) | 74.125.21.106 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:37.415976048 CEST | 1.1.1.1 | 192.168.2.4 | 0xb84b | No error (0) | 74.125.21.105 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:37.416505098 CEST | 1.1.1.1 | 192.168.2.4 | 0x8573 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 17, 2025 08:13:38.886326075 CEST | 1.1.1.1 | 192.168.2.4 | 0x5d26 | No error (0) | ctp.wtp.trendmicro.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:38.886326075 CEST | 1.1.1.1 | 192.168.2.4 | 0x5d26 | No error (0) | ctp-proxy.prod.wrs.trendmicro.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:38.886667013 CEST | 1.1.1.1 | 192.168.2.4 | 0x7853 | No error (0) | ctp.wtp.trendmicro.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:38.886667013 CEST | 1.1.1.1 | 192.168.2.4 | 0x7853 | No error (0) | ctp-proxy.prod.wrs.trendmicro.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:38.886667013 CEST | 1.1.1.1 | 192.168.2.4 | 0x7853 | No error (0) | 35.163.45.223 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:38.886667013 CEST | 1.1.1.1 | 192.168.2.4 | 0x7853 | No error (0) | 44.239.11.255 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:38.886667013 CEST | 1.1.1.1 | 192.168.2.4 | 0x7853 | No error (0) | 44.237.245.30 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:44.778219938 CEST | 1.1.1.1 | 192.168.2.4 | 0x9edd | No error (0) | 35.241.186.140 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:45.729579926 CEST | 1.1.1.1 | 192.168.2.4 | 0x5a14 | No error (0) | urldefense.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:45.729579926 CEST | 1.1.1.1 | 192.168.2.4 | 0x5a14 | No error (0) | 52.204.90.22 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:45.729579926 CEST | 1.1.1.1 | 192.168.2.4 | 0x5a14 | No error (0) | 52.71.28.102 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:45.729579926 CEST | 1.1.1.1 | 192.168.2.4 | 0x5a14 | No error (0) | 52.6.56.188 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:45.731033087 CEST | 1.1.1.1 | 192.168.2.4 | 0x4745 | No error (0) | urldefense.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:46.401128054 CEST | 1.1.1.1 | 192.168.2.4 | 0xd9b0 | No error (0) | 172.233.49.32 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.50.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.52.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.55.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.54.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.48.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.51.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.53.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 2.18.49.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 23.40.100.207 | A (IP address) | IN (0x0001) | false | ||
Apr 17, 2025 08:13:47.361462116 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f38 | No error (0) | 23.7.244.207 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49733 | 172.253.124.94 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 17, 2025 08:13:44.262365103 CEST | 200 | OUT | |
Apr 17, 2025 08:13:44.369836092 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49728 | 35.163.45.223 | 443 | 5944 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-17 06:13:39 UTC | 1399 | OUT | |
2025-04-17 06:13:44 UTC | 700 | IN | |
2025-04-17 06:13:44 UTC | 572 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49735 | 35.241.186.140 | 443 | 5944 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-17 06:13:45 UTC | 1190 | OUT | |
2025-04-17 06:13:45 UTC | 465 | IN | |
2025-04-17 06:13:45 UTC | 361 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49736 | 52.204.90.22 | 443 | 5944 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-17 06:13:46 UTC | 955 | OUT | |
2025-04-17 06:13:46 UTC | 359 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49738 | 172.233.49.32 | 443 | 5944 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-17 06:13:46 UTC | 673 | OUT | |
2025-04-17 06:13:47 UTC | 286 | IN | |
2025-04-17 06:13:47 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49739 | 2.18.50.207 | 443 | 5944 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-17 06:13:48 UTC | 659 | OUT |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 02:13:28 |
Start date: | 17/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 02:13:32 |
Start date: | 17/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 7 |
Start time: | 02:13:38 |
Start date: | 17/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |