Windows
Analysis Report
https://bit.ly/INQUIRYNO03875
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3740 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3004 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2448 --fi eld-trial- handle=224 8,i,170177 0382558855 2381,14886 2820173103 28945,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6320 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://bit.l y/INQUIRYN O03875" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
2% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
virtltra.us | 188.114.97.3 | true | false | unknown | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | unknown | |
bit.ly | 67.199.248.10 | true | false | unknown | |
www.google.com | 172.217.18.4 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.217.18.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
188.114.97.3 | virtltra.us | European Union | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
67.199.248.10 | bit.ly | United States | 396982 | GOOGLE-PRIVATE-CLOUDUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1523265 |
Start date and time: | 2024-10-01 11:33:45 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://bit.ly/INQUIRYNO03875 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@22/6@8/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 74.125.71.84, 142.250.186.142, 34.104.35.123, 142.250.185.234, 216.58.206.74, 172.217.18.10, 142.250.186.138, 142.250.185.170, 172.217.23.106, 142.250.184.202, 142.250.185.202, 142.250.185.138, 142.250.184.234, 142.250.186.106, 142.250.181.234, 142.250.185.74, 142.250.185.106, 172.217.16.202, 216.58.212.138, 93.184.221.240, 192.229.221.95, 13.95.31.18, 172.217.16.195, 216.58.206.46
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
Input | Output |
---|---|
URL: https://virtltra.us/loading.php Model: jbxai | { "brand":[], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"Copy", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "has_visible_qrcode":false} |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2966 |
Entropy (8bit): | 5.285494210168886 |
Encrypted: | false |
SSDEEP: | 48:Swbq+g8d7+CZirJpGs3kGKsljbMeiHr6Gn3kIVhlK6uHqIYPqNpAu07C3kIS73kL:SuC51MHr6G1LXCNpk7MesB |
MD5: | 16F9BECDACAE380114A1C99BB4D528E7 |
SHA1: | D7C4E5B15078C8A9EA1CF452BEAFBA8EB45C4C95 |
SHA-256: | D9CD6DFCA94282619431285858508ADF7A4552A70C2BB6DC4F30B0C83D9B1615 |
SHA-512: | 41BD0206EB091E9649954A35EACBE0C1F56F04CAA49C68D5982C81F23EF3AEF688B775F0DE8EC57807DA354D8D4439D0E0F6484432814C1FA73C0EF7D7D013A8 |
Malicious: | false |
Reputation: | low |
URL: | https://virtltra.us/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.75 |
Encrypted: | false |
SSDEEP: | 3:HdhkYn:R |
MD5: | F1F187E22DE12A01774C36D3F0DF9FA9 |
SHA1: | C1F869A1CA62C4AAD0020ADC3FD7F2FA85163B61 |
SHA-256: | 6F99AD71696E2328CD909DDDCC3AB4CD831C5FF71112C4FC60AF03F82C296222 |
SHA-512: | 4CF15FA065B1CC37B9F21D372574AF3CCF174AE9A3E8FF38B4E4E8D486251B47049BF2B644AB2BE459F17860E7117F6FBF3D6A0EAF21C436A9931766A1B81186 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAlGBLIMl2cxrhIFDQprpws=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2916 |
Entropy (8bit): | 4.151014603646156 |
Encrypted: | false |
SSDEEP: | 48:hd9PVhdUCCGiDPFWasCZGg9w6h2qNpGFOtL8:jdVhdZCGiDPFWasCZnNh2qyAL8 |
MD5: | 83B7C0F7CE08ABAEA173FE6CDBC1D688 |
SHA1: | 507F36A6926CEF65741A4003AAA3A2F7A026A20C |
SHA-256: | 955D1D71F44F10EADD12BD778D5B1EAFB5E3DDD409D79316B38FB372EE8214A5 |
SHA-512: | 1C2D3C0F102DE27AD96DA3D482DC348F8A703E5FB65E9FCADDD41390A72B79E747E633E97507AFD2F0C142E448368D986BFB388D18ADA83315C3EFE10293702C |
Malicious: | false |
Reputation: | low |
URL: | https://virtltra.us/loading.php |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 1, 2024 11:34:29.757225990 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Oct 1, 2024 11:34:39.365638018 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Oct 1, 2024 11:34:40.428699970 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.428756952 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.428818941 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.428864956 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.428930998 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.428987026 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.429068089 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.429084063 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.429208994 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.429241896 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.895015955 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.895334005 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.895358086 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.896248102 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.896266937 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.896339893 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.896889925 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.896940947 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.897351027 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.897411108 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.897562027 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.898603916 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.898683071 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.899436951 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.899527073 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.939461946 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.949465036 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:40.949486017 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:40.996818066 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:41.012522936 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:41.012981892 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:41.013298988 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:41.013319016 CEST | 443 | 49735 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:41.013351917 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:41.013382912 CEST | 49735 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:41.040635109 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.040662050 CEST | 443 | 49737 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.040720940 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.041049004 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.041060925 CEST | 443 | 49737 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.090394020 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:41.090416908 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:34:41.140955925 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:34:41.553097963 CEST | 443 | 49737 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.553570986 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.553584099 CEST | 443 | 49737 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.554434061 CEST | 443 | 49737 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.554495096 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.555629969 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.555656910 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.555681944 CEST | 443 | 49737 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.555727005 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.555749893 CEST | 49737 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.555989981 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.556045055 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:41.556116104 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.556302071 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:41.556317091 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:42.336081028 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:42.379302979 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:42.726639986 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:42.726670027 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:42.727700949 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:42.727835894 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:42.729404926 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:42.729470968 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:42.729789972 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:42.729799032 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:42.739162922 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:42.739209890 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:42.739269018 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:42.740010023 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:42.740024090 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:42.772699118 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.084578991 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.084614038 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.084640980 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.084661961 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.084681034 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.084714890 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.084721088 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.084758997 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.089775085 CEST | 49740 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.089791059 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.324225903 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.324275970 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.324510098 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.324821949 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.324836969 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.384901047 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:43.385235071 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:43.385253906 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:43.386878967 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:43.386950016 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:43.476105928 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:43.476160049 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:43.476229906 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:43.478068113 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:43.478099108 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:43.753971100 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:43.754446983 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:43.775692940 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.789163113 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.789190054 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.790168047 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.790249109 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.790683031 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.790704012 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.790743113 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.790750980 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.790924072 CEST | 443 | 49743 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.790987015 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.791007996 CEST | 49743 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.791295052 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.791402102 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.791481972 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.791812897 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:43.791848898 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:43.797135115 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:43.797154903 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:43.843166113 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:44.135816097 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.135910034 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:44.150461912 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:44.150523901 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.150748014 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.193810940 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:44.259322882 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.269166946 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:44.269207001 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.269542933 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.318806887 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:44.335781097 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:44.340226889 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:44.340364933 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.349893093 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:44.383407116 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.395401001 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.525065899 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.525114059 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.525185108 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:44.534756899 CEST | 49744 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:44.534794092 CEST | 443 | 49744 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:44.669207096 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.669255018 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.669358015 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:44.669400930 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.669491053 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:44.670582056 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:45.115814924 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.115855932 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.115928888 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.116676092 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.116689920 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.213099957 CEST | 49745 | 443 | 192.168.2.4 | 188.114.97.3 |
Oct 1, 2024 11:34:45.213171005 CEST | 443 | 49745 | 188.114.97.3 | 192.168.2.4 |
Oct 1, 2024 11:34:45.337640047 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:45.337660074 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:45.337752104 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:45.338383913 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:45.338396072 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:45.576793909 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.577066898 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.577086926 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.577949047 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.578013897 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.807966948 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.808135033 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.808159113 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.855429888 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.940645933 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.940722942 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.941149950 CEST | 49748 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.941165924 CEST | 443 | 49748 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.943240881 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.943327904 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.943438053 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.943892002 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:45.943928003 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.977816105 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:45.977885962 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:45.980715990 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:45.980721951 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:45.980968952 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:45.981972933 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:46.027431011 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:46.255112886 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:46.255175114 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:46.255321980 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:46.258697987 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:46.258711100 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:46.258719921 CEST | 49749 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 1, 2024 11:34:46.258723974 CEST | 443 | 49749 | 184.28.90.27 | 192.168.2.4 |
Oct 1, 2024 11:34:46.416407108 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.416909933 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:46.416958094 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.417303085 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.417782068 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:46.417850018 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.418275118 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:46.463406086 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.556807041 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.556869984 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:46.556963921 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:46.557327986 CEST | 49750 | 443 | 192.168.2.4 | 35.190.80.1 |
Oct 1, 2024 11:34:46.557367086 CEST | 443 | 49750 | 35.190.80.1 | 192.168.2.4 |
Oct 1, 2024 11:34:52.453212023 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:52.453263044 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:52.453454971 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:52.455192089 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:52.455212116 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:53.065551996 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:53.065632105 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:53.072132111 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:53.072149038 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:53.072525024 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:53.115453959 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:53.278934002 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:53.279016018 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:53.279083014 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:53.390353918 CEST | 49741 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:34:53.390374899 CEST | 443 | 49741 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:34:54.046273947 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.091403008 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250725031 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250780106 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250799894 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250843048 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.250859022 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250864029 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.250890970 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250905991 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.250910997 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.250937939 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.250962019 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.251096964 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.251163960 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:54.251179934 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.251274109 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:54.251367092 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:55.028029919 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:55.028057098 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:34:55.028110981 CEST | 49751 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 1, 2024 11:34:55.028119087 CEST | 443 | 49751 | 20.12.23.50 | 192.168.2.4 |
Oct 1, 2024 11:35:20.654062986 CEST | 55979 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:35:20.658860922 CEST | 53 | 55979 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:35:20.658927917 CEST | 55979 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:35:20.658946991 CEST | 55979 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:35:20.663713932 CEST | 53 | 55979 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:35:21.103780031 CEST | 53 | 55979 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:35:21.108949900 CEST | 55979 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:35:21.114347935 CEST | 53 | 55979 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:35:21.114413023 CEST | 55979 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:35:26.091114998 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:35:26.091173887 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:35:31.606893063 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:31.606955051 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:31.607053041 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:31.607670069 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:31.607701063 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.410626888 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.410867929 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.520466089 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.520529032 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.521545887 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.559752941 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.603446960 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821130991 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821182013 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821202040 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821239948 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821264029 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.821278095 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821304083 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.821316004 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.821346998 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.821369886 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.822181940 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.822247982 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.822261095 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.822297096 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.822333097 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.822443962 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.822499990 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.832722902 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.832776070 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:32.832808971 CEST | 55981 | 443 | 192.168.2.4 | 4.175.87.197 |
Oct 1, 2024 11:35:32.832827091 CEST | 443 | 55981 | 4.175.87.197 | 192.168.2.4 |
Oct 1, 2024 11:35:41.264097929 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:35:41.264300108 CEST | 443 | 49736 | 67.199.248.10 | 192.168.2.4 |
Oct 1, 2024 11:35:41.264475107 CEST | 49736 | 443 | 192.168.2.4 | 67.199.248.10 |
Oct 1, 2024 11:35:42.750504017 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:42.750538111 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:42.750600100 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:42.751081944 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:42.751096964 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:43.385802984 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:43.386542082 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:43.386558056 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:43.387656927 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:43.389264107 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:43.389440060 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:43.443533897 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:47.131180048 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Oct 1, 2024 11:35:47.131306887 CEST | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Oct 1, 2024 11:35:47.136548996 CEST | 80 | 49723 | 199.232.210.172 | 192.168.2.4 |
Oct 1, 2024 11:35:47.136641026 CEST | 49723 | 80 | 192.168.2.4 | 199.232.210.172 |
Oct 1, 2024 11:35:47.136931896 CEST | 80 | 49724 | 199.232.210.172 | 192.168.2.4 |
Oct 1, 2024 11:35:47.136986971 CEST | 49724 | 80 | 192.168.2.4 | 199.232.210.172 |
Oct 1, 2024 11:35:53.302908897 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:53.302989960 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Oct 1, 2024 11:35:53.303057909 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:55.227104902 CEST | 55983 | 443 | 192.168.2.4 | 172.217.18.4 |
Oct 1, 2024 11:35:55.227148056 CEST | 443 | 55983 | 172.217.18.4 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 1, 2024 11:34:39.048937082 CEST | 53 | 52167 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:39.051923990 CEST | 53 | 61588 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:40.229794979 CEST | 53 | 62843 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:40.420525074 CEST | 52548 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:40.420799017 CEST | 55246 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:40.427242994 CEST | 53 | 52548 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:40.428006887 CEST | 53 | 55246 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:41.015525103 CEST | 52711 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:41.015656948 CEST | 52899 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:41.029083014 CEST | 53 | 52899 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:41.040112019 CEST | 53 | 52711 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:42.727823973 CEST | 50401 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:42.728111029 CEST | 49982 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:42.734905958 CEST | 53 | 50401 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:42.737196922 CEST | 53 | 49982 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:43.272130966 CEST | 53 | 64406 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.107480049 CEST | 62748 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:45.108016014 CEST | 52729 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 1, 2024 11:34:45.114818096 CEST | 53 | 62748 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:45.114856005 CEST | 53 | 52729 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:57.530591011 CEST | 53 | 56254 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:34:58.699629068 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Oct 1, 2024 11:35:16.608586073 CEST | 53 | 57752 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:35:20.653593063 CEST | 53 | 55712 | 1.1.1.1 | 192.168.2.4 |
Oct 1, 2024 11:35:38.453789949 CEST | 53 | 52371 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 1, 2024 11:34:40.420525074 CEST | 192.168.2.4 | 1.1.1.1 | 0x39cf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:34:40.420799017 CEST | 192.168.2.4 | 1.1.1.1 | 0x3e4a | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:34:41.015525103 CEST | 192.168.2.4 | 1.1.1.1 | 0xc16e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:34:41.015656948 CEST | 192.168.2.4 | 1.1.1.1 | 0x875a | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:34:42.727823973 CEST | 192.168.2.4 | 1.1.1.1 | 0x1aa0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:34:42.728111029 CEST | 192.168.2.4 | 1.1.1.1 | 0x73b5 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 1, 2024 11:34:45.107480049 CEST | 192.168.2.4 | 1.1.1.1 | 0x74c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 1, 2024 11:34:45.108016014 CEST | 192.168.2.4 | 1.1.1.1 | 0x9426 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 1, 2024 11:34:40.427242994 CEST | 1.1.1.1 | 192.168.2.4 | 0x39cf | No error (0) | 67.199.248.10 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:40.427242994 CEST | 1.1.1.1 | 192.168.2.4 | 0x39cf | No error (0) | 67.199.248.11 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:41.029083014 CEST | 1.1.1.1 | 192.168.2.4 | 0x875a | No error (0) | 65 | IN (0x0001) | false | |||
Oct 1, 2024 11:34:41.040112019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc16e | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:41.040112019 CEST | 1.1.1.1 | 192.168.2.4 | 0xc16e | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:42.734905958 CEST | 1.1.1.1 | 192.168.2.4 | 0x1aa0 | No error (0) | 172.217.18.4 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:42.737196922 CEST | 1.1.1.1 | 192.168.2.4 | 0x73b5 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 1, 2024 11:34:45.114818096 CEST | 1.1.1.1 | 192.168.2.4 | 0x74c | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:54.063791037 CEST | 1.1.1.1 | 192.168.2.4 | 0x4e71 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 1, 2024 11:34:54.063791037 CEST | 1.1.1.1 | 192.168.2.4 | 0x4e71 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Oct 1, 2024 11:35:07.452122927 CEST | 1.1.1.1 | 192.168.2.4 | 0x2fbe | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 1, 2024 11:35:07.452122927 CEST | 1.1.1.1 | 192.168.2.4 | 0x2fbe | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49735 | 67.199.248.10 | 443 | 3004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:40 UTC | 663 | OUT | |
2024-10-01 09:34:41 UTC | 493 | IN | |
2024-10-01 09:34:41 UTC | 118 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49740 | 188.114.97.3 | 443 | 3004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:42 UTC | 665 | OUT | |
2024-10-01 09:34:43 UTC | 606 | IN | |
2024-10-01 09:34:43 UTC | 763 | IN | |
2024-10-01 09:34:43 UTC | 1369 | IN | |
2024-10-01 09:34:43 UTC | 791 | IN | |
2024-10-01 09:34:43 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49744 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:44 UTC | 161 | OUT | |
2024-10-01 09:34:44 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49745 | 188.114.97.3 | 443 | 3004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:44 UTC | 589 | OUT | |
2024-10-01 09:34:44 UTC | 690 | IN | |
2024-10-01 09:34:44 UTC | 679 | IN | |
2024-10-01 09:34:44 UTC | 1369 | IN | |
2024-10-01 09:34:44 UTC | 925 | IN | |
2024-10-01 09:34:44 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49748 | 35.190.80.1 | 443 | 3004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:45 UTC | 532 | OUT | |
2024-10-01 09:34:45 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49749 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:45 UTC | 239 | OUT | |
2024-10-01 09:34:46 UTC | 515 | IN | |
2024-10-01 09:34:46 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49750 | 35.190.80.1 | 443 | 3004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:46 UTC | 478 | OUT | |
2024-10-01 09:34:46 UTC | 423 | OUT | |
2024-10-01 09:34:46 UTC | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49751 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:34:54 UTC | 306 | OUT | |
2024-10-01 09:34:54 UTC | 560 | IN | |
2024-10-01 09:34:54 UTC | 15824 | IN | |
2024-10-01 09:34:54 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 55981 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 09:35:32 UTC | 306 | OUT | |
2024-10-01 09:35:32 UTC | 560 | IN | |
2024-10-01 09:35:32 UTC | 15824 | IN | |
2024-10-01 09:35:32 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 05:34:33 |
Start date: | 01/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 05:34:36 |
Start date: | 01/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 05:34:39 |
Start date: | 01/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |