Windows
Analysis Report
https://wainleom.com/cloudflare.msi
Overview
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1060 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 1488 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1956,i ,501179616 0746768708 ,108553562 1366088971 3,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=1992 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6536 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= printing.m ojom.Unsan dboxedPrin tBackendHo st --lang= en-US --se rvice-sand box-type=n one --no-p re-read-ma in-dll --f ield-trial -handle=19 56,i,50117 9616074676 8708,10855 3562136608 89713,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction - -variation s-seed-ver sion=20250 306-183004 .429000 -- mojo-platf orm-channe l-handle=3 840 /prefe tch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6804 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://wainl eom.com/cl oudflare.m si" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • AV Detection
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 192.178.49.164 | true | false | high | |
wainleom.com | 104.21.40.64 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
192.178.49.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.21.40.64 | wainleom.com | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1671097 |
Start date and time: | 2025-04-22 16:27:20 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 48s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://wainleom.com/cloudflare.msi |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@23/2@4/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, s ppsvc.exe, SIHClient.exe, Sgrm Broker.exe, conhost.exe, svcho st.exe - Excluded IPs from analysis (wh
itelisted): 142.250.68.227, 14 2.250.69.14, 142.251.2.84, 23. 220.73.19, 192.178.49.163, 142 .250.69.3, 184.29.183.29, 172. 202.163.200 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fe3cr.deliv ery.mp.microsoft.com, c2a9c95e 369881c67228a6591cac2686.clo.f ootprintdns.com, ax-ring.msedg e.net, clients2.google.com, ed gedl.me.gvt1.com, redirector.g vt1.com, update.googleapis.com , clients.l.google.com, c.pki. goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//wainleom.com/cloudflare.msi
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 255 |
Entropy (8bit): | 3.165118300518646 |
Encrypted: | false |
SSDEEP: | 3:CdeouVHFnIJL/F2GKHjJMzVJu+1zWqZjbd/FEAEtvxL//OacD/ER0DFV:CdWNCJL/kGeMRJVCqZcAEdxKXAGDv |
MD5: | 5CD039A81ABEA75EAC6F6B21E6ED4DAC |
SHA1: | 1E465B7CD78936DE5184027A425D185D2E58B608 |
SHA-256: | 0C3B9C73BCF6ADDBF917600549F1BFC61E3CCC532F58F55CB20C218E5293FF57 |
SHA-512: | 60C1C5FCF4D96622E52D5ACDC4A986386DE5EE796068A173425C029F6DFE6D7AC8D7750A33B3A39E5BABD3180712FEE0DC961F6ADACD268361A9D673ADB8A431 |
Malicious: | false |
Reputation: | low |
URL: | https://wainleom.com/cloudflare.msi |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 40
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 16:28:03.298297882 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:03.610596895 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:04.219893932 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:05.423019886 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:07.829268932 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:11.699919939 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:12.001744032 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:12.610537052 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:12.688642979 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:13.813832045 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:15.535221100 CEST | 49701 | 80 | 192.168.2.5 | 192.178.49.195 |
Apr 22, 2025 16:28:15.683232069 CEST | 80 | 49701 | 192.178.49.195 | 192.168.2.5 |
Apr 22, 2025 16:28:15.683320045 CEST | 49701 | 80 | 192.168.2.5 | 192.178.49.195 |
Apr 22, 2025 16:28:15.683489084 CEST | 49701 | 80 | 192.168.2.5 | 192.178.49.195 |
Apr 22, 2025 16:28:15.831433058 CEST | 80 | 49701 | 192.178.49.195 | 192.168.2.5 |
Apr 22, 2025 16:28:15.831897974 CEST | 80 | 49701 | 192.178.49.195 | 192.168.2.5 |
Apr 22, 2025 16:28:15.875988007 CEST | 49701 | 80 | 192.168.2.5 | 192.178.49.195 |
Apr 22, 2025 16:28:16.219741106 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:17.237662077 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:17.237699032 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:17.237801075 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:17.237978935 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:17.237993002 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:17.558075905 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:17.558151007 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:17.559302092 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:17.559310913 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:17.559557915 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:17.610924959 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:18.097045898 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.097100973 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.097189903 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.097804070 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.097820997 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.098988056 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.099028111 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.099127054 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.099219084 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.099234104 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.414165974 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.414247990 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.416659117 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.416745901 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.419382095 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.419395924 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.419660091 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.420907021 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.420917988 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.421057940 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.421179056 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:18.463725090 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:18.464283943 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:19.265932083 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:19.266063929 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:19.266122103 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:19.267306089 CEST | 49703 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:19.267329931 CEST | 443 | 49703 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:21.032819986 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:22.298424959 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 22, 2025 16:28:27.566051006 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:27.566108942 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:27.566173077 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:28.050750971 CEST | 49702 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:28:28.050772905 CEST | 443 | 49702 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:28:28.430296898 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 22, 2025 16:28:28.430296898 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 22, 2025 16:28:28.430346012 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 22, 2025 16:28:28.430356979 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 22, 2025 16:28:28.801307917 CEST | 49707 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 16:28:28.801340103 CEST | 443 | 49707 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 16:28:28.801400900 CEST | 49707 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 16:28:28.801784992 CEST | 49707 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 16:28:28.801799059 CEST | 443 | 49707 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 16:28:29.246478081 CEST | 443 | 49707 | 150.171.27.254 | 192.168.2.5 |
Apr 22, 2025 16:28:29.246562958 CEST | 49707 | 443 | 192.168.2.5 | 150.171.27.254 |
Apr 22, 2025 16:28:30.642055035 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 22, 2025 16:28:33.403058052 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:33.403161049 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:28:33.403318882 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:34.050206900 CEST | 49704 | 443 | 192.168.2.5 | 104.21.40.64 |
Apr 22, 2025 16:28:34.050228119 CEST | 443 | 49704 | 104.21.40.64 | 192.168.2.5 |
Apr 22, 2025 16:29:15.970938921 CEST | 49701 | 80 | 192.168.2.5 | 192.178.49.195 |
Apr 22, 2025 16:29:16.119153976 CEST | 80 | 49701 | 192.178.49.195 | 192.168.2.5 |
Apr 22, 2025 16:29:16.119223118 CEST | 49701 | 80 | 192.168.2.5 | 192.178.49.195 |
Apr 22, 2025 16:29:17.158535004 CEST | 49713 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:29:17.158590078 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:29:17.158683062 CEST | 49713 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:29:17.158850908 CEST | 49713 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:29:17.158865929 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:29:17.473768950 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:29:17.474127054 CEST | 49713 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:29:17.474145889 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:29:27.466274977 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:29:27.466336012 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Apr 22, 2025 16:29:27.466464996 CEST | 49713 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:29:28.050869942 CEST | 49713 | 443 | 192.168.2.5 | 192.178.49.164 |
Apr 22, 2025 16:29:28.050900936 CEST | 443 | 49713 | 192.178.49.164 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 16:28:12.840200901 CEST | 53 | 56797 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:12.966052055 CEST | 53 | 55207 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:14.147439957 CEST | 53 | 59720 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:14.823982954 CEST | 53 | 57584 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:17.096179962 CEST | 56214 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 16:28:17.096385002 CEST | 58144 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 16:28:17.236645937 CEST | 53 | 56214 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:17.236664057 CEST | 53 | 58144 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:17.883411884 CEST | 51162 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 16:28:17.884701014 CEST | 60680 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 22, 2025 16:28:18.096106052 CEST | 53 | 60680 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:18.096493006 CEST | 53 | 51162 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:31.893523932 CEST | 53 | 50782 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:28:50.847405910 CEST | 53 | 63235 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:29:12.554131985 CEST | 53 | 54445 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:29:13.544132948 CEST | 53 | 59284 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:29:14.193695068 CEST | 53 | 62079 | 1.1.1.1 | 192.168.2.5 |
Apr 22, 2025 16:29:14.946341038 CEST | 138 | 138 | 192.168.2.5 | 192.168.2.255 |
Apr 22, 2025 16:29:15.847588062 CEST | 53 | 54017 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 22, 2025 16:28:17.096179962 CEST | 192.168.2.5 | 1.1.1.1 | 0x7130 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:28:17.096385002 CEST | 192.168.2.5 | 1.1.1.1 | 0x8ceb | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:28:17.883411884 CEST | 192.168.2.5 | 1.1.1.1 | 0x53cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:28:17.884701014 CEST | 192.168.2.5 | 1.1.1.1 | 0x2c83 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 22, 2025 16:28:17.236645937 CEST | 1.1.1.1 | 192.168.2.5 | 0x7130 | No error (0) | 192.178.49.164 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:28:17.236664057 CEST | 1.1.1.1 | 192.168.2.5 | 0x8ceb | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:28:18.096106052 CEST | 1.1.1.1 | 192.168.2.5 | 0x2c83 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:28:18.096493006 CEST | 1.1.1.1 | 192.168.2.5 | 0x53cb | No error (0) | 104.21.40.64 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:28:18.096493006 CEST | 1.1.1.1 | 192.168.2.5 | 0x53cb | No error (0) | 172.67.178.42 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.5 | 49701 | 192.178.49.195 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 22, 2025 16:28:15.683489084 CEST | 200 | OUT | |
Apr 22, 2025 16:28:15.831897974 CEST | 1243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49703 | 104.21.40.64 | 443 | 1488 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:28:18 UTC | 676 | OUT | |
2025-04-22 14:28:19 UTC | 295 | IN | |
2025-04-22 14:28:19 UTC | 261 | IN | |
2025-04-22 14:28:19 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 10:28:06 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78b440000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 10:28:10 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78b440000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 9 |
Start time: | 10:28:13 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78b440000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 12 |
Start time: | 10:28:16 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78b440000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |