Windows
Analysis Report
http://www.coolcatalogue.eu/np/cool2024/hu/files/content-page/55a9d7862d5de5084903c7ae3adf5dff.zip
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6312 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6976 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2180 --fi eld-trial- handle=198 0,i,100275 7591893841 6306,16167 8557752971 27617,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6644 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://www.co olcatalogu e.eu/np/co ol2024/hu/ files/cont ent-page/5 5a9d7862d5 de5084903c 7ae3adf5df f.zip" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- rundll32.exe (PID: 3364 cmdline:
C:\Windows \System32\ rundll32.e xe C:\Wind ows\System 32\shell32 .dll,SHCre ateLocalSe rverRunDll {9aa46009 -3ce0-458a -a354-7156 10a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_ZipBomb | Yara detected ZipBomb | Joe Security | ||
JoeSecurity_ZipBomb | Yara detected ZipBomb | Joe Security |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-01T11:10:08.226755+0200 | 2018575 | 1 | A Network Trojan was detected | 95.131.50.86 | 443 | 192.168.2.16 | 49717 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-01T11:10:08.226755+0200 | 2018576 | 1 | A Network Trojan was detected | 95.131.50.86 | 443 | 192.168.2.16 | 49717 | TCP |
Click to jump to signature section
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | File dump: | Jump to dropped file |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Rundll32 | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
google.com | 142.250.184.206 | true | false | unknown | |
cool-catalogue.eu | 95.131.50.86 | true | true | unknown | |
www.google.com | 142.250.184.228 | true | false | unknown | |
coolcatalogue.eu | 95.131.50.86 | true | true | unknown | |
www.coolcatalogue.eu | unknown | unknown | false | unknown | |
cool-catalogue.eunp | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
false |
| unknown | |
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.184.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
95.131.50.86 | cool-catalogue.eu | Hungary | 12301 | INVITECHHU | true |
IP |
---|
192.168.2.23 |
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1523255 |
Start date and time: | 2024-10-01 11:09:10 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://www.coolcatalogue.eu/np/cool2024/hu/files/content-page/55a9d7862d5de5084903c7ae3adf5dff.zip |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal60.evad.win@25/12@24/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.99, 74.125.133.84, 142.250.186.174, 34.104.35.123, 172.217.18.3, 172.217.16.206
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9777605293666114 |
Encrypted: | false |
SSDEEP: | 48:8jd3TvyI4H/idAKZdA1FehwiZUklqehs5y+3:8NGI4jy |
MD5: | 8C552AE349D0CC45C0E43759392FC996 |
SHA1: | 48C1C51A6D614261FC1B81FC3D297341382DDCF8 |
SHA-256: | 33FC4841661C9E87B625B8A03A4ED6C6F36EA16FB8C6EA36BD65978DA023D69A |
SHA-512: | DCB023B26383B4B51E8B01164EBBF23904226715723A0A769F2778770A80979420E36795FF8F9802090AE1D2C8AC09B4A9586BCF929BCD051089B3246D17EE9D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9937751319032713 |
Encrypted: | false |
SSDEEP: | 48:8gd3TvyI4H/idAKZdA1seh/iZUkAQkqehh5y+2:8UGIO9Qey |
MD5: | AB3922947368C1D7B5E9AD9CCFE60C03 |
SHA1: | C5DBDFE6B766C1D1A15E4531C9ADD7321DCE498A |
SHA-256: | 40B83E08EFB4BC6EDF2C03D29C390A6D5A50001B91C3FD43FEC14679257E8DD7 |
SHA-512: | 8323C3463A00CCF0496E5882490077B97C4723533BBBDD9E6094C15BDEAD794F8ADADCEAD68380D0DDF2BE54DF1CA7417AA25374B8631F8964E799A3FBB0A285 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.003926989118602 |
Encrypted: | false |
SSDEEP: | 48:8ad3TvyIAH/idAKZdA14meh7sFiZUkmgqeh7sf5y+BX:8OGIin3y |
MD5: | D3863DEB9DF5D56E631E96C015052876 |
SHA1: | CF425ADE33CD7EE62306629EEA9A7DA908F5E3EF |
SHA-256: | 822AA789332E5C732848EF8E8AE3526E2BFEEEB063A2976F5C9344EDDAA0EACF |
SHA-512: | 7616EA467A38C682FAF218B1A51A94C869B54167E87957D4D76FE6261A507DB9195FF38B3B7FBF3187143BD7939631F77479EEAC49835990CC56B6086D4D167A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9905768173934075 |
Encrypted: | false |
SSDEEP: | 48:82Sd3TvyI4H/idAKZdA1TehDiZUkwqehl5y+R:82WGIl5y |
MD5: | B30D7E7C242B25BD657C36555ED5B010 |
SHA1: | 49EFDD4E938861EB6B7AA034E9FCE7837E975EEB |
SHA-256: | 97D3C75DF50141B43F50501B8816A5A98FBA5411041DAF156A176FA1D0F617EB |
SHA-512: | E6677395A6024408FAB0AA964C728700513156C304EAF883C88A4F978FBD2A14A4413261EF665847420B5E8EB2B8212D9715ACF173A321CCEF4B7CF273AAEAE3 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9797142983392724 |
Encrypted: | false |
SSDEEP: | 48:85d3TvyI4H/idAKZdA1dehBiZUk1W1qehb5y+C:87GIV9ly |
MD5: | 1B5C13AB8B2F719E4F6E3DEBA4AE4DE0 |
SHA1: | B68DC47B4C57FB6AAE2BE2DED7E8B70368DB5768 |
SHA-256: | CBA7C19371DBDC4563653EDA9880537AC4AF18B1DC66EDE104A07402CF8CB56D |
SHA-512: | B1E9DF588C06FDF6FA11799C7A0DEC4BE127A38EBCB1E73521894242C766A2A25ED8F848F637F363B1093BAE722DB874AFBFA996E16712657BD101A7676C555F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.990159824087372 |
Encrypted: | false |
SSDEEP: | 48:8/K+d3TvyI4H/idAKZdA1duTeehOuTbbiZUk5OjqehOuTbd5y+yT+:8/KaGIdTfTbxWOvTb3y7T |
MD5: | 9230ED277524C54AC9DE3F4094A6F8D7 |
SHA1: | 48482763C1E239CA4818446C26211C76F0683A35 |
SHA-256: | 27267A41AC1BA07025CEAC8D24F5B21E390B5EED420DF3AB4167EE998DD700AB |
SHA-512: | C5A12AA6ABFF441212BFB5B601DB4DA779567266FD1DF1EC5FF823B815725A1C65B2773B8C50768E36CF3F78D7C627D8E2DB6F81BC787DA7099C6343CCC0D747 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 133611 |
Entropy (8bit): | 7.960021636413181 |
Encrypted: | false |
SSDEEP: | 3072:KTNtt8NHkV9i2wITzGbhfooJ4hTFCNvoQz3+rXC80dRW0OzqnFa6:KTHeNE7U4zGbhfLJyFcvl3+TC80dRWze |
MD5: | CFF2C29ADBF021D690ACF2586841C1CD |
SHA1: | 7F68C8159C5046843EE4B6B2A5AD048C91EB2DB6 |
SHA-256: | 35299AE86DAAD35B36A710CAD99F60AD23A18666AEE1468A41136DB5B4E754CC |
SHA-512: | 83E23801BF24D73D5F63EB138F6B8B8257260A89E04F8E0AA5FF5EC2A8DCF80F8CEC2F4820A0E8FFC80CE1A8AE302CB48BC352D6F03ECBD58EF9213F343DED86 |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 133611 |
Entropy (8bit): | 7.960021636413181 |
Encrypted: | false |
SSDEEP: | 3072:KTNtt8NHkV9i2wITzGbhfooJ4hTFCNvoQz3+rXC80dRW0OzqnFa6:KTHeNE7U4zGbhfLJyFcvl3+TC80dRWze |
MD5: | CFF2C29ADBF021D690ACF2586841C1CD |
SHA1: | 7F68C8159C5046843EE4B6B2A5AD048C91EB2DB6 |
SHA-256: | 35299AE86DAAD35B36A710CAD99F60AD23A18666AEE1468A41136DB5B4E754CC |
SHA-512: | 83E23801BF24D73D5F63EB138F6B8B8257260A89E04F8E0AA5FF5EC2A8DCF80F8CEC2F4820A0E8FFC80CE1A8AE302CB48BC352D6F03ECBD58EF9213F343DED86 |
Malicious: | true |
Yara Hits: |
|
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3751 |
Entropy (8bit): | 5.851433785290175 |
Encrypted: | false |
SSDEEP: | 96:HilizH6666nVdr7bmHHgbwf/q61TyoWdNO57dsRBqfD22X9dfQfffo:HQQH6666nfr273q61WOrsmD2+91 |
MD5: | CAEA04B5622F8B636924A5B00F164605 |
SHA1: | EFF5EFF815E3F49EE2B53BD7BCB803E24815E791 |
SHA-256: | 86FEF94A1A33261C5566EC88EE5FB8A202A11496C2874B1C45157ADEB05E7740 |
SHA-512: | 5AFAE1DDA3E1F5C091E2A334554C70A13ADCF723E67A46142841F5782F1627F7AC4074C7D36F86F2C7624C090BFB80AF9442F6996D821F2008E2E7A4F04E0997 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 133611 |
Entropy (8bit): | 7.960021636413181 |
Encrypted: | false |
SSDEEP: | 3072:KTNtt8NHkV9i2wITzGbhfooJ4hTFCNvoQz3+rXC80dRW0OzqnFa6:KTHeNE7U4zGbhfLJyFcvl3+TC80dRWze |
MD5: | CFF2C29ADBF021D690ACF2586841C1CD |
SHA1: | 7F68C8159C5046843EE4B6B2A5AD048C91EB2DB6 |
SHA-256: | 35299AE86DAAD35B36A710CAD99F60AD23A18666AEE1468A41136DB5B4E754CC |
SHA-512: | 83E23801BF24D73D5F63EB138F6B8B8257260A89E04F8E0AA5FF5EC2A8DCF80F8CEC2F4820A0E8FFC80CE1A8AE302CB48BC352D6F03ECBD58EF9213F343DED86 |
Malicious: | false |
Reputation: | low |
URL: | https://cool-catalogue.eu/np/cool2024/hu/files/content-page/55a9d7862d5de5084903c7ae3adf5dff.zip |
Preview: |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-01T11:10:08.226755+0200 | 2018575 | ET MALWARE Possible Andromeda download with fake Zip header (1) | 1 | 95.131.50.86 | 443 | 192.168.2.16 | 49717 | TCP |
2024-10-01T11:10:08.226755+0200 | 2018576 | ET MALWARE Possible Andromeda download with fake Zip header (2) | 1 | 95.131.50.86 | 443 | 192.168.2.16 | 49717 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 1, 2024 11:09:42.627710104 CEST | 49706 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:42.627985954 CEST | 49707 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:42.632641077 CEST | 80 | 49706 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:09:42.632731915 CEST | 49706 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:42.632791042 CEST | 80 | 49707 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:09:42.632848978 CEST | 49707 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:42.632910013 CEST | 49706 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:42.637643099 CEST | 80 | 49706 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:09:42.942648888 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:09:43.245623112 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:09:43.279963017 CEST | 80 | 49706 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:09:43.324620008 CEST | 49706 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:43.850605965 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:09:45.053597927 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:09:45.696803093 CEST | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:09:46.515677929 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:46.515738964 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:46.515913963 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:46.516195059 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:46.516206980 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:47.158607006 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:47.158937931 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:47.158967972 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:47.160022974 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:47.160092115 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:47.161570072 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:47.161674976 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:47.206561089 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:47.206590891 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:47.254576921 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:47.462579966 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:09:48.285478115 CEST | 80 | 49706 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:09:48.285582066 CEST | 49706 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:49.208048105 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:49.208138943 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:49.208239079 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:49.209803104 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:49.209839106 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:49.420562029 CEST | 49706 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:09:49.425407887 CEST | 80 | 49706 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:09:49.848936081 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:49.849034071 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:49.852691889 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:49.852708101 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:49.852961063 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:49.895539999 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:49.943401098 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.121067047 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.121159077 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.121270895 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.121318102 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.121318102 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.121342897 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.121355057 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.164489985 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.164520025 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.164593935 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.164979935 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.164995909 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.824398994 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.824537992 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.826307058 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.826319933 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.826585054 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:50.828144073 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:50.871432066 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:51.112912893 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:09:51.415568113 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:09:51.415754080 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:51.415832996 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:51.417526007 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:51.417596102 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:51.417596102 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 1, 2024 11:09:51.417634964 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:51.417660952 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 1, 2024 11:09:51.425332069 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:51.425375938 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:51.425571918 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:51.427040100 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:51.427050114 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.021563053 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:09:52.191577911 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.191705942 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.194330931 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.194341898 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.194720030 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.245543003 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.259062052 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.277538061 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:09:52.303419113 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511347055 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511368036 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511377096 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511404991 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511420965 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511429071 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511446953 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.511460066 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.511573076 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.512171984 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.512258053 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.512264967 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.512276888 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.512332916 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.524862051 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.524862051 CEST | 49715 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:09:52.524888039 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:52.524899006 CEST | 443 | 49715 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:09:53.221534967 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:09:55.585654974 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:09:55.633671999 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:09:55.888516903 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:09:56.494518995 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:09:57.076802015 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:57.076874971 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:09:57.076951027 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:57.707473993 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:09:57.947777033 CEST | 49711 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:09:57.947805882 CEST | 443 | 49711 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:00.116504908 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:10:00.434550047 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:10:00.734702110 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:00.734778881 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:00.734878063 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:00.735523939 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:00.735574007 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.381006002 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.381459951 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.381511927 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.382149935 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.382468939 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.382572889 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.382596016 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.423574924 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.423597097 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.672756910 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.672822952 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.672852993 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.672970057 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.673001051 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.673058987 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.674910069 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.675286055 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.675369024 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.675498009 CEST | 49716 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:01.675530910 CEST | 443 | 49716 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:01.885490894 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 1, 2024 11:10:04.930475950 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:10:06.881903887 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:06.882010937 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:06.882105112 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:06.882229090 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:06.882250071 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:06.882312059 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:06.882431030 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:06.882461071 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:06.882579088 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:06.882599115 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.819571972 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.819925070 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.819988966 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.821099043 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.821213007 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.823195934 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.825378895 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.825397015 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.827028990 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.827114105 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.828105927 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.828208923 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.828286886 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.828396082 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.828408003 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.828424931 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.870439053 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.870439053 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:07.870482922 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:07.919620991 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.022846937 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.078408003 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.124125004 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.124140024 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.124185085 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.124200106 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.124222040 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.124229908 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.124281883 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.124315023 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.124349117 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.125627041 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.125637054 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.125658035 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.125708103 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.125735044 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.125761032 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.125782013 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.225075960 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.225115061 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.225183964 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.225270987 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.225322008 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.225322962 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.226787090 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.226815939 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.226881027 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.226897001 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.226948977 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.226948977 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.227731943 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.227751970 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.227818966 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.227835894 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.227889061 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.229537010 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.229561090 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.229635000 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.229656935 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.229717016 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.339762926 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.339792967 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.339895964 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.339952946 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340014935 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340078115 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340096951 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340136051 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340151072 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340173006 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340178013 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340204000 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340214968 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340264082 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340275049 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:08.340327024 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340409994 CEST | 49717 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:08.340440989 CEST | 443 | 49717 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:10.037344933 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 1, 2024 11:10:14.544373035 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 1, 2024 11:10:27.636329889 CEST | 49707 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:27.641249895 CEST | 80 | 49707 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:27.836107016 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:27.836239100 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:27.836368084 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:27.957281113 CEST | 49718 | 443 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:27.957351923 CEST | 443 | 49718 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:28.802658081 CEST | 49697 | 80 | 192.168.2.16 | 199.232.210.172 |
Oct 1, 2024 11:10:28.802791119 CEST | 49698 | 80 | 192.168.2.16 | 199.232.210.172 |
Oct 1, 2024 11:10:28.807996035 CEST | 80 | 49697 | 199.232.210.172 | 192.168.2.16 |
Oct 1, 2024 11:10:28.808084965 CEST | 49697 | 80 | 192.168.2.16 | 199.232.210.172 |
Oct 1, 2024 11:10:28.808574915 CEST | 80 | 49698 | 199.232.210.172 | 192.168.2.16 |
Oct 1, 2024 11:10:28.808638096 CEST | 49698 | 80 | 192.168.2.16 | 199.232.210.172 |
Oct 1, 2024 11:10:29.032905102 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:29.032963991 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:29.033071995 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:29.033524036 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:29.033543110 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:29.805027008 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:29.805136919 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:29.806514978 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:29.806538105 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:29.806864023 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:29.808655024 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:29.855420113 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.125744104 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.125796080 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.125837088 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.125896931 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.125933886 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.125957012 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.125994921 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.126544952 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.126591921 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.126619101 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.126629114 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.126668930 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.126761913 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.126817942 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.129160881 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.129179955 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:30.129204035 CEST | 49719 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 1, 2024 11:10:30.129213095 CEST | 443 | 49719 | 4.245.163.56 | 192.168.2.16 |
Oct 1, 2024 11:10:34.764740944 CEST | 80 | 49707 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:34.764802933 CEST | 49707 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:35.947679043 CEST | 49707 | 80 | 192.168.2.16 | 95.131.50.86 |
Oct 1, 2024 11:10:35.952528954 CEST | 80 | 49707 | 95.131.50.86 | 192.168.2.16 |
Oct 1, 2024 11:10:46.565675020 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:46.565711975 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:46.565784931 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:46.566029072 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:46.566040993 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:47.196990013 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:47.197360992 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:47.197391033 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:47.197853088 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:47.198250055 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:47.198333025 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:47.252115965 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:57.111026049 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:57.111108065 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:10:57.111165047 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:57.946547031 CEST | 49721 | 443 | 192.168.2.16 | 142.250.184.228 |
Oct 1, 2024 11:10:57.946573019 CEST | 443 | 49721 | 142.250.184.228 | 192.168.2.16 |
Oct 1, 2024 11:11:19.475080967 CEST | 49700 | 80 | 192.168.2.16 | 192.229.221.95 |
Oct 1, 2024 11:11:19.481614113 CEST | 80 | 49700 | 192.229.221.95 | 192.168.2.16 |
Oct 1, 2024 11:11:19.481688976 CEST | 49700 | 80 | 192.168.2.16 | 192.229.221.95 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 1, 2024 11:09:41.732845068 CEST | 53 | 57153 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:41.751152992 CEST | 53 | 54683 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:42.605144024 CEST | 51894 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:42.606010914 CEST | 58998 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:42.626661062 CEST | 53 | 58998 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:42.627207041 CEST | 53 | 51894 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:42.749772072 CEST | 53 | 64284 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:43.282522917 CEST | 55326 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:43.282691956 CEST | 59948 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:43.291749001 CEST | 53 | 55326 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:43.303015947 CEST | 53 | 59948 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:43.303806067 CEST | 54494 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:43.313711882 CEST | 53 | 54494 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:43.360671997 CEST | 50502 | 53 | 192.168.2.16 | 8.8.8.8 |
Oct 1, 2024 11:09:43.361205101 CEST | 55752 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:43.367510080 CEST | 53 | 50502 | 8.8.8.8 | 192.168.2.16 |
Oct 1, 2024 11:09:43.368041992 CEST | 53 | 55752 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:44.380336046 CEST | 58267 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:44.380491018 CEST | 52143 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:44.396653891 CEST | 53 | 52143 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:44.397490025 CEST | 53 | 58267 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:46.506958961 CEST | 54916 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:46.507354975 CEST | 52311 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:46.513956070 CEST | 53 | 54916 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:46.514750957 CEST | 53 | 52311 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:49.419498920 CEST | 53574 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:49.419634104 CEST | 53034 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:49.429044962 CEST | 53 | 53034 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:49.435519934 CEST | 53 | 53574 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:49.436140060 CEST | 49199 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:09:49.451369047 CEST | 53 | 49199 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:09:59.773458004 CEST | 53 | 62280 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:06.797641993 CEST | 50299 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:10:06.797827959 CEST | 55569 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:10:06.866647005 CEST | 53 | 55569 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:06.881330013 CEST | 53 | 50299 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:18.828032970 CEST | 53 | 63312 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:38.044347048 CEST | 58596 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:10:38.044507980 CEST | 50565 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:10:38.063452005 CEST | 53 | 50565 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:38.063467026 CEST | 53 | 58596 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:38.064171076 CEST | 59717 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:10:38.079937935 CEST | 53 | 59717 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:41.367679119 CEST | 53 | 53833 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:41.654563904 CEST | 53 | 53163 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:10:47.280452013 CEST | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Oct 1, 2024 11:10:54.760548115 CEST | 61544 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:10:54.776014090 CEST | 53 | 61544 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:11:09.297240019 CEST | 53 | 51047 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:11:24.379492998 CEST | 64805 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:11:24.396135092 CEST | 53 | 64805 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:11:38.089459896 CEST | 49619 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:11:38.089587927 CEST | 52179 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:11:38.096173048 CEST | 53 | 52179 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:11:38.103864908 CEST | 53 | 49619 | 1.1.1.1 | 192.168.2.16 |
Oct 1, 2024 11:11:38.104557991 CEST | 55581 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 1, 2024 11:11:38.113522053 CEST | 53 | 55581 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 1, 2024 11:09:42.605144024 CEST | 192.168.2.16 | 1.1.1.1 | 0xdc40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:42.606010914 CEST | 192.168.2.16 | 1.1.1.1 | 0x5d64 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.282522917 CEST | 192.168.2.16 | 1.1.1.1 | 0x3092 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.282691956 CEST | 192.168.2.16 | 1.1.1.1 | 0x1622 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.303806067 CEST | 192.168.2.16 | 1.1.1.1 | 0x2977 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.360671997 CEST | 192.168.2.16 | 8.8.8.8 | 0x2341 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.361205101 CEST | 192.168.2.16 | 1.1.1.1 | 0x4028 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:44.380336046 CEST | 192.168.2.16 | 1.1.1.1 | 0xc20b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:44.380491018 CEST | 192.168.2.16 | 1.1.1.1 | 0x3152 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:46.506958961 CEST | 192.168.2.16 | 1.1.1.1 | 0x8f49 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:46.507354975 CEST | 192.168.2.16 | 1.1.1.1 | 0x5fc3 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:49.419498920 CEST | 192.168.2.16 | 1.1.1.1 | 0xf00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:49.419634104 CEST | 192.168.2.16 | 1.1.1.1 | 0x126b | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:49.436140060 CEST | 192.168.2.16 | 1.1.1.1 | 0xd5cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:06.797641993 CEST | 192.168.2.16 | 1.1.1.1 | 0xbd81 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:06.797827959 CEST | 192.168.2.16 | 1.1.1.1 | 0xe4cd | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:10:38.044347048 CEST | 192.168.2.16 | 1.1.1.1 | 0xd432 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:38.044507980 CEST | 192.168.2.16 | 1.1.1.1 | 0x75d2 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:10:38.064171076 CEST | 192.168.2.16 | 1.1.1.1 | 0x971f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:54.760548115 CEST | 192.168.2.16 | 1.1.1.1 | 0xd1e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:11:24.379492998 CEST | 192.168.2.16 | 1.1.1.1 | 0x7af4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:11:38.089459896 CEST | 192.168.2.16 | 1.1.1.1 | 0x4b1a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:11:38.089587927 CEST | 192.168.2.16 | 1.1.1.1 | 0xdc75 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:11:38.104557991 CEST | 192.168.2.16 | 1.1.1.1 | 0xba05 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 1, 2024 11:09:42.626661062 CEST | 1.1.1.1 | 192.168.2.16 | 0x5d64 | No error (0) | coolcatalogue.eu | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 1, 2024 11:09:42.627207041 CEST | 1.1.1.1 | 192.168.2.16 | 0xdc40 | No error (0) | coolcatalogue.eu | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 1, 2024 11:09:42.627207041 CEST | 1.1.1.1 | 192.168.2.16 | 0xdc40 | No error (0) | 95.131.50.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:09:43.291749001 CEST | 1.1.1.1 | 192.168.2.16 | 0x3092 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.303015947 CEST | 1.1.1.1 | 192.168.2.16 | 0x1622 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.313711882 CEST | 1.1.1.1 | 192.168.2.16 | 0x2977 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:43.367510080 CEST | 8.8.8.8 | 192.168.2.16 | 0x2341 | No error (0) | 142.250.184.206 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:09:43.368041992 CEST | 1.1.1.1 | 192.168.2.16 | 0x4028 | No error (0) | 142.250.186.142 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:09:44.396653891 CEST | 1.1.1.1 | 192.168.2.16 | 0x3152 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:44.397490025 CEST | 1.1.1.1 | 192.168.2.16 | 0xc20b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:46.513956070 CEST | 1.1.1.1 | 192.168.2.16 | 0x8f49 | No error (0) | 142.250.184.228 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:09:46.514750957 CEST | 1.1.1.1 | 192.168.2.16 | 0x5fc3 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 1, 2024 11:09:49.429044962 CEST | 1.1.1.1 | 192.168.2.16 | 0x126b | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:09:49.435519934 CEST | 1.1.1.1 | 192.168.2.16 | 0xf00 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:09:49.451369047 CEST | 1.1.1.1 | 192.168.2.16 | 0xd5cb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:06.881330013 CEST | 1.1.1.1 | 192.168.2.16 | 0xbd81 | No error (0) | 95.131.50.86 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:10:38.063452005 CEST | 1.1.1.1 | 192.168.2.16 | 0x75d2 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:10:38.063467026 CEST | 1.1.1.1 | 192.168.2.16 | 0xd432 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:38.079937935 CEST | 1.1.1.1 | 192.168.2.16 | 0x971f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:10:54.776014090 CEST | 1.1.1.1 | 192.168.2.16 | 0xd1e6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:11:24.396135092 CEST | 1.1.1.1 | 192.168.2.16 | 0x7af4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:11:38.096173048 CEST | 1.1.1.1 | 192.168.2.16 | 0xdc75 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:11:38.103864908 CEST | 1.1.1.1 | 192.168.2.16 | 0x4b1a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:11:38.113522053 CEST | 1.1.1.1 | 192.168.2.16 | 0xba05 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49706 | 95.131.50.86 | 80 | 6976 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 11:09:42.632910013 CEST | 505 | OUT | |
Oct 1, 2024 11:09:43.279963017 CEST | 612 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49707 | 95.131.50.86 | 80 | 6976 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 1, 2024 11:10:27.636329889 CEST | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49713 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:09:49 UTC | 161 | OUT | |
2024-10-01 09:09:50 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49714 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:09:50 UTC | 239 | OUT | |
2024-10-01 09:09:51 UTC | 515 | IN | |
2024-10-01 09:09:51 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49715 | 4.245.163.56 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:09:52 UTC | 306 | OUT | |
2024-10-01 09:09:52 UTC | 560 | IN | |
2024-10-01 09:09:52 UTC | 15824 | IN | |
2024-10-01 09:09:52 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49716 | 142.250.184.228 | 443 | 6976 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:10:01 UTC | 613 | OUT | |
2024-10-01 09:10:01 UTC | 1266 | IN | |
2024-10-01 09:10:01 UTC | 124 | IN | |
2024-10-01 09:10:01 UTC | 1390 | IN | |
2024-10-01 09:10:01 UTC | 1390 | IN | |
2024-10-01 09:10:01 UTC | 419 | IN | |
2024-10-01 09:10:01 UTC | 110 | IN | |
2024-10-01 09:10:01 UTC | 338 | IN | |
2024-10-01 09:10:01 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49717 | 95.131.50.86 | 443 | 6976 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:10:07 UTC | 730 | OUT | |
2024-10-01 09:10:08 UTC | 276 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 16384 | IN | |
2024-10-01 09:10:08 UTC | 2539 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49719 | 4.245.163.56 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:10:29 UTC | 306 | OUT | |
2024-10-01 09:10:30 UTC | 560 | IN | |
2024-10-01 09:10:30 UTC | 15824 | IN | |
2024-10-01 09:10:30 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 05:09:40 |
Start date: | 01/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 05:09:40 |
Start date: | 01/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 05:09:41 |
Start date: | 01/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 15 |
Start time: | 05:10:52 |
Start date: | 01/10/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff604540000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |