Windows
Analysis Report
https://omg-4wg.pages.dev/
Overview
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 5268 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6444 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2152 --fi eld-trial- handle=199 2,i,325977 0013940246 589,147214 3914517981 2169,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6168 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://omg-4 wg.pages.d ev/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_BlockedWebSite | Yara detected BlockedWebSite | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_BlockedWebSite | Yara detected BlockedWebSite | Joe Security | ||
JoeSecurity_BlockedWebSite | Yara detected BlockedWebSite | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | SlashNext: |
Phishing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | SlashNext | Credential Stealing type: Phishing & Social Engineering |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.181.228 | true | false | unknown | |
omg-4wg.pages.dev | 188.114.96.3 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
188.114.97.3 | unknown | European Union | 13335 | CLOUDFLARENETUS | false | |
142.250.181.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
188.114.96.3 | omg-4wg.pages.dev | European Union | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.8 |
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1520923 |
Start date and time: | 2024-09-28 01:43:03 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://omg-4wg.pages.dev/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.phis.win@16/16@6/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.67, 172.217.16.142, 142.250.110.84, 34.104.35.123, 13.85.23.86, 192.229.221.95, 52.165.164.15, 142.250.185.67
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://omg-4wg.pages.dev/
Input | Output |
---|---|
URL: https://omg-4wg.pages.dev/ Model: jbxai | { "brand":["Cloudflare"], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"Learn More", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "has_visible_qrcode":false} |
URL: https://omg-4wg.pages.dev/ Model: jbxai | { "brand":["Cloudflare"], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"Learn More", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "has_visible_qrcode":false} |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9799972200121987 |
Encrypted: | false |
SSDEEP: | 48:8V0dxT5h++HnidAKZdA1oehwiZUklqeh6y+3:8VSng5y |
MD5: | DB6793DCB38C01E7467A1021B0934A68 |
SHA1: | 993408EE1B30FFA2EDECDB48CFC3D74B96252957 |
SHA-256: | 1E3E85B625A0D4A439201EAAEDB5CCFCB63FC946BA5FE0F9B2694505B647EE4F |
SHA-512: | A1F32846308CD37624BF6FD9DD2C7152249378A136A0BF449F2E0E2D6BA94A677CDA01949011FFFA21DBB02712D5267054F99D6E314E0B118609F06E19A225ED |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.0005904370744085 |
Encrypted: | false |
SSDEEP: | 48:8B0dxT5h++HnidAKZdA1leh/iZUkAQkqehpy+2:8BSna9Q8y |
MD5: | 5563844044C1A9F6834253F6227648FE |
SHA1: | 311915D7FEF1C3F05BEEC30155DD055BAD52CAE0 |
SHA-256: | 0F2E8D70A2DB17B845FD646B70E047384E2C4CC27065961F5BE01198718A05E3 |
SHA-512: | 3741E5A7A66AAE71AC33809476FE7B5187B55FD6225B743094863E782118565BAB6F0B7C5D5FB1D8946A9F1198B624728DB7DE4FD0E3EB5A18AC28508462A8BF |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.008682068936418 |
Encrypted: | false |
SSDEEP: | 48:8o0dxT5hbHnidAKZdA14t5eh7sFiZUkmgqeh7sTy+BX:8oSnmnFy |
MD5: | E0B0663EFB597BD95D20A7047A2A8143 |
SHA1: | B9763FDE19A5603FA33CDB54B29065AA5979E7A1 |
SHA-256: | A1DDB40572100262FCFAFE74E97945BE479D1067E8361D15F5380560B26190E6 |
SHA-512: | 4DDFD0C100334B9E68A85A0508E9FDABEB212345607B1B4F52786FA75B2006C5472787DF1401F1FAC2E97BAABBD7B3CDBEFC901DC7234D7A79F96A2F1ECE318A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.996996733495735 |
Encrypted: | false |
SSDEEP: | 48:8A40dxT5h++HnidAKZdA16ehDiZUkwqeh9y+R:8A4SnRry |
MD5: | 4685E0B19CCD213481FC436E88FD0F81 |
SHA1: | DB19BFE93E2205B91FDA8E36BA6AC62CEB60DB3D |
SHA-256: | 9AC1D00C9D904CB3F7338F5B643637A3FBB104F4209C5AB4E9AA945211CAB05D |
SHA-512: | 64567D724CA5E133456A9CEAC3F830381AF92CE5B356248157AB3CA34E3C0210A6AE8827C0F3F256F47359EEC57CC87E1CFA558FA3E17585BCA4A68F3F166D82 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9861826939336704 |
Encrypted: | false |
SSDEEP: | 48:8c0dxT5h++HnidAKZdA1UehBiZUk1W1qeh/y+C:8cSnR9fy |
MD5: | B2139FC8443AA26AD17AFD3F869FF12A |
SHA1: | 6050B522C8128A848D07AA40ED6A324404A408A1 |
SHA-256: | 9AEB64B3595738101D99D0F88E0BA1DF3B7B41D40074640C39823876546A6E8C |
SHA-512: | 6046E40465970FC942C326B16D6CB04156E1C5A6D481876DE36A51227E547C4C00A0DC8AC24E576EADD523EF07F1A746CB54ADA45BC9AB89D13D4914D6D1A2BD |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.995807787542547 |
Encrypted: | false |
SSDEEP: | 48:8h0dxT5h++HnidAKZdA1duTrehOuTbbiZUk5OjqehOuTbFy+yT+:8hSnuTYTbxWOvTbFy7T |
MD5: | 05C7B29EE71E934E214785FCC59FB7FF |
SHA1: | 88259BF4C7BC6D2C531F3F8835D96CE21B8DF7F5 |
SHA-256: | 92762967E514EB5C8F0C1CF797991A3CAADD3132F3568648C2B5E713D7F2B555 |
SHA-512: | 19C2C9CDF576C81BFAE8EA98FA5C3848B88F2B0F0D500A131DBA38EE3E0037A31E50286D6FA16792B4FCC1EABB4709C638E262DF68A10827A22D37E3940864E8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 24051 |
Entropy (8bit): | 4.941039417164537 |
Encrypted: | false |
SSDEEP: | 192:VuR/6okgTQwq23gGM8lUR9YRGQ2BwoX6zp+1+nDT1FvxKSI7/UsV7MSE6XZ2dKzk:JwV+oUcoQJpdf1dxKSI7/Ue7ZX2qk |
MD5: | 5E8C69A459A691B5D1B9BE442332C87D |
SHA1: | F24DD1AD7C9080575D92A9A9A2C42620725EF836 |
SHA-256: | 84E3C77025ACE5AF143972B4A40FC834DCDFD4E449D4B36A57E62326F16B3091 |
SHA-512: | 6DB74B262D717916DE0B0B600EEAD2CC6A10E52A9E26D701FAE761FCBC931F35F251553669A92BE3B524F380F32E62AC6AD572BEA23C78965228CE9EFB92ED42 |
Malicious: | false |
Reputation: | low |
URL: | https://omg-4wg.pages.dev/cdn-cgi/styles/cf.errors.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 452 |
Entropy (8bit): | 7.0936408308765495 |
Encrypted: | false |
SSDEEP: | 12:6v/7EljW8E6Cl2SYh8SZM4tf70FSDvMXDxJp6ScFChY9:U8hCl2SIdZBtAFSDUX/ozIhK |
MD5: | C33DE66281E933259772399D10A6AFE8 |
SHA1: | B9F9D500F8814381451011D4DCF59CD2D90AD94F |
SHA-256: | F1591A5221136C49438642155691AE6C68E25B7241F3D7EBE975B09A77662016 |
SHA-512: | 5834FB9D66F550E6CECFE484B7B6A14F3FCA795405DECE8E652BD69AD917B94B6BBDCDF7639161B9C07F0D33EABD3E79580446B5867219F72F4FC43FD43B98C3 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4394 |
Entropy (8bit): | 5.09230430451693 |
Encrypted: | false |
SSDEEP: | 96:1j9jwIjYjUDK/D5DMF+BOismMA2ZLimvrR49PaQxJbGD:1j9jhjYjIK/Vo+tsPZOmvrO9ieJGD |
MD5: | 4321438C90690A74424E375101B048DE |
SHA1: | 3196580F74AD651F00FAF85D8B9E49A81CB6A01D |
SHA-256: | CEC6CE33B26929118B4E1412E6260A46610B3AF3A241B8C02F922AE564646ACA |
SHA-512: | 5A7F6BDD9A1D47BD7DD58055EBB95D9899231DA13439722CD3FD87379016807DB7563FE4F9D6C3A03C161F214B9B657F522C449BE11881CF9C481EF2D97237F2 |
Malicious: | false |
Reputation: | low |
URL: | https://omg-4wg.pages.dev/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2409 |
Entropy (8bit): | 7.8337791782799115 |
Encrypted: | false |
SSDEEP: | 48:aZ3wanKjwC5o1Tt7WeBs0ThqaFfga5INLKr:2gdwC+1TEANq0fP6Wr |
MD5: | 1635ED0E8715C40D4BED875B7494A93A |
SHA1: | CA2C72821B30194B9B6DAF9C8C0CE1723FE54614 |
SHA-256: | 504B4621E486970F8C1721D5297561C9F33296F516C83FBB33A0FF3F4F7C1357 |
SHA-512: | F710268687FCD3DA9BD9FFEE9CBF166D21598CAB5FF1172C510FD478F57300AF7112F35132BA345A2242B65FF53CDE9DE6EBF0F1EA8CF7F5FCE17C832A5A85D8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 452 |
Entropy (8bit): | 7.0936408308765495 |
Encrypted: | false |
SSDEEP: | 12:6v/7EljW8E6Cl2SYh8SZM4tf70FSDvMXDxJp6ScFChY9:U8hCl2SIdZBtAFSDUX/ozIhK |
MD5: | C33DE66281E933259772399D10A6AFE8 |
SHA1: | B9F9D500F8814381451011D4DCF59CD2D90AD94F |
SHA-256: | F1591A5221136C49438642155691AE6C68E25B7241F3D7EBE975B09A77662016 |
SHA-512: | 5834FB9D66F550E6CECFE484B7B6A14F3FCA795405DECE8E652BD69AD917B94B6BBDCDF7639161B9C07F0D33EABD3E79580446B5867219F72F4FC43FD43B98C3 |
Malicious: | false |
Reputation: | low |
URL: | https://omg-4wg.pages.dev/cdn-cgi/images/icon-exclamation.png?1376755637 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2409 |
Entropy (8bit): | 7.8337791782799115 |
Encrypted: | false |
SSDEEP: | 48:aZ3wanKjwC5o1Tt7WeBs0ThqaFfga5INLKr:2gdwC+1TEANq0fP6Wr |
MD5: | 1635ED0E8715C40D4BED875B7494A93A |
SHA1: | CA2C72821B30194B9B6DAF9C8C0CE1723FE54614 |
SHA-256: | 504B4621E486970F8C1721D5297561C9F33296F516C83FBB33A0FF3F4F7C1357 |
SHA-512: | F710268687FCD3DA9BD9FFEE9CBF166D21598CAB5FF1172C510FD478F57300AF7112F35132BA345A2242B65FF53CDE9DE6EBF0F1EA8CF7F5FCE17C832A5A85D8 |
Malicious: | false |
Reputation: | low |
URL: | https://omg-4wg.pages.dev/favicon.ico |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 28, 2024 01:43:53.136868000 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:43:53.465037107 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:43:53.793093920 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Sep 28, 2024 01:43:55.058850050 CEST | 49671 | 443 | 192.168.2.8 | 204.79.197.203 |
Sep 28, 2024 01:43:55.418191910 CEST | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Sep 28, 2024 01:44:01.557817936 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:01.557871103 CEST | 443 | 49710 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:01.557946920 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:01.558165073 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:01.558207035 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:01.558264971 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:01.558461905 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:01.558480978 CEST | 443 | 49710 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:01.558748007 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:01.558763981 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.034753084 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.040294886 CEST | 443 | 49710 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.088994980 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.090081930 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.204969883 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.204983950 CEST | 443 | 49710 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.205282927 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.205303907 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.206156969 CEST | 443 | 49710 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.206234932 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.206435919 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.206445932 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.206491947 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219060898 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219086885 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219153881 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219166994 CEST | 443 | 49711 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.219227076 CEST | 49711 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219521046 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219595909 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.219693899 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219957113 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.219995022 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.220043898 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.220046997 CEST | 443 | 49710 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.220097065 CEST | 49710 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.220784903 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.220809937 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.220858097 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.221513033 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.221548080 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.222131014 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.222142935 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.684674025 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.698072910 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.698230028 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.698241949 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.698405981 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.698483944 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.699404955 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.699464083 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.699476004 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.699528933 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.714708090 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.714807987 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.715548992 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.715686083 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.716377974 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.716388941 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.744246006 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:02.769927025 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.769973040 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.770010948 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.815428972 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.815466881 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.815481901 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.815512896 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.815532923 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.815570116 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.815725088 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.815799952 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.815845013 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.816340923 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.901169062 CEST | 49713 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.901195049 CEST | 443 | 49713 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:02.909123898 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:02.951411009 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011163950 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011204004 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011300087 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.011323929 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011363983 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011382103 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011421919 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011428118 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.011430025 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011475086 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011492968 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.011864901 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011888027 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011914968 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.011928082 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.011987925 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.016206026 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.067590952 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.067632914 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:03.100554943 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.101506948 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.101526976 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.101577044 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.101602077 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.101716995 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.101728916 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.101905107 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.101960897 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.107136011 CEST | 49712 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.107173920 CEST | 443 | 49712 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.232629061 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.232712030 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.232784986 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.233186960 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.233232021 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.393703938 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Sep 28, 2024 01:44:03.685990095 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.686252117 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.686278105 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.687264919 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.687329054 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.687676907 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.687735081 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.687745094 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.687802076 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.687813997 CEST | 443 | 49716 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.687830925 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.687879086 CEST | 49716 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.688105106 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.688179016 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:03.688298941 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.688570976 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:03.688589096 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.136795044 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.136826038 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.136940956 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.137214899 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.137227058 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.144961119 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.145174026 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.145206928 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.145540953 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.152611017 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.152681112 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.152707100 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.194766045 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.194780111 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.282636881 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.282712936 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.282768011 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.756079912 CEST | 49717 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.756100893 CEST | 443 | 49717 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.767549038 CEST | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:04.767627001 CEST | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:04.769752979 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.770041943 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.770051956 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.771094084 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.771155119 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.787182093 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.787353039 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.797434092 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.797475100 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.797557116 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.798508883 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:04.798523903 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:04.832489014 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:04.832498074 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:04.879415989 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:05.255552053 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.258789062 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.258814096 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.259841919 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.259902000 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.260694981 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.260715961 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.260756016 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.260940075 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.260955095 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.260965109 CEST | 443 | 49719 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.260979891 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.260992050 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.261014938 CEST | 49719 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.261428118 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.261498928 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.261562109 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.261744022 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:05.261759043 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.471127987 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:05.471165895 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:05.471252918 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:05.473265886 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:05.473280907 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:05.866848946 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:05.866883993 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:05.867049932 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:05.877357006 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:05.877370119 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.008718967 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.009287119 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.009300947 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.010747910 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.010835886 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.011296988 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.011379957 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.011768103 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.011778116 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.050622940 CEST | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Sep 28, 2024 01:44:06.066240072 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.117686987 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.117782116 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.137288094 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.137325048 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.137397051 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.137413979 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.137562037 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.195919991 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.195946932 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.196521044 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.238121986 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.330950022 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.359786034 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.359817982 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.361000061 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.361077070 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.361444950 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.361510038 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.361536026 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.361634016 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.361634016 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.361649036 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.361973047 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.361974001 CEST | 49722 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.362011909 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.362082958 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.372028112 CEST | 49720 | 443 | 192.168.2.8 | 188.114.96.3 |
Sep 28, 2024 01:44:06.372065067 CEST | 443 | 49720 | 188.114.96.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.388089895 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.388108015 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.482897997 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.487441063 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.487488031 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.487552881 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.488008976 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.488027096 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.523418903 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.668179989 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.668579102 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.668656111 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.668700933 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.668720007 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.668734074 CEST | 49721 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.668739080 CEST | 443 | 49721 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.733936071 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.733979940 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.734069109 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.734482050 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:06.734497070 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:06.872915030 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.873938084 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.873954058 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.875469923 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.875566006 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.876436949 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.876554966 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.876656055 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.919404984 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.925349951 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.925360918 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.972316027 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.984564066 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.993065119 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:06.993093014 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.994261980 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:06.994344950 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.013195992 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.013302088 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.013439894 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.022104979 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.022135973 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.022284031 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.022295952 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.022399902 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.022751093 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.022795916 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.022859097 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.023575068 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.023595095 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.025283098 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.025300980 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.385889053 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.386210918 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:07.396747112 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:07.396764040 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.397113085 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.398230076 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:07.439393997 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.496752977 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.497030973 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.497052908 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.497361898 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.498550892 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.498600960 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.498853922 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.539396048 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.657983065 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.658020973 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.658094883 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.658143997 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.660595894 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 28, 2024 01:44:07.660610914 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 28, 2024 01:44:07.664911985 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.665003061 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.665133953 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:07.775955915 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:07.775955915 CEST | 49726 | 443 | 192.168.2.8 | 184.28.90.27 |
Sep 28, 2024 01:44:07.775983095 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:07.775993109 CEST | 443 | 49726 | 184.28.90.27 | 192.168.2.8 |
Sep 28, 2024 01:44:14.675028086 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:14.675101042 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:14.675188065 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:16.138001919 CEST | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:16.138003111 CEST | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:16.138880014 CEST | 49730 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:16.138937950 CEST | 443 | 49730 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:16.139255047 CEST | 49730 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:16.142261028 CEST | 49730 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:16.142276049 CEST | 443 | 49730 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:16.142884970 CEST | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:16.142921925 CEST | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:16.268857002 CEST | 49718 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:44:16.268893003 CEST | 443 | 49718 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:44:16.757987022 CEST | 443 | 49730 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:16.758218050 CEST | 49730 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:35.991616011 CEST | 443 | 49730 | 23.206.229.226 | 192.168.2.8 |
Sep 28, 2024 01:44:35.991835117 CEST | 49730 | 443 | 192.168.2.8 | 23.206.229.226 |
Sep 28, 2024 01:44:45.410947084 CEST | 49703 | 80 | 192.168.2.8 | 93.184.221.240 |
Sep 28, 2024 01:44:45.416032076 CEST | 80 | 49703 | 93.184.221.240 | 192.168.2.8 |
Sep 28, 2024 01:44:45.416110039 CEST | 49703 | 80 | 192.168.2.8 | 93.184.221.240 |
Sep 28, 2024 01:45:04.125691891 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:04.125806093 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:04.125907898 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:04.126283884 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:04.126322985 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:04.774288893 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:04.774648905 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:04.774677992 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:04.775027037 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:04.776249886 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:04.776339054 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:04.819962978 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:14.703713894 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:14.703798056 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Sep 28, 2024 01:45:14.704432011 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:16.209348917 CEST | 49733 | 443 | 192.168.2.8 | 142.250.181.228 |
Sep 28, 2024 01:45:16.209382057 CEST | 443 | 49733 | 142.250.181.228 | 192.168.2.8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 28, 2024 01:44:00.037885904 CEST | 53 | 64827 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:00.050410032 CEST | 53 | 60003 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:01.035286903 CEST | 53 | 58687 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:01.544384003 CEST | 49882 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 28, 2024 01:44:01.544511080 CEST | 61187 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 28, 2024 01:44:01.555701017 CEST | 53 | 49882 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:01.557224035 CEST | 53 | 61187 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:04.074733973 CEST | 57923 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 28, 2024 01:44:04.074968100 CEST | 60930 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 28, 2024 01:44:04.081778049 CEST | 53 | 57923 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:04.082005024 CEST | 53 | 60930 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:05.850572109 CEST | 58045 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 28, 2024 01:44:05.851089001 CEST | 53756 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 28, 2024 01:44:05.861795902 CEST | 53 | 58045 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:05.863672018 CEST | 53 | 53756 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:18.293801069 CEST | 53 | 49200 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:37.121054888 CEST | 53 | 55262 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:44.216491938 CEST | 138 | 138 | 192.168.2.8 | 192.168.2.255 |
Sep 28, 2024 01:44:59.317409039 CEST | 53 | 55596 | 1.1.1.1 | 192.168.2.8 |
Sep 28, 2024 01:44:59.910054922 CEST | 53 | 63149 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 28, 2024 01:44:01.544384003 CEST | 192.168.2.8 | 1.1.1.1 | 0x71a5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 28, 2024 01:44:01.544511080 CEST | 192.168.2.8 | 1.1.1.1 | 0xc530 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 28, 2024 01:44:04.074733973 CEST | 192.168.2.8 | 1.1.1.1 | 0x563f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 28, 2024 01:44:04.074968100 CEST | 192.168.2.8 | 1.1.1.1 | 0xef74 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 28, 2024 01:44:05.850572109 CEST | 192.168.2.8 | 1.1.1.1 | 0x516f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 28, 2024 01:44:05.851089001 CEST | 192.168.2.8 | 1.1.1.1 | 0xe346 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 28, 2024 01:44:01.555701017 CEST | 1.1.1.1 | 192.168.2.8 | 0x71a5 | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:01.555701017 CEST | 1.1.1.1 | 192.168.2.8 | 0x71a5 | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:01.557224035 CEST | 1.1.1.1 | 192.168.2.8 | 0xc530 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 28, 2024 01:44:04.081778049 CEST | 1.1.1.1 | 192.168.2.8 | 0x563f | No error (0) | 142.250.181.228 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:04.082005024 CEST | 1.1.1.1 | 192.168.2.8 | 0xef74 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 28, 2024 01:44:05.861795902 CEST | 1.1.1.1 | 192.168.2.8 | 0x516f | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:05.861795902 CEST | 1.1.1.1 | 192.168.2.8 | 0x516f | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:05.863672018 CEST | 1.1.1.1 | 192.168.2.8 | 0xe346 | No error (0) | 65 | IN (0x0001) | false | |||
Sep 28, 2024 01:44:14.288578033 CEST | 1.1.1.1 | 192.168.2.8 | 0xd1ab | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:14.288578033 CEST | 1.1.1.1 | 192.168.2.8 | 0xd1ab | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:27.902089119 CEST | 1.1.1.1 | 192.168.2.8 | 0x55fd | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:27.902089119 CEST | 1.1.1.1 | 192.168.2.8 | 0x55fd | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:52.214402914 CEST | 1.1.1.1 | 192.168.2.8 | 0x2ba9 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 28, 2024 01:44:52.214402914 CEST | 1.1.1.1 | 192.168.2.8 | 0x2ba9 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Sep 28, 2024 01:45:12.434254885 CEST | 1.1.1.1 | 192.168.2.8 | 0xd1a9 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 28, 2024 01:45:12.434254885 CEST | 1.1.1.1 | 192.168.2.8 | 0xd1a9 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49713 | 188.114.96.3 | 443 | 6444 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:02 UTC | 660 | OUT | |
2024-09-27 23:44:02 UTC | 602 | IN | |
2024-09-27 23:44:02 UTC | 767 | IN | |
2024-09-27 23:44:02 UTC | 1369 | IN | |
2024-09-27 23:44:02 UTC | 1369 | IN | |
2024-09-27 23:44:02 UTC | 897 | IN | |
2024-09-27 23:44:02 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49712 | 188.114.96.3 | 443 | 6444 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:02 UTC | 561 | OUT | |
2024-09-27 23:44:03 UTC | 411 | IN | |
2024-09-27 23:44:03 UTC | 958 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN | |
2024-09-27 23:44:03 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49717 | 188.114.96.3 | 443 | 6444 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:04 UTC | 653 | OUT | |
2024-09-27 23:44:04 UTC | 409 | IN | |
2024-09-27 23:44:04 UTC | 452 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49720 | 188.114.96.3 | 443 | 6444 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:06 UTC | 590 | OUT | |
2024-09-27 23:44:06 UTC | 720 | IN | |
2024-09-27 23:44:06 UTC | 649 | IN | |
2024-09-27 23:44:06 UTC | 1369 | IN | |
2024-09-27 23:44:06 UTC | 391 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49721 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:06 UTC | 161 | OUT | |
2024-09-27 23:44:06 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49723 | 188.114.97.3 | 443 | 6444 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:06 UTC | 387 | OUT | |
2024-09-27 23:44:07 UTC | 409 | IN | |
2024-09-27 23:44:07 UTC | 452 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.8 | 49726 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:07 UTC | 239 | OUT | |
2024-09-27 23:44:07 UTC | 515 | IN | |
2024-09-27 23:44:07 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.8 | 49727 | 188.114.97.3 | 443 | 6444 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 23:44:07 UTC | 352 | OUT | |
2024-09-27 23:44:07 UTC | 720 | IN | |
2024-09-27 23:44:07 UTC | 649 | IN | |
2024-09-27 23:44:07 UTC | 1369 | IN | |
2024-09-27 23:44:07 UTC | 391 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 19:43:54 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 19:43:58 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 19:44:00 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |