Windows
Analysis Report
http://allupdatenow.com
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 1268 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 1624 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2372,i ,145450689 5324260812 7,18194059 5366893492 59,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n=20250306 -183004.42 9000 --moj o-platform -channel-h andle=2400 /prefetch :3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6864 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://allupd atenow.com " MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
allupdatenow.com | 172.67.211.33 | true | false | unknown | |
www.google.com | 142.250.69.4 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false | unknown | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.69.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.67.211.33 | allupdatenow.com | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1671115 |
Start date and time: | 2025-04-22 16:50:43 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://allupdatenow.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@22/12@8/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, a udiodg.exe, sppsvc.exe, Runtim eBroker.exe, ShellExperienceHo st.exe, SIHClient.exe, SgrmBro ker.exe, backgroundTaskHost.ex e, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 142.251.2.84, 142. 250.68.238, 142.250.68.227, 14 2.250.69.14, 199.232.214.172, 192.178.49.195, 184.29.183.29, 52.149.20.212 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, clients2.google.com, edged l.me.gvt1.com, accounts.google .com, redirector.gvt1.com, sls cr.update.microsoft.com, updat e.googleapis.com, ctldl.window supdate.com, clientservices.go ogleapis.com, clients.l.google .com, c.pki.goog, fe3cr.delive ry.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data. - VT rate limit hit for: http:/
/allupdatenow.com
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 715 |
Entropy (8bit): | 7.3533249502413565 |
Encrypted: | false |
SSDEEP: | 12:6v/7et+/37c7jvBjLg+UnhdeNdLI4dACGHJovQpMZP5ajgj7xbKwkRR/:Lu490+NdcCqJlpMZxajnwCR/ |
MD5: | 226DCB8F6144BDAAFDFBD8F2F354BE64 |
SHA1: | 3785CC5B3BF52F8E398177B0FF1020B24AA86B8C |
SHA-256: | 8C873472F4925D5D47521DB4D52532D2983E9CB1BDE8B43143A6CC6DB56C35DB |
SHA-512: | ED898B12C4895F7ACEAAB443C1071E6376DB71B4DFDBD769F5F3BE71D562438A18B5E5DC36DD7CC610926E380603A894B2E81DF4302680C736A412BFD3360D3A |
Malicious: | false |
Reputation: | low |
URL: | https://allupdatenow.com/cdn-cgi/images/browser-bar.png?1376755637 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 24051 |
Entropy (8bit): | 4.941039417164537 |
Encrypted: | false |
SSDEEP: | 192:VuR/6okgTQwq23gGM8lUR9YRGQ2BwoX6zp+1+nDT1FvxKSI7/UsV7MSE6XZ2dKzk:JwV+oUcoQJpdf1dxKSI7/Ue7ZX2qk |
MD5: | 5E8C69A459A691B5D1B9BE442332C87D |
SHA1: | F24DD1AD7C9080575D92A9A9A2C42620725EF836 |
SHA-256: | 84E3C77025ACE5AF143972B4A40FC834DCDFD4E449D4B36A57E62326F16B3091 |
SHA-512: | 6DB74B262D717916DE0B0B600EEAD2CC6A10E52A9E26D701FAE761FCBC931F35F251553669A92BE3B524F380F32E62AC6AD572BEA23C78965228CE9EFB92ED42 |
Malicious: | false |
Reputation: | low |
URL: | https://allupdatenow.com/cdn-cgi/styles/cf.errors.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4552 |
Entropy (8bit): | 4.999949626836067 |
Encrypted: | false |
SSDEEP: | 96:1j9jwIjYj5jDK/D5DMFWC8lZqXKHvpIkdlV7RFlvaQxvbK:1j9jhjYj9K/VoWn2aHvFdlV7XlCejK |
MD5: | B6C730F2FAFA26C6037B512FEE3E7F9D |
SHA1: | 4342E49E25438E2966FA8973DD19A164FBE8177E |
SHA-256: | ACDA1F863314AE4D3F0CF116078683132CFD7E770DAC56E16A0BD97E262F77FB |
SHA-512: | BE21C8C304C0D1ABF7597D31CD6CB22FF9B999F269BBCBD1D1F8EB6BADD4F621D9ED1D8ADE7BE05F6DF93A26729351C8E17BBFD64C3331738E32E100929E447F |
Malicious: | false |
Reputation: | low |
URL: | https://allupdatenow.com/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3213 |
Entropy (8bit): | 7.553565995366911 |
Encrypted: | false |
SSDEEP: | 96:35QRRzQqgtYCWBzmuvuLf33Pf309TxeL+vD+7SrQ9o6Br2eJk:GRRsqgOBzvcnM9TxVk9JCeJk |
MD5: | 0D768CBC261841D3AFFC933B9AC3130E |
SHA1: | AFF136A4C761E1DF1ADA7E5D9A6ED0EBEA74A4B7 |
SHA-256: | 1C53772285052E52BB7C12AD46A85A55747ED7BF66963FE1993FCEF91FF5B0D0 |
SHA-512: | CE5B1BBB8CF6B0C3D1FA146D1700DB2300ABD6F2BDBE43ECAAC6AEBC911BE6E1BCD2F8C6704A2CFA67BBB45598793DDEC017E05C2C37CE387293AAE08E7C342F |
Malicious: | false |
Reputation: | low |
URL: | https://allupdatenow.com/cdn-cgi/images/cf-no-screenshot-error.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 715 |
Entropy (8bit): | 7.3533249502413565 |
Encrypted: | false |
SSDEEP: | 12:6v/7et+/37c7jvBjLg+UnhdeNdLI4dACGHJovQpMZP5ajgj7xbKwkRR/:Lu490+NdcCqJlpMZxajnwCR/ |
MD5: | 226DCB8F6144BDAAFDFBD8F2F354BE64 |
SHA1: | 3785CC5B3BF52F8E398177B0FF1020B24AA86B8C |
SHA-256: | 8C873472F4925D5D47521DB4D52532D2983E9CB1BDE8B43143A6CC6DB56C35DB |
SHA-512: | ED898B12C4895F7ACEAAB443C1071E6376DB71B4DFDBD769F5F3BE71D562438A18B5E5DC36DD7CC610926E380603A894B2E81DF4302680C736A412BFD3360D3A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3213 |
Entropy (8bit): | 7.553565995366911 |
Encrypted: | false |
SSDEEP: | 96:35QRRzQqgtYCWBzmuvuLf33Pf309TxeL+vD+7SrQ9o6Br2eJk:GRRsqgOBzvcnM9TxVk9JCeJk |
MD5: | 0D768CBC261841D3AFFC933B9AC3130E |
SHA1: | AFF136A4C761E1DF1ADA7E5D9A6ED0EBEA74A4B7 |
SHA-256: | 1C53772285052E52BB7C12AD46A85A55747ED7BF66963FE1993FCEF91FF5B0D0 |
SHA-512: | CE5B1BBB8CF6B0C3D1FA146D1700DB2300ABD6F2BDBE43ECAAC6AEBC911BE6E1BCD2F8C6704A2CFA67BBB45598793DDEC017E05C2C37CE387293AAE08E7C342F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4552 |
Entropy (8bit): | 4.998898644038814 |
Encrypted: | false |
SSDEEP: | 96:1j9jwIjYj5jDK/D5DMFWC8lZqXKHvpIkdlYP7RFlvaQxvbK:1j9jhjYj9K/VoWn2aHvFdlE7XlCejK |
MD5: | F70E29563B8875B8CE372091350BD9AB |
SHA1: | CCDCA1B7D9A5C6025E1995BD1EFD179B18708E8B |
SHA-256: | 816EC66DD11A96B2168998126E3180C1528754AC6D45F5BFCD9BF804337E4FE2 |
SHA-512: | 34DE2F561D3890EE7051438B49438867DC159B144CA47FF0783B020B87807711B06EAA80CDD37AD6B323CCA39A1519B440B480A703D6B5F900CA9A38D92D05BA |
Malicious: | false |
Reputation: | low |
URL: | https://allupdatenow.com/favicon.ico |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 117
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 16:51:34.552016020 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 22, 2025 16:51:41.146174908 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:51:41.567688942 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:51:42.259520054 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:51:43.567527056 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:51:44.161283016 CEST | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Apr 22, 2025 16:51:46.067653894 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:51:46.585697889 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:46.585741043 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:46.585813046 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:46.586015940 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:46.586030960 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:46.909627914 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:46.909717083 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:46.911514044 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:46.911524057 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:46.911768913 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:46.957954884 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:48.500261068 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:48.500299931 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:48.500360966 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:48.500551939 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:48.500564098 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:48.811835051 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:48.811908007 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:48.813051939 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:48.813072920 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:48.813323975 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:48.813663006 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:48.860268116 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161303997 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161350965 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161377907 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161398888 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161451101 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.161451101 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.161463022 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161480904 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.161535025 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.162818909 CEST | 49723 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.162846088 CEST | 443 | 49723 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.225939989 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.225996017 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.226068020 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.227799892 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.227854013 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.536113024 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.537483931 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.537519932 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.537720919 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.537728071 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.697879076 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:51:49.890723944 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.890777111 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.890805960 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.890837908 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.890850067 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.890867949 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.890907049 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.890922070 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.890971899 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.890979052 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.891318083 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.891343117 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.891360998 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.891366959 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.891403913 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.892002106 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892060041 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892117023 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.892122030 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892854929 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892883062 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892909050 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892913103 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.892918110 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.892951965 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.893615007 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.893675089 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.893680096 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.893711090 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.893779993 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.894104958 CEST | 49726 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.894120932 CEST | 443 | 49726 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.925738096 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.925784111 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.925868988 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.926517963 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.926558018 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.926656961 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.926667929 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.926696062 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.930948973 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:49.930963993 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:49.999625921 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:51:50.233984947 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.239367008 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.282938004 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.283116102 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.293632984 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.293649912 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.294101954 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.294111967 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.294270039 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.294275045 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.294392109 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.294397116 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587582111 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587632895 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587661028 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587691069 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.587712049 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587755919 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.587762117 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587773085 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.587816954 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.593060970 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.593168020 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.593219042 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.605027914 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:51:50.609759092 CEST | 49728 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.609771967 CEST | 443 | 49728 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.613807917 CEST | 49729 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.613835096 CEST | 443 | 49729 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.668034077 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.668082952 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.668154955 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.668389082 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.668402910 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.877799034 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:51:50.935856104 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.935894012 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.935983896 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.936280012 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.936295033 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.936346054 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.936608076 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.936624050 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.936716080 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.936727047 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.978744984 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.979042053 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.979072094 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:50.979257107 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:50.979262114 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.250330925 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.250411987 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.250888109 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.250900984 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.251171112 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.251456976 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.278458118 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.278538942 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.279098034 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.279108047 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.279306889 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.279633045 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.296266079 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.324268103 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341437101 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341514111 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341552973 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341562986 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.341576099 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341618061 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.341623068 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341654062 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.341737032 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.344206095 CEST | 49730 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.344216108 CEST | 443 | 49730 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.616637945 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.616697073 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.616723061 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.616772890 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.616800070 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.616817951 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.616838932 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.616868019 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.618354082 CEST | 49732 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.618377924 CEST | 443 | 49732 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.654655933 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.654928923 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.654990911 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.655510902 CEST | 49731 | 443 | 192.168.2.4 | 172.67.211.33 |
Apr 22, 2025 16:51:51.655525923 CEST | 443 | 49731 | 172.67.211.33 | 192.168.2.4 |
Apr 22, 2025 16:51:51.817291021 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:51:54.223308086 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:51:54.508783102 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.510247946 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.510272026 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.666841030 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.667996883 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.668009996 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.668059111 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.668716908 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.669338942 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.669358015 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.671979904 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.671999931 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.672049999 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.674751043 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:54.827446938 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.832725048 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.834985018 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.834999084 CEST | 443 | 49711 | 131.253.33.254 | 192.168.2.4 |
Apr 22, 2025 16:51:54.835052013 CEST | 49711 | 443 | 192.168.2.4 | 131.253.33.254 |
Apr 22, 2025 16:51:56.911581039 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:56.911653042 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:56.911710024 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:57.633852959 CEST | 49722 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:51:57.633883953 CEST | 443 | 49722 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:51:59.042112112 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:52:00.492090940 CEST | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Apr 22, 2025 16:52:08.646053076 CEST | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Apr 22, 2025 16:52:46.506305933 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:52:46.506367922 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:52:46.506447077 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:52:46.506652117 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:52:46.506659031 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:52:46.822164059 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:52:46.822520018 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:52:46.822556973 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:52:56.807313919 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:52:56.807382107 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Apr 22, 2025 16:52:56.807456970 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:52:57.632647991 CEST | 49742 | 443 | 192.168.2.4 | 142.250.69.4 |
Apr 22, 2025 16:52:57.632683992 CEST | 443 | 49742 | 142.250.69.4 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 22, 2025 16:51:42.591413975 CEST | 53 | 59383 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:42.594202995 CEST | 53 | 54134 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:43.489805937 CEST | 53 | 60402 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:43.729013920 CEST | 53 | 53085 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:46.443802118 CEST | 62529 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:46.444010973 CEST | 49232 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:46.584177017 CEST | 53 | 49232 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:46.584691048 CEST | 53 | 62529 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:48.305354118 CEST | 60986 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:48.305782080 CEST | 64489 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:48.325037956 CEST | 59529 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:48.325217009 CEST | 55995 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:48.490192890 CEST | 53 | 64489 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:48.490241051 CEST | 53 | 55995 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:48.490860939 CEST | 53 | 60986 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:48.499638081 CEST | 53 | 59529 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:50.779933929 CEST | 50114 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:50.780250072 CEST | 58967 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 22, 2025 16:51:50.931205988 CEST | 53 | 58967 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:51:50.935383081 CEST | 53 | 50114 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:52:00.700594902 CEST | 53 | 51098 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:52:19.708980083 CEST | 53 | 63761 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:52:42.259040117 CEST | 53 | 52413 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:52:42.552752972 CEST | 53 | 49841 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:52:45.147202969 CEST | 53 | 58325 | 1.1.1.1 | 192.168.2.4 |
Apr 22, 2025 16:52:49.137284040 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Apr 22, 2025 16:51:48.490945101 CEST | 192.168.2.4 | 1.1.1.1 | c206 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 22, 2025 16:51:46.443802118 CEST | 192.168.2.4 | 1.1.1.1 | 0x4e2e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:51:46.444010973 CEST | 192.168.2.4 | 1.1.1.1 | 0xa9de | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:51:48.305354118 CEST | 192.168.2.4 | 1.1.1.1 | 0x33b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:51:48.305782080 CEST | 192.168.2.4 | 1.1.1.1 | 0x8cfa | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:51:48.325037956 CEST | 192.168.2.4 | 1.1.1.1 | 0x2e59 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:51:48.325217009 CEST | 192.168.2.4 | 1.1.1.1 | 0xb7be | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 22, 2025 16:51:50.779933929 CEST | 192.168.2.4 | 1.1.1.1 | 0xb55 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 22, 2025 16:51:50.780250072 CEST | 192.168.2.4 | 1.1.1.1 | 0xd2a7 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 22, 2025 16:51:46.584177017 CEST | 1.1.1.1 | 192.168.2.4 | 0xa9de | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:51:46.584691048 CEST | 1.1.1.1 | 192.168.2.4 | 0x4e2e | No error (0) | 142.250.69.4 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:51:48.490192890 CEST | 1.1.1.1 | 192.168.2.4 | 0x8cfa | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:51:48.490241051 CEST | 1.1.1.1 | 192.168.2.4 | 0xb7be | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:51:48.490860939 CEST | 1.1.1.1 | 192.168.2.4 | 0x33b6 | No error (0) | 172.67.211.33 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:51:48.490860939 CEST | 1.1.1.1 | 192.168.2.4 | 0x33b6 | No error (0) | 104.21.85.209 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:51:48.499638081 CEST | 1.1.1.1 | 192.168.2.4 | 0x2e59 | No error (0) | 172.67.211.33 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:51:48.499638081 CEST | 1.1.1.1 | 192.168.2.4 | 0x2e59 | No error (0) | 104.21.85.209 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:51:50.931205988 CEST | 1.1.1.1 | 192.168.2.4 | 0xd2a7 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 22, 2025 16:51:50.935383081 CEST | 1.1.1.1 | 192.168.2.4 | 0xb55 | No error (0) | 172.67.211.33 | A (IP address) | IN (0x0001) | false | ||
Apr 22, 2025 16:51:50.935383081 CEST | 1.1.1.1 | 192.168.2.4 | 0xb55 | No error (0) | 104.21.85.209 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49723 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:48 UTC | 666 | OUT | |
2025-04-22 14:51:49 UTC | 259 | IN | |
2025-04-22 14:51:49 UTC | 1110 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 712 | IN | |
2025-04-22 14:51:49 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49726 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:49 UTC | 566 | OUT | |
2025-04-22 14:51:49 UTC | 177 | IN | |
2025-04-22 14:51:49 UTC | 1192 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN | |
2025-04-22 14:51:49 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49729 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:50 UTC | 653 | OUT | |
2025-04-22 14:51:50 UTC | 178 | IN | |
2025-04-22 14:51:50 UTC | 722 | IN | |
2025-04-22 14:51:50 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49728 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:50 UTC | 653 | OUT | |
2025-04-22 14:51:50 UTC | 178 | IN | |
2025-04-22 14:51:50 UTC | 1191 | IN | |
2025-04-22 14:51:50 UTC | 1369 | IN | |
2025-04-22 14:51:50 UTC | 660 | IN | |
2025-04-22 14:51:50 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49730 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:50 UTC | 595 | OUT | |
2025-04-22 14:51:51 UTC | 259 | IN | |
2025-04-22 14:51:51 UTC | 1369 | IN | |
2025-04-22 14:51:51 UTC | 1369 | IN | |
2025-04-22 14:51:51 UTC | 1369 | IN | |
2025-04-22 14:51:51 UTC | 453 | IN | |
2025-04-22 14:51:51 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49732 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:51 UTC | 421 | OUT | |
2025-04-22 14:51:51 UTC | 178 | IN | |
2025-04-22 14:51:51 UTC | 1191 | IN | |
2025-04-22 14:51:51 UTC | 1369 | IN | |
2025-04-22 14:51:51 UTC | 660 | IN | |
2025-04-22 14:51:51 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49731 | 172.67.211.33 | 443 | 1624 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-22 14:51:51 UTC | 421 | OUT | |
2025-04-22 14:51:51 UTC | 178 | IN | |
2025-04-22 14:51:51 UTC | 722 | IN | |
2025-04-22 14:51:51 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 10:51:37 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 10:51:40 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 10:51:47 |
Start date: | 22/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |