Windows
Analysis Report
http://Twx.remoteservice.navify.com
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 4040 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 4468 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2272,i ,138761644 1093977932 9,18436548 2663668707 11,262144 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --va riations-s eed-versio n --mojo-p latform-ch annel-hand le=2308 /p refetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7012 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://Twx.re moteservic e.navify.c om" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
twx.remoteservice.navify.com | 193.58.155.1 | true | false | high | |
www.google.com | 142.250.69.4 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.69.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
193.58.155.1 | twx.remoteservice.navify.com | Switzerland | 208031 | MAZAYANETPS | false |
IP |
---|
192.168.2.16 |
192.168.2.6 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1674321 |
Start date and time: | 2025-04-25 19:04:57 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://Twx.remoteservice.navify.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@24/8@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe, Text InputHost.exe - Excluded IPs from analysis (wh
itelisted): 142.250.69.3, 192. 178.49.174, 142.251.2.84, 192. 178.49.206, 192.178.49.202, 19 2.178.49.170, 142.250.69.10, 1 42.250.68.234, 199.232.214.172 , 192.178.49.163, 142.250.68.2 27, 184.29.183.29, 20.12.23.50 - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, accounts.google.com, conte nt-autofill.googleapis.com, sl scr.update.microsoft.com, ctld l.windowsupdate.com, clientser vices.googleapis.com, fe3cr.de livery.mp.microsoft.com, clien ts2.google.com, edgedl.me.gvt1 .com, redirector.gvt1.com, upd ate.googleapis.com, clients.l. google.com, c.pki.goog - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data. - VT rate limit hit for: http:/
/Twx.remoteservice.navify.com
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 386 |
Entropy (8bit): | 5.2873892587518645 |
Encrypted: | false |
SSDEEP: | 12:hnMEwuiuX4wpBk6Qclfhe/FNOHqQRCXxcRyQL:hMNmlBkspe/dQRC0 |
MD5: | F427265F7A93565B8AD98838F4EA719A |
SHA1: | 94A6B12710EB70E4D14AF457D1204820EF1C8B74 |
SHA-256: | 6EA478C07F1143D03F05F47C3F63980B2CB0F1C51EE43F08ECD5D4FE6C2887B3 |
SHA-512: | 295F584E257DC0B4D5D8B0F1328A213D0089A07A2F486B761C7800956DBF2D7F7DB89514FD9B5CE872E0A519C41F822F6A09FEF944E448CBD43E81124B373279 |
Malicious: | false |
Reputation: | low |
URL: | https://twx.remoteservice.navify.com/Thingworx/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.875 |
Encrypted: | false |
SSDEEP: | 3:HDf:jf |
MD5: | 1F4E7CC6A67AD8F2A3EA6C11F0CBDAB3 |
SHA1: | F9D1CECBEA21D9D48D751A22CAAE8E1698F1E6D2 |
SHA-256: | 90BBC4E215B563FAF384ADA0239FDAE3A180D1D3720A490770AB7AC676AA86B3 |
SHA-512: | 7182840C8F22E50BA2C61E4D3EF13A105AABE3610443E8CB40005DA9A691051A2321D56B993D57B6FC1A105E25F0333E364A60479AE0B25338A8AE0867319A86 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCRtDZ49VZjznEgUNXUy4VSEzd7zn0poPMQ==?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 439 |
Entropy (8bit): | 5.3005069836649925 |
Encrypted: | false |
SSDEEP: | 6:qTthqzcqHCamX6jHzKRwszpuEIRuL5loXFNRXuRYA/bRIM2PLVe/NX96lEUHCaR:qTOUdgH/sI0llokRt/Jq5e/mefu |
MD5: | 9A389F3F53BA43A8B3581E929D777635 |
SHA1: | 197CFE06BD69F659584808FE320E37D066EEEB41 |
SHA-256: | E2DF620FF6C76C6529734638E25E9163D8D70F45DF5D3D5807E8D635FA4F3487 |
SHA-512: | B535DFB71D51624506EE765F2C652AC9DFB788D702AFA447B4233B4FF8182AECDD8CFCF994F41A1103EB5D115DE705E90C7575DF8F9A7B46F0CEF334439F3ACC |
Malicious: | false |
Reputation: | low |
URL: | https://twx.remoteservice.navify.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 22215 |
Entropy (8bit): | 5.065677782130981 |
Encrypted: | false |
SSDEEP: | 384:nIna2Y4EyaWtY3bI09rcES8QNQcZSjIaHDbHhmhXkk4ByjEl/u0z8c3zxZlYlyxD:CP1tY3U09nZQN103/g6Wj6W0zf3z9zd |
MD5: | B81269AA73A4B1158BACC7BA72598FB3 |
SHA1: | 872B74AA59BF8FF1C51777AEED3BF614EDEFE455 |
SHA-256: | 9604F100D025A3A2FBFB3BE72DF7A95208BA0BC899B26D116FB1015D4D20853F |
SHA-512: | 5E76F2E165CBD07FD6A3D8B60E6F8C6BF7FF1784E7E09961B3651AFA680493245ADB3FAEE03F370246DA53AF3E932A35CFA870EF085A7759C17FC3C67398BAA0 |
Malicious: | false |
Reputation: | low |
URL: | https://twx.remoteservice.navify.com/Thingworx/Home |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 110
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 25, 2025 19:05:51.112726927 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:05:51.425769091 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:05:52.035157919 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:05:53.238293886 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:05:55.800782919 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:05:59.645370007 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:05:59.957560062 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:06:00.287837029 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:00.287875891 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:00.287938118 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:00.288271904 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:00.288285017 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:00.566953897 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:06:00.609313965 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:00.609379053 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:00.610533953 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:00.610543013 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:00.610788107 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:00.613802910 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:06:00.660675049 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:01.714469910 CEST | 49697 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:01.714956045 CEST | 49698 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:01.719676971 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:01.719712019 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.723444939 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:01.723711014 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:01.723725080 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.772263050 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:06:01.854347944 CEST | 80 | 49697 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.854460001 CEST | 49697 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:01.854742050 CEST | 80 | 49698 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.854804993 CEST | 49698 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.018884897 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.018961906 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.024024963 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.024044037 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.024336100 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.026093960 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.068279028 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.937694073 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.937854052 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.937918901 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.938314915 CEST | 49699 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.938333988 CEST | 443 | 49699 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.940535069 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.940562963 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:02.940690041 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.940932035 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:02.940943003 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.229913950 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.230134964 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.230165958 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.230267048 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.230273008 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.995999098 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.996068954 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.996124029 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.996830940 CEST | 49700 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.996848106 CEST | 443 | 49700 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.998966932 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.999018908 CEST | 443 | 49701 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:03.999115944 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.999253035 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:03.999270916 CEST | 443 | 49701 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.178864956 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:06:04.290256023 CEST | 443 | 49701 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.290580034 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.290612936 CEST | 443 | 49701 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.290846109 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.290852070 CEST | 443 | 49701 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.553716898 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.553823948 CEST | 443 | 49701 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.553916931 CEST | 49701 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.556350946 CEST | 49697 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.696355104 CEST | 80 | 49697 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.713928938 CEST | 80 | 49697 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.716201067 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.716249943 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.716346979 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.716495991 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:04.716511011 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:04.754690886 CEST | 49697 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.006083965 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.006170988 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.010526896 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.010543108 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.010809898 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.011322975 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.052280903 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.524966002 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.525300026 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.527439117 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.527445078 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.527478933 CEST | 443 | 49703 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.527492046 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.527580023 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.527601957 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.527601957 CEST | 49703 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.527754068 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.527761936 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.818289995 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.818717003 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.818742037 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:05.819324017 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:05.819329023 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.612951994 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.613018990 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.613094091 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.613454103 CEST | 49704 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.613468885 CEST | 443 | 49704 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.618217945 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.618251085 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.618311882 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.618486881 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.618496895 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.913260937 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.913562059 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.913580894 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:06.913727045 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:06.913732052 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.395391941 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.395528078 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.395577908 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.438581944 CEST | 49705 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.438621998 CEST | 443 | 49705 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.499762058 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.499816895 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.499872923 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.500096083 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.500143051 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.500288010 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.500462055 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.500473022 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.500691891 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.500703096 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.790914059 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.791177988 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.791225910 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.791263103 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.791366100 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.791393042 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.791503906 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.791511059 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:07.791565895 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:07.791572094 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.157373905 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.157490015 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.157552958 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.161842108 CEST | 49706 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.161870003 CEST | 443 | 49706 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238460064 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238528967 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238575935 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238579988 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.238609076 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238643885 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.238651991 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238693953 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238733053 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.238739967 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.238990068 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239033937 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239032984 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.239047050 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239089012 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.239097118 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239861012 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239897013 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239916086 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.239926100 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.239962101 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.239968061 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.240504980 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.240542889 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.240550041 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.240628958 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.240668058 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.341195107 CEST | 49707 | 443 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:08.341231108 CEST | 443 | 49707 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.982414007 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:06:09.940064907 CEST | 49714 | 80 | 192.168.2.6 | 192.178.49.195 |
Apr 25, 2025 19:06:10.089519978 CEST | 80 | 49714 | 192.178.49.195 | 192.168.2.6 |
Apr 25, 2025 19:06:10.093410969 CEST | 49714 | 80 | 192.168.2.6 | 192.178.49.195 |
Apr 25, 2025 19:06:10.093772888 CEST | 49714 | 80 | 192.168.2.6 | 192.178.49.195 |
Apr 25, 2025 19:06:10.223210096 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Apr 25, 2025 19:06:10.241758108 CEST | 80 | 49714 | 192.178.49.195 | 192.168.2.6 |
Apr 25, 2025 19:06:10.242207050 CEST | 80 | 49714 | 192.178.49.195 | 192.168.2.6 |
Apr 25, 2025 19:06:10.285696030 CEST | 49714 | 80 | 192.168.2.6 | 192.178.49.195 |
Apr 25, 2025 19:06:10.590512991 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:10.590569973 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:10.590703011 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:11.209881067 CEST | 49694 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:06:11.209913015 CEST | 443 | 49694 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:06:16.996480942 CEST | 80 | 49698 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:16.996578932 CEST | 49698 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:17.224865913 CEST | 49698 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:17.365246058 CEST | 80 | 49698 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:06:18.582748890 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Apr 25, 2025 19:06:49.723839998 CEST | 49697 | 80 | 192.168.2.6 | 193.58.155.1 |
Apr 25, 2025 19:06:49.863821983 CEST | 80 | 49697 | 193.58.155.1 | 192.168.2.6 |
Apr 25, 2025 19:07:00.209003925 CEST | 49719 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:07:00.209038973 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:07:00.209093094 CEST | 49719 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:07:00.209275007 CEST | 49719 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:07:00.209296942 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:07:00.523330927 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:07:00.523730993 CEST | 49719 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:07:00.523766041 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:07:10.395797968 CEST | 49714 | 80 | 192.168.2.6 | 192.178.49.195 |
Apr 25, 2025 19:07:10.513448954 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:07:10.513505936 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Apr 25, 2025 19:07:10.513578892 CEST | 49719 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:07:10.543981075 CEST | 80 | 49714 | 192.178.49.195 | 192.168.2.6 |
Apr 25, 2025 19:07:10.544074059 CEST | 49714 | 80 | 192.168.2.6 | 192.178.49.195 |
Apr 25, 2025 19:07:11.210236073 CEST | 49719 | 443 | 192.168.2.6 | 142.250.69.4 |
Apr 25, 2025 19:07:11.210268974 CEST | 443 | 49719 | 142.250.69.4 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 25, 2025 19:05:56.055205107 CEST | 53 | 58370 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:05:56.075093985 CEST | 53 | 63906 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:05:57.436077118 CEST | 53 | 58834 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:00.146440983 CEST | 55520 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 25, 2025 19:06:00.146692038 CEST | 59555 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 25, 2025 19:06:00.286724091 CEST | 53 | 55520 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:00.286786079 CEST | 53 | 59555 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.552041054 CEST | 65319 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 25, 2025 19:06:01.552336931 CEST | 55698 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 25, 2025 19:06:01.568778038 CEST | 65103 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 25, 2025 19:06:01.568989992 CEST | 52502 | 53 | 192.168.2.6 | 1.1.1.1 |
Apr 25, 2025 19:06:01.706752062 CEST | 53 | 55698 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.710124016 CEST | 53 | 65319 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.711189032 CEST | 53 | 65103 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:01.716177940 CEST | 53 | 52502 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:08.864984989 CEST | 53 | 53897 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:14.443190098 CEST | 53 | 65293 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:33.333275080 CEST | 53 | 51707 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:55.602910995 CEST | 53 | 52295 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:55.803257942 CEST | 53 | 55299 | 1.1.1.1 | 192.168.2.6 |
Apr 25, 2025 19:06:57.730135918 CEST | 138 | 138 | 192.168.2.6 | 192.168.2.255 |
Apr 25, 2025 19:06:58.755840063 CEST | 53 | 59862 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 25, 2025 19:06:00.146440983 CEST | 192.168.2.6 | 1.1.1.1 | 0x778c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 25, 2025 19:06:00.146692038 CEST | 192.168.2.6 | 1.1.1.1 | 0x9d3b | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 25, 2025 19:06:01.552041054 CEST | 192.168.2.6 | 1.1.1.1 | 0x5397 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 25, 2025 19:06:01.552336931 CEST | 192.168.2.6 | 1.1.1.1 | 0xcc18 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 25, 2025 19:06:01.568778038 CEST | 192.168.2.6 | 1.1.1.1 | 0xbd6e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 25, 2025 19:06:01.568989992 CEST | 192.168.2.6 | 1.1.1.1 | 0xf3eb | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 25, 2025 19:06:00.286724091 CEST | 1.1.1.1 | 192.168.2.6 | 0x778c | No error (0) | 142.250.69.4 | A (IP address) | IN (0x0001) | false | ||
Apr 25, 2025 19:06:00.286786079 CEST | 1.1.1.1 | 192.168.2.6 | 0x9d3b | No error (0) | 65 | IN (0x0001) | false | |||
Apr 25, 2025 19:06:01.710124016 CEST | 1.1.1.1 | 192.168.2.6 | 0x5397 | No error (0) | 193.58.155.1 | A (IP address) | IN (0x0001) | false | ||
Apr 25, 2025 19:06:01.711189032 CEST | 1.1.1.1 | 192.168.2.6 | 0xbd6e | No error (0) | 193.58.155.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49697 | 193.58.155.1 | 80 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 25, 2025 19:06:04.556350946 CEST | 443 | OUT | |
Apr 25, 2025 19:06:04.713928938 CEST | 499 | IN | |
Apr 25, 2025 19:06:49.723839998 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.6 | 49714 | 192.178.49.195 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 25, 2025 19:06:10.093772888 CEST | 200 | OUT | |
Apr 25, 2025 19:06:10.242207050 CEST | 1242 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49699 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:02 UTC | 678 | OUT | |
2025-04-25 17:06:02 UTC | 277 | IN | |
2025-04-25 17:06:02 UTC | 144 | IN | |
2025-04-25 17:06:02 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49700 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:03 UTC | 687 | OUT | |
2025-04-25 17:06:03 UTC | 382 | IN | |
2025-04-25 17:06:03 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49701 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:04 UTC | 761 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49703 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:05 UTC | 751 | OUT | |
2025-04-25 17:06:05 UTC | 277 | IN | |
2025-04-25 17:06:05 UTC | 144 | IN | |
2025-04-25 17:06:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49704 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:05 UTC | 760 | OUT | |
2025-04-25 17:06:06 UTC | 264 | IN | |
2025-04-25 17:06:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49705 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:06 UTC | 761 | OUT | |
2025-04-25 17:06:07 UTC | 478 | IN | |
2025-04-25 17:06:07 UTC | 393 | IN | |
2025-04-25 17:06:07 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49707 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:07 UTC | 810 | OUT | |
2025-04-25 17:06:08 UTC | 385 | IN | |
2025-04-25 17:06:08 UTC | 984 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN | |
2025-04-25 17:06:08 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49706 | 193.58.155.1 | 443 | 4468 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-25 17:06:07 UTC | 702 | OUT | |
2025-04-25 17:06:08 UTC | 376 | IN | |
2025-04-25 17:06:08 UTC | 446 | IN | |
2025-04-25 17:06:08 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 13:05:51 |
Start date: | 25/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 13:05:54 |
Start date: | 25/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 12 |
Start time: | 13:06:00 |
Start date: | 25/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |