Analysis Report https://outpk.000webhostapp.com/
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
|
Malware Configuration |
---|
No configs have been found |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_OutlookPhishing | Yara detected Outlook Phishing page | Joe Security |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Signature Overview |
---|
- • AV Detection
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
AV Detection: |
---|
Antivirus / Scanner detection for submitted sample |
Source: | SlashNext: | |||
Source: | UrlScan: | Perma Link |
Phishing: |
---|
Phishing site detected (based on logo template match) |
Source: | Matcher: |
Yara detected Outlook Phishing page |
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | Process Injection1 | Masquerading1 | OS Credential Dumping | File and Directory Discovery1 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel2 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Process Injection1 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Non-Application Layer Protocol1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information1 | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Application Layer Protocol2 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
1% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
100% | SlashNext | Fake Login Page type: Phishing & Social Engineering | ||
100% | UrlScan | phishing brand: outlook web access | Browse |
No Antivirus matches |
---|
No Antivirus matches |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
us-east-1.route-1.000webhost.awex.io | 145.14.144.71 | true | false |
| unknown |
outpk.000webhostapp.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
145.14.144.71 | unknown | Netherlands | 204915 | AWEXUS | false |
General Information |
---|
Joe Sandbox Version: | 31.0.0 Red Diamond |
Analysis ID: | 339155 |
Start date: | 13.01.2021 |
Start time: | 16:21:34 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 34s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://outpk.000webhostapp.com/ |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.phis.win@3/16@2/1 |
Cookbook Comments: |
|
Warnings: | Show All
|
No simulations |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
No context |
---|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 30296 |
Entropy (8bit): | 1.853464283056483 |
Encrypted: | false |
SSDEEP: | 192:rQZHZ12E9WLWtQifHX5zMXRBCLDfsfQX0jX:rA5sEUL2dejsK5 |
MD5: | B6BC0815AE0E501E616FA75A11C45749 |
SHA1: | F304CE8C5A3A89979410DD87E338BE7819CC48BD |
SHA-256: | 702417316D20B8EC1FE728DFE4A287EB64CFCE1DEDFBD6078C2389E6026BB932 |
SHA-512: | DBCC0107FEAA701936E7FEB709257FE006996D65241D9F3D035F9B0111142406C672B8A294A50EBB03C44224B7E5BC341453AE8C0A1DFB085000D40EB44020A2 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 27632 |
Entropy (8bit): | 1.78947247002123 |
Encrypted: | false |
SSDEEP: | 96:rYZDQv69BSWoFj52ckWnMeY8yv20vGwDiwr:rYZDQv69kWoFj52ckWnMeY8yv20Nr |
MD5: | F75EFC0E32B7CEAAD0C8056B307DB4E2 |
SHA1: | AB4449D6467B3621B8D3FDFDF4F764F146B98B8E |
SHA-256: | 136A81AD8406377EE28187695059C9FB506C198945F204F2263556C5BC0D3589 |
SHA-512: | BC7DBCFE82F0735E9B4BE9F49CE55B5CF0B2E868C2FAA5F397061B9A7D7AF8A8C96685DF35D321BDCB92411C31931D4039CDE5171D7DCA2FE945C642128B370F |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16984 |
Entropy (8bit): | 1.5661429956373378 |
Encrypted: | false |
SSDEEP: | 48:IwkGcprNGwpa4G4pQwGrapbS5rGQpK5G7HpRcxsTGIpG:r4ZXQo6OBS5FAYTcx4A |
MD5: | 62961E115FAA567F9045A8FD9C942B31 |
SHA1: | AC6E89AD614396F33509C755877DC51556AEB4E4 |
SHA-256: | 614DEF4C37558152B72B9780CFB4AB689C620B7EA03A953F52BDB148F67BFF4B |
SHA-512: | ADB6182AF7A56C6CD6E24BE9F0CA5B054660D938A6E7F2983E4170073480CC9BBC1E63E37DA87F21B48DBB5D527E349B75C414A1AB13B679CC8AD79C0D40D890 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 656 |
Entropy (8bit): | 5.090974676043847 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxOEsJ2JhnWimI002EtM3MHdNMNxOEsJ2JhnWimI00OYGVbkEtMb:2d6NxO54HSZHKd6NxO54HSZ7YLb |
MD5: | 00A02669E2C1898C78952D2C0A1F39D8 |
SHA1: | F9A90132B34EC032F3A4E7959BE2F67287C0EA1D |
SHA-256: | 9E7270E634AD23064903541895131D51772EB9DDFB670F76792A01430B4123DE |
SHA-512: | AE6544ED1C3E61AC489E666E030BC44D3ED25A82F83EA7E53268743EAB5C8157BBDAE88ED47B587D975FE6BE66A937DB35EDBA90DC7E98126A38D5F847C0EE26 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 653 |
Entropy (8bit): | 5.103665488159048 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxe2k/0gnWimI002EtM3MHdNMNxe2k/0gnWimI00OYGkak6EtMb:2d6NxrG0gSZHKd6NxrG0gSZ7Yza7b |
MD5: | 48D1A0CC4AF009FAE0997D0B53F40727 |
SHA1: | 170CAD3D5697A2256EC1EE345690EE0DBD6B968A |
SHA-256: | C02D87027C5022014A9806112CD38937BA87F42BBDD69224A24F9ED72EC038BE |
SHA-512: | C1A396B0B4B079263AEFE16A92F06412EB5D5D4B00EF636866C49526FB4002CBFBFF6CDC44F3539DD195EFF009E1BB0CF14DEAC43B04A55F04BBFA470E39EEE5 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 662 |
Entropy (8bit): | 5.100999308141718 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxvLfYQYgnWimI002EtM3MHdNMNxvLfYQYgnWimI00OYGmZEtMb:2d6Nxv83gSZHKd6Nxv83gSZ7Yjb |
MD5: | 68FCF37584A94E98AAF04799767D3ACF |
SHA1: | 02F5FFB35CF9F20DBD53E7829BCDDB8842B7D4E7 |
SHA-256: | 1AF7DF55D6DBFF97829194A677F91F8896A0C220115F6696185E5D804AF96552 |
SHA-512: | 204F631B4F9CA217B3D2014A9F3F8A6885C2D56B35F06548BE5A1B7E76009895AA673452499E01196DFF07DC45C68EFA63B2524ED2F8D01722DBF1FCD1FD2F61 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 647 |
Entropy (8bit): | 5.124693943645652 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxiLnWimI002EtM3MHdNMNxiAJhnWimI00OYGd5EtMb:2d6Nx4SZHKd6NxdHSZ7YEjb |
MD5: | 2C84A5AB526E2972D01486F49B7F5B2F |
SHA1: | 5CE7FADAD4AAF8993DB006CD061F229B23A221F8 |
SHA-256: | 1A3C95A3CF8C12FBA0A596D33B0C5687BAD2F33C2ED2ADB887F7D050C36951F2 |
SHA-512: | D11F0FDB8BE2B9B273B9BF1A83E36C8A64F896DD0C407753F161A9D628D99DEEF3BEA49694F3CBBC7338B069FC014700B6AAC1F1BAD5785B1C6E42B4B64B2A0D |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 656 |
Entropy (8bit): | 5.110224507906991 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxhGwfYQYgnWimI002EtM3MHdNMNxhGwfYQYgnWimI00OYG8K075EtMb:2d6NxQx3gSZHKd6NxQx3gSZ7YrKajb |
MD5: | 9706822E4ABCA3E0F1C331BB8CCFBA2F |
SHA1: | F1BBD9ED8795164566BEBF0233CA98F2DDD0B126 |
SHA-256: | 79698BDF536D31AB0435457D45F325530DFDD40EE7CDA6C25872AAFEC4793B1C |
SHA-512: | 9EC1781E776C58EE48446982F152C1F269DED190F6D54388BA393F465E4985FD2BEA72250F02AD72343EFE9883234D7EBCEBBB84951816927FC26B4BA159D6DC |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 653 |
Entropy (8bit): | 5.092172984576542 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNx0nsJ2JhnWimI002EtM3MHdNMNx0nsJ2JhnWimI00OYGxEtMb:2d6Nx0s4HSZHKd6Nx0s4HSZ7Ygb |
MD5: | A7E761D9C4848E64EB75D5A791226270 |
SHA1: | E264241A30BD5C95D86BC097DCD67EDD7070317B |
SHA-256: | 34847B76D99A05CFFA3D8604BFEB55D100F6AA29D6F17B62F2B731539635B434 |
SHA-512: | BBE2AB328D7D3B2655BE725637DFCAE053C767934C5EC2619AEF214DE6DE01B9C6D83149375A75A122314C8560318B3F5995FDCC3D3BDCEB245081072DD30E7E |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 656 |
Entropy (8bit): | 5.13060995537164 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxxsJ2JhnWimI002EtM3MHdNMNxxsJ2JhnWimI00OYG6Kq5EtMb:2d6Nxy4HSZHKd6Nxy4HSZ7Yhb |
MD5: | F7F44CA403F1E573B656FC7539270AED |
SHA1: | 0CD0CDF1BD237488819D6372C160F90C471C3A49 |
SHA-256: | 4B9097F4B7100180A6069794E18BD0A3D90A48585C45AC813E99424D9C2EC080 |
SHA-512: | ABAA62BAB5F53467108FA1A14FF82CBE8A097EED50A9FAD7F6D570E53205764B8A38C637AD3E400D2E459BF62D85A16D07EB4F69BE15E1A70A61BF4FAEC45A1A |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 659 |
Entropy (8bit): | 5.11799029220686 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxcLnWimI002EtM3MHdNMNxcLnWimI00OYGVEtMb:2d6Nx6SZHKd6Nx6SZ7Ykb |
MD5: | CF9C69261366196B8F2100623C915484 |
SHA1: | 5BB062010EF5F01F578E66F195B739C14F0E544E |
SHA-256: | 60FFE11FFA2E03D1322AE88747D1F7769CC58EC9AE7045D2374AAFBDDFE40681 |
SHA-512: | 2BCBD37887E344F1469AB6502EBD2B9A16216B65199318D1C2E106599FF7CB5F06E3A433F6136E8541695ECCA2E4918EC30D69AB1735B1E09AFBD5C8099DC7CB |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 653 |
Entropy (8bit): | 5.104415792954829 |
Encrypted: | false |
SSDEEP: | 12:TMHdNMNxfnLnWimI002EtM3MHdNMNxfnLnWimI00OYGe5EtMb:2d6NxzSZHKd6NxzSZ7YLjb |
MD5: | CE933E2D9A415A722FADFDD7C63F406A |
SHA1: | D55D520D8D2A3C959EB6DDD8165085E266464BDE |
SHA-256: | 034E1F289DF5D450B721D8B499FFACCF41DC014423624F5BD0A24812CD2CFA42 |
SHA-512: | 8BC9FD28CBD2CD8501F2498FABB3E4841AF6530CC2C7E033AD560D0E3540019F414C9A971F769ED9DE3205053997B63C99CC31A64CC003CC3234B332C96C4329 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 56302 |
Entropy (8bit): | 5.926282404818103 |
Encrypted: | false |
SSDEEP: | 768:I3yDwuJmtz7e05NnfviyaD2g9kzdKV7aQblNoJmgK4e2Fuz1QfYtcs:CtzK05N3aD2g9EkF5F4nFu7cs |
MD5: | DDDF6CA65E984B88C44C81DE03460054 |
SHA1: | F939B377A6D4DE0E251ECF18A6F4E08B8A81CEA2 |
SHA-256: | 9EE521F334F10BDB6B622068B2C1E8A2100215F8EECD424C31C77D65094374B7 |
SHA-512: | 2BB0CDC8DE21FEDC0F7E85471239EBED2F7936001A4773940C1CEA432430C9BFB37A245365A50149525A3AF512CED7635A3DAEBFBB2FB5948A1287276748AD80 |
Malicious: | true |
Yara Hits: |
|
Reputation: | low |
IE Cache URL: | https://outpk.000webhostapp.com/ |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35393 |
Entropy (8bit): | 0.4870084048606524 |
Encrypted: | false |
SSDEEP: | 48:kBqoxKAuvScS+S0e3bIbI5n/SW/00zW/R/H/k/C0+bwDi:kBqoxKAuvScS+S0e3EE20vGwDi |
MD5: | 4997F38144EB0F123716DADE09726A28 |
SHA1: | 1783EF7DA47434B4DEDC4AFCA247341EB0EF8043 |
SHA-256: | CB21D4BBDB47249BE165EBC96287BAFEB24ECE89A173ABBD062AFE2B820CD7A6 |
SHA-512: | DE05E5867A0821C50C67E187C4029514F2A7321D15A464B21358BCB22A9702B263EA1DDC8560F396E8AD21E4740BB04C72AD72FD51A07F454BA30C3D8E4315B8 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13029 |
Entropy (8bit): | 0.4732385856578803 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lo29lom9lWEHuW6:kBqoIx3EK |
MD5: | A136E3700189DDA4DC6272205C063E1E |
SHA1: | 83F958C67DB7073BEBA3AC9A32789AE22534AD7B |
SHA-256: | AE3C8CB90A38B683753C7C0AE4598D3E679E529B83FBB27B865E68E391976AC9 |
SHA-512: | EF09317D7CB1ED99E7279C89927065D7180F3C41B221B29CEA7E201E9B07057230F2BFFF8E3AAB3A7760405C3EBBD936CE02EBF872A99EB170EAFB738A8057A1 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Process: | C:\Program Files\internet explorer\iexplore.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25441 |
Entropy (8bit): | 0.27918767598683664 |
Encrypted: | false |
SSDEEP: | 24:c9lLh9lLh9lIn9lIn9lRx/9lRJ9lTb9lTb9lSSU9lSSU9laAa/9laA:kBqoxxJhHWSVSEab |
MD5: | AB889A32AB9ACD33E816C2422337C69A |
SHA1: | 1190C6B34DED2D295827C2A88310D10A8B90B59B |
SHA-256: | 4D6EC54B8D244E63B0F04FBE2B97402A3DF722560AD12F218665BA440F4CEFDA |
SHA-512: | BD250855747BB4CEC61814D0E44F810156D390E3E9F120A12935EFDF80ACA33C4777AD66257CCA4E4003FEF0741692894980B9298F01C4CDD2D8A9C7BB522FB6 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
No static file info |
---|
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
01/13/21-16:22:27.255858 | ICMP | 402 | ICMP Destination Unreachable Port Unreachable | 192.168.2.4 | 8.8.8.8 |
Network Port Distribution |
---|
- Total Packets: 119
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 13, 2021 16:22:27.250967979 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.251611948 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.408588886 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.408641100 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.408776999 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.408863068 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.414135933 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.414719105 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.568872929 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.569825888 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571037054 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571085930 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571130037 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571156025 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571183920 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571218967 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.571222067 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571244001 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.571249008 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.571252108 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.571254969 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.571259975 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571290016 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571309090 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571326017 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.571440935 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.626750946 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.634314060 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.634557962 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.635015965 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.635363102 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.781923056 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.781974077 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.782007933 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.782059908 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.782763004 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.789201021 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.789277077 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.789971113 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.790003061 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.790046930 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.790093899 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.790652037 CET | 49752 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.790704966 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.790766954 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.790770054 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.790829897 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.790931940 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.790990114 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.791013002 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.791069031 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.791191101 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.791224957 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.791794062 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.792759895 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.792813063 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.937144995 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.937206030 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.937242985 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.937292099 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.937302113 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.937345028 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.937350035 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.944044113 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.944092035 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.944175959 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.944204092 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945476055 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945528030 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945571899 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945578098 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945617914 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945635080 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945646048 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945669889 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945677996 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945715904 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945734024 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945755005 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945772886 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945795059 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.945812941 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.945852041 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.946491003 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.946530104 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:27.946564913 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.946584940 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:27.984371901 CET | 443 | 49752 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.077769995 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.134948969 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.233901978 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.233943939 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.233966112 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.233987093 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.234008074 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.234102964 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.234121084 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.234138012 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.234208107 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.234272003 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.234332085 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.234334946 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.234386921 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.234407902 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.234461069 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291224003 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291322947 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291377068 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291445017 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291454077 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291476965 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291507006 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291520119 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291527987 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291551113 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291582108 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291591883 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291613102 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291632891 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291663885 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291682005 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.291685104 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.291735888 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.293544054 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.303446054 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.450239897 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450273037 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450295925 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450314999 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450333118 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450345039 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.450397015 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.450715065 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450741053 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450759888 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450774908 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.450778008 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.450809002 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.450849056 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.453062057 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.460450888 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.460480928 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.460504055 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.460539103 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.460561991 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.460562944 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.460616112 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.460618973 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.460670948 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.460758924 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.460813999 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.462127924 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.462151051 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.462167025 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Jan 13, 2021 16:22:28.462207079 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.462222099 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.464636087 CET | 49753 | 443 | 192.168.2.4 | 145.14.144.71 |
Jan 13, 2021 16:22:28.619405985 CET | 443 | 49753 | 145.14.144.71 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 13, 2021 16:22:19.943916082 CET | 63153 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:19.992297888 CET | 53 | 63153 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:20.715531111 CET | 52991 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:20.763569117 CET | 53 | 52991 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:21.484412909 CET | 53700 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:21.540623903 CET | 53 | 53700 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:22.522850990 CET | 51726 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:22.571039915 CET | 53 | 51726 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:24.591592073 CET | 56794 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:24.639610052 CET | 53 | 56794 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:25.012329102 CET | 56534 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:25.070869923 CET | 53 | 56534 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:25.445122004 CET | 56627 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:25.495992899 CET | 53 | 56627 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:26.073151112 CET | 56621 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:27.077255964 CET | 56621 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:27.094121933 CET | 63116 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:27.142160892 CET | 53 | 63116 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:27.191807985 CET | 53 | 56621 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:27.255723000 CET | 53 | 56621 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:29.071619987 CET | 64078 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:29.122507095 CET | 53 | 64078 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:29.894270897 CET | 64801 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:29.942435980 CET | 53 | 64801 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:30.682485104 CET | 61721 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:30.730329990 CET | 53 | 61721 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:31.479811907 CET | 51255 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:31.530529976 CET | 53 | 51255 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:32.328007936 CET | 61522 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:32.378712893 CET | 53 | 61522 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:33.159765005 CET | 52337 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:33.207676888 CET | 53 | 52337 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:47.983841896 CET | 55046 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:48.031755924 CET | 53 | 55046 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:53.342299938 CET | 49612 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:53.400038958 CET | 53 | 49612 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:55.021217108 CET | 49285 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:55.069087029 CET | 53 | 49285 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:55.708477974 CET | 50601 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:55.759172916 CET | 53 | 50601 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:56.057106972 CET | 49285 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:56.105171919 CET | 53 | 49285 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:56.720074892 CET | 50601 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:56.771049976 CET | 53 | 50601 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:57.101314068 CET | 49285 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:57.149624109 CET | 53 | 49285 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:57.769347906 CET | 50601 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:57.820348024 CET | 53 | 50601 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:59.095104933 CET | 49285 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:59.143136024 CET | 53 | 49285 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:22:59.767205954 CET | 50601 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:22:59.818098068 CET | 53 | 50601 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:03.111078978 CET | 49285 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:03.159060955 CET | 53 | 49285 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:03.783003092 CET | 50601 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:03.842489958 CET | 53 | 50601 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:05.703586102 CET | 60875 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:05.777966022 CET | 53 | 60875 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:06.717330933 CET | 56448 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:06.781887054 CET | 53 | 56448 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:07.400512934 CET | 59172 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:07.470441103 CET | 53 | 59172 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:07.487596989 CET | 62420 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:07.545517921 CET | 53 | 62420 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:08.103362083 CET | 60579 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:08.159745932 CET | 53 | 60579 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:09.286958933 CET | 50183 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:09.343265057 CET | 53 | 50183 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:09.454813957 CET | 60875 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:09.505642891 CET | 53 | 60875 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:09.773036003 CET | 61531 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:09.832304955 CET | 53 | 61531 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:10.293000937 CET | 49228 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:10.352088928 CET | 53 | 49228 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:10.800995111 CET | 59794 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:10.857148886 CET | 53 | 59794 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:11.419680119 CET | 55916 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:11.467937946 CET | 53 | 55916 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:12.123123884 CET | 52752 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:12.182306051 CET | 53 | 52752 | 8.8.8.8 | 192.168.2.4 |
Jan 13, 2021 16:23:12.593471050 CET | 60542 | 53 | 192.168.2.4 | 8.8.8.8 |
Jan 13, 2021 16:23:12.652611971 CET | 53 | 60542 | 8.8.8.8 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 13, 2021 16:22:27.255857944 CET | 192.168.2.4 | 8.8.8.8 | d03d | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Jan 13, 2021 16:22:26.073151112 CET | 192.168.2.4 | 8.8.8.8 | 0x6588 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jan 13, 2021 16:22:27.077255964 CET | 192.168.2.4 | 8.8.8.8 | 0x6588 | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Jan 13, 2021 16:22:27.191807985 CET | 8.8.8.8 | 192.168.2.4 | 0x6588 | No error (0) | us-east-1.route-1.000webhost.awex.io | CNAME (Canonical name) | IN (0x0001) | ||
Jan 13, 2021 16:22:27.191807985 CET | 8.8.8.8 | 192.168.2.4 | 0x6588 | No error (0) | 145.14.144.71 | A (IP address) | IN (0x0001) | ||
Jan 13, 2021 16:22:27.255723000 CET | 8.8.8.8 | 192.168.2.4 | 0x6588 | No error (0) | us-east-1.route-1.000webhost.awex.io | CNAME (Canonical name) | IN (0x0001) | ||
Jan 13, 2021 16:22:27.255723000 CET | 8.8.8.8 | 192.168.2.4 | 0x6588 | No error (0) | 145.14.144.136 | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Source Port | Dest IP | Dest Port | Subject | Issuer | Not Before | Not After | JA3 SSL Client Fingerprint | JA3 SSL Client Digest |
---|---|---|---|---|---|---|---|---|---|---|
Jan 13, 2021 16:22:27.571130037 CET | 145.14.144.71 | 443 | 192.168.2.4 | 49752 | CN=*.000webhostapp.com CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Tue Jun 11 02:00:00 CEST 2019 Mon Nov 06 13:23:33 CET 2017 Fri Nov 10 01:00:00 CET 2006 | Sat Jul 10 14:00:00 CEST 2021 Sat Nov 06 13:23:33 CET 2027 Mon Nov 10 01:00:00 CET 2031 | 771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,0 | 9e10692f1b7f78228b2d4e424db3a98c |
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Mon Nov 06 13:23:33 CET 2017 | Sat Nov 06 13:23:33 CET 2027 | |||||||
CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Fri Nov 10 01:00:00 CET 2006 | Mon Nov 10 01:00:00 CET 2031 | |||||||
Jan 13, 2021 16:22:27.571290016 CET | 145.14.144.71 | 443 | 192.168.2.4 | 49753 | CN=*.000webhostapp.com CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Tue Jun 11 02:00:00 CEST 2019 Mon Nov 06 13:23:33 CET 2017 Fri Nov 10 01:00:00 CET 2006 | Sat Jul 10 14:00:00 CEST 2021 Sat Nov 06 13:23:33 CET 2027 Mon Nov 10 01:00:00 CET 2031 | 771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,0 | 9e10692f1b7f78228b2d4e424db3a98c |
CN=RapidSSL RSA CA 2018, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Mon Nov 06 13:23:33 CET 2017 | Sat Nov 06 13:23:33 CET 2027 | |||||||
CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US | Fri Nov 10 01:00:00 CET 2006 | Mon Nov 10 01:00:00 CET 2031 |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
Behavior |
---|
Click to jump to process
System Behavior |
---|
Start time: | 16:22:23 |
Start date: | 13/01/2021 |
Path: | C:\Program Files\internet explorer\iexplore.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6616e0000 |
File size: | 823560 bytes |
MD5 hash: | 6465CB92B25A7BC1DF8E01D8AC5E7596 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
Network Activities
Object Security Activities
LPC Port Activities
Start time: | 16:22:24 |
Start date: | 13/01/2021 |
Path: | C:\Program Files (x86)\Internet Explorer\iexplore.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x11a0000 |
File size: | 822536 bytes |
MD5 hash: | 071277CC2E3DF41EEEA8013E2AB58D5A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
File Activities
Section Activities
Registry Activities
Mutex Activities
Process Activities
Thread Activities
Memory Activities
System Activities
Timing Activities
Windows UI Activities
Network Activities
Object Security Activities
LPC Port Activities
Disassembly |
---|