Windows
Analysis Report
https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w11x64_office
chrome.exe (PID: 1780 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: DBE43C1D0092437B88CFF7BD9ABC336C) chrome.exe (PID: 3472 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1996,i ,109753502 3057962796 2,12600055 5348109534 32,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250316 -180048.77 6000 --moj o-platform -channel-h andle=2104 /prefetch :11 MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
chrome.exe (PID: 6412 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://east- rifle-cc2. notion.sit e/Build-In g-Baumanag ement-GmbH -1d1fd018c 7d0807f937 9d1f18d30b 7ea?pvs=4" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.69.4 | true | false | high | |
east-rifle-cc2.notion.site | 208.103.161.32 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.69.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
208.103.161.32 | east-rifle-cc2.notion.site | United States | 394835 | SNAGAJOBUS | false |
IP |
---|
192.168.2.24 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1670978 |
Start date and time: | 2025-04-22 13:07:28 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://east-rifle-cc2.notion.site/Build-Ing-Baumanagement-GmbH-1d1fd018c7d0807f9379d1f18d30b7ea?pvs=4 |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@21/2@4/3 |
- Exclude process from analysis
(whitelisted): SystemSettingsB roker.exe, SIHClient.exe, appi dcertstorecheck.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.68.227, 14 2.250.69.14, 142.251.2.84, 199 .232.214.172, 192.178.49.170, 192.178.49.202, 142.250.69.10, 142.250.68.234, 192.178.49.19 5, 199.232.210.172, 184.29.183 .29, 4.175.87.197, 4.245.163.5 6 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, www.googlea pis.com, fe3cr.delivery.mp.mic rosoft.com, clients2.google.co m, edgedl.me.gvt1.com, redirec tor.gvt1.com, update.googleapi s.com, clients.l.google.com, c .pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//east-rifle-cc2.notion.site/B uild-Ing-Baumanagement-GmbH-1d 1fd018c7d0807f9379d1f18d30b7ea ?pvs=4
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 28 |
Entropy (8bit): | 4.066108939837481 |
Encrypted: | false |
SSDEEP: | 3:YIzDIwexY:YI3IwexY |
MD5: | 51E5E1C1DE8270ED97825FCB1C860A21 |
SHA1: | AEC7BEA085966632454B8CE8E79691F104C2B1D8 |
SHA-256: | 42AB2C45AB6F9DC749C112B7BB3DCACC8A2464F661E28FC8D9006D8E31593F32 |
SHA-512: | 14B6A068423D537F75D8D947BBCDDF9BB59F33037F62EBA69D16C99FA35A24111E884EC90912F3E2902813B6EC4A0F31DB05D67A34491FC297DDC4A912E6D436 |
Malicious: | false |
Reputation: | low |
URL: | https://east-rifle-cc2.notion.site/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 57
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 13:08:31.432888031 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:31.432928085 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:31.433017015 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:31.433208942 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:31.433222055 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:31.751702070 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:31.751817942 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:31.752913952 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:31.752919912 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:31.753112078 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:31.806427956 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:32.452267885 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.452308893 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.452378035 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.452629089 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.452641010 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.452697039 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.452766895 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.452780962 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.452929020 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.452940941 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.742026091 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.742091894 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.746902943 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.746969938 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.748898029 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.748914003 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.749124050 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.749496937 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.749501944 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.749754906 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.749830961 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:32.789726019 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:32.792284966 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.180883884 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.180970907 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.181030035 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.181052923 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.181093931 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.181099892 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.181305885 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.181348085 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.181353092 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.181710005 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.181762934 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.188664913 CEST | 60835 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.188679934 CEST | 443 | 60835 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.597707987 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.644274950 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.754249096 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.754365921 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.754405975 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.754425049 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:33.754443884 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.754547119 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.758172989 CEST | 60836 | 443 | 192.168.2.24 | 208.103.161.32 |
Apr 22, 2025 13:08:33.758194923 CEST | 443 | 60836 | 208.103.161.32 | 192.168.2.24 |
Apr 22, 2025 13:08:39.605827093 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:39.605927944 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:39.605927944 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:39.884723902 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:39.884749889 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:39.884761095 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.132539034 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.132596016 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.133469105 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.133486986 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.133517981 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.133528948 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.156024933 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.170330048 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.435013056 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.449244022 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.455133915 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.455183029 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.456234932 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.456250906 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.456278086 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.456304073 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.468504906 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.468699932 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.734158039 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.734172106 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.734217882 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.734237909 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.740175009 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.740186930 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:40.740246058 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:40.742321968 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:41.061722040 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:41.065049887 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:41.065268040 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:41.065983057 CEST | 443 | 60817 | 2.19.122.66 | 192.168.2.24 |
Apr 22, 2025 13:08:41.066054106 CEST | 60817 | 443 | 192.168.2.24 | 2.19.122.66 |
Apr 22, 2025 13:08:41.750294924 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:41.750353098 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:08:41.750406981 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:42.266045094 CEST | 60832 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:08:42.266072989 CEST | 443 | 60832 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:31.353169918 CEST | 60849 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:09:31.353216887 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:31.353311062 CEST | 60849 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:09:31.353456974 CEST | 60849 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:09:31.353465080 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:31.666085005 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:31.666444063 CEST | 60849 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:09:31.666471958 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:41.668693066 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:41.668742895 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Apr 22, 2025 13:09:41.668806076 CEST | 60849 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:09:42.275846004 CEST | 60849 | 443 | 192.168.2.24 | 142.250.69.4 |
Apr 22, 2025 13:09:42.275868893 CEST | 443 | 60849 | 142.250.69.4 | 192.168.2.24 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 13:08:27.061499119 CEST | 53 | 49390 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:27.116419077 CEST | 53 | 60653 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:28.229568958 CEST | 53 | 62377 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:31.291563034 CEST | 56197 | 53 | 192.168.2.24 | 1.1.1.1 |
Apr 22, 2025 13:08:31.291841984 CEST | 58140 | 53 | 192.168.2.24 | 1.1.1.1 |
Apr 22, 2025 13:08:31.431740046 CEST | 53 | 56197 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:31.431826115 CEST | 53 | 58140 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:32.296298027 CEST | 52000 | 53 | 192.168.2.24 | 1.1.1.1 |
Apr 22, 2025 13:08:32.296447992 CEST | 58940 | 53 | 192.168.2.24 | 1.1.1.1 |
Apr 22, 2025 13:08:32.451247931 CEST | 53 | 52000 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:32.451416969 CEST | 53 | 58940 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:45.305445910 CEST | 53 | 54774 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:55.171993017 CEST | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Apr 22, 2025 13:08:55.929596901 CEST | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Apr 22, 2025 13:08:56.411168098 CEST | 53 | 57995 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:08:56.679666042 CEST | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Apr 22, 2025 13:09:04.106143951 CEST | 53 | 62896 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:09:26.398890972 CEST | 53 | 59089 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:09:26.777453899 CEST | 53 | 54765 | 1.1.1.1 | 192.168.2.24 |
Apr 22, 2025 13:09:29.993489981 CEST | 53 | 58563 | 1.1.1.1 | 192.168.2.24 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 22, 2025 13:08:31.291563034 CEST | 192.168.2.24 | 1.1.1.1 | 0x2559 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 13:08:31.291841984 CEST | 192.168.2.24 | 1.1.1.1 | 0xebaa | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 13:08:32.296298027 CEST | 192.168.2.24 | 1.1.1.1 | 0x29f1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 13:08:32.296447992 CEST | 192.168.2.24 | 1.1.1.1 | 0xdd9f | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 22, 2025 13:08:31.431740046 CEST | 1.1.1.1 | 192.168.2.24 | 0x2559 | No error (0) | 142.250.69.4 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:08:31.431826115 CEST | 1.1.1.1 | 192.168.2.24 | 0xebaa | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 13:08:32.451247931 CEST | 1.1.1.1 | 192.168.2.24 | 0x29f1 | No error (0) | 208.103.161.32 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:08:32.451247931 CEST | 1.1.1.1 | 192.168.2.24 | 0x29f1 | No error (0) | 208.103.161.33 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 13:08:32.451416969 CEST | 1.1.1.1 | 192.168.2.24 | 0xdd9f | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.24 | 60835 | 208.103.161.32 | 443 | 3472 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 11:08:32 UTC | 743 | OUT | |
2025-04-22 11:08:33 UTC | 604 | IN | |
2025-04-22 11:08:33 UTC | 6220 | IN | |
2025-04-22 11:08:33 UTC | 480 | IN | |
2025-04-22 11:08:33 UTC | 1369 | IN | |
2025-04-22 11:08:33 UTC | 1369 | IN | |
2025-04-22 11:08:33 UTC | 1369 | IN | |
2025-04-22 11:08:33 UTC | 96 | IN | |
2025-04-22 11:08:33 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 60836 | 208.103.161.32 | 443 | 3472 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 11:08:33 UTC | 829 | OUT | |
2025-04-22 11:08:33 UTC | 347 | IN | |
2025-04-22 11:08:33 UTC | 6198 | IN | |
2025-04-22 11:08:33 UTC | 28 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 07:08:24 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff773ba0000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 07:08:25 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff773ba0000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 07:08:31 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff773ba0000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |