Windows
Analysis Report
tmpF603.html
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6912 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6396 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2076,i ,112482272 8983117946 1,87731705 2256510258 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion --vari ations-see d-version= 20250306-1 83004.4290 00 --mojo- platform-c hannel-han dle=2176 / prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 7332 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= printing.m ojom.Unsan dboxedPrin tBackendHo st --lang= en-US --se rvice-sand box-type=n one --no-p re-read-ma in-dll --f ield-trial -handle=20 76,i,11248 2272898311 79461,8773 1705225651 0258,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction -- variations -seed-vers ion=202503 06-183004. 429000 --m ojo-platfo rm-channel -handle=31 92 /prefet ch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7548 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "C:\ Users\user \Desktop\t mpF603.htm l" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-04-22T08:57:18.379346+0200 | 2812237 | 1 | Successful Credential Theft Detected | 192.168.2.5 | 49707 | 213.133.104.46 | 443 | TCP |
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Stealing of Sensitive Information
Click to jump to signature section
Phishing |
---|
Source: | File source: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Stealing of Sensitive Information |
---|
Source: | HTTP Parser: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Obfuscated Files or Information | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 192.178.49.164 | true | false | high | |
maxkirschke.de | 213.133.104.46 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false | unknown | ||
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
192.178.49.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
213.133.104.46 | maxkirschke.de | Germany | 24940 | HETZNER-ASDE | false |
IP |
---|
192.168.2.13 |
192.168.2.23 |
192.168.2.14 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1670872 |
Start date and time: | 2025-04-22 08:56:05 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowshtmlcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Power Change |
Sample name: | tmpF603.html |
Detection: | MAL |
Classification: | mal52.phis.winHTML@26/5@6/6 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, W MIADAP.exe, SIHClient.exe, Sgr mBroker.exe, conhost.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 199.232.210.172, 1 42.250.69.3, 142.250.68.238, 1 42.251.2.84, 142.250.69.14, 19 2.178.49.163, 142.250.68.227, 184.29.183.29, 172.202.163.200 , 20.12.23.50 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fs.microsoft.com, accou nts.google.com, slscr.update.m icrosoft.com, ctldl.windowsupd ate.com, clientservices.google apis.com, fe3cr.delivery.mp.mi crosoft.com, c2a9c95e369881c67 228a6591cac2686.clo.footprintd ns.com, ax-ring.msedge.net, cl ients2.google.com, edgedl.me.g vt1.com, redirector.gvt1.com, update.googleapis.com, clients .l.google.com, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found .
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
HETZNER-ASDE | Get hash | malicious | Prometei | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Amadey, LockBit ransomware, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
| ||
Get hash | malicious | Prometei | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1028 |
Entropy (8bit): | 7.338665590494435 |
Encrypted: | false |
SSDEEP: | 24:OJf+I/wOSKR0o0XxDuLHeOWXG4OZ7DAJuLHenX3k8w78aTva3:UfDoOSKRFuERAWZ77a3 |
MD5: | 18F71A68CF6E0C0BE56B84E5FFA2C8EB |
SHA1: | FC4C828ED63EE6951DD353F7B6635DC6EE16DDD0 |
SHA-256: | 3F6E92AEC070642AE9B18ACF4A1F0F987EB679869AD12E6B42ADA0646760EBBE |
SHA-512: | E5EA2FAF79970BC14181DBF596356AE5560C69559167B92F4125C5D8424765B8C758113C45DB3631BEBDC5420B709D6D5C6ED6454B6571ED236354DFFB8BD80D |
Malicious: | false |
Reputation: | low |
URL: | https://maxkirschke.de/wp-content/uploads/2018/10/cropped-IMG_E2822-color_cut-32x32.jpg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 264 |
Entropy (8bit): | 5.114514561937613 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwIgsozEr6VyF02xxdGzsQWrKRVONq8oD:J0+oxBgsozR4F0+dgsQoKLONq8+ |
MD5: | B805897C140E32A87A4356D86931E7BC |
SHA1: | 6404DC3D73F8E675111AB78F67753DFE1920DF20 |
SHA-256: | 5647C473AA4107893DBBF92FEBD1EE05F4A4B3594ED1ECEEF31FEF10E8315BB4 |
SHA-512: | DF85F5616835641DFBAEBC683B48C2DBD1AD4649DC855097AFBE73819101C89CCC3734252084A883EA5AFAF13F825EC251C821ECB5B6F6F5466E83460B3057DB |
Malicious: | false |
Reputation: | low |
URL: | https://maxkirschke.de/po/access.php |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1028 |
Entropy (8bit): | 7.338665590494435 |
Encrypted: | false |
SSDEEP: | 24:OJf+I/wOSKR0o0XxDuLHeOWXG4OZ7DAJuLHenX3k8w78aTva3:UfDoOSKRFuERAWZ77a3 |
MD5: | 18F71A68CF6E0C0BE56B84E5FFA2C8EB |
SHA1: | FC4C828ED63EE6951DD353F7B6635DC6EE16DDD0 |
SHA-256: | 3F6E92AEC070642AE9B18ACF4A1F0F987EB679869AD12E6B42ADA0646760EBBE |
SHA-512: | E5EA2FAF79970BC14181DBF596356AE5560C69559167B92F4125C5D8424765B8C758113C45DB3631BEBDC5420B709D6D5C6ED6454B6571ED236354DFFB8BD80D |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.013945334778745 |
TrID: |
|
File name: | tmpF603.html |
File size: | 59'928 bytes |
MD5: | 485cce7fd35cedac715cdcec93aded83 |
SHA1: | 141b5a43a2be5ebf6a9a5c72d2a3918416ecbfc8 |
SHA256: | 543e1e5587dc5519ad892e61e93cce1a8541baac0804500516239c4cc94f9092 |
SHA512: | 5f75e5775e591e7788f21b9721e0182328d8bc6af8d7138830af9734eaea27d5ab146a06832d1393781d10d5e8e240ebaa49007648a5a488e41546beb8cf5daa |
SSDEEP: | 1536:2L4W7InsqRubnEARMovNOkFaM2CYUjYO9LPdF7yG5Xh4G:2L4Wcnc1vAkF/2pUjrcG5XZ |
TLSH: | FC43C0775301280D2DF58D79C40273887F2A9A835C1D2B46B6EC85DEDA8D6BCC760D9D |
File Content Preview: | <html>..<title>m.s - onefortyone.com</title>..<meta name="viewport" content="width=device-width, initial-scale=1">..<style>button:hover {opacity: 0.8;}@keyframes animatezoom {from {transform: scale(0)}to {transform: scale(1)}}</style>..</head><body style= |
Download Network PCAP: filtered – full
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-04-22T08:57:18.379346+0200 | 2812237 | ETPRO PHISHING Possible Successful Generic Phish July 28 | 1 | 192.168.2.5 | 49707 | 213.133.104.46 | 443 | TCP |
- Total Packets: 55
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 08:56:51.715817928 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 08:56:56.036997080 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:56:56.341191053 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:56:56.528655052 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 08:56:56.951083899 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:56:58.153634071 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:57:00.700531006 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:57:04.750845909 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:04.750884056 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:04.750977993 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:04.751173019 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:04.751188993 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:05.069816113 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:05.069991112 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:05.071229935 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:05.071247101 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:05.071547985 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:05.122283936 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:05.512876987 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:57:06.134953022 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 08:57:15.054066896 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:15.054133892 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:15.054265976 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:15.123095036 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 08:57:15.468115091 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:57:15.468147993 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:57:16.348537922 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 22, 2025 08:57:16.348572969 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 22, 2025 08:57:17.255337954 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.255392075 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.255476952 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.255759954 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.255800009 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.255856991 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.255918026 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.255937099 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.256011009 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.256026983 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.351963043 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 08:57:17.351991892 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 08:57:17.352104902 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 08:57:17.352406025 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 08:57:17.352421045 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 08:57:17.795047045 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 08:57:17.795130968 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 08:57:17.824368954 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.824439049 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.824480057 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.824567080 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.825701952 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.825707912 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.826004982 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.826040983 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.826052904 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.826328039 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.826482058 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:17.872282982 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:17.873573065 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:18.379367113 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:18.379472971 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:18.379699945 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:18.380295038 CEST | 49707 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:18.380306959 CEST | 443 | 49707 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:18.485913038 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:18.528280973 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:19.420093060 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:19.420192003 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:19.423088074 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:19.492866039 CEST | 49706 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:19.492885113 CEST | 443 | 49706 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:19.497540951 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:19.497565031 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:19.497636080 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:19.498919964 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:19.498940945 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.068133116 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.068552971 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.068572044 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.068943024 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.068948984 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.638076067 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.638164043 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.638245106 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.639679909 CEST | 49709 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.639694929 CEST | 443 | 49709 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.788894892 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.788937092 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:20.789021015 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.789222956 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:20.789239883 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.361211061 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.361350060 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:21.361946106 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:21.361953974 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.362198114 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.362504005 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:21.408262968 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.921683073 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.921766043 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:57:21.921827078 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:21.923209906 CEST | 49710 | 443 | 192.168.2.5 | 213.133.104.46 |
Apr 22, 2025 08:57:21.923223972 CEST | 443 | 49710 | 213.133.104.46 | 192.168.2.5 |
Apr 22, 2025 08:58:04.671191931 CEST | 49715 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:58:04.671240091 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:04.671323061 CEST | 49715 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:58:04.671475887 CEST | 49715 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:58:04.671492100 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:04.986043930 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:04.986388922 CEST | 49715 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:58:04.986412048 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:14.991134882 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:14.991194010 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:14.991244078 CEST | 49715 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:58:15.469871998 CEST | 49715 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:58:15.469908953 CEST | 443 | 49715 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:58:33.404093027 CEST | 49682 | 443 | 192.168.2.5 | 150.171.28.10 |
Apr 22, 2025 08:59:04.735862970 CEST | 49721 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:59:04.735913992 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:04.735997915 CEST | 49721 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:59:04.737190962 CEST | 49721 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:59:04.737204075 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:05.050612926 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:05.050971985 CEST | 49721 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:59:05.051007986 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:15.094245911 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:15.094309092 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:15.094387054 CEST | 49721 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:59:15.468801975 CEST | 49721 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 08:59:15.468836069 CEST | 443 | 49721 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 08:59:26.244426966 CEST | 443 | 49708 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 08:59:26.244636059 CEST | 49708 | 443 | 192.168.2.5 | 150.171.27.254 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 08:57:00.312686920 CEST | 53 | 53198 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:00.442605019 CEST | 53 | 58827 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:01.470520973 CEST | 53 | 52415 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:04.608064890 CEST | 64259 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 08:57:04.608064890 CEST | 64089 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 08:57:04.749600887 CEST | 53 | 64259 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:04.749614954 CEST | 53 | 64089 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:17.101794958 CEST | 62627 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 08:57:17.101902962 CEST | 57600 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 08:57:17.254575968 CEST | 53 | 57600 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:17.254590988 CEST | 53 | 62627 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:18.421538115 CEST | 53 | 61866 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:20.646157980 CEST | 60957 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 08:57:20.646327972 CEST | 57532 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 08:57:20.786983013 CEST | 53 | 60957 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:20.788328886 CEST | 53 | 57532 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:37.233913898 CEST | 53 | 56702 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:57:58.831536055 CEST | 138 | 138 | 192.168.2.5 | 192.168.2.255 |
Apr 22, 2025 08:58:00.069673061 CEST | 53 | 65217 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:58:00.076292992 CEST | 53 | 55625 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:58:03.330229044 CEST | 53 | 60009 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:58:30.516946077 CEST | 53 | 53596 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 08:59:16.238368988 CEST | 53 | 49173 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 22, 2025 08:57:04.608064890 CEST | 192.168.2.5 | 1.1.1.1 | 0xbeaa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 08:57:04.608064890 CEST | 192.168.2.5 | 1.1.1.1 | 0x771c | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 08:57:17.101794958 CEST | 192.168.2.5 | 1.1.1.1 | 0xf0b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 08:57:17.101902962 CEST | 192.168.2.5 | 1.1.1.1 | 0x1dcf | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 08:57:20.646157980 CEST | 192.168.2.5 | 1.1.1.1 | 0xc4d4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 08:57:20.646327972 CEST | 192.168.2.5 | 1.1.1.1 | 0x45a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 22, 2025 08:57:04.749600887 CEST | 1.1.1.1 | 192.168.2.5 | 0xbeaa | No error (0) | 192.178.49.164 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 08:57:04.749614954 CEST | 1.1.1.1 | 192.168.2.5 | 0x771c | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 08:57:17.254590988 CEST | 1.1.1.1 | 192.168.2.5 | 0xf0b7 | No error (0) | 213.133.104.46 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 08:57:20.786983013 CEST | 1.1.1.1 | 192.168.2.5 | 0xc4d4 | No error (0) | 213.133.104.46 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49707 | 213.133.104.46 | 443 | 6396 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 06:57:17 UTC | 793 | OUT | |
2025-04-22 06:57:17 UTC | 50 | OUT | |
2025-04-22 06:57:18 UTC | 164 | IN | |
2025-04-22 06:57:18 UTC | 264 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49706 | 213.133.104.46 | 443 | 6396 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 06:57:18 UTC | 604 | OUT | |
2025-04-22 06:57:19 UTC | 393 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49709 | 213.133.104.46 | 443 | 6396 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 06:57:20 UTC | 657 | OUT | |
2025-04-22 06:57:20 UTC | 256 | IN | |
2025-04-22 06:57:20 UTC | 1028 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49710 | 213.133.104.46 | 443 | 6396 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 06:57:21 UTC | 442 | OUT | |
2025-04-22 06:57:21 UTC | 256 | IN | |
2025-04-22 06:57:21 UTC | 1028 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 02:56:54 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7def70000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 02:56:58 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7def70000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 7 |
Start time: | 02:57:01 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7def70000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 02:57:04 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7def70000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |