Windows
Analysis Report
http://185.234.216.64:8000
Overview
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6892 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7080 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2064 --fi eld-trial- handle=187 6,i,108593 9418172084 8727,27476 5806155760 6207,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6512 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://185.23 4.216.64:8 000" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | 1 Ingress Tool Transfer | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 216.58.206.36 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.234.216.64 | unknown | Poland | 197226 | SPRINT-SDCPL | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1525183 |
Start date and time: | 2024-10-03 20:39:54 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://185.234.216.64:8000 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.troj.win@25/8@2/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.16.195, 142.250.186.46, 142.251.168.84, 34.104.35.123, 87.248.205.0, 142.250.181.227, 216.58.206.78
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: http://185.234.216.64:8000
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9876410530255573 |
Encrypted: | false |
SSDEEP: | 48:8TWdoTMoFHHWidAKZdA1FehwiZUklqehN5y+3:8TpvG05y |
MD5: | 5C062EEF75BB8366820F3E40985BE772 |
SHA1: | 9DD5406C22E9E3B6ED2B9765F73E95CCDF3F82DC |
SHA-256: | D20874D17BCB9F6CC366DFE3C89A81159C19C5748D309A42A7273A2765D18A6B |
SHA-512: | 8444AE1BD3C5C0360B3E3B2898145691C60015B7E719F25ADDC8CAABBB6410E688C014C0B2E628545FBA93E2695216B67D35C620B764CA6961C0C29C07FCA992 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.003977458730038 |
Encrypted: | false |
SSDEEP: | 48:87doTMoFHHWidAKZdA1seh/iZUkAQkqehk5y+2:8WvA9Q35y |
MD5: | 866EDF3C5700C2450BD646DE22292D47 |
SHA1: | 6ECCF05034AFA1A246E4FE8066B8F1B8DDACA09A |
SHA-256: | E5A2797BDCEF4036E8214A170ED5D73CF931375ED91AA4D8566AF3C9A7C04D8F |
SHA-512: | 6EE8E8A09170A9B25A514BE535E23BA9AF03698391CEC2EDC880BF1B0E150A43A159C818B1ACEDF3DB1D942A1BAFE4BFCD6B5A60FBB35C5662F8E20928F7E4F6 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.011008404872158 |
Encrypted: | false |
SSDEEP: | 48:8FdoTMoAHHWidAKZdA14meh7sFiZUkmgqeh7sW5y+BX:8QvTn45y |
MD5: | 528EDC5238BF5D12C3F6AAAF82017D21 |
SHA1: | 4C1B414505FC63B98E3EE8938FDBDB9DE54B0246 |
SHA-256: | E9C6A9BFDCDE3DC6C963DCDCBA3CC2D8E60BB0DDD83BAF11F6B168C9832224E2 |
SHA-512: | A61F1B2B3A5F0E1DFEF1EF6B880344522F4FCF1E86941327D97D6C099898D487319145A376FE97FB3AFDA92B72E49B6764E0A2EE96B19A2D9453941EC6CF292D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.000911298632474 |
Encrypted: | false |
SSDEEP: | 48:8KdoTMoFHHWidAKZdA1TehDiZUkwqehA5y+R:81vbe5y |
MD5: | 08276A273D2765F943C8D24B6DB6B0D8 |
SHA1: | 8B2EA48A5CBD8C91407F6AF9E74E0E33944A3491 |
SHA-256: | 09B50B21C6253F999AE048FD43C35B81087406CE0E81DB8365D46AE77E60579E |
SHA-512: | 658BF260742662B14D13D00C687726E8D44D8FCCEB6CD88C04048618C3D3DF0DD6CA5E060451229DBEE1BE2F62AB7A6A87D0065933EAABE92839DED811768E44 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.991850985250431 |
Encrypted: | false |
SSDEEP: | 48:8vdoTMoFHHWidAKZdA1dehBiZUk1W1qeh65y+C:8Svb9a5y |
MD5: | 2BAD184F2AB4FCFCB63CBA82815BE1C5 |
SHA1: | FD5A0C8A2896CF5B5852EB833608D93A7EEAB154 |
SHA-256: | 22CD4FAE30E1C59AF57A77D2C80127D80BD66C8146C9D908F1C64E881E50155C |
SHA-512: | 1792757E3F5BF4B0A0BF7AFE73F201F5F09DB430B0A02ED03B1B9938F9407AC44A4400536458DAB9F64BCEC422DF01440334757CC8C6C502B8BB132E3D87773A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.998981731120395 |
Encrypted: | false |
SSDEEP: | 48:8IdoTMoFHHWidAKZdA1duTeehOuTbbiZUk5OjqehOuTb45y+yT+:8bv/TfTbxWOvTb45y7T |
MD5: | 276CE00B05A2775A97643FC9DA601835 |
SHA1: | 5EA5C3ABE836981217A5E257979507405E1485FE |
SHA-256: | B4D545457F5615452305D680377C82280A4477F52F2C23A25A2FFD1B93F2C916 |
SHA-512: | F0C328D9C81D6DD1EB75010017E7BFE78F5BCD1DF25D315EF9F102A9AF1188A74974E7275B77DA3713A833DA4485E797C02B5602E117226B2969FFA09862AD1E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 135 |
Entropy (8bit): | 4.822807935095228 |
Encrypted: | false |
SSDEEP: | 3:Vw0Oz5QowwBHsLpHbGWjLwWkzXFETH1u4:Vw0Oz5Qo5BHsLRGAwWeXFEL13 |
MD5: | AFD16C1B9C6FE1DDB2F862D575322CFA |
SHA1: | ECF27BB9EAB9137698FF33A32AAC39FA2172145D |
SHA-256: | AA8CCE1B2777F8A11661F5870BA06AD3C10ADAB64FB252B7EFF2DD4E6D02D6E2 |
SHA-512: | BD0879CBD219D9AD7500CC3E59C9B469A54D407C42FA4D9F31B7772097278856202785197400F4ABC440DBBBAF02B30238719257B4B4F2D26B613ECCE706E78A |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=185.234.216.64%3A&oit=3&cp=15&pgcl=4&gs_rn=42&psi=utPzvPmCOetUeW7j&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 3, 2024 20:40:21.133304119 CEST | 49700 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:21.133538008 CEST | 49701 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:21.138267994 CEST | 8000 | 49700 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:21.138348103 CEST | 49700 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:21.138365984 CEST | 8000 | 49701 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:21.138416052 CEST | 49701 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:21.138683081 CEST | 49700 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:21.143662930 CEST | 8000 | 49700 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:22.920722961 CEST | 8000 | 49700 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:22.920869112 CEST | 49700 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:22.921165943 CEST | 49700 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:22.922202110 CEST | 8000 | 49701 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:22.922271013 CEST | 49701 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:22.925949097 CEST | 8000 | 49700 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:22.942302942 CEST | 49701 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:22.948786020 CEST | 8000 | 49701 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:23.839665890 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:23.958355904 CEST | 49703 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:23.958549976 CEST | 49704 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:23.963259935 CEST | 8000 | 49703 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:23.963403940 CEST | 49703 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:23.963514090 CEST | 49703 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:23.963553905 CEST | 8000 | 49704 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:23.963606119 CEST | 49704 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:23.971355915 CEST | 8000 | 49703 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:24.143374920 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:24.750365019 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:25.033627987 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.033678055 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.033756018 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.033957005 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.033973932 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.713567972 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.713843107 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.713871956 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.714922905 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.714988947 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.715964079 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.716054916 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.728543043 CEST | 8000 | 49704 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:25.728632927 CEST | 49704 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:25.747086048 CEST | 8000 | 49703 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:25.747160912 CEST | 49703 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:25.747562885 CEST | 49703 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:25.753340006 CEST | 8000 | 49703 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:25.762295008 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.762321949 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:25.807316065 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:25.951502085 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:26.577142954 CEST | 49704 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:26.585249901 CEST | 8000 | 49704 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:27.680989027 CEST | 49690 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:28.362294912 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:29.660208941 CEST | 49711 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:29.660370111 CEST | 49712 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:29.665122986 CEST | 8000 | 49711 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:29.665144920 CEST | 8000 | 49712 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:29.665234089 CEST | 49711 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:29.665481091 CEST | 49711 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:29.665482998 CEST | 49712 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:29.670564890 CEST | 8000 | 49711 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:30.025657892 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.025705099 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.025790930 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.027430058 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.027441025 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.688173056 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.688262939 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.692404985 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.692425013 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.692717075 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.734288931 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.739079952 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.783406019 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.961133003 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.961213112 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.961287975 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.961385012 CEST | 49713 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.961405993 CEST | 443 | 49713 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.994076014 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.994126081 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:30.994301081 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.994561911 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:30.994576931 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.415996075 CEST | 8000 | 49711 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:31.416121960 CEST | 49711 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:31.416380882 CEST | 49711 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:31.421195030 CEST | 8000 | 49711 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:31.448961020 CEST | 8000 | 49712 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:31.449057102 CEST | 49712 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:31.688458920 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.688621998 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:31.690371990 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:31.690382004 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.690664053 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.691898108 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:31.739413977 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.969189882 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.969269991 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.969454050 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:31.970283985 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:31.970309019 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:31.970320940 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 20:40:31.970326900 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 20:40:32.008719921 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:32.312325001 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:32.583977938 CEST | 49712 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:32.588917017 CEST | 8000 | 49712 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:32.915369987 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:32.932769060 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:32.932807922 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:32.932904005 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:32.933968067 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:32.933979034 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:33.171330929 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:33.722246885 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:33.722485065 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:33.726279020 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:33.726295948 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:33.726599932 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:33.778337002 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:33.783679008 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:33.831404924 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052428961 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052455902 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052463055 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052480936 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052486897 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052489042 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052530050 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.052552938 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.052597046 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.052611113 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.053082943 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.053154945 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.053172112 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.053489923 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.053529978 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.064698935 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.064719915 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.064752102 CEST | 49715 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:40:34.064759016 CEST | 443 | 49715 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:40:34.131412029 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:35.607438087 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:35.607515097 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:35.607574940 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:36.435766935 CEST | 49705 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:36.435806990 CEST | 443 | 49705 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:36.436089039 CEST | 49716 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:36.436295986 CEST | 49717 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:36.443779945 CEST | 8000 | 49716 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:36.443792105 CEST | 8000 | 49717 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:36.443881989 CEST | 49716 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:36.443922043 CEST | 49717 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:36.444165945 CEST | 49717 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:36.450604916 CEST | 8000 | 49717 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:36.476564884 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:36.540316105 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:36.780322075 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:37.387331963 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:38.196646929 CEST | 8000 | 49716 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:38.196748018 CEST | 49716 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:38.213937998 CEST | 8000 | 49717 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:38.214030981 CEST | 49717 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:38.214328051 CEST | 49717 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:38.219115973 CEST | 8000 | 49717 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:38.572910070 CEST | 49716 | 8000 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:38.578181028 CEST | 8000 | 49716 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:38.587373972 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:41.000339985 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:41.352406025 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:42.773385048 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 20:40:44.705924034 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:44.705976963 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:44.706064939 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:44.706321001 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:44.706341028 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:45.334322929 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:45.334827900 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:45.334867001 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:45.335155964 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:45.335505962 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:45.335566998 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:45.389394045 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:45.804369926 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:47.918937922 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:47.959418058 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:48.135186911 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:48.137871027 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:48.138204098 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:48.138832092 CEST | 49718 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:40:48.138858080 CEST | 443 | 49718 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:40:49.805213928 CEST | 49719 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.805272102 CEST | 443 | 49719 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.805380106 CEST | 49719 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.805951118 CEST | 49720 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.806009054 CEST | 443 | 49720 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.806068897 CEST | 49720 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.810884953 CEST | 49720 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.810899973 CEST | 443 | 49720 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.810945988 CEST | 443 | 49720 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.811544895 CEST | 49719 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.811568975 CEST | 443 | 49719 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.811610937 CEST | 443 | 49719 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.814007998 CEST | 49721 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.814043999 CEST | 443 | 49721 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.814130068 CEST | 49721 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.814487934 CEST | 49721 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:49.814495087 CEST | 443 | 49721 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:49.814510107 CEST | 443 | 49721 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.837866068 CEST | 49722 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.837924004 CEST | 443 | 49722 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.838006973 CEST | 49722 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.838238001 CEST | 49723 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.838330984 CEST | 443 | 49723 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.838393927 CEST | 49723 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.839484930 CEST | 49722 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.839503050 CEST | 443 | 49722 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.839556932 CEST | 443 | 49722 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.839833021 CEST | 49723 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.839855909 CEST | 443 | 49723 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.839994907 CEST | 443 | 49723 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.840529919 CEST | 49724 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.840578079 CEST | 443 | 49724 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.840646982 CEST | 49724 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.840791941 CEST | 49724 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:50.840810061 CEST | 443 | 49724 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.840828896 CEST | 443 | 49724 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:50.957397938 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 20:40:55.418399096 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 20:40:55.859803915 CEST | 49725 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.859847069 CEST | 443 | 49725 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.859915018 CEST | 49725 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.860084057 CEST | 49726 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.860095024 CEST | 443 | 49726 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.860140085 CEST | 49726 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.861298084 CEST | 49725 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.861315966 CEST | 443 | 49725 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.861418009 CEST | 443 | 49725 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.861737013 CEST | 49726 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.861747026 CEST | 443 | 49726 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.861815929 CEST | 443 | 49726 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.862201929 CEST | 49727 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.862302065 CEST | 443 | 49727 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.862382889 CEST | 49727 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.862504005 CEST | 49727 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:40:55.862541914 CEST | 443 | 49727 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:40:55.862582922 CEST | 443 | 49727 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:10.464849949 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:10.464915991 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:10.465023994 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:10.465409040 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:10.465432882 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.255626917 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.255745888 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.257148981 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.257172108 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.257402897 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.258894920 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.299420118 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.608236074 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.608263969 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.608280897 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.608478069 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.608520985 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.608577967 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.609771967 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.609805107 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.609900951 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.609913111 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.610718966 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.610804081 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.614095926 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.614128113 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:11.614145994 CEST | 49728 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 20:41:11.614151955 CEST | 443 | 49728 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 20:41:25.087616920 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:25.087682962 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:25.087826967 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:25.088079929 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:25.088095903 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:25.747802973 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:25.748262882 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:25.748285055 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:25.748569012 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:25.748922110 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:25.748967886 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:25.790596962 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:25.878650904 CEST | 49731 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.878712893 CEST | 443 | 49731 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.878803968 CEST | 49732 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.878818989 CEST | 49731 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.878889084 CEST | 443 | 49732 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.878958941 CEST | 49732 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.880091906 CEST | 49731 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.880109072 CEST | 443 | 49731 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.880220890 CEST | 443 | 49731 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.880520105 CEST | 49732 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.880562067 CEST | 443 | 49732 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.880628109 CEST | 443 | 49732 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.881012917 CEST | 49733 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.881047010 CEST | 443 | 49733 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.881102085 CEST | 49733 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.881213903 CEST | 49733 | 443 | 192.168.2.16 | 185.234.216.64 |
Oct 3, 2024 20:41:25.881226063 CEST | 443 | 49733 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:25.881279945 CEST | 443 | 49733 | 185.234.216.64 | 192.168.2.16 |
Oct 3, 2024 20:41:35.653058052 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:35.653131962 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:41:35.653199911 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:36.586133003 CEST | 49730 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:41:36.586152077 CEST | 443 | 49730 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:42:25.140779972 CEST | 49735 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:42:25.140836000 CEST | 443 | 49735 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:42:25.140945911 CEST | 49735 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:42:25.141277075 CEST | 49735 | 443 | 192.168.2.16 | 216.58.206.36 |
Oct 3, 2024 20:42:25.141289949 CEST | 443 | 49735 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:42:25.809333086 CEST | 443 | 49735 | 216.58.206.36 | 192.168.2.16 |
Oct 3, 2024 20:42:25.858582973 CEST | 49735 | 443 | 192.168.2.16 | 216.58.206.36 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 3, 2024 20:40:20.266129971 CEST | 53 | 57831 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:40:20.267991066 CEST | 53 | 60848 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:40:22.502624035 CEST | 53 | 49630 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:40:25.025048018 CEST | 55285 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 20:40:25.025157928 CEST | 56739 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 20:40:25.032174110 CEST | 53 | 56739 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:40:25.032795906 CEST | 53 | 55285 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:40:39.252574921 CEST | 53 | 62828 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:40:58.184864044 CEST | 53 | 49761 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:41:20.179614067 CEST | 53 | 60057 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:41:21.101080894 CEST | 53 | 65336 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 20:41:28.177186966 CEST | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Oct 3, 2024 20:41:49.055969954 CEST | 53 | 50342 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 3, 2024 20:40:25.025048018 CEST | 192.168.2.16 | 1.1.1.1 | 0xd1f7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 20:40:25.025157928 CEST | 192.168.2.16 | 1.1.1.1 | 0x9761 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 3, 2024 20:40:25.032174110 CEST | 1.1.1.1 | 192.168.2.16 | 0x9761 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 3, 2024 20:40:25.032795906 CEST | 1.1.1.1 | 192.168.2.16 | 0xd1f7 | No error (0) | 216.58.206.36 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49700 | 185.234.216.64 | 8000 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:21.138683081 CEST | 434 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49703 | 185.234.216.64 | 8000 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:23.963514090 CEST | 460 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49711 | 185.234.216.64 | 8000 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:29.665481091 CEST | 460 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49717 | 185.234.216.64 | 8000 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:36.444165945 CEST | 460 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49720 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:49.810884953 CEST | 433 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49719 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:49.811544895 CEST | 433 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49721 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:49.814487934 CEST | 433 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49722 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:50.839484930 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49723 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:50.839833021 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49724 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:50.840791941 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.16 | 49725 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:55.861298084 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.16 | 49726 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:55.861737013 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.16 | 49727 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:40:55.862504005 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.16 | 49731 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:41:25.880091906 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.16 | 49732 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:41:25.880520105 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.16 | 49733 | 185.234.216.64 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 3, 2024 20:41:25.881213903 CEST | 459 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49713 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 18:40:30 UTC | 161 | OUT | |
2024-10-03 18:40:30 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49714 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 18:40:31 UTC | 239 | OUT | |
2024-10-03 18:40:31 UTC | 515 | IN | |
2024-10-03 18:40:31 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49715 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 18:40:33 UTC | 306 | OUT | |
2024-10-03 18:40:34 UTC | 560 | IN | |
2024-10-03 18:40:34 UTC | 15824 | IN | |
2024-10-03 18:40:34 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49718 | 216.58.206.36 | 443 | 7080 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 18:40:47 UTC | 664 | OUT | |
2024-10-03 18:40:48 UTC | 1266 | IN | |
2024-10-03 18:40:48 UTC | 124 | IN | |
2024-10-03 18:40:48 UTC | 17 | IN | |
2024-10-03 18:40:48 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49728 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 18:41:11 UTC | 306 | OUT | |
2024-10-03 18:41:11 UTC | 560 | IN | |
2024-10-03 18:41:11 UTC | 15824 | IN | |
2024-10-03 18:41:11 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 14:40:18 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 14:40:19 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 14:40:20 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |