Windows
Analysis Report
https://cbre-my.sharepoint.com/:f:/p/ryan_tornatore/Eg1sorlzC3dEvfKwplo2INEBM138N8ngH7z5Fh6OMIvXyg
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 396 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 4948 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2096 --fi eld-trial- handle=168 0,i,761046 3420695366 055,737685 6383366979 022,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
chrome.exe (PID: 6516 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://cbre- my.sharepo int.com/:f :/p/ryan_t ornatore/E g1sorlzC3d EvfKwplo2I NEBM138N8n gH7z5Fh6OM IvXyg" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_10 | Yara detected HtmlPhish_10 | Joe Security |
- • Phishing
- • Compliance
- • Networking
- • System Summary
Click to jump to signature section
Phishing |
---|
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
dual-spo-0005.spo-msedge.net | 13.107.136.10 | true | false | unknown | |
www.google.com | 172.217.16.132 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
cbre-my.sharepoint.com | unknown | unknown | false | unknown | |
m365cdn.nel.measure.office.net | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
13.107.136.10 | dual-spo-0005.spo-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.217.16.132 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1464638 |
Start date and time: | 2024-06-29 15:41:11 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://cbre-my.sharepoint.com/:f:/p/ryan_tornatore/Eg1sorlzC3dEvfKwplo2INEBM138N8ngH7z5Fh6OMIvXyg |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.phis.win@16/24@10/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, W MIADAP.exe, SIHClient.exe, con host.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 216.58.206.67, 142 .250.185.110, 64.233.167.84, 3 4.104.35.123, 2.23.209.37, 2.2 3.209.42, 216.58.212.170, 142. 250.185.170, 142.250.185.234, 142.250.185.106, 172.217.18.10 , 142.250.186.138, 142.250.181 .234, 142.250.186.42, 216.58.2 06.42, 142.250.185.202, 142.25 0.185.138, 172.217.18.106, 142 .250.184.202, 142.250.186.170, 172.217.16.138, 142.250.186.7 4, 2.19.126.89, 2.19.126.84, 2 .19.126.163, 2.19.126.137, 192 .229.221.95, 13.95.31.18, 20.3 .187.198, 142.250.184.227 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, e40491.dscd.akam aiedge.net, clientservices.goo gleapis.com, res-1.cdn.office. net, a767.dspw65.akamai.net, a 1894.dscb.akamai.net, clients2 .google.com, 193809-ipv4v6w.fa rm.dprodmgd105.sharepointonlin e.com.akadns.net, ocsp.digicer t.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.traffic manager.net, update.googleapis .com, wu-b-net.trafficmanager. net, res-1.cdn.office.net-c.ed gekey.net.globalredir.akadns.n et, fs.microsoft.com, accounts .google.com, content-autofill. googleapis.com, ctldl.windowsu pdate.com.delivery.microsoft.c om, ctldl.windowsupdate.com, d ownload.windowsupdate.com.edge suite.net, fe3cr.delivery.mp.m icrosoft.com, fe3.delivery.mp. microsoft.com, edgedl.me.gvt1. com, nel.measure.office.net.ed gesuite.net, clients.l.google. com, res-1.cdn.office.net-c.ed gekey.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtSetInformationFile c alls found. - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data.
Input | Output |
---|---|
URL: https://cbre-my.sharepoint.com/:f:/p/ryan_tornatore/Eg1sorlzC3dEvfKwplo2INEBM138N8ngH7z5Fh6OMIvXyg Model: Perplexity: mixtral-8x7b-instruct | {"loginform": true,"urgency": false, |
Title: Sharing Link Validation OCR: OneDrive Microsoft Verify Your Identity You've received a secure link to: 1500 Broadway Pre Build RFP To open this secure link. we'll need you to enter the email that this item was shared to. O Enter email Next By clicking Next you allow CBRE, Inc. to use your email address In accordance with their privacy statement. CBRE. Inc. has not prmided links to their terms for you to review. 2017 Microsoft Privacy & Cookies |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 69031 |
Entropy (8bit): | 5.666938977411791 |
Encrypted: | false |
SSDEEP: | 1536:PlgguXNRhpYWXBOxSPSW8N6fGNNKyioJs2wVXUaH3J:PLuPCGeTKyiTVXUi |
MD5: | 383DC4CD7C3B996B9B50B4545026C318 |
SHA1: | 2C485413AA2D1AF9191840E6B107E0A76C95A924 |
SHA-256: | 44ECBEFC00C14DECD26802908D4C10A7BCE73B12574F7C88D8D751221D76035B |
SHA-512: | 24D76E693980F14593E10D885413EF7F4725F308526358BC6EA0F8D271B3C05765E0A23EE8C680793C0238EFFEC12B787CE5BD4BC8550E11265B1F410C04B9DC |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/:f:/p/ryan_tornatore/Eg1sorlzC3dEvfKwplo2INEBM138N8ngH7z5Fh6OMIvXyg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3331 |
Entropy (8bit): | 7.927896166439245 |
Encrypted: | false |
SSDEEP: | 96:zHjOKn3csE3x5liVsCo4GcPIZpV6x5cge8oo9:zDOK3zE3x5TCwcP4LQNeq |
MD5: | EF884BDEDEF280DF97A4C5604058D8DB |
SHA1: | 6F04244B51AD2409659E267D308B97E09CE9062B |
SHA-256: | 825DE044D5AC6442A094FF95099F9F67E9249A8110A2FBD57128285776632ADB |
SHA-512: | A083381C53070B65B3B8A7A7293D5D2674D2F6EC69C0E19748823D3FDD6F527E8D3D31D311CCEF8E26FC531770F101CDAF95F23ECC990DB405B5EF48B0C91BA2 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3331 |
Entropy (8bit): | 7.927896166439245 |
Encrypted: | false |
SSDEEP: | 96:zHjOKn3csE3x5liVsCo4GcPIZpV6x5cge8oo9:zDOK3zE3x5TCwcP4LQNeq |
MD5: | EF884BDEDEF280DF97A4C5604058D8DB |
SHA1: | 6F04244B51AD2409659E267D308B97E09CE9062B |
SHA-256: | 825DE044D5AC6442A094FF95099F9F67E9249A8110A2FBD57128285776632ADB |
SHA-512: | A083381C53070B65B3B8A7A7293D5D2674D2F6EC69C0E19748823D3FDD6F527E8D3D31D311CCEF8E26FC531770F101CDAF95F23ECC990DB405B5EF48B0C91BA2 |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/_layouts/15/images/microsoft-logo.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17672 |
Entropy (8bit): | 5.233316811547578 |
Encrypted: | false |
SSDEEP: | 384:lpLsOooX8uvFBiRh+HnEDuvvy1pqvuvDX/0ohHK9mm+tMHvVOPoQeOMmuI:QnoX8uNB2YHnEDsvy1pqvub/0iq4NMHM |
MD5: | 6EFDDF589864D2E146A55C01C6764A35 |
SHA1: | EFA8BBA46CB97877EEC5430C43F0AC32585B6B2F |
SHA-256: | 2D92F0CE8491D2F9A27EA16D261A15089C4A9BE879D1EEDCB6F4A3859E7F1999 |
SHA-512: | 1AFC735660AAE010C04EF89C732D08EBA1B87BE6048164F273BEAEBECA3F30062812B4CD141DDF0291A6AB54F730875D597678A3564C0EED2AAC11E5400F951A |
Malicious: | false |
Reputation: | low |
URL: | https://res-1.cdn.office.net/bld/_layouts/15/16.0.25012.12008/require.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 26951 |
Entropy (8bit): | 4.514992390210281 |
Encrypted: | false |
SSDEEP: | 384:jMgviMjM4if38GmhXeC1QRwweTkBE9wbOY4Jf/JhRZ5h+73hNVt8oC4veONhLYVi:CLEiJSdo11vIYHqb5Klo8v |
MD5: | B3D7A123BE5203A1A3F0F10233ED373F |
SHA1: | F4C61F321D8F79A805B356C6EC94090C0D96215C |
SHA-256: | EF9453F74B2617D43DCEF4242CF5845101FCFB57289C81BCEB20042B0023A192 |
SHA-512: | A01BFE8546E59C8AF83280A795B3F56DFA23D556B992813A4EB70089E80621686C7B51EE87B3109502667CAF1F95CBCA074BF607E543A0390BF6F8BB3ECD992B |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/ScriptResource.axd?d=GgWJx4W4lMI5EXR00JJ5kkqnXTV54JRXPw13ydwDn47hKD5aSHMa_gWdopWBc9-FvZEWF-DKKWo7zsXN7dl5xlCgIbeupxjhWEBNL6PUjN0_WuQhS7AHUiAlDeYoVI2XBdgbEaB_J5Br5wjl41QZkpP-DVAYi0OgeBbcMZLm_BM1&t=ffffffffa8ad04d3 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 23063 |
Entropy (8bit): | 4.7535440881548165 |
Encrypted: | false |
SSDEEP: | 384:GvUzYI+Vi4g1V5it1ONhA6w+Kv8i/4CYzLKL4DrLU0iTxZTAzIzrwDlTWMClQip9:bkON69kClQq8hDRJHp2tWU25Zt/gREVG |
MD5: | 90EA7274F19755002360945D54C2A0D7 |
SHA1: | 647B5D8BF7D119A2C97895363A07A0C6EB8CD284 |
SHA-256: | 40732E9DCFA704CF615E4691BB07AECFD1CC5E063220A46E4A7FF6560C77F5DB |
SHA-512: | 7474667800FF52A0031029CC338F81E1586F237EB07A49183008C8EC44A8F67B37E5E896573F089A50283DF96A1C8F185E53D667741331B647894532669E2C07 |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/WebResource.axd?d=n1XvOt_rEdjTpVoBxKKZZ4Z_0JswuigM5GkRS3HzRUfJorMUXSpqKNhJBGTWgLZ3GjPkONRk6-PpHYKtac_YLrAIhutOy5x7dbKVujcVnO81&t=638533172441064469 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7886 |
Entropy (8bit): | 3.9482833105763633 |
Encrypted: | false |
SSDEEP: | 48:gubb4a2MNTgopLqyhFTv07EVc91JbV5FIXH0wp53O:Bbb4a5NTX1c9L6E |
MD5: | 0B60F3C9E4DA6E807E808DA7360F24F2 |
SHA1: | 9AFC7ABB910DE855EFB426206E547574A1E074B7 |
SHA-256: | ADDEEDEEEF393B6B1BE5BBB099B656DCD797334FF972C495CCB09CFCB1A78341 |
SHA-512: | 1328363987ABBAD1B927FC95F0A3D5646184EF69D66B42F32D1185EE06603AE1A574FAC64472FB6E349C2CE99F9B54407BA72B2908CA7AB01D023EC2F47E7E80 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 102801 |
Entropy (8bit): | 5.336080509196147 |
Encrypted: | false |
SSDEEP: | 1536:MGLiogSomRYvoGtT+KHsVS0bT79DSsi46j/LPyR7kbE:MGLXGFKT79DSs6WCE |
MD5: | C89EAA5B28DF1E17376BE71D71649173 |
SHA1: | 2B34DF4C66BB57DE5A24A2EF0896271DFCA4F4CD |
SHA-256: | 66B804E7A96A87C11E1DD74EA04AC2285DF5AD9043F48046C3E5000114D39B1C |
SHA-512: | B73D56304986CD587DA17BEBF21341B450D41861824102CC53885D863B118F6FDF2456B20791B9A7AE56DF91403F342550AF9E46F7401429FBA1D4A15A6BD3C0 |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/ScriptResource.axd?d=FqJX8RbykGoP5HtvCL_K_k8W23t34rZuHzHaG9-X30qJSTF9FRjPT255nRLEZlCkI7Tho4QtvvlXlH-BepCmTSP9brO63RDzvQe9HZtACRtigIOhqbrNcdLGaYzs5LnYyiPgmQajB0hKVKuyw7UEberh5SXJ8z9WKE4LTc-XhwhsUCWjlI4W4yL00am1DpsD0&t=74258c30 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7886 |
Entropy (8bit): | 3.9482833105763633 |
Encrypted: | false |
SSDEEP: | 48:gubb4a2MNTgopLqyhFTv07EVc91JbV5FIXH0wp53O:Bbb4a5NTX1c9L6E |
MD5: | 0B60F3C9E4DA6E807E808DA7360F24F2 |
SHA1: | 9AFC7ABB910DE855EFB426206E547574A1E074B7 |
SHA-256: | ADDEEDEEEF393B6B1BE5BBB099B656DCD797334FF972C495CCB09CFCB1A78341 |
SHA-512: | 1328363987ABBAD1B927FC95F0A3D5646184EF69D66B42F32D1185EE06603AE1A574FAC64472FB6E349C2CE99F9B54407BA72B2908CA7AB01D023EC2F47E7E80 |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/_layouts/15/images/favicon.ico?rev=47 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 40326 |
Entropy (8bit): | 5.245555585297941 |
Encrypted: | false |
SSDEEP: | 384:bvrc3TrJ1vMZCKZ4pLRy6DkfDLcbTzcXanT2rxb64aKQr1vySAwBaPUge6ydE:bTaYB4Hy7mTzcaTKStrwSAwBaPUTdE |
MD5: | DA9DC1C32E89C02FC1E9EEB7E5AAB91E |
SHA1: | 3EFB110EFA6068CE6B586A67F87DA5125310BC30 |
SHA-256: | 398CDF1B27EF247E5BC77805F266BB441E60355463FC3D1776F41AAE58B08CF1 |
SHA-512: | D4730EBC4CA62624B8300E292F27FD79D42A9277E409545DF7DC916189ED9DF13E46FAA37E3924B85A7C7EA8C76BF65A05ECA69B4029B550430536EC6DF8552A |
Malicious: | false |
Reputation: | low |
URL: | https://cbre-my.sharepoint.com/ScriptResource.axd?d=6CVFfrA0n2PJi2tvKe7apJ7_1XcBTf-UZq-voRBLN6hd6xziDcTls0rKD-f30Ox5NXEzfPyAKpJD11wAzqlLBQ0HM-Soy6yLK9SCaco61JXaboYhnCUvaYI9pgMEc2blfc93egR8djptRULYh6sRxax1neyaevaIAOBBXEeeyIulweQD5OST_Qi0TJhwB8zL0&t=74258c30 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.702819531114783 |
Encrypted: | false |
SSDEEP: | 3:H6xhkY:aQY |
MD5: | 858372DD32511CB4DD08E48A93B4F175 |
SHA1: | CE4555B7B2EFBBD644D8E34CF3453A0E8CAA3C43 |
SHA-256: | 3D18F3E1469C83D62CF3A39BA93F8EAA5B22447FE630E59F39DC1B7747635359 |
SHA-512: | 6A57E0D4A1C23CB693AA9312F6FDAA1FC4309B5BC91D1B2279B5792BEE3534749FD3693C19AA95E0768800472D11D438EC3116F337679A249C28BE0E038E6DE0 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAl0Clez6_lj6RIFDfSCVyI=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 40512 |
Entropy (8bit): | 5.386921349191213 |
Encrypted: | false |
SSDEEP: | 768:Tkv+rkfa2aH5m7UYfXLMQWGjaKEstpgG9ycj:Pr8LaZkzLM46G9 |
MD5: | 8DCE60169BA666CA03A31D123DB49908 |
SHA1: | 956C46BB6058C23D35440DCC656CE61C7B151399 |
SHA-256: | F9F5A40C01C6D569373CE61EE77849F30E4176E1310652FF17D458C68680CF75 |
SHA-512: | 26BA15ADE0F62393413156C5061B04AA8FCE3A5A5EE06EE35DFC42D3F76AF850980731A38DCF7094711E7FAB18C80EF66C9B354C029D06FA2E846330ACCC7E9E |
Malicious: | false |
Reputation: | low |
URL: | https://res-1.cdn.office.net/files/odsp-web-prod_2024-06-14.009/spoguestaccesswebpack/spoguestaccess.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 215 |
Entropy (8bit): | 5.296880601579995 |
Encrypted: | false |
SSDEEP: | 6:JiMVBdgqZjZWtMfgRTH1it9PIY6XcRIQT2g6n:MMHdVBZWyUTMEXC6 |
MD5: | 8A26CCD8021CEAA9A4BBAA78EC0BF51B |
SHA1: | BB986724EE1491D22D55AA23413C0B7DA9D45478 |
SHA-256: | AC872DD2837E4F1707A42C8FB20834A7FB8008BB22D305258DE2E32B4260321A |
SHA-512: | 042DCCB5558D42FB4B723E6467B764C0D1E2BC2949A3FB8B3072483C42E1A900BC9353378E58C83320715531704A062D112F4D6E2F8144D0D11DEA99BBAB2887 |
Malicious: | false |
Reputation: | low |
URL: | https://res-1.cdn.office.net/files/odsp-web-prod_2024-06-14.009/@uifabric/file-type-icons/lib/initializeFileTypeIcons.js |
Preview: |
Download Network PCAP: filtered – full
- Total Packets: 227
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 29, 2024 15:41:55.937874079 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jun 29, 2024 15:42:05.625365973 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jun 29, 2024 15:42:08.697045088 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:08.697082996 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:08.697158098 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:08.697366953 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:08.697410107 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:08.697467089 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:08.697707891 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:08.697726011 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:08.697865963 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:08.697885990 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.274828911 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.275096893 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.275116920 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.275593042 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.275752068 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.275779963 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.276200056 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.276293993 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.276825905 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.276890993 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.277307987 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.277371883 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.277861118 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.277868986 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.278283119 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.278353930 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.328289032 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.328319073 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.328332901 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.373903990 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.555614948 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.555649996 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.555721045 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.555737972 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.555990934 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.555999041 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.556054115 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.556062937 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.556889057 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.556943893 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.556951046 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.609266996 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.635370970 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.635385036 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.635402918 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.635448933 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.635508060 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.635518074 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.636276007 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.636284113 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.636347055 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.636353970 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.637152910 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.637187004 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.637214899 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.637221098 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.637248039 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.644908905 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.644985914 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.644994020 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.685863972 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.724872112 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.724883080 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.724971056 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.724984884 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725028992 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725035906 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725078106 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.725083113 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725106955 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.725820065 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725879908 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.725884914 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725933075 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.725976944 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.756212950 CEST | 49737 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.756253004 CEST | 443 | 49737 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.758516073 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.758558035 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.758619070 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.759094954 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.759119987 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.759176970 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.759519100 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.759608984 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.759696007 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.760385990 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.762406111 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.762422085 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.762913942 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.762927055 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.763195992 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.763262987 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.800508022 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.934628963 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.934659004 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.934720993 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.934742928 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.934782982 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.935337067 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.935347080 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.935375929 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.935384989 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.935427904 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:09.936028004 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:09.936074972 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.024144888 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.024158955 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.024218082 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.024245024 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.024316072 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.024362087 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.141726971 CEST | 49736 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.141782045 CEST | 443 | 49736 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.330894947 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.331267118 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.331280947 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.331610918 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.332592964 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.332648993 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.333015919 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.346330881 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.346580982 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.346602917 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.346910954 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.347732067 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.347733974 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.347794056 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.348820925 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.349315882 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.349399090 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.350863934 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.350929022 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.351617098 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.351706028 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.351809978 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.351830959 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.376501083 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.392505884 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.405234098 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.512754917 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.512779951 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.512820959 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.512834072 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.512868881 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.513739109 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.513746977 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.513787031 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.513797998 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.513803005 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.513843060 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.521147013 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.521173954 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.521348953 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.521380901 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.521430969 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.522161007 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.522170067 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.522274017 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.522274971 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.522291899 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.522324085 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.524816990 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.524837017 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.524889946 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.524912119 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.524972916 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.526185989 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.526194096 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.526222944 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.526232004 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.526268959 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.526277065 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.562793970 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.578783035 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602272987 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602334976 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602349043 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602370024 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602418900 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602426052 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602478027 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602577925 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602639914 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602689028 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602802992 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602817059 CEST | 443 | 49743 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.602827072 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.602864981 CEST | 49743 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.605360031 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.605400085 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.605448961 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.605676889 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.605688095 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.613596916 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.613609076 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.613671064 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.613707066 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.614662886 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.614690065 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.614718914 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.614733934 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.614758015 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.615561008 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.615619898 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.615633965 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.615711927 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.615762949 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.615892887 CEST | 49744 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.615909100 CEST | 443 | 49744 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.617429018 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.617439985 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.617491961 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.617511988 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.618853092 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.618908882 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.618917942 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.619714022 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.619779110 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.619790077 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.620598078 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.620661020 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.620668888 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.674777031 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.709837914 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.709850073 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.709932089 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.709948063 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.710273981 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.710282087 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.710326910 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.710336924 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.711061001 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.711102009 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.711127996 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.711136103 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.711153030 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.711275101 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.711328030 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.711335897 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.711996078 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.712047100 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.712055922 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.712786913 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.712848902 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.712857008 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.712939024 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.712977886 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.712985039 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.712996960 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:10.713030100 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.713144064 CEST | 49742 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:10.713159084 CEST | 443 | 49742 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.163981915 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.167896986 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.167916059 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.168248892 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.179701090 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.179770947 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.180414915 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.224508047 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.229935884 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.230000019 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:11.230113983 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.230370045 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.230391979 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:11.350806952 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.350842953 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.350892067 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.350908041 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.350919008 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.350959063 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.350965023 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.351001024 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.351058960 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.365179062 CEST | 49745 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.365194082 CEST | 443 | 49745 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.442662001 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.442703962 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.442795038 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.443109035 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.443126917 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.616224051 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:11.616275072 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:11.616386890 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:11.620646954 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:11.620668888 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:11.696978092 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.697027922 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.697356939 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.697913885 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:11.697926998 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:11.875096083 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:11.896696091 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.896720886 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:11.897727013 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:11.897792101 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.914217949 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.914310932 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:11.968072891 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:11.968113899 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:12.014425993 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:12.016186953 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.016407967 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.016438961 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.016746998 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.017119884 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.017178059 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.017237902 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.060508013 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.196863890 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.196886063 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.196919918 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.196938038 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.196959019 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.196985960 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.197741032 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.197794914 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.199243069 CEST | 49749 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.199256897 CEST | 443 | 49749 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.292042971 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.292174101 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.295773029 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.296540022 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.296556950 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.296789885 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.304856062 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.304879904 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.306370974 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.306444883 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.342576027 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.344671011 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.344865084 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.348543882 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.348565102 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.389431953 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.419163942 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.464498043 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.471431971 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.471473932 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.471539021 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.493838072 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.493868113 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514442921 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514467955 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514522076 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514524937 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.514548063 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514590025 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.514619112 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514684916 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.514767885 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.543657064 CEST | 49751 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:12.543688059 CEST | 443 | 49751 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:12.610867023 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.610928059 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.611144066 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.611311913 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.611330986 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.611365080 CEST | 49750 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.611372948 CEST | 443 | 49750 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.781589031 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.781635046 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:12.781788111 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.783571959 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:12.783585072 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.057826042 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.058120012 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.058142900 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.058478117 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.059021950 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.059079885 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.059241056 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.100505114 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.108861923 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.240906000 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.240925074 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.240977049 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.241002083 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.241216898 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.241265059 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.241271973 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.241475105 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.241636992 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.242703915 CEST | 49752 | 443 | 192.168.2.4 | 13.107.136.10 |
Jun 29, 2024 15:42:13.242723942 CEST | 443 | 49752 | 13.107.136.10 | 192.168.2.4 |
Jun 29, 2024 15:42:13.459302902 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.459376097 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:13.460648060 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:13.460659981 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.460936069 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.461930990 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:13.504506111 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.741750956 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.741818905 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.741869926 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:13.742655039 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:13.742672920 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:13.742683887 CEST | 49755 | 443 | 192.168.2.4 | 184.28.90.27 |
Jun 29, 2024 15:42:13.742695093 CEST | 443 | 49755 | 184.28.90.27 | 192.168.2.4 |
Jun 29, 2024 15:42:17.924974918 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:17.925023079 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:17.925364017 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:17.926255941 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:17.926274061 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:18.620419979 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:18.620507002 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:18.622694969 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:18.622704029 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:18.622932911 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:18.671106100 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:19.483971119 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:19.528501034 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715019941 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715044975 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715054035 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715064049 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715095043 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715141058 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:19.715166092 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715182066 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:19.715209007 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:19.715246916 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715298891 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:19.715306044 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715336084 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:19.715395927 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:20.605237961 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:20.605264902 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:20.605277061 CEST | 49757 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:20.605282068 CEST | 443 | 49757 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:21.774837017 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:21.774930954 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:21.775130987 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:23.090256929 CEST | 49746 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:42:23.090310097 CEST | 443 | 49746 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:42:57.117145061 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:57.117197990 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:57.117260933 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:57.117953062 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:57.117964983 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:57.819071054 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:57.819139957 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:57.823395967 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:57.823407888 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:57.823678970 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:57.832814932 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:57.876514912 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.087979078 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.088004112 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.088018894 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.088068962 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.088098049 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.088149071 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.089410067 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.089454889 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.089490891 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.089498997 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.089521885 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.089669943 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.089721918 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.093823910 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.093823910 CEST | 49763 | 443 | 192.168.2.4 | 13.85.23.86 |
Jun 29, 2024 15:42:58.093842030 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:42:58.093849897 CEST | 443 | 49763 | 13.85.23.86 | 192.168.2.4 |
Jun 29, 2024 15:43:11.235342026 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:11.235465050 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:11.235569000 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:11.235810995 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:11.235856056 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:11.984324932 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:11.984652042 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:11.984685898 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:11.986376047 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:11.986715078 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:11.986908913 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:12.031023979 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:12.437469959 CEST | 49723 | 80 | 192.168.2.4 | 199.232.214.172 |
Jun 29, 2024 15:43:12.437556028 CEST | 49724 | 80 | 192.168.2.4 | 93.184.221.240 |
Jun 29, 2024 15:43:12.442909956 CEST | 80 | 49723 | 199.232.214.172 | 192.168.2.4 |
Jun 29, 2024 15:43:12.442928076 CEST | 80 | 49724 | 93.184.221.240 | 192.168.2.4 |
Jun 29, 2024 15:43:12.442979097 CEST | 49723 | 80 | 192.168.2.4 | 199.232.214.172 |
Jun 29, 2024 15:43:12.442995071 CEST | 49724 | 80 | 192.168.2.4 | 93.184.221.240 |
Jun 29, 2024 15:43:21.779020071 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:21.779103041 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Jun 29, 2024 15:43:21.779225111 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:23.040393114 CEST | 49765 | 443 | 192.168.2.4 | 172.217.16.132 |
Jun 29, 2024 15:43:23.040467024 CEST | 443 | 49765 | 172.217.16.132 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 29, 2024 15:42:06.660790920 CEST | 53 | 57032 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:06.777576923 CEST | 53 | 50356 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:07.835650921 CEST | 53 | 51085 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:08.647500992 CEST | 53291 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:08.651292086 CEST | 63362 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:11.183931112 CEST | 61414 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:11.184191942 CEST | 52929 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:11.190674067 CEST | 53 | 61414 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:11.190726995 CEST | 53 | 52929 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:11.246134996 CEST | 53 | 56262 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:11.612411022 CEST | 51129 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:11.612848997 CEST | 65249 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:12.582214117 CEST | 52854 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:12.582719088 CEST | 55044 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:42:24.026199102 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Jun 29, 2024 15:42:24.790853977 CEST | 53 | 63454 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:42:43.830758095 CEST | 53 | 61495 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:43:06.589684010 CEST | 53 | 55517 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:43:06.609308958 CEST | 53 | 55808 | 1.1.1.1 | 192.168.2.4 |
Jun 29, 2024 15:43:13.535686016 CEST | 53074 | 53 | 192.168.2.4 | 1.1.1.1 |
Jun 29, 2024 15:43:13.535835981 CEST | 50479 | 53 | 192.168.2.4 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jun 29, 2024 15:42:08.647500992 CEST | 192.168.2.4 | 1.1.1.1 | 0x53f8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 29, 2024 15:42:08.651292086 CEST | 192.168.2.4 | 1.1.1.1 | 0x655b | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 29, 2024 15:42:11.183931112 CEST | 192.168.2.4 | 1.1.1.1 | 0x9cb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 29, 2024 15:42:11.184191942 CEST | 192.168.2.4 | 1.1.1.1 | 0x1f4b | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 29, 2024 15:42:11.612411022 CEST | 192.168.2.4 | 1.1.1.1 | 0x2aca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 29, 2024 15:42:11.612848997 CEST | 192.168.2.4 | 1.1.1.1 | 0x34f2 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 29, 2024 15:42:12.582214117 CEST | 192.168.2.4 | 1.1.1.1 | 0x4796 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 29, 2024 15:42:12.582719088 CEST | 192.168.2.4 | 1.1.1.1 | 0xbdd3 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 29, 2024 15:43:13.535686016 CEST | 192.168.2.4 | 1.1.1.1 | 0x8a34 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 29, 2024 15:43:13.535835981 CEST | 192.168.2.4 | 1.1.1.1 | 0x33ba | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | cbre.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | 328-ipv4v6e.clump.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | 193809-ipv4v6e.farm.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | 193809-ipv4v6w.farm.dprodmgd105.sharepointonline.com.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | dual-spo-0005.spo-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | 13.107.136.10 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.688153982 CEST | 1.1.1.1 | 192.168.2.4 | 0x53f8 | No error (0) | 13.107.138.10 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.696368933 CEST | 1.1.1.1 | 192.168.2.4 | 0x655b | No error (0) | cbre.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.696368933 CEST | 1.1.1.1 | 192.168.2.4 | 0x655b | No error (0) | 328-ipv4v6e.clump.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.696368933 CEST | 1.1.1.1 | 192.168.2.4 | 0x655b | No error (0) | 193809-ipv4v6e.farm.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:08.696368933 CEST | 1.1.1.1 | 192.168.2.4 | 0x655b | No error (0) | 193809-ipv4v6w.farm.dprodmgd105.sharepointonline.com.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.190674067 CEST | 1.1.1.1 | 192.168.2.4 | 0x9cb8 | No error (0) | 172.217.16.132 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.190726995 CEST | 1.1.1.1 | 192.168.2.4 | 0x1f4b | No error (0) | 65 | IN (0x0001) | false | |||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | cbre.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | 328-ipv4v6e.clump.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | 193809-ipv4v6e.farm.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | 193809-ipv4v6w.farm.dprodmgd105.sharepointonline.com.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | dual-spo-0005.spo-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | 13.107.136.10 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.679209948 CEST | 1.1.1.1 | 192.168.2.4 | 0x2aca | No error (0) | 13.107.138.10 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.695954084 CEST | 1.1.1.1 | 192.168.2.4 | 0x34f2 | No error (0) | cbre.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.695954084 CEST | 1.1.1.1 | 192.168.2.4 | 0x34f2 | No error (0) | 328-ipv4v6e.clump.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.695954084 CEST | 1.1.1.1 | 192.168.2.4 | 0x34f2 | No error (0) | 193809-ipv4v6e.farm.dprodmgd105.aa-rt.sharepoint.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:11.695954084 CEST | 1.1.1.1 | 192.168.2.4 | 0x34f2 | No error (0) | 193809-ipv4v6w.farm.dprodmgd105.sharepointonline.com.akadns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:12.590095043 CEST | 1.1.1.1 | 192.168.2.4 | 0x4796 | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:12.593187094 CEST | 1.1.1.1 | 192.168.2.4 | 0xbdd3 | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:19.500402927 CEST | 1.1.1.1 | 192.168.2.4 | 0xf3fb | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:19.500402927 CEST | 1.1.1.1 | 192.168.2.4 | 0xf3fb | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:32.913012981 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a5c | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:32.913012981 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a5c | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:58.915118933 CEST | 1.1.1.1 | 192.168.2.4 | 0x5afb | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:42:58.915118933 CEST | 1.1.1.1 | 192.168.2.4 | 0x5afb | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Jun 29, 2024 15:43:13.543215990 CEST | 1.1.1.1 | 192.168.2.4 | 0x8a34 | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:43:13.544008017 CEST | 1.1.1.1 | 192.168.2.4 | 0x33ba | No error (0) | nel.measure.office.net.edgesuite.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:43:20.210505962 CEST | 1.1.1.1 | 192.168.2.4 | 0x480a | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 29, 2024 15:43:20.210505962 CEST | 1.1.1.1 | 192.168.2.4 | 0x480a | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 34.117.186.192 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:41:54 UTC | 59 | OUT | |
2024-06-29 13:41:54 UTC | 513 | IN | |
2024-06-29 13:41:54 UTC | 319 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:09 UTC | 732 | OUT | |
2024-06-29 13:42:09 UTC | 1984 | IN | |
2024-06-29 13:42:09 UTC | 1631 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 4699 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 5357 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49736 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:09 UTC | 743 | OUT | |
2024-06-29 13:42:09 UTC | 753 | IN | |
2024-06-29 13:42:09 UTC | 3539 | IN | |
2024-06-29 13:42:09 UTC | 8192 | IN | |
2024-06-29 13:42:09 UTC | 4022 | IN | |
2024-06-29 13:42:10 UTC | 7310 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49743 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:10 UTC | 808 | OUT | |
2024-06-29 13:42:10 UTC | 773 | IN | |
2024-06-29 13:42:10 UTC | 3235 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 4306 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 3026 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49742 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:10 UTC | 821 | OUT | |
2024-06-29 13:42:10 UTC | 773 | IN | |
2024-06-29 13:42:10 UTC | 3397 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 4144 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49744 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:10 UTC | 821 | OUT | |
2024-06-29 13:42:10 UTC | 776 | IN | |
2024-06-29 13:42:10 UTC | 3394 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 4144 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 8192 | IN | |
2024-06-29 13:42:10 UTC | 20 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49745 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:11 UTC | 693 | OUT | |
2024-06-29 13:42:11 UTC | 734 | IN | |
2024-06-29 13:42:11 UTC | 1487 | IN | |
2024-06-29 13:42:11 UTC | 1844 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49749 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:12 UTC | 693 | OUT | |
2024-06-29 13:42:12 UTC | 738 | IN | |
2024-06-29 13:42:12 UTC | 1813 | IN | |
2024-06-29 13:42:12 UTC | 6073 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49751 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:12 UTC | 383 | OUT | |
2024-06-29 13:42:12 UTC | 731 | IN | |
2024-06-29 13:42:12 UTC | 1500 | IN | |
2024-06-29 13:42:12 UTC | 1831 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49750 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:12 UTC | 161 | OUT | |
2024-06-29 13:42:12 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49752 | 13.107.136.10 | 443 | 4948 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:13 UTC | 383 | OUT | |
2024-06-29 13:42:13 UTC | 736 | IN | |
2024-06-29 13:42:13 UTC | 2383 | IN | |
2024-06-29 13:42:13 UTC | 5503 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49755 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:13 UTC | 239 | OUT | |
2024-06-29 13:42:13 UTC | 515 | IN | |
2024-06-29 13:42:13 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49757 | 13.85.23.86 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:19 UTC | 306 | OUT | |
2024-06-29 13:42:19 UTC | 560 | IN | |
2024-06-29 13:42:19 UTC | 15824 | IN | |
2024-06-29 13:42:19 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49763 | 13.85.23.86 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-06-29 13:42:57 UTC | 306 | OUT | |
2024-06-29 13:42:58 UTC | 560 | IN | |
2024-06-29 13:42:58 UTC | 15824 | IN | |
2024-06-29 13:42:58 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 09:41:59 |
Start date: | 29/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 09:42:05 |
Start date: | 29/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 09:42:07 |
Start date: | 29/06/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |