Windows
Analysis Report
https://wtb-api-hub.swaven.com/wtb/v3/outbound_click?wtbid=63ff2f752967f260f2a2ee25&module=wtb&touchpoint=ST&lang=en&sid=851_WEB&avpid=9300657021863&prc=6.00&prc_currency=AUD&clkurlt=3&clkurlaff=1&clkurlaff_prgid=11637&url=aHR0cHM6Ly9kMnhtazIwNC5uYTEudzNsb2QuY29tL2tkP3NmPWIyTXZ3N2FTQlNaTEJqMTVxQzZ2N
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5608 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 5740 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2476,i ,123970795 6494035920 9,11217634 2569230590 50,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=2452 /prefetch :3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6800 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://wtb-a pi-hub.swa ven.com/wt b/v3/outbo und_click? wtbid=63ff 2f752967f2 60f2a2ee25 &module=wt b&touchpoi nt=ST&lang =en&sid=85 1_WEB&avpi d=93006570 21863&prc= 6.00&prc_c urrency=AU D&clkurlt= 3&clkurlaf f=1&clkurl aff_prgid= 11637&url= aHR0cHM6Ly 9kMnhtazIw NC5uYTEudz Nsb2QuY29t L2tkP3NmPW IyTXZ3N2FT QlNaTEJqMT VxQzZ2NzJk QlRFcnlpMk ZxYVZwX2Vp d21ybVBfQk FuSE5CYU9O aTVGZE1tNm d2d09lendM bnpuMTNPa0 5ac1NpLWpp LTh3&v=168 9090747277 &s_url=htt ps%3A%2F%2 Fwww.heinz .com.au%2F mayo%2Fpro duct%2F930 0657021863 %2Fheinz-s eriously-g ood-origin al-mayonna ise-500ml& rfr2=https %3A%2F%2Fw ww.heinz.c om.au%2Fma yo%2Fprodu ct%2F93006 57021863%2 Fheinz-ser iously-goo d-original -mayonnais e-500ml&s_ rfr=%7BSWN -SRFR%7D&r fr=%7BSWN- RFR%7D&url _to=aHR0cH M6Ly93d3cu YW1hem9uLm NvbS5hdS9k cC9CMDdQN0 w1TThH" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • AV Detection
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
tesla.com | 2.18.52.207 | true | false | high | |
adst.w3lod.com | 104.26.5.102 | true | false | unknown | |
www.google.com | 142.250.69.4 | true | false | high | |
d2hljrvl8gfxid.cloudfront.net | 18.154.144.78 | true | false | unknown | |
d2xmk204.na1.w3lod.com | 104.26.4.102 | true | false | unknown | |
wtb-api-hub.swaven.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false | high | ||
false |
| unknown | |
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.69.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.26.5.102 | adst.w3lod.com | United States | 13335 | CLOUDFLARENETUS | false | |
2.18.52.207 | tesla.com | European Union | 33905 | AKAMAI-AMSEU | false | |
18.154.144.78 | d2hljrvl8gfxid.cloudfront.net | United States | 16509 | AMAZON-02US | false | |
104.26.4.102 | d2xmk204.na1.w3lod.com | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.4 |
192.168.2.6 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1671093 |
Start date and time: | 2025-04-22 16:20:28 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://wtb-api-hub.swaven.com/wtb/v3/outbound_click?wtbid=63ff2f752967f260f2a2ee25&module=wtb&touchpoint=ST&lang=en&sid=851_WEB&avpid=9300657021863&prc=6.00&prc_currency=AUD&clkurlt=3&clkurlaff=1&clkurlaff_prgid=11637&url=aHR0cHM6Ly9kMnhtazIwNC5uYTEudzNsb2QuY29tL2tkP3NmPWIyTXZ3N2FTQlNaTEJqMTVxQzZ2NzJkQlRFcnlpMkZxYVZwX2Vpd21ybVBfQkFuSE5CYU9OaTVGZE1tNmd2d09lendMbnpuMTNPa05ac1NpLWppLTh3&v=1689090747277&s_url=https%3A%2F%2Fwww.heinz.com.au%2Fmayo%2Fproduct%2F9300657021863%2Fheinz-seriously-good-original-mayonnaise-500ml&rfr2=https%3A%2F%2Fwww.heinz.com.au%2Fmayo%2Fproduct%2F9300657021863%2Fheinz-seriously-good-original-mayonnaise-500ml&s_rfr={SWN-SRFR}&rfr={SWN-RFR}&url_to=aHR0cHM6Ly93d3cuYW1hem9uLmNvbS5hdS9kcC9CMDdQN0w1TThH |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@21/0@10/8 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHC lient.exe, SgrmBroker.exe, bac kgroundTaskHost.exe, conhost.e xe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.69.14, 142 .250.69.3, 142.250.68.238, 142 .250.141.84, 199.232.210.172, 192.178.49.195, 142.250.68.227 , 184.29.183.29, 52.149.20.212 - Excluded domains from analysis
(whitelisted): clients1.googl e.com, fs.microsoft.com, accou nts.google.com, slscr.update.m icrosoft.com, ctldl.windowsupd ate.com, clientservices.google apis.com, fe3cr.delivery.mp.mi crosoft.com, clients2.google.c om, edgedl.me.gvt1.com, redire ctor.gvt1.com, update.googleap is.com, clients.l.google.com, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//wtb-api-hub.swaven.com/wtb/v 3/outbound_click?wtbid=63ff2f7 52967f260f2a2ee25&module=w tb&touchpoint=ST&lang= en&sid=851_WEB&avpid=9 300657021863&prc=6.00& prc_currency=AUD&clkurlt=3 &clkurlaff=1&clkurlaff _prgid=11637&url=aHR0cHM6L y9kMnhtazIwNC5uYTEudzNsb2QuY29 tL2tkP3NmPWIyTXZ3N2FTQlNaTEJqM TVxQzZ2NzJkQlRFcnlpMkZxYVZwX2V pd21ybVBfQkFuSE5CYU9OaTVGZE1tN md2d09lendMbnpuMTNPa05ac1NpLWp pLTh3&v=1689090747277& s_url=https%3A%2F%2Fwww.heinz. com.au%2Fmayo%2Fproduct%2F9300 657021863%2Fheinz-seriously-go od-original-mayonnaise-500ml&a mp;rfr2=https%3A%2F%2Fwww.hein z.com.au%2Fmayo%2Fproduct%2F93 00657021863%2Fheinz-seriously- good-original-mayonnaise-500ml &s_rfr=%7BSWN-SRFR%7D& rfr=%7BSWN-RFR%7D&url_to=a HR0cHM6Ly93d3cuYW1hem9uLmNvbS5 hdS9kcC9CMDdQN0w1TThH
Download Network PCAP: filtered – full
- Total Packets: 98
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 16:21:19.387847900 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 22, 2025 16:21:27.763910055 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:28.201864958 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:28.837466002 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:29.090559959 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 22, 2025 16:21:30.045092106 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:30.439450979 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:30.439487934 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:30.439620972 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:30.439878941 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:30.439894915 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:30.757692099 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:30.757755041 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:30.758865118 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:30.758872032 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:30.759100914 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:30.810714960 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:32.449562073 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:32.919034004 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:32.919065952 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:32.919141054 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:32.919400930 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:32.919430971 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:32.919673920 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:32.919688940 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:32.919709921 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:32.919855118 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:32.919869900 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.223898888 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.223968029 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.224323988 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.224384069 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.225824118 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.225836039 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.226133108 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.227168083 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.227179050 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.227421045 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.227425098 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.272268057 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.279364109 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.963237047 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.963344097 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:33.963435888 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.972198009 CEST | 49726 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:21:33.972213030 CEST | 443 | 49726 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:21:34.180304050 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.180340052 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.180438042 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.180629969 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.180648088 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.474011898 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.474102020 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.475761890 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.475769043 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.476006031 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.476414919 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.520268917 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.922276974 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.922441006 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:34.922521114 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.923234940 CEST | 49727 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:34.923245907 CEST | 443 | 49727 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.069820881 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.069849014 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.069925070 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.070044041 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.070059061 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.365164042 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.365240097 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.369169950 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.369187117 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.369493008 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.369752884 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.416311026 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.969382048 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.969455957 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.969521999 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.971113920 CEST | 49729 | 443 | 192.168.2.4 | 104.26.5.102 |
Apr 22, 2025 16:21:35.971127987 CEST | 443 | 49729 | 104.26.5.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.972035885 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:35.972090006 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:35.972168922 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:35.972341061 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:35.972352982 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.260175943 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.260438919 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:36.260466099 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.260689974 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:36.260695934 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.530710936 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:21:36.755036116 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.755172968 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.755358934 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:36.755713940 CEST | 49731 | 443 | 192.168.2.4 | 104.26.4.102 |
Apr 22, 2025 16:21:36.755738974 CEST | 443 | 49731 | 104.26.4.102 | 192.168.2.4 |
Apr 22, 2025 16:21:36.844193935 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:21:36.920768023 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:21:36.920809984 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:21:36.920902967 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:21:36.924470901 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:21:36.924487114 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:21:37.249608994 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:37.452476978 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:21:37.499874115 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:21:37.499947071 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:21:37.501090050 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:21:37.501100063 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:21:37.501339912 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:21:37.501677036 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:21:37.544265985 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:21:38.657963037 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:21:39.139266968 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.140233040 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.140275002 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.297668934 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.298213959 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.298227072 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.298712969 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.298780918 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.299115896 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.299257040 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.301064968 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.301079988 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.301137924 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.301151037 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.304780006 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.458373070 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.463372946 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.465809107 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.465830088 CEST | 443 | 49710 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:21:39.465878963 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:39.465914011 CEST | 49710 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:21:40.786942959 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:40.787014008 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:40.788431883 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:41.064496040 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:21:41.521399975 CEST | 49720 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:21:41.521433115 CEST | 443 | 49720 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:21:45.874355078 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:21:46.852137089 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:21:55.483441114 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:22:03.216370106 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:22:03.216497898 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:22:03.216658115 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:22:03.516405106 CEST | 49725 | 443 | 192.168.2.4 | 18.154.144.78 |
Apr 22, 2025 16:22:03.516423941 CEST | 443 | 49725 | 18.154.144.78 | 192.168.2.4 |
Apr 22, 2025 16:22:22.546633959 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:22:22.546664000 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:22:30.356712103 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:22:30.356750965 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:22:30.356822968 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:22:30.357075930 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:22:30.357089043 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:22:30.671616077 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:22:30.671968937 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:22:30.671989918 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:22:40.673939943 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:22:40.674005985 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:22:40.674052000 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:22:41.518981934 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:22:41.518995047 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:23:07.561836958 CEST | 49732 | 443 | 192.168.2.4 | 2.18.52.207 |
Apr 22, 2025 16:23:07.561851978 CEST | 443 | 49732 | 2.18.52.207 | 192.168.2.4 |
Apr 22, 2025 16:23:10.639617920 CEST | 49708 | 443 | 192.168.2.4 | 52.113.196.254 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 16:21:27.676055908 CEST | 53 | 63136 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:27.690253973 CEST | 53 | 61494 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:28.828164101 CEST | 53 | 64308 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:30.297518969 CEST | 53391 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:30.297734976 CEST | 60990 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:30.437845945 CEST | 53 | 53391 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:30.437866926 CEST | 53 | 60990 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:32.755454063 CEST | 63302 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:32.755769968 CEST | 56028 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:32.910146952 CEST | 53 | 56028 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:32.917418003 CEST | 53 | 63302 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:33.973500967 CEST | 50636 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:33.973733902 CEST | 51938 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:34.162167072 CEST | 53 | 51938 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:34.179441929 CEST | 53 | 50636 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:34.925270081 CEST | 60059 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:34.925647974 CEST | 51617 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:35.069224119 CEST | 53 | 51617 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:35.069241047 CEST | 53 | 60059 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:36.757749081 CEST | 60112 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:36.757944107 CEST | 51035 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:21:36.912414074 CEST | 53 | 51035 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:36.920181036 CEST | 53 | 60112 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:21:45.920293093 CEST | 53 | 55835 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:22:04.935847998 CEST | 53 | 49952 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:22:27.079408884 CEST | 53 | 51602 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:22:27.514681101 CEST | 53 | 50117 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:22:29.029088974 CEST | 53 | 65125 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:22:35.959043980 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Apr 22, 2025 16:22:57.091176987 CEST | 53 | 55534 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 22, 2025 16:21:30.297518969 CEST | 192.168.2.4 | 1.1.1.1 | 0x194c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:21:30.297734976 CEST | 192.168.2.4 | 1.1.1.1 | 0xdf65 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:21:32.755454063 CEST | 192.168.2.4 | 1.1.1.1 | 0x6e89 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:21:32.755769968 CEST | 192.168.2.4 | 1.1.1.1 | 0x3afc | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:21:33.973500967 CEST | 192.168.2.4 | 1.1.1.1 | 0xe2f0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:21:33.973733902 CEST | 192.168.2.4 | 1.1.1.1 | 0x62c9 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:21:34.925270081 CEST | 192.168.2.4 | 1.1.1.1 | 0x15e0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:21:34.925647974 CEST | 192.168.2.4 | 1.1.1.1 | 0x512e | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:21:36.757749081 CEST | 192.168.2.4 | 1.1.1.1 | 0xce85 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:21:36.757944107 CEST | 192.168.2.4 | 1.1.1.1 | 0xfb3d | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 22, 2025 16:21:30.437845945 CEST | 1.1.1.1 | 192.168.2.4 | 0x194c | No error (0) | 142.250.69.4 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:30.437866926 CEST | 1.1.1.1 | 192.168.2.4 | 0xdf65 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:21:32.910146952 CEST | 1.1.1.1 | 192.168.2.4 | 0x3afc | No error (0) | d2hljrvl8gfxid.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:32.917418003 CEST | 1.1.1.1 | 192.168.2.4 | 0x6e89 | No error (0) | d2hljrvl8gfxid.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:32.917418003 CEST | 1.1.1.1 | 192.168.2.4 | 0x6e89 | No error (0) | 18.154.144.78 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:32.917418003 CEST | 1.1.1.1 | 192.168.2.4 | 0x6e89 | No error (0) | 18.154.144.80 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:32.917418003 CEST | 1.1.1.1 | 192.168.2.4 | 0x6e89 | No error (0) | 18.154.144.122 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:32.917418003 CEST | 1.1.1.1 | 192.168.2.4 | 0x6e89 | No error (0) | 18.154.144.96 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:34.162167072 CEST | 1.1.1.1 | 192.168.2.4 | 0x62c9 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:21:34.179441929 CEST | 1.1.1.1 | 192.168.2.4 | 0xe2f0 | No error (0) | 104.26.4.102 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:34.179441929 CEST | 1.1.1.1 | 192.168.2.4 | 0xe2f0 | No error (0) | 104.26.5.102 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:34.179441929 CEST | 1.1.1.1 | 192.168.2.4 | 0xe2f0 | No error (0) | 172.67.74.105 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:35.069224119 CEST | 1.1.1.1 | 192.168.2.4 | 0x512e | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:21:35.069241047 CEST | 1.1.1.1 | 192.168.2.4 | 0x15e0 | No error (0) | 104.26.5.102 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:35.069241047 CEST | 1.1.1.1 | 192.168.2.4 | 0x15e0 | No error (0) | 104.26.4.102 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:35.069241047 CEST | 1.1.1.1 | 192.168.2.4 | 0x15e0 | No error (0) | 172.67.74.105 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.52.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 23.7.244.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.53.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.55.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.48.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.49.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.51.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.50.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 23.40.100.207 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:21:36.920181036 CEST | 1.1.1.1 | 192.168.2.4 | 0xce85 | No error (0) | 2.18.54.207 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49726 | 18.154.144.78 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:21:33 UTC | 1380 | OUT | |
2025-04-22 14:21:33 UTC | 587 | IN | |
2025-04-22 14:21:33 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49727 | 104.26.4.102 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:21:34 UTC | 764 | OUT | |
2025-04-22 14:21:34 UTC | 1361 | IN | |
2025-04-22 14:21:34 UTC | 270 | IN | |
2025-04-22 14:21:34 UTC | 191 | IN | |
2025-04-22 14:21:34 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49729 | 104.26.5.102 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:21:35 UTC | 793 | OUT | |
2025-04-22 14:21:35 UTC | 966 | IN | |
2025-04-22 14:21:35 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49731 | 104.26.4.102 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:21:36 UTC | 911 | OUT | |
2025-04-22 14:21:36 UTC | 1368 | IN | |
2025-04-22 14:21:36 UTC | 1 | IN | |
2025-04-22 14:21:36 UTC | 51 | IN | |
2025-04-22 14:21:36 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49732 | 2.18.52.207 | 443 | 5740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:21:37 UTC | 659 | OUT |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 10:21:23 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 10:21:25 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 10:21:32 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |