Windows
Analysis Report
https://7dnvo4dz9orl5r86.click.mailersend.net/tl/cws/eyJpdiI6Im1vSXBOU29SdUliTUxsWTZMeDAzZlE9PSIsInZhbHVlIjoiQUdpRWxMYjJ5Z2JkdXdzNENzMnBPNzBwdFk3OHA3d1FKU1JmS2pUK0N1RERNSzlGTWthQVVhZThxMjlEZExCcTRaWTVCVysrYmI3K3QxbGpmeDY0cytiMGtvMC9ua05DS3dRMnBiWC9zWUFCRCtCUFByc1l6RVFNUnZMYnoyRm4iLCJtYWMiOiIxMjQyNzZ
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 7004 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6360 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2200 --fi eld-trial- handle=198 8,i,120717 2685004413 991,178806 9001840999 2597,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 2756 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://7dnvo 4dz9orl5r8 6.click.ma ilersend.n et/tl/cws/ eyJpdiI6Im 1vSXBOU29S dUliTUxsWT ZMeDAzZlE9 PSIsInZhbH VlIjoiQUdp RWxMYjJ5Z2 JkdXdzNENz MnBPNzBwdF k3OHA3d1FK U1JmS2pUK0 N1RERNSzlG TWthQVVhZT hxMjlEZExC cTRaWTVCVy srYmI3K3Qx bGpmeDY0cy tiMGtvMC9u a05DS3dRMn BiWC9zWUFC RCtCUFByc1 l6RVFNUnZM YnoyRm4iLC JtYWMiOiIx MjQyNzZhYW FjNjY5ZDll MzUwN2Y1Zj g0ZTM3ODFl NmUzYzExZj gwYWU1YTBi NjgxZGM0Nj Y2ODMzN2Q4 YzQxIiwidG FnIjoiIn0" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cutt.ly | 104.22.1.232 | true | false | unknown | |
7dnvo4dz9orl5r86.click.mailersend.net | 104.26.7.57 | true | false | unknown | |
www.google.com | 142.250.185.68 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.67.8.238 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.185.68 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
104.26.7.57 | 7dnvo4dz9orl5r86.click.mailersend.net | United States | 13335 | CLOUDFLARENETUS | false | |
104.22.1.232 | cutt.ly | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1524985 |
Start date and time: | 2024-10-03 14:53:25 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 1m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://7dnvo4dz9orl5r86.click.mailersend.net/tl/cws/eyJpdiI6Im1vSXBOU29SdUliTUxsWTZMeDAzZlE9PSIsInZhbHVlIjoiQUdpRWxMYjJ5Z2JkdXdzNENzMnBPNzBwdFk3OHA3d1FKU1JmS2pUK0N1RERNSzlGTWthQVVhZThxMjlEZExCcTRaWTVCVysrYmI3K3QxbGpmeDY0cytiMGtvMC9ua05DS3dRMnBiWC9zWUFCRCtCUFByc1l6RVFNUnZMYnoyRm4iLCJtYWMiOiIxMjQyNzZhYWFjNjY5ZDllMzUwN2Y1Zjg0ZTM3ODFlNmUzYzExZjgwYWU1YTBiNjgxZGM0NjY2ODMzN2Q4YzQxIiwidGFnIjoiIn0 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@17/20@8/6 |
- Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.184.227, 142.250.185.174, 142.250.110.84, 34.104.35.123
- Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://7dnvo4dz9orl5r86.click.mailersend.net/tl/cws/eyJpdiI6Im1vSXBOU29SdUliTUxsWTZMeDAzZlE9PSIsInZhbHVlIjoiQUdpRWxMYjJ5Z2JkdXdzNENzMnBPNzBwdFk3OHA3d1FKU1JmS2pUK0N1RERNSzlGTWthQVVhZThxMjlEZExCcTRaWTVCVysrYmI3K3QxbGpmeDY0cytiMGtvMC9ua05DS3dRMnBiWC9zWUFCRCtCUFByc1l6RVFNUnZMYnoyRm4iLCJtYWMiOiIxMjQyNzZhYWFjNjY5ZDllMzUwN2Y1Zjg0ZTM3ODFlNmUzYzExZjgwYWU1YTBiNjgxZGM0NjY2ODMzN2Q4YzQxIiwidGFnIjoiIn0
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9834508153511154 |
Encrypted: | false |
SSDEEP: | 48:8od1TZL9YH9idAKZdA1FehwiZUklqehLy+3:8Ktxuky |
MD5: | 9F33EE5174C4DAAA70CBB176861B0D74 |
SHA1: | E0472A84FCE631CAAEC2E7CDE875DA4F162D023A |
SHA-256: | 9E78B19397D7A57BB71EA00CD79B34EC334E770CE407C34CE74E31A051D92234 |
SHA-512: | 81837363AEA770F012DAF87CC1C09FDB2150E2C2D9C218C5A0DE75A5B6C7E6E590CCE715DFCDA894C8BE56D51FBBE1AEE849BD0EC242BE0DDB677B5C34C0FFFE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.995870868455106 |
Encrypted: | false |
SSDEEP: | 48:8L9d1TZL9YH9idAKZdA1seh/iZUkAQkqehUy+2:8LFtxI9QBy |
MD5: | 45EFDD9B968662CF0A1FD00089F48781 |
SHA1: | 15F55F1B5888A514629FFC48F9EC3E26C6BEC4F4 |
SHA-256: | B52BE9C829B5265325A6DFEB19D71B99238119807FCEAE451AAA958EB3184AF3 |
SHA-512: | 8DAB45AC8B5E54ED589016E823631250AACDE2517E40B4D1377D48EFCD638E5CA5014AF7FEDBB150DB2FFAF26B7A089DC1AFFAC1FB0767A4652ABE7FC9CB6CF5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.006057323732305 |
Encrypted: | false |
SSDEEP: | 48:8Wd1TZL9AH9idAKZdA14meh7sFiZUkmgqeh7sSy+BX:8Itx8noy |
MD5: | 61B360366819C3A91CB8D8071AAB8968 |
SHA1: | D25078CE9795EC5F9DD7BB6E548EF4EEE58D7D75 |
SHA-256: | A5CACC9E3D9B9DF2143256786F523BCD2BC6A0893ACF4FCB90C4606394B4FF4F |
SHA-512: | E92EA27FFB32C440914875638CEE05E0DDF20E642CDF98ED6CF4D1F398C62BC2F541B94D7E704607984BEE8980521B6FAF5D4AAFA8C5D5337FE1AA279D3E9903 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.995123713385769 |
Encrypted: | false |
SSDEEP: | 48:8Iqd1TZL9YH9idAKZdA1TehDiZUkwqehAy+R:8LtxjKy |
MD5: | 834C836C66C7BBBB47EA6396B9D7FCF4 |
SHA1: | 0B616E281E8269C315689839F96C88703F549BB8 |
SHA-256: | 04039161063CF5DA9B4B3CE9861A505EB9CCE8B6532F84FF1C881CE72B72BC43 |
SHA-512: | FC463D42908C78B2FD9A18009B62D2947E0BDE3A42E2B954250DC1DD8FB0748D0AE8CBB599C89EC1C79309CB3A3BC935478712E53B7527F7D34C00EE97F181DB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.984694189884949 |
Encrypted: | false |
SSDEEP: | 48:8xd1TZL9YH9idAKZdA1dehBiZUk1W1qehWy+C:8RtxT92y |
MD5: | 5F416EB5DE256835F1F5CEFEE1F6DC91 |
SHA1: | D41FC892081CA18B96A682638B73FF879D88E7E0 |
SHA-256: | 6479C8E681876E82D4F8A103671863C813ED8848E35492D03694DEBFBB404E22 |
SHA-512: | 2C836EFA0152FB76B89ADD1776C7B49EF15698255200E250808B74E205CFB90E8A6A9CACD568E41BF249D79BF6E03CC4C6AC0CEFAF8779EDB4FE4ADAE09517AB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.992019758265573 |
Encrypted: | false |
SSDEEP: | 48:8Sd1TZL9YH9idAKZdA1duTeehOuTbbiZUk5OjqehOuTboy+yT+:88tx3TfTbxWOvTboy7T |
MD5: | ABC17DAE82CC62DF798AC7776337463F |
SHA1: | 2A1FCC69049C83CB8BECE4C3EAAD5E4BD4B7818B |
SHA-256: | B0DD2C37CED0FCF514C57D0A1B18DD1271D8382EDFA163E02DE353EEB09F7AC6 |
SHA-512: | FA1EDE719B5DF49B7E151DB66588111D0AE0FF14BA3D2FEC6FBF9EA41285405061E0E7E684A056F49D33FA60B9DE30F6D6EE0412C3C8DC45B207C053038226B7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3213 |
Entropy (8bit): | 7.553565995366911 |
Encrypted: | false |
SSDEEP: | 96:35QRRzQqgtYCWBzmuvuLf33Pf309TxeL+vD+7SrQ9o6Br2eJk:GRRsqgOBzvcnM9TxVk9JCeJk |
MD5: | 0D768CBC261841D3AFFC933B9AC3130E |
SHA1: | AFF136A4C761E1DF1ADA7E5D9A6ED0EBEA74A4B7 |
SHA-256: | 1C53772285052E52BB7C12AD46A85A55747ED7BF66963FE1993FCEF91FF5B0D0 |
SHA-512: | CE5B1BBB8CF6B0C3D1FA146D1700DB2300ABD6F2BDBE43ECAAC6AEBC911BE6E1BCD2F8C6704A2CFA67BBB45598793DDEC017E05C2C37CE387293AAE08E7C342F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2309 |
Entropy (8bit): | 5.840442899371648 |
Encrypted: | false |
SSDEEP: | 48:g+6N8KlgZ01RuVBgzatpcpYFGApJEHIpQtNqc9kmiTAReuSEqHfffffo:5Wvli3BcbYEA6Iskc9zikafffffo |
MD5: | 1DFABDD9039EC295CEB24C006B2752D7 |
SHA1: | 02AECA5E71C27BD1C487CD3A682825E79FAE0DE5 |
SHA-256: | 9E79F8EB474B8F462335D52FFB6E1FBD2DB55828B7852291432BBB679E39B8DA |
SHA-512: | 13338A2DC4E1FF32F10CD6E0A0008FBDCB4BC1D92D55917D111A3FE7578C942281D44D939AD1540506112C21D0627E4EBFEC7CE8324660A00F1653697B4311D8 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 715 |
Entropy (8bit): | 7.3533249502413565 |
Encrypted: | false |
SSDEEP: | 12:6v/7et+/37c7jvBjLg+UnhdeNdLI4dACGHJovQpMZP5ajgj7xbKwkRR/:Lu490+NdcCqJlpMZxajnwCR/ |
MD5: | 226DCB8F6144BDAAFDFBD8F2F354BE64 |
SHA1: | 3785CC5B3BF52F8E398177B0FF1020B24AA86B8C |
SHA-256: | 8C873472F4925D5D47521DB4D52532D2983E9CB1BDE8B43143A6CC6DB56C35DB |
SHA-512: | ED898B12C4895F7ACEAAB443C1071E6376DB71B4DFDBD769F5F3BE71D562438A18B5E5DC36DD7CC610926E380603A894B2E81DF4302680C736A412BFD3360D3A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 8165 |
Entropy (8bit): | 4.700248176825761 |
Encrypted: | false |
SSDEEP: | 96:/JStuMKDoaHiJbGaDZbBXgAfRSu2+zYhwPTw4AGrlN+GM+vIFtwwWhAS9J4b1qVZ:gu52KahBQAJSCksN+GstTb1ypjVl |
MD5: | 5FBAAEFDC84350073458E5F08CF568B4 |
SHA1: | F8D875149B7DA69307D303D0CCB406D22868E482 |
SHA-256: | A05BA56B2DE5AA755BD3EE49A56E2BD21B706A963CA3FA394373C542B0929FB9 |
SHA-512: | 6FA191367F73B7867D8B3702EB45BC31E5315AC68C88C6C03BD7658786C49C4495B967881D34CC49F68E8998C0EE4E83A6DBAC64F1E1D787C20D45E8EF49EBA6 |
Malicious: | false |
Reputation: | low |
URL: | https://cutt.ly/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 24051 |
Entropy (8bit): | 4.941039417164537 |
Encrypted: | false |
SSDEEP: | 192:VuR/6okgTQwq23gGM8lUR9YRGQ2BwoX6zp+1+nDT1FvxKSI7/UsV7MSE6XZ2dKzk:JwV+oUcoQJpdf1dxKSI7/Ue7ZX2qk |
MD5: | 5E8C69A459A691B5D1B9BE442332C87D |
SHA1: | F24DD1AD7C9080575D92A9A9A2C42620725EF836 |
SHA-256: | 84E3C77025ACE5AF143972B4A40FC834DCDFD4E449D4B36A57E62326F16B3091 |
SHA-512: | 6DB74B262D717916DE0B0B600EEAD2CC6A10E52A9E26D701FAE761FCBC931F35F251553669A92BE3B524F380F32E62AC6AD572BEA23C78965228CE9EFB92ED42 |
Malicious: | false |
Reputation: | low |
URL: | https://cutt.ly/cdn-cgi/styles/cf.errors.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3213 |
Entropy (8bit): | 7.553565995366911 |
Encrypted: | false |
SSDEEP: | 96:35QRRzQqgtYCWBzmuvuLf33Pf309TxeL+vD+7SrQ9o6Br2eJk:GRRsqgOBzvcnM9TxVk9JCeJk |
MD5: | 0D768CBC261841D3AFFC933B9AC3130E |
SHA1: | AFF136A4C761E1DF1ADA7E5D9A6ED0EBEA74A4B7 |
SHA-256: | 1C53772285052E52BB7C12AD46A85A55747ED7BF66963FE1993FCEF91FF5B0D0 |
SHA-512: | CE5B1BBB8CF6B0C3D1FA146D1700DB2300ABD6F2BDBE43ECAAC6AEBC911BE6E1BCD2F8C6704A2CFA67BBB45598793DDEC017E05C2C37CE387293AAE08E7C342F |
Malicious: | false |
Reputation: | low |
URL: | https://cutt.ly/cdn-cgi/images/cf-no-screenshot-error.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 715 |
Entropy (8bit): | 7.3533249502413565 |
Encrypted: | false |
SSDEEP: | 12:6v/7et+/37c7jvBjLg+UnhdeNdLI4dACGHJovQpMZP5ajgj7xbKwkRR/:Lu490+NdcCqJlpMZxajnwCR/ |
MD5: | 226DCB8F6144BDAAFDFBD8F2F354BE64 |
SHA1: | 3785CC5B3BF52F8E398177B0FF1020B24AA86B8C |
SHA-256: | 8C873472F4925D5D47521DB4D52532D2983E9CB1BDE8B43143A6CC6DB56C35DB |
SHA-512: | ED898B12C4895F7ACEAAB443C1071E6376DB71B4DFDBD769F5F3BE71D562438A18B5E5DC36DD7CC610926E380603A894B2E81DF4302680C736A412BFD3360D3A |
Malicious: | false |
Reputation: | low |
URL: | https://cutt.ly/cdn-cgi/images/browser-bar.png?1376755637 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4508 |
Entropy (8bit): | 5.012820600851543 |
Encrypted: | false |
SSDEEP: | 96:1j9jwIjYj5jDK/D5DMF+C8/ZqXKHvpIkdNgrR49PaQxJbGD:1j9jhjYj9K/Vo+n8aHvFdNgrO9ieJGD |
MD5: | BC58DE451428802BBE0D8A808A9CB501 |
SHA1: | 76D0CB0CC97B5B94B6F89163CE5C89F25ECBE566 |
SHA-256: | F6B2932AE0323662E3F64FE8B6602AC1454AD50D8C0D1C75A06506455E2B9DD9 |
SHA-512: | 745B10A9FBB15978FF07B7D358CB1DEAF396A792CE9042093738449ECB6E6D05946A6208EFFD632D50F663F09378A367BB384C50B702F29DE41575043581AC46 |
Malicious: | false |
Reputation: | low |
URL: | https://cutt.ly/guard/XeImGtal |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 3, 2024 14:53:55.668729067 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 14:53:58.069987059 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 14:53:59.250762939 CEST | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:53:59.725850105 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:53:59.725874901 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:53:59.725970030 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:53:59.726847887 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:53:59.726865053 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.370151043 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.370703936 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.374967098 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.374980927 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.375406981 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.401161909 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.447400093 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.642086029 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.642251968 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.642282963 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.642322063 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.642338991 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.642338991 CEST | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.642348051 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.642354012 CEST | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.672346115 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.672389984 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:00.672514915 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.672852993 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:00.672873020 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.007025957 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.007061958 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.007131100 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.008152008 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.008203030 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.008344889 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.008769035 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.008781910 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.009670019 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.009691000 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.362907887 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.363049030 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:01.364403963 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:01.364417076 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.364648104 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.365695953 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:01.411402941 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.471889019 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.472186089 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.472208977 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.473267078 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.473350048 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.474765062 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.474838018 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.475147963 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.475157976 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.504250050 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.504569054 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.504592896 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.506035089 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.506128073 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.506840944 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.506923914 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.526879072 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.558938980 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.558962107 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.606030941 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.645354986 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.645533085 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.645641088 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:01.651865005 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:01.651890993 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.651904106 CEST | 49711 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 14:54:01.651910067 CEST | 443 | 49711 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 14:54:01.705254078 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:01.980460882 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.980591059 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.980654955 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.981059074 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.981091022 CEST | 443 | 49712 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:01.981096983 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.981214046 CEST | 49712 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:01.991579056 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:01.991607904 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:01.991772890 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:01.992059946 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:01.992072105 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.018889904 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:02.460640907 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.461107969 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.461138964 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.462336063 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.462414026 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.465023994 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.465097904 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.465471983 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.465481997 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.512890100 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.623882055 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:02.751971960 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.752022982 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.752288103 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.754072905 CEST | 49714 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.754095078 CEST | 443 | 49714 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.754780054 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.754808903 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.754944086 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.755155087 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:02.755168915 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:02.878891945 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 14:54:03.214204073 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.214565039 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.214595079 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.214942932 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.216067076 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.216128111 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.216306925 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.263407946 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.351891994 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.352020025 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.352078915 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.352096081 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.352190018 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.352255106 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.352262020 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.352320910 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.352473974 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.353492975 CEST | 49716 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.353511095 CEST | 443 | 49716 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.384469032 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.384512901 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.384603024 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.384840012 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.384860039 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.833951950 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:03.857580900 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.857928991 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.857944012 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.858295918 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.858671904 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.858824015 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:03.858829021 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.858875036 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:03.914239883 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.033576965 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.033773899 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.033848047 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.033859015 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.033888102 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.034008026 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.034023046 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.034408092 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.034576893 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.034590960 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.034614086 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.034687996 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.034701109 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.038269997 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.038351059 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.038460970 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.038486958 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.038604975 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.038619041 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.087887049 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.121901989 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.122061968 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.122581959 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.122683048 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.122776985 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.122941971 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.123009920 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.123009920 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.127175093 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.129009962 CEST | 49717 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.129026890 CEST | 443 | 49717 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.164050102 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.164098978 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.164199114 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.164515972 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.164566040 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.164746046 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.164875984 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.164895058 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.165185928 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.165203094 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.830351114 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.830748081 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.830763102 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.831252098 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.831465006 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:04.831511974 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:04.831598997 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:04.831967115 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:04.831983089 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:04.831994057 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.832072020 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.832093954 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.832746983 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.833230972 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.833256960 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.834357023 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.834778070 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.834956884 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.834971905 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.875401974 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.879400015 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.879940987 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.879966021 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.949114084 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.949237108 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.949314117 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.949930906 CEST | 49719 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.949955940 CEST | 443 | 49719 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.950129986 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.950262070 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.950378895 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.950515032 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.950556040 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.950594902 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.952718973 CEST | 49718 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.952744007 CEST | 443 | 49718 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.958365917 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.958421946 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.958506107 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.958826065 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:04.958838940 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:04.973586082 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:04.973654032 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:04.973699093 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:04.973747015 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:04.973747969 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:04.973813057 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:04.973962069 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:04.973984003 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:04.974088907 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:04.974109888 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.428941965 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.429300070 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.429328918 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.429817915 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.430035114 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.430063963 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.430423975 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.430744886 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.430807114 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.430829048 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.430936098 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.431009054 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.431018114 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.431296110 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.431375980 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.431422949 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.431453943 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.431474924 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.431483030 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.432864904 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.432945967 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.433190107 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.433274031 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.433275938 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.471967936 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.475405931 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.475411892 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.487934113 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.487955093 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.509874105 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:05.510211945 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:05.510243893 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:05.511312962 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:05.511461973 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:05.512655020 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:05.512722969 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:05.535934925 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.544050932 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.544497013 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.545876980 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.546021938 CEST | 49722 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.546046972 CEST | 443 | 49722 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.551959991 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:05.551976919 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:05.558836937 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.558993101 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.559040070 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.559118986 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.559132099 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.559178114 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.559509039 CEST | 49723 | 443 | 192.168.2.16 | 172.67.8.238 |
Oct 3, 2024 14:54:05.559526920 CEST | 443 | 49723 | 172.67.8.238 | 192.168.2.16 |
Oct 3, 2024 14:54:05.598963976 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:05.613086939 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613123894 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613224030 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.613250971 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613682032 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613712072 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613749027 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613790035 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.613794088 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613804102 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613862991 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.613876104 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613892078 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:05.613941908 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.614474058 CEST | 49721 | 443 | 192.168.2.16 | 104.22.1.232 |
Oct 3, 2024 14:54:05.614492893 CEST | 443 | 49721 | 104.22.1.232 | 192.168.2.16 |
Oct 3, 2024 14:54:06.174125910 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:54:06.237904072 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:06.482232094 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:54:07.084922075 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:54:08.299920082 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:54:08.304461956 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:08.304493904 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:08.304794073 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:08.307051897 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:08.307071924 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.121256113 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.121330976 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.124037027 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.124047041 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.124320030 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.163912058 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.181641102 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.227395058 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440587044 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440648079 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440673113 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440721989 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440749884 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.440778017 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440788031 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.440802097 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.440835953 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.440866947 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.441345930 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.441425085 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.441435099 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.441775084 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.441833973 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.450834990 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.450834990 CEST | 49726 | 443 | 192.168.2.16 | 4.245.163.56 |
Oct 3, 2024 14:54:09.450870037 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:09.450879097 CEST | 443 | 49726 | 4.245.163.56 | 192.168.2.16 |
Oct 3, 2024 14:54:10.711891890 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:54:11.046916008 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:12.481139898 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 14:54:15.402170897 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:15.402230978 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:15.402384043 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:15.524941921 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 14:54:16.285228014 CEST | 49720 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:16.285268068 CEST | 443 | 49720 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:16.436342001 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:16.436428070 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:16.436574936 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:17.093735933 CEST | 49713 | 443 | 192.168.2.16 | 104.26.7.57 |
Oct 3, 2024 14:54:17.093765020 CEST | 443 | 49713 | 104.26.7.57 | 192.168.2.16 |
Oct 3, 2024 14:54:17.094095945 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:17.094146013 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:17.094237089 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:17.094604015 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:17.094614029 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:17.734733105 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:17.735233068 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:17.735253096 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:17.735580921 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:17.736016035 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:17.736068964 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:17.736210108 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:17.779432058 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:18.041513920 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:18.041563988 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:18.041714907 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:18.041733980 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:18.046935081 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:18.047044992 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:18.047192097 CEST | 49727 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 3, 2024 14:54:18.047208071 CEST | 443 | 49727 | 142.250.185.68 | 192.168.2.16 |
Oct 3, 2024 14:54:20.652939081 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 14:54:25.130927086 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 3, 2024 14:54:00.065968037 CEST | 53 | 60372 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:00.148765087 CEST | 53 | 63942 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:00.910939932 CEST | 51759 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:00.911130905 CEST | 62500 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:01.002218962 CEST | 53 | 51759 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:01.004904032 CEST | 53 | 62500 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:01.349318027 CEST | 53 | 62968 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:01.983539104 CEST | 59531 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:01.983539104 CEST | 63336 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:01.990686893 CEST | 53 | 63336 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:01.991116047 CEST | 53 | 59531 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:04.819320917 CEST | 52664 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:04.819463015 CEST | 61721 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:04.829327106 CEST | 53 | 52664 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:04.830497980 CEST | 53 | 61721 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:04.963753939 CEST | 59524 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:04.963876009 CEST | 49456 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 14:54:04.970545053 CEST | 53 | 59524 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:04.973108053 CEST | 53 | 49456 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 14:54:18.244103909 CEST | 53 | 63320 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 3, 2024 14:54:00.910939932 CEST | 192.168.2.16 | 1.1.1.1 | 0x80d6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 14:54:00.911130905 CEST | 192.168.2.16 | 1.1.1.1 | 0xca6f | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 3, 2024 14:54:01.983539104 CEST | 192.168.2.16 | 1.1.1.1 | 0x3fec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 14:54:01.983539104 CEST | 192.168.2.16 | 1.1.1.1 | 0x8958 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 3, 2024 14:54:04.819320917 CEST | 192.168.2.16 | 1.1.1.1 | 0x6fae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 14:54:04.819463015 CEST | 192.168.2.16 | 1.1.1.1 | 0x1363 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 3, 2024 14:54:04.963753939 CEST | 192.168.2.16 | 1.1.1.1 | 0xcf70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 14:54:04.963876009 CEST | 192.168.2.16 | 1.1.1.1 | 0x2197 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 3, 2024 14:54:01.002218962 CEST | 1.1.1.1 | 192.168.2.16 | 0x80d6 | No error (0) | 104.26.7.57 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:01.002218962 CEST | 1.1.1.1 | 192.168.2.16 | 0x80d6 | No error (0) | 104.26.6.57 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:01.002218962 CEST | 1.1.1.1 | 192.168.2.16 | 0x80d6 | No error (0) | 172.67.74.79 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:01.004904032 CEST | 1.1.1.1 | 192.168.2.16 | 0xca6f | No error (0) | 65 | IN (0x0001) | false | |||
Oct 3, 2024 14:54:01.991116047 CEST | 1.1.1.1 | 192.168.2.16 | 0x3fec | No error (0) | 104.22.1.232 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:01.991116047 CEST | 1.1.1.1 | 192.168.2.16 | 0x3fec | No error (0) | 104.22.0.232 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:01.991116047 CEST | 1.1.1.1 | 192.168.2.16 | 0x3fec | No error (0) | 172.67.8.238 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:04.829327106 CEST | 1.1.1.1 | 192.168.2.16 | 0x6fae | No error (0) | 142.250.185.68 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:04.830497980 CEST | 1.1.1.1 | 192.168.2.16 | 0x1363 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 3, 2024 14:54:04.970545053 CEST | 1.1.1.1 | 192.168.2.16 | 0xcf70 | No error (0) | 172.67.8.238 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:04.970545053 CEST | 1.1.1.1 | 192.168.2.16 | 0xcf70 | No error (0) | 104.22.1.232 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 14:54:04.970545053 CEST | 1.1.1.1 | 192.168.2.16 | 0xcf70 | No error (0) | 104.22.0.232 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.16 | 49707 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:00 UTC | 161 | OUT | |
2024-10-03 12:54:00 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.16 | 49711 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:01 UTC | 239 | OUT | |
2024-10-03 12:54:01 UTC | 514 | IN | |
2024-10-03 12:54:01 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49712 | 104.26.7.57 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:01 UTC | 1026 | OUT | |
2024-10-03 12:54:01 UTC | 765 | IN | |
2024-10-03 12:54:01 UTC | 349 | IN | |
2024-10-03 12:54:01 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49714 | 104.22.1.232 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:02 UTC | 658 | OUT | |
2024-10-03 12:54:02 UTC | 649 | IN | |
2024-10-03 12:54:02 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49716 | 104.22.1.232 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:03 UTC | 710 | OUT | |
2024-10-03 12:54:03 UTC | 459 | IN | |
2024-10-03 12:54:03 UTC | 910 | IN | |
2024-10-03 12:54:03 UTC | 1369 | IN | |
2024-10-03 12:54:03 UTC | 1369 | IN | |
2024-10-03 12:54:03 UTC | 860 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49717 | 104.22.1.232 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:03 UTC | 601 | OUT | |
2024-10-03 12:54:04 UTC | 411 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49719 | 104.22.1.232 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:04 UTC | 674 | OUT | |
2024-10-03 12:54:04 UTC | 409 | IN | |
2024-10-03 12:54:04 UTC | 715 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49718 | 104.22.1.232 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:04 UTC | 674 | OUT | |
2024-10-03 12:54:04 UTC | 410 | IN | |
2024-10-03 12:54:04 UTC | 959 | IN | |
2024-10-03 12:54:04 UTC | 1369 | IN | |
2024-10-03 12:54:04 UTC | 885 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49721 | 104.22.1.232 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:05 UTC | 630 | OUT | |
2024-10-03 12:54:05 UTC | 453 | IN | |
2024-10-03 12:54:05 UTC | 916 | IN | |
2024-10-03 12:54:05 UTC | 1369 | IN | |
2024-10-03 12:54:05 UTC | 1369 | IN | |
2024-10-03 12:54:05 UTC | 1369 | IN | |
2024-10-03 12:54:05 UTC | 1369 | IN | |
2024-10-03 12:54:05 UTC | 1369 | IN | |
2024-10-03 12:54:05 UTC | 412 | IN | |
2024-10-03 12:54:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49722 | 172.67.8.238 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:05 UTC | 418 | OUT | |
2024-10-03 12:54:05 UTC | 409 | IN | |
2024-10-03 12:54:05 UTC | 715 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.16 | 49723 | 172.67.8.238 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:05 UTC | 418 | OUT | |
2024-10-03 12:54:05 UTC | 410 | IN | |
2024-10-03 12:54:05 UTC | 959 | IN | |
2024-10-03 12:54:05 UTC | 1369 | IN | |
2024-10-03 12:54:05 UTC | 885 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.16 | 49726 | 4.245.163.56 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:09 UTC | 306 | OUT | |
2024-10-03 12:54:09 UTC | 560 | IN | |
2024-10-03 12:54:09 UTC | 15824 | IN | |
2024-10-03 12:54:09 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.16 | 49727 | 142.250.185.68 | 443 | 6360 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 12:54:17 UTC | 613 | OUT | |
2024-10-03 12:54:18 UTC | 1266 | IN | |
2024-10-03 12:54:18 UTC | 124 | IN | |
2024-10-03 12:54:18 UTC | 1390 | IN | |
2024-10-03 12:54:18 UTC | 802 | IN | |
2024-10-03 12:54:18 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 08:53:58 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 08:53:58 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:53:59 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |