Windows
Analysis Report
http://facturacion30345.iamallama.com/
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6520 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 7072 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2008,i ,990563254 9315311955 ,563814544 8524907450 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion --vari ations-see d-version= 20250306-1 83004.4290 00 --mojo- platform-c hannel-han dle=2112 / prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6724 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= printing.m ojom.Unsan dboxedPrin tBackendHo st --lang= en-US --se rvice-sand box-type=n one --no-p re-read-ma in-dll --f ield-trial -handle=20 08,i,99056 3254931531 1955,56381 4544852490 7450,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction -- variations -seed-vers ion=202503 06-183004. 429000 --m ojo-platfo rm-channel -handle=50 44 /prefet ch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7348 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://factur acion30345 .iamallama .com/" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
facturacion30345.iamallama.com | 156.227.0.99 | true | false | unknown | |
www.google.com | 142.250.69.4 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.69.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
156.227.0.99 | facturacion30345.iamallama.com | Seychelles | 134548 | DXTL-HKDXTLTseungKwanOServiceHK | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1672188 |
Start date and time: | 2025-04-23 17:04:13 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://facturacion30345.iamallama.com/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@27/0@6/3 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, conhost.exe, svc host.exe - Excluded IPs from analysis (wh
itelisted): 184.29.183.29, 23. 220.73.6, 192.178.49.174, 192. 178.49.195, 74.125.137.84, 142 .250.69.14, 4.175.87.197 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, slscr .update.microsoft.com, ctldl.w indowsupdate.com, clientservic es.googleapis.com, fs-wildcard .microsoft.com.edgekey.net, fs -wildcard.microsoft.com.edgeke y.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe 3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2 686.clo.footprintdns.com, ax-r ing.msedge.net, clients2.googl e.com, edgedl.me.gvt1.com, red irector.gvt1.com, update.googl eapis.com, clients.l.google.co m, prod.fs.microsoft.com.akadn s.net, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: http:/
/facturacion30345.iamallama.co m/
Download Network PCAP: filtered – full
- Total Packets: 89
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 23, 2025 17:05:06.062413931 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:06.373003006 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:06.982343912 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:07.029237986 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 23, 2025 17:05:08.185488939 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:10.591726065 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:15.513849020 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:16.666776896 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 23, 2025 17:05:18.562724113 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:18.562760115 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:18.562871933 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:18.563087940 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:18.563101053 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:18.883507967 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:18.883580923 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:18.884596109 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:18.884607077 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:18.884840012 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:18.935748100 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:19.894179106 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:19.894229889 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:19.894325018 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:19.894506931 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:19.894524097 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:19.896138906 CEST | 49705 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:19.896308899 CEST | 49706 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:20.171797037 CEST | 80 | 49705 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:20.171866894 CEST | 80 | 49706 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:20.171892881 CEST | 49705 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:20.172015905 CEST | 49706 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:20.464140892 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:20.464226961 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:20.465228081 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:20.465240002 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:20.465574026 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:20.465831995 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:20.512279987 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:21.041960001 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:21.042052984 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:21.042570114 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:21.064868927 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:21.064910889 CEST | 443 | 49704 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:21.064948082 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:21.064976931 CEST | 49704 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:25.123622894 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 23, 2025 17:05:28.194201946 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.194201946 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.194250107 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:28.194264889 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:28.194278002 CEST | 49675 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.194295883 CEST | 443 | 49675 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:28.213993073 CEST | 49711 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.214049101 CEST | 443 | 49711 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:28.214167118 CEST | 49711 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.214426041 CEST | 49711 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.214435101 CEST | 443 | 49711 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:28.563817978 CEST | 49712 | 443 | 192.168.2.5 | 150.171.28.254 |
Apr 23, 2025 17:05:28.563854933 CEST | 443 | 49712 | 150.171.28.254 | 192.168.2.5 |
Apr 23, 2025 17:05:28.563941002 CEST | 49712 | 443 | 192.168.2.5 | 150.171.28.254 |
Apr 23, 2025 17:05:28.564657927 CEST | 49712 | 443 | 192.168.2.5 | 150.171.28.254 |
Apr 23, 2025 17:05:28.564671993 CEST | 443 | 49712 | 150.171.28.254 | 192.168.2.5 |
Apr 23, 2025 17:05:28.774601936 CEST | 443 | 49711 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:28.774727106 CEST | 49711 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:28.897041082 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:28.897099018 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:28.897386074 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:29.011980057 CEST | 443 | 49712 | 150.171.28.254 | 192.168.2.5 |
Apr 23, 2025 17:05:29.012092113 CEST | 49712 | 443 | 192.168.2.5 | 150.171.28.254 |
Apr 23, 2025 17:05:29.454444885 CEST | 49703 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:05:29.454485893 CEST | 443 | 49703 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:05:32.549299002 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:32.549302101 CEST | 49714 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:32.549356937 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:32.549360991 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:32.552237034 CEST | 49714 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:32.552241087 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:32.552630901 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:32.552630901 CEST | 49714 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:32.552647114 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:32.552650928 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.108612061 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.109087944 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:33.109111071 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.109240055 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:33.109246016 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.109411001 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.109555006 CEST | 49714 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:33.109579086 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.686351061 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.686414957 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:33.686688900 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:33.688030005 CEST | 49713 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:33.688047886 CEST | 443 | 49713 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:48.044508934 CEST | 443 | 49711 | 2.23.227.208 | 192.168.2.5 |
Apr 23, 2025 17:05:48.044594049 CEST | 49711 | 443 | 192.168.2.5 | 2.23.227.208 |
Apr 23, 2025 17:05:51.788762093 CEST | 80 | 49706 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:51.788777113 CEST | 80 | 49705 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:51.788816929 CEST | 49706 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:51.788851023 CEST | 49705 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:53.385042906 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:53.385117054 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:05:53.385230064 CEST | 49714 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:53.453521967 CEST | 49714 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:05:53.453547001 CEST | 443 | 49714 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:05.185801029 CEST | 49705 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:05.185844898 CEST | 49706 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:05.461395025 CEST | 80 | 49705 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:05.461411953 CEST | 80 | 49706 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.413096905 CEST | 49716 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.413140059 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.413204908 CEST | 49716 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.413599968 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.413651943 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.413702011 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.413881063 CEST | 49716 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.413892031 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.413995981 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.414009094 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.971764088 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.972722054 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.994713068 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.994760036 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.994980097 CEST | 49716 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.995006084 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:09.995198011 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:09.995210886 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:10.552916050 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:10.552987099 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:10.553039074 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:10.553560019 CEST | 49717 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:10.553581953 CEST | 443 | 49717 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:12.084816933 CEST | 80 | 49705 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:12.084860086 CEST | 80 | 49706 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:12.084964991 CEST | 49705 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:12.084965944 CEST | 49706 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:12.461560011 CEST | 49705 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:12.461591005 CEST | 49706 | 80 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:12.737246037 CEST | 80 | 49705 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:12.737272978 CEST | 80 | 49706 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:18.488723993 CEST | 49721 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:06:18.488770962 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:18.489094973 CEST | 49721 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:06:18.489706039 CEST | 49721 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:06:18.489723921 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:18.802654982 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:18.802973032 CEST | 49721 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:06:18.803005934 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:28.848104000 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:28.848160028 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:28.848359108 CEST | 49721 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:06:29.441209078 CEST | 49721 | 443 | 192.168.2.5 | 142.250.69.4 |
Apr 23, 2025 17:06:29.441250086 CEST | 443 | 49721 | 142.250.69.4 | 192.168.2.5 |
Apr 23, 2025 17:06:30.265026093 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:30.265110970 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Apr 23, 2025 17:06:30.265175104 CEST | 49716 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:30.453583002 CEST | 49716 | 443 | 192.168.2.5 | 156.227.0.99 |
Apr 23, 2025 17:06:30.453609943 CEST | 443 | 49716 | 156.227.0.99 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 23, 2025 17:05:14.255357981 CEST | 53 | 49626 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:14.257523060 CEST | 53 | 53974 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:15.457307100 CEST | 53 | 50042 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:18.421247959 CEST | 59162 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 23, 2025 17:05:18.421474934 CEST | 52128 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 23, 2025 17:05:18.561429977 CEST | 53 | 59162 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:18.561912060 CEST | 53 | 52128 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:19.371000051 CEST | 61301 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 23, 2025 17:05:19.371321917 CEST | 64505 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 23, 2025 17:05:19.385654926 CEST | 51567 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 23, 2025 17:05:19.385976076 CEST | 60346 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 23, 2025 17:05:19.893341064 CEST | 53 | 60346 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:19.893579960 CEST | 53 | 51567 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:19.894259930 CEST | 53 | 64505 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:19.895339966 CEST | 53 | 61301 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:32.453816891 CEST | 53 | 65190 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:05:51.313374996 CEST | 53 | 58602 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:06:09.336486101 CEST | 138 | 138 | 192.168.2.5 | 192.168.2.255 |
Apr 23, 2025 17:06:13.905126095 CEST | 53 | 54693 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:06:13.967478991 CEST | 53 | 51335 | 1.1.1.1 | 192.168.2.5 |
Apr 23, 2025 17:06:17.140429974 CEST | 53 | 51075 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 23, 2025 17:05:18.421247959 CEST | 192.168.2.5 | 1.1.1.1 | 0x3bc0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 23, 2025 17:05:18.421474934 CEST | 192.168.2.5 | 1.1.1.1 | 0x9fe2 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 23, 2025 17:05:19.371000051 CEST | 192.168.2.5 | 1.1.1.1 | 0x1d49 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 23, 2025 17:05:19.371321917 CEST | 192.168.2.5 | 1.1.1.1 | 0x9217 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 23, 2025 17:05:19.385654926 CEST | 192.168.2.5 | 1.1.1.1 | 0x2c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 23, 2025 17:05:19.385976076 CEST | 192.168.2.5 | 1.1.1.1 | 0x773 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 23, 2025 17:05:18.561429977 CEST | 1.1.1.1 | 192.168.2.5 | 0x3bc0 | No error (0) | 142.250.69.4 | A (IP address) | IN (0x0001) | false | ||
Apr 23, 2025 17:05:18.561912060 CEST | 1.1.1.1 | 192.168.2.5 | 0x9fe2 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 23, 2025 17:05:19.893579960 CEST | 1.1.1.1 | 192.168.2.5 | 0x2c7 | No error (0) | 156.227.0.99 | A (IP address) | IN (0x0001) | false | ||
Apr 23, 2025 17:05:19.895339966 CEST | 1.1.1.1 | 192.168.2.5 | 0x1d49 | No error (0) | 156.227.0.99 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49705 | 156.227.0.99 | 80 | 7072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 23, 2025 17:06:05.185801029 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49706 | 156.227.0.99 | 80 | 7072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 23, 2025 17:06:05.185844898 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49704 | 156.227.0.99 | 443 | 7072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-23 15:05:20 UTC | 680 | OUT | |
2025-04-23 15:05:21 UTC | 173 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49713 | 156.227.0.99 | 443 | 7072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-23 15:05:33 UTC | 712 | OUT | |
2025-04-23 15:05:33 UTC | 173 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49717 | 156.227.0.99 | 443 | 7072 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-23 15:06:09 UTC | 712 | OUT | |
2025-04-23 15:06:10 UTC | 173 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 11:05:08 |
Start date: | 23/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff695ee0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 11:05:12 |
Start date: | 23/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff695ee0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 11:05:15 |
Start date: | 23/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff695ee0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 11:05:18 |
Start date: | 23/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff695ee0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |