Windows
Analysis Report
https://security.microsoft.com/url?url=https%3A%2F%2Facrobat.adobe.com%2Fid%2Furn%3Aaaid%3Asc%3AEU%3Aeafa7db4-a870-4976-bc32-05395f2fb53a
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 6228 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 7060 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1972,i ,927655674 6409924089 ,171069215 9050839235 8,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2008 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6152 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= printing.m ojom.Unsan dboxedPrin tBackendHo st --lang= en-US --se rvice-sand box-type=n one --no-p re-read-ma in-dll --f ield-trial -handle=19 72,i,92765 5674640992 4089,17106 9215905083 92358,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction - -variation s-seed-ver sion=20250 306-183004 .429000 -- mojo-platf orm-channe l-handle=5 020 /prefe tch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7292 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://secur ity.micros oft.com/ur l?url=http s%3A%2F%2F acrobat.ad obe.com%2F id%2Furn%3 Aaaid%3Asc %3AEU%3Aea fa7db4-a87 0-4976-bc3 2-05395f2f b53a" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
e329293.dscd.akamaiedge.net | 23.62.226.164 | true | false | high | |
www.google.com | 192.178.49.196 | true | false | high | |
www.tm.a.prd.aadg.akadns.net | 40.126.62.130 | true | false | high | |
s-part-0043.t-0009.t-msedge.net | 13.107.246.71 | true | false | high | |
a1894.dscb.akamai.net | 23.55.241.136 | true | false | high | |
www.tm.a.prd.aadg.trafficmanager.net | 20.190.151.67 | true | false | high | |
identity.nel.measure.office.net | unknown | unknown | false | high | |
aadcdn.msftauth.net | unknown | unknown | false | high | |
login.microsoftonline.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
192.178.49.196 | www.google.com | United States | 15169 | GOOGLEUS | false | |
40.126.62.130 | www.tm.a.prd.aadg.akadns.net | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
23.55.241.136 | a1894.dscb.akamai.net | United States | 20940 | AKAMAI-ASN1EU | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1676169 |
Start date and time: | 2025-04-28 12:10:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://security.microsoft.com/url?url=https%3A%2F%2Facrobat.adobe.com%2Fid%2Furn%3Aaaid%3Asc%3AEU%3Aeafa7db4-a870-4976-bc32-05395f2fb53a |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@24/35@12/4 |
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, conhost.exe, svc host.exe - Excluded IPs from analysis (wh
itelisted): 23.220.73.6, 142.2 50.188.238, 142.250.72.163, 19 2.178.49.174, 142.250.141.84, 192.178.49.206, 13.107.6.192, 20.190.151.68, 20.190.151.134, 20.190.151.133, 142.250.68.23 4, 192.178.49.170, 142.250.69. 10, 192.178.49.202, 172.217.12 .142, 142.251.40.46, 142.250.6 8.227, 20.42.73.27, 52.168.117 .175, 20.190.151.67, 20.190.15 1.132, 20.190.151.131, 20.190. 151.8, 20.190.151.9, 184.29.18 3.29, 69.192.44.226, 13.107.24 6.71, 4.175.87.197 - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//security.microsoft.com/url?u rl=https%3A%2F%2Facrobat.adobe .com%2Fid%2Furn%3Aaaid%3Asc%3A EU%3Aeafa7db4-a870-4976-bc32-0 5395f2fb53a
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 61052 |
Entropy (8bit): | 7.996159932827634 |
Encrypted: | true |
SSDEEP: | 1536:HQaq1Q7XOos5ZBIp+1Zr52IGmCJijm1qAxTe9wzf:fq1HoUBIpU5TG7JSmwuTe+b |
MD5: | C1E82BF71ADD622AD0F3BF8572F634FC |
SHA1: | 6CA863D4CAB96669202548D301693B3F5F80B0D5 |
SHA-256: | BA48AF15D297DB450DC4870242482145ADDB2D18375A4871C490429E2DC5464A |
SHA-512: | 820A7F8A0C8EA33A8FE1E90CDC35F45DC1E143E836B0D8EA047E1E312F8CAEC72CDEE4E7DB54760A4D749CD0ACFE103A27E39A9A56EB2D704E448A67B0D0C079 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1435 |
Entropy (8bit): | 7.8613342322590265 |
Encrypted: | false |
SSDEEP: | 24:XjtSZi0kq+yVCGYXVrO4vDxik/N/z5VaLPbholJvf6dblke68eRZJyBDz3BnZcNX:XgDkpyVCGca4b//9z5oPXdbl9688qRzY |
MD5: | 9F368BC4580FED907775F31C6B26D6CF |
SHA1: | E393A40B3E337F43057EEE3DE189F197AB056451 |
SHA-256: | 7ECBBA946C099539C3D9C03F4B6804958900E5B90D48336EEA7E5A2ED050FA36 |
SHA-512: | 0023B04D1EEC26719363AED57C95C1A91244C5AFF0BB53091938798FB16E230680E1F972D166B633C1D2B314B34FE0B9D7C18442410DB7DD6024E279AAFD61B0 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1435 |
Entropy (8bit): | 7.8613342322590265 |
Encrypted: | false |
SSDEEP: | 24:XjtSZi0kq+yVCGYXVrO4vDxik/N/z5VaLPbholJvf6dblke68eRZJyBDz3BnZcNX:XgDkpyVCGca4b//9z5oPXdbl9688qRzY |
MD5: | 9F368BC4580FED907775F31C6B26D6CF |
SHA1: | E393A40B3E337F43057EEE3DE189F197AB056451 |
SHA-256: | 7ECBBA946C099539C3D9C03F4B6804958900E5B90D48336EEA7E5A2ED050FA36 |
SHA-512: | 0023B04D1EEC26719363AED57C95C1A91244C5AFF0BB53091938798FB16E230680E1F972D166B633C1D2B314B34FE0B9D7C18442410DB7DD6024E279AAFD61B0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 35168 |
Entropy (8bit): | 7.993219152622706 |
Encrypted: | true |
SSDEEP: | 768:j6PfHtcQsNe72gH9i6EndaklFS0VBrXFm4soWu7VOYpRf0WL/:5xoCgH9i6EFFhrXFmUW4JpRc+/ |
MD5: | E9745F803E3FBA8FA0CC8C1E6E4506C6 |
SHA1: | 87E8B2D2F29CB42BAD597390234F66745642D080 |
SHA-256: | D5496BC436AAD08CCA3F391A3CA8D7DAFC076B081567511A8B1358F860DA8003 |
SHA-512: | C74C91DD85D312ED34E2275E13AC778E186581BF43F70B379C3B370755AF46EDA4EE0FE1C52997385848084C90CE2466AB3E7F71D9A2EBE1B6BB85AD0FB66AD6 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_4f75990aeef30238698e.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 124082 |
Entropy (8bit): | 7.9975238263371935 |
Encrypted: | true |
SSDEEP: | 3072:6WGkF9qkuami5zUIL2+MdueBQzQR14h4STyAKTey8Pd/Y8L1B0:fFfX5LMdpQzqSh4STyAKTedPd/Y8A |
MD5: | 36ACAEABB66EB3389B8BBA56FF4F9BAF |
SHA1: | 9E85A77464893DBC5B5791BDB0219C01A9136AC9 |
SHA-256: | E4F3CC8D144B38F1B49FE19F8B15A75E988C3693D1AD59B25E7943F8FA70C571 |
SHA-512: | F79ABAB6F7E40DA2AD6131276DE6DC86EDA6229730BC427D261DD2B168BCB9EA80045605D54296985A1436FE8B94CBDC87A207AF2398E9AF289A95C4AE867070 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/ConvergedLogin_PCore_EA9_0LNszQ27kSRR18wFAw2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 50005 |
Entropy (8bit): | 7.995240163178497 |
Encrypted: | true |
SSDEEP: | 1536:JxgptniuBMYzToxuuJ2N+YmXUlf9LFYI1k:JehBhmuq2N+YJlkgk |
MD5: | 384EEF4959483B40CCFF18C8B269B794 |
SHA1: | C359F400CE19D445AF3DB8AEFC6447148194836B |
SHA-256: | 9F44936C83C55C9870458CCCEBAF44FF9AD9E22F0C411F4CBA05EA565C7A9067 |
SHA-512: | C593AE92C6ED49E70ACCA13CEFEB3351EBCA7CFA1F94F55C64A89FEDCBC1267D6003355FBC8381E3C8D253836A39BE7D823B10F4933F917A723596E9BBE6CB4B |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/BssoInterrupt_Core_bazYuVH6rF7OQmuNhACwPg2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 621 |
Entropy (8bit): | 7.673946009263606 |
Encrypted: | false |
SSDEEP: | 12:Xp7fmqfW/e4YC2L0E5DZLB62y/+6lbPa1Gotq8mdd2Xmy2QLBwxD+QkCfBJ:Xp6qf2SCk3LBpy/rtPa1GKq8mOX5jLcD |
MD5: | 4761405717E938D7E7400BB15715DB1E |
SHA1: | 76FED7C229D353A27DB3257F5927C1EAF0AB8DE9 |
SHA-256: | F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF |
SHA-512: | E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16714 |
Entropy (8bit): | 7.987160006931144 |
Encrypted: | false |
SSDEEP: | 384:TplwL5Bt/vaGc5eK6IaRSSzjnl0Y6kxKNUb6ptH:wL5riGcacQjnKk+vr |
MD5: | 878F0134D5623C12145B3C539CCB0A31 |
SHA1: | 8DA453BA5ACE4E06F9E3599DD765E1E2C8D17AA9 |
SHA-256: | FDE7337DB19DC211784EEEE2AAD0856785D1A940C2EA73A6E6B6659233D3AFC7 |
SHA-512: | 73C1C7735E6A442CB54CC2818B5004201AB556737B35FDA1064EEC8430BF9B2F012AA3B32F04350A8C3B9AEC1821B75548FCE9C36EB4354C57AA3BC3074E08E7 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_l8i1wwom7wbodda4l9b6dw2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 621 |
Entropy (8bit): | 7.673946009263606 |
Encrypted: | false |
SSDEEP: | 12:Xp7fmqfW/e4YC2L0E5DZLB62y/+6lbPa1Gotq8mdd2Xmy2QLBwxD+QkCfBJ:Xp6qf2SCk3LBpy/rtPa1GKq8mOX5jLcD |
MD5: | 4761405717E938D7E7400BB15715DB1E |
SHA1: | 76FED7C229D353A27DB3257F5927C1EAF0AB8DE9 |
SHA-256: | F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF |
SHA-512: | E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3620 |
Entropy (8bit): | 6.867828878374734 |
Encrypted: | false |
SSDEEP: | 48:ZumKaT5ezv47j2/ZiRDlq16x8XvEUcg777shHdpHVGJqFd:Eal647jPDlL8XvEUcg77kVGyd |
MD5: | B540A8E518037192E32C4FE58BF2DBAB |
SHA1: | 3047C1DB97B86F6981E0AD2F96AF40CDF43511AF |
SHA-256: | 8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D |
SHA-512: | E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 100 |
Entropy (8bit): | 5.139401470035981 |
Encrypted: | false |
SSDEEP: | 3:LiczUCWdLmwkMKXZIwPiFXuGFrgMBdrY:LiczidLmR1Pitu/KM |
MD5: | FF2300A7D8C46BBBCDBCE2F5F39F0B3B |
SHA1: | F3E190506568515BF088594BBB6C11ED2762C1E7 |
SHA-256: | 123C9BC8E48555D7739BFEC27A2567E8C6CFE558BBCA79A31A7DFFC75ABFCCC6 |
SHA-512: | E6AF264DAC46295945146F6B0F2C6698A549BC682DA1B0AB085A7F6EDF8F49FAE62D3DCA8505EB64BDD96CE4A15EF9CA412E7E31C1AEF9804FE50ED8AC10B97B |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIgCYICaXLWAdtdEgUN0VtRUhIFDVd69_0h5O4-ZHSZs-k=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 673 |
Entropy (8bit): | 7.6596900876595075 |
Encrypted: | false |
SSDEEP: | 12:Xl0t8TUViiYi5m6FhSBXWPsigK99WCqKMvBBFThSqfLd81CK6bC+k7LqZLsFlD:XFUVpkNK0Rwid81p6btk7LqZ6D |
MD5: | 0E176276362B94279A4492511BFCBD98 |
SHA1: | 389FE6B51F62254BB98939896B8C89EBEFFE2A02 |
SHA-256: | 9A2C174AE45CAC057822844211156A5ED293E65C5F69E1D211A7206472C5C80C |
SHA-512: | 8D61C9E464C8F3C77BF1729E32F92BBB1B426A19907E418862EFE117DBD1F0A26FCC3A6FE1D1B22B836853D43C964F6B6D25E414649767FBEA7FE10D2048D7A1 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2672 |
Entropy (8bit): | 6.640973516071413 |
Encrypted: | false |
SSDEEP: | 48:ZaOdwduTYPpS9pZy9vDNi1miicsvrJkafMiS+MGQ09DU/X9/4Xp6m5Z9SQcq:4CIuTYPpSTc9vcPZX9/2gzQ/ |
MD5: | 166DE53471265253AB3A456DEFE6DA23 |
SHA1: | 17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D |
SHA-256: | A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13 |
SHA-512: | 80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.241202481433726 |
Encrypted: | false |
SSDEEP: | 3:YozDD/RNgQJzRWWlKFiFD3e4xCzY:YovtNgmzR/wYFDxkY |
MD5: | 9E576E34B18E986347909C29AE6A82C6 |
SHA1: | 532C767978DC2B55854B3CA2D2DF5B4DB221C934 |
SHA-256: | 88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D |
SHA-512: | 5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 20410 |
Entropy (8bit): | 7.980582012022051 |
Encrypted: | false |
SSDEEP: | 384:8RvmaMFysnOXZ2m9zM+udO6GGUpeAU02oDGnN5EsQwWUQGTS8r2k:8pmm7ZFM+ObGGUIjN5PJV3Tp |
MD5: | 3BA4D76A17ADD0A6C34EE696F28C8541 |
SHA1: | 5E8A4B8334539A7EAB798A7799F6E232016CB263 |
SHA-256: | 17D6FF63DD857A72F37292B5906B40DC087EA27D7B1DEFCFA6DD1BA82AEA0B59 |
SHA-512: | 8DA16A9759BB68A6B408F9F274B882ABB3EE7BA19F888448E495B721094BDB2CE5664E9A26BAE306A00491235EB94C143E53F618CCD6D50307C3C7F2EF1B4455 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_81imvbluez-v5hbzpkxfcg2.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2672 |
Entropy (8bit): | 6.640973516071413 |
Encrypted: | false |
SSDEEP: | 48:ZaOdwduTYPpS9pZy9vDNi1miicsvrJkafMiS+MGQ09DU/X9/4Xp6m5Z9SQcq:4CIuTYPpSTc9vcPZX9/2gzQ/ |
MD5: | 166DE53471265253AB3A456DEFE6DA23 |
SHA1: | 17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D |
SHA-256: | A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13 |
SHA-512: | 80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 673 |
Entropy (8bit): | 7.6596900876595075 |
Encrypted: | false |
SSDEEP: | 12:Xl0t8TUViiYi5m6FhSBXWPsigK99WCqKMvBBFThSqfLd81CK6bC+k7LqZLsFlD:XFUVpkNK0Rwid81p6btk7LqZ6D |
MD5: | 0E176276362B94279A4492511BFCBD98 |
SHA1: | 389FE6B51F62254BB98939896B8C89EBEFFE2A02 |
SHA-256: | 9A2C174AE45CAC057822844211156A5ED293E65C5F69E1D211A7206472C5C80C |
SHA-512: | 8D61C9E464C8F3C77BF1729E32F92BBB1B426A19907E418862EFE117DBD1F0A26FCC3A6FE1D1B22B836853D43C964F6B6D25E414649767FBEA7FE10D2048D7A1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3620 |
Entropy (8bit): | 6.867828878374734 |
Encrypted: | false |
SSDEEP: | 48:ZumKaT5ezv47j2/ZiRDlq16x8XvEUcg777shHdpHVGJqFd:Eal647jPDlL8XvEUcg77kVGyd |
MD5: | B540A8E518037192E32C4FE58BF2DBAB |
SHA1: | 3047C1DB97B86F6981E0AD2F96AF40CDF43511AF |
SHA-256: | 8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D |
SHA-512: | E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | 24:QSNTmTFxg4lyyyyyyyyyyyyyio7eeeeeeeeekzgsLsLsLsLsLsQZp:nfgyyyyyyyyyyyyynzQQQQQO |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 116364 |
Entropy (8bit): | 7.997236503670438 |
Encrypted: | true |
SSDEEP: | 3072:7EoTCjm+KsUvGOonzI627JoxMrHDGqMzn4:/Cy+KNvGVns6+MijGTT4 |
MD5: | 991F65CE1AA4809A6ED028BD54B3D1E3 |
SHA1: | 18B2197389C0AE376309E3A5D03CC1C039337685 |
SHA-256: | 3C2C2CFEA40049D60B0BCEA06AE9A3558D0D264B318F06DD180A920774EC6365 |
SHA-512: | 32F2D67286A4A813A3FBC60DA16923D5B210237D39F331244A4ADDB52A9AF66A606E38CE64D219F78A8FBDC20756B42382B136210DE75FF4FE2ED39C154E27F9 |
Malicious: | false |
Reputation: | low |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_41f36656d3c0bb04c90c.js |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 68
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 28, 2025 12:10:58.582998037 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:10:58.895170927 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:10:59.504625082 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:10:59.551471949 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 28, 2025 12:11:00.707664013 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:11:02.387645006 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.35 |
Apr 28, 2025 12:11:02.535661936 CEST | 80 | 49691 | 142.251.40.35 | 192.168.2.5 |
Apr 28, 2025 12:11:02.535737991 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.35 |
Apr 28, 2025 12:11:02.637876987 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.35 |
Apr 28, 2025 12:11:02.785888910 CEST | 80 | 49691 | 142.251.40.35 | 192.168.2.5 |
Apr 28, 2025 12:11:02.786648035 CEST | 80 | 49691 | 142.251.40.35 | 192.168.2.5 |
Apr 28, 2025 12:11:02.832664967 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.35 |
Apr 28, 2025 12:11:03.113925934 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:11:07.926451921 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:11:09.205863953 CEST | 49672 | 443 | 192.168.2.5 | 204.79.197.203 |
Apr 28, 2025 12:11:12.553623915 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:12.553654909 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:12.553806067 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:12.553968906 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:12.553982973 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:12.871644974 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:12.871757984 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:12.872826099 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:12.872837067 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:12.873037100 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:12.927264929 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:17.544562101 CEST | 49676 | 443 | 192.168.2.5 | 20.189.173.14 |
Apr 28, 2025 12:11:18.021699905 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.021728039 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.021789074 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.021920919 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.021934032 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.353882074 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.353956938 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.354976892 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.354985952 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.355184078 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.355432034 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.400266886 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.663597107 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.663758039 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.663809061 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.665224075 CEST | 49712 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.665245056 CEST | 443 | 49712 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.665941954 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.665985107 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.666049957 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.666193008 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.666208029 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.991836071 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.992121935 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.992136002 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.992264986 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.992270947 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:18.992286921 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:18.992297888 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:19.713845015 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:19.713908911 CEST | 443 | 49716 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:11:19.714206934 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:19.714207888 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:19.714260101 CEST | 49716 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:11:22.902811050 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:22.902872086 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:22.902982950 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:23.134233952 CEST | 49701 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:11:23.134260893 CEST | 443 | 49701 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:11:35.145304918 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.145344973 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.145427942 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.145602942 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.145617008 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.581259012 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.581342936 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.582505941 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.582510948 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.582758904 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.583177090 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.583192110 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.911529064 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.911596060 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.911606073 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:11:35.911657095 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.913126945 CEST | 49737 | 443 | 192.168.2.5 | 40.126.62.130 |
Apr 28, 2025 12:11:35.913141012 CEST | 443 | 49737 | 40.126.62.130 | 192.168.2.5 |
Apr 28, 2025 12:12:02.926884890 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.35 |
Apr 28, 2025 12:12:03.074954033 CEST | 80 | 49691 | 142.251.40.35 | 192.168.2.5 |
Apr 28, 2025 12:12:03.075005054 CEST | 49691 | 80 | 192.168.2.5 | 142.251.40.35 |
Apr 28, 2025 12:12:12.486759901 CEST | 49742 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:12:12.486799002 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:12:12.486906052 CEST | 49742 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:12:12.487129927 CEST | 49742 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:12:12.487145901 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:12:12.800842047 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:12:12.801143885 CEST | 49742 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:12:12.801166058 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:12:17.835864067 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:17.835901976 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:17.836016893 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:17.836242914 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:17.836261988 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.169368982 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.169873953 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.169892073 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.169955969 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.169960022 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.489715099 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.489841938 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.489914894 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.490210056 CEST | 49744 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.490221977 CEST | 443 | 49744 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.661322117 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.661354065 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.661449909 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.661550999 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.661567926 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.995642900 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.995937109 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.995964050 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.996108055 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.996113062 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:18.996136904 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:18.996141911 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:19.441868067 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:19.441915989 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:19.442074060 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:19.442161083 CEST | 49746 | 443 | 192.168.2.5 | 23.55.241.136 |
Apr 28, 2025 12:12:19.442174911 CEST | 443 | 49746 | 23.55.241.136 | 192.168.2.5 |
Apr 28, 2025 12:12:22.800288916 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:12:22.800338030 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Apr 28, 2025 12:12:22.800412893 CEST | 49742 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:12:23.619533062 CEST | 49742 | 443 | 192.168.2.5 | 192.178.49.196 |
Apr 28, 2025 12:12:23.619576931 CEST | 443 | 49742 | 192.178.49.196 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 28, 2025 12:11:07.877830029 CEST | 53 | 64733 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:08.100086927 CEST | 53 | 58280 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:09.211806059 CEST | 53 | 57107 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:12.412604094 CEST | 63905 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:12.412724018 CEST | 64918 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:12.552601099 CEST | 53 | 63905 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:12.552771091 CEST | 53 | 64918 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:14.203408957 CEST | 63127 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:14.203562021 CEST | 50291 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:14.344093084 CEST | 53 | 63127 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:14.344160080 CEST | 53 | 50291 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:17.823504925 CEST | 51641 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:17.823916912 CEST | 59523 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:17.998152971 CEST | 53 | 51641 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:18.014585018 CEST | 61243 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:18.014734030 CEST | 55093 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:18.020029068 CEST | 53 | 59523 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:18.154711962 CEST | 53 | 61243 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:18.154758930 CEST | 53 | 55093 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:22.197575092 CEST | 53 | 65515 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:26.286485910 CEST | 53 | 49863 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:34.994895935 CEST | 59998 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:34.995023012 CEST | 64962 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:11:35.135061979 CEST | 53 | 59998 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:35.144604921 CEST | 53 | 64962 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:11:45.219726086 CEST | 53 | 61263 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:12:01.854372978 CEST | 138 | 138 | 192.168.2.5 | 192.168.2.255 |
Apr 28, 2025 12:12:07.790983915 CEST | 53 | 64307 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:12:07.808022022 CEST | 53 | 63527 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:12:11.122008085 CEST | 53 | 53582 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:12:18.491022110 CEST | 62214 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:12:18.491192102 CEST | 50140 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 28, 2025 12:12:18.631897926 CEST | 53 | 62214 | 1.1.1.1 | 192.168.2.5 |
Apr 28, 2025 12:12:18.672082901 CEST | 53 | 50140 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Apr 28, 2025 12:11:18.398917913 CEST | 192.168.2.5 | 1.1.1.1 | c2ce | (Port unreachable) | Destination Unreachable |
Apr 28, 2025 12:12:18.672168970 CEST | 192.168.2.5 | 1.1.1.1 | c285 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 28, 2025 12:11:12.412604094 CEST | 192.168.2.5 | 1.1.1.1 | 0xe0d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 28, 2025 12:11:12.412724018 CEST | 192.168.2.5 | 1.1.1.1 | 0x7680 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 28, 2025 12:11:14.203408957 CEST | 192.168.2.5 | 1.1.1.1 | 0x291b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 28, 2025 12:11:14.203562021 CEST | 192.168.2.5 | 1.1.1.1 | 0xa29 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 28, 2025 12:11:17.823504925 CEST | 192.168.2.5 | 1.1.1.1 | 0x61cc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 28, 2025 12:11:17.823916912 CEST | 192.168.2.5 | 1.1.1.1 | 0x34a6 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 28, 2025 12:11:18.014585018 CEST | 192.168.2.5 | 1.1.1.1 | 0x66af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 28, 2025 12:11:18.014734030 CEST | 192.168.2.5 | 1.1.1.1 | 0x18a6 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 28, 2025 12:11:34.994895935 CEST | 192.168.2.5 | 1.1.1.1 | 0x14ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 28, 2025 12:11:34.995023012 CEST | 192.168.2.5 | 1.1.1.1 | 0xc240 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 28, 2025 12:12:18.491022110 CEST | 192.168.2.5 | 1.1.1.1 | 0x2520 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 28, 2025 12:12:18.491192102 CEST | 192.168.2.5 | 1.1.1.1 | 0x6e81 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 28, 2025 12:11:12.552601099 CEST | 1.1.1.1 | 192.168.2.5 | 0xe0d0 | No error (0) | 192.178.49.196 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:12.552771091 CEST | 1.1.1.1 | 192.168.2.5 | 0x7680 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | login.mso.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | ak.privatelink.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | www.tm.a.prd.aadg.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.67 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.69 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.6 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.9 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.131 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.132 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.8 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344093084 CEST | 1.1.1.1 | 192.168.2.5 | 0x291b | No error (0) | 20.190.151.7 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344160080 CEST | 1.1.1.1 | 192.168.2.5 | 0xa29 | No error (0) | login.mso.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344160080 CEST | 1.1.1.1 | 192.168.2.5 | 0xa29 | No error (0) | ak.privatelink.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:14.344160080 CEST | 1.1.1.1 | 192.168.2.5 | 0xa29 | No error (0) | www.tm.a.prd.aadg.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:15.680129051 CEST | 1.1.1.1 | 192.168.2.5 | 0x7cf5 | No error (0) | s-part-0043.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:15.680129051 CEST | 1.1.1.1 | 192.168.2.5 | 0x7cf5 | No error (0) | 13.107.246.71 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:17.998152971 CEST | 1.1.1.1 | 192.168.2.5 | 0x61cc | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:17.998152971 CEST | 1.1.1.1 | 192.168.2.5 | 0x61cc | No error (0) | a1894.dscb.akamai.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:17.998152971 CEST | 1.1.1.1 | 192.168.2.5 | 0x61cc | No error (0) | 23.55.241.136 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:17.998152971 CEST | 1.1.1.1 | 192.168.2.5 | 0x61cc | No error (0) | 23.55.241.139 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.020029068 CEST | 1.1.1.1 | 192.168.2.5 | 0x34a6 | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.020029068 CEST | 1.1.1.1 | 192.168.2.5 | 0x34a6 | No error (0) | a1894.dscb.akamai.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154711962 CEST | 1.1.1.1 | 192.168.2.5 | 0x66af | No error (0) | www.tm.aadcdn.msftauth.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154711962 CEST | 1.1.1.1 | 192.168.2.5 | 0x66af | No error (0) | aadcdn.msftauth.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154711962 CEST | 1.1.1.1 | 192.168.2.5 | 0x66af | No error (0) | e329293.dscd.akamaiedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154711962 CEST | 1.1.1.1 | 192.168.2.5 | 0x66af | No error (0) | 23.62.226.164 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154711962 CEST | 1.1.1.1 | 192.168.2.5 | 0x66af | No error (0) | 23.62.226.176 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154758930 CEST | 1.1.1.1 | 192.168.2.5 | 0x18a6 | No error (0) | www.tm.aadcdn.msftauth.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154758930 CEST | 1.1.1.1 | 192.168.2.5 | 0x18a6 | No error (0) | aadcdn.msftauth.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:18.154758930 CEST | 1.1.1.1 | 192.168.2.5 | 0x18a6 | No error (0) | e329293.dscd.akamaiedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:21.545818090 CEST | 1.1.1.1 | 192.168.2.5 | 0xfa41 | No error (0) | s-part-0043.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:21.545818090 CEST | 1.1.1.1 | 192.168.2.5 | 0xfa41 | No error (0) | 13.107.246.71 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | login.mso.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | ak.privatelink.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | www.tm.a.prd.aadg.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 40.126.62.130 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 20.190.190.196 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 20.190.190.130 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 20.190.190.129 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 20.190.190.193 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 40.126.62.132 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 40.126.62.131 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.135061979 CEST | 1.1.1.1 | 192.168.2.5 | 0x14ac | No error (0) | 20.190.190.132 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.144604921 CEST | 1.1.1.1 | 192.168.2.5 | 0xc240 | No error (0) | login.mso.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.144604921 CEST | 1.1.1.1 | 192.168.2.5 | 0xc240 | No error (0) | ak.privatelink.msidentity.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:11:35.144604921 CEST | 1.1.1.1 | 192.168.2.5 | 0xc240 | No error (0) | www.tm.a.prd.aadg.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:12:18.631897926 CEST | 1.1.1.1 | 192.168.2.5 | 0x2520 | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:12:18.631897926 CEST | 1.1.1.1 | 192.168.2.5 | 0x2520 | No error (0) | a1894.dscb.akamai.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:12:18.631897926 CEST | 1.1.1.1 | 192.168.2.5 | 0x2520 | No error (0) | 23.55.241.136 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:12:18.631897926 CEST | 1.1.1.1 | 192.168.2.5 | 0x2520 | No error (0) | 23.55.241.139 | A (IP address) | IN (0x0001) | false | ||
Apr 28, 2025 12:12:18.672082901 CEST | 1.1.1.1 | 192.168.2.5 | 0x6e81 | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 28, 2025 12:12:18.672082901 CEST | 1.1.1.1 | 192.168.2.5 | 0x6e81 | No error (0) | a1894.dscb.akamai.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.5 | 49691 | 142.251.40.35 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Apr 28, 2025 12:11:02.637876987 CEST | 200 | OUT | |
Apr 28, 2025 12:11:02.786648035 CEST | 1240 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49712 | 23.55.241.136 | 443 | 7060 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-28 10:11:18 UTC | 441 | OUT | |
2025-04-28 10:11:18 UTC | 319 | IN | |
2025-04-28 10:11:18 UTC | 7 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49716 | 23.55.241.136 | 443 | 7060 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-28 10:11:18 UTC | 417 | OUT | |
2025-04-28 10:11:18 UTC | 1276 | OUT | |
2025-04-28 10:11:19 UTC | 399 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49737 | 40.126.62.130 | 443 | 7060 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-28 10:11:35 UTC | 1490 | OUT | |
2025-04-28 10:11:35 UTC | 1562 | IN | |
2025-04-28 10:11:35 UTC | 164 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49744 | 23.55.241.136 | 443 | 7060 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-28 10:12:18 UTC | 441 | OUT | |
2025-04-28 10:12:18 UTC | 319 | IN | |
2025-04-28 10:12:18 UTC | 7 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49746 | 23.55.241.136 | 443 | 7060 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-04-28 10:12:18 UTC | 417 | OUT | |
2025-04-28 10:12:18 UTC | 1280 | OUT | |
2025-04-28 10:12:19 UTC | 399 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 06:11:02 |
Start date: | 28/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7464b0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 06:11:06 |
Start date: | 28/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7464b0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 06:11:09 |
Start date: | 28/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7464b0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 06:11:12 |
Start date: | 28/04/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7464b0000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |