Windows
Analysis Report
Play_VM-Now(Cbequipment)CLQD.html
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6900 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t C:\Users \user\Desk top\Play_V M-Now(Cbeq uipment)CL QD.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3940 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2164 --fi eld-trial- handle=187 2,i,207304 7645121184 980,734565 8105367128 517,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Phishing |
---|
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTP traffic: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
google.com | 142.250.186.174 | true | false | unknown | |
118fix.com | 185.213.11.22 | true | false | unknown | |
www.google.com | 142.250.186.132 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.36 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.186.174 | google.com | United States | 15169 | GOOGLEUS | false | |
142.250.186.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
185.213.11.22 | 118fix.com | Iran (ISLAMIC Republic Of) | 205588 | DAFTARE-TABLIGHATE-ESLAMIIR | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1525218 |
Start date and time: | 2024-10-03 21:42:04 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Play_VM-Now(Cbequipment)CLQD.html |
Detection: | MAL |
Classification: | mal52.phis.winHTML@15/17@8/6 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.186.46, 74.125.71.84, 34.104.35.123, 142.250.184.227
- Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: Play_VM-Now(Cbequipment)CLQD.html
Input | Output |
---|---|
URL: https://google.com/404/#nilgesb@cbequipment.com Model: jbxai | { "brand":["Google"], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"unknown", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "has_visible_qrcode":false} |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
239.255.255.250 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Credential Flusher | Browse | |||
Get hash | malicious | Phisher | Browse | |||
185.213.11.22 | Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
118fix.com | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
DAFTARE-TABLIGHATE-ESLAMIIR | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9783315014823226 |
Encrypted: | false |
SSDEEP: | 48:81rvXdTTbD4H2idAKZdA1FehwiZUklqehQy+3:8vDJvy |
MD5: | 62DE9809C268DE0D76CEA48E7E1B27F8 |
SHA1: | B662135EC0D1A03A0EB9285AFED173E3F0BFF107 |
SHA-256: | 234855CF0ADA2FF4BC78B942BCFC31AF6408148F7F1ED5EDEC8CCCF50E60EFE7 |
SHA-512: | 594F83A2E72B8BC599AFB96F5FFF1F83EC49ADE4B1ABC59CDEDEA8C25CCE6EFC3156FCA60B0B879A0067D4540CB35B4EC5D99E1BDFF1B344B4B01C0CE4BEDC10 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.994299451219871 |
Encrypted: | false |
SSDEEP: | 48:8VXdTTbD4H2idAKZdA1seh/iZUkAQkqehfy+2:8zD/9QWy |
MD5: | E873D97F8C5AE6597333BCD143E5C115 |
SHA1: | 0E42B6DFFA9575EAF329B2FC1F13A7936314429E |
SHA-256: | 651D99E122A92B3AB067E5AF8C5A7251DFA3C0CF9F98583B1F796C381788683C |
SHA-512: | 0601243A6B2DB4C080B64720D6B61F930FD9EFD6780E225ED4715F0C622DD077422ABB0EC4ED946E0FC2608813E72CCF7F97ECB564CB5F05AACC4537DDEB0458 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.004715452103768 |
Encrypted: | false |
SSDEEP: | 48:8zdTTbDAH2idAKZdA14meh7sFiZUkmgqeh7sVy+BX:8BDznjy |
MD5: | 8F4736684235A6C8ED275B3D37335B60 |
SHA1: | 5F3C8DB05A5D1AE8CE753271971AFFF315D51B08 |
SHA-256: | 5C42014A04874E0FA6A79DE1555CAE29A6860BA7B7FE8C161C4F72AFE40E0D1B |
SHA-512: | 952A01E51C6B2B6DCFDF9B6B2FE10909547EFF6E0BBAFD1A1253CC76EA426A4731B4207BA4DE624C7A26E8C4BD16A8610B43122BB764906BDF5379DB326C5414 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.991362560921544 |
Encrypted: | false |
SSDEEP: | 48:8uXdTTbD4H2idAKZdA1TehDiZUkwqehLy+R:8iDMdy |
MD5: | D2907512904365231C104AEEF9D88560 |
SHA1: | EF15C2259E470CF666809D7C29059533A73B859B |
SHA-256: | 9A0569DB7845B947A2870C990E69F82F163F097075FCB3D1C11D7BD2A8AE67D7 |
SHA-512: | 6065E0690C1718CF5CA1079476AB290E18295CF3D38631AF5B4D2F7066A5E0F4A7950C81F3673073CCF894E9EF96E456B666343FEBFA9C6902B58BA15ACD30E5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9826753176150955 |
Encrypted: | false |
SSDEEP: | 48:89XdTTbD4H2idAKZdA1dehBiZUk1W1qehJy+C:8bDc9py |
MD5: | 3125DAC01DE19E502A6C8CDA5CA94429 |
SHA1: | 22188D1F2C31FD7A3F59184009C8316A526A45F1 |
SHA-256: | 6471FDBFEC53831665C26825ED6FDB70FAAF10349DC4022D4C63B9E6542782A7 |
SHA-512: | 3A99801F614A342EEC77F7935670C032726CB994F44120E05CF90394F5D26220BDA03F90ACFE49F7AD20BDF563A2D226F2BC2C1CAA01A772CE7ADABDCD98195A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9908285486912103 |
Encrypted: | false |
SSDEEP: | 48:8wXdTTbD4H2idAKZdA1duTeehOuTbbiZUk5OjqehOuTbjy+yT+:8MDuTfTbxWOvTbjy7T |
MD5: | 9CC42CE087A3D881C697391E825A02E1 |
SHA1: | 56D4D19950346CCED2C4DA359E8AA2B369C2ECC1 |
SHA-256: | 762035F0E28B1E0C80152E8E590147965977A024BEFB68D422683F4FE46C9F57 |
SHA-512: | 0B44423CCEFE4B3CBB0DC83801CAF7B0AB94687334D2C08F4B50633529B03AB2D63CFC9E08E5575373B5CAF4438C9F646888AB5AFFC7C98ED7A097D8495FB95E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
URL: | https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | high, very likely benign file |
URL: | https://www.google.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
URL: | https://www.google.com/images/errors/robot.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1565 |
Entropy (8bit): | 5.2675078899224985 |
Encrypted: | false |
SSDEEP: | 24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xKdS8f:3qD+2+pUAew85zsKQA |
MD5: | BC0AD2DB3272298238C3933EA0D944D1 |
SHA1: | CCB1767CAF616C73513DC921CD3F5DA072582A77 |
SHA-256: | 0A6AD5109827EFF80F61F2106F29D9FB38CE486FA397551E506BF5B6ED861F36 |
SHA-512: | 064388FD474E86ECB2D17082C79F6C9232DB605F62979598D9EA525600B8F9786716B758220D7C3ECC116E8E84AF8BB6AB6297C4005BCEF26E69DD64F4D61A72 |
Malicious: | false |
URL: | https://google.com/404/ |
Preview: |
File type: | |
Entropy (8bit): | 5.74994291214848 |
TrID: |
|
File name: | Play_VM-Now(Cbequipment)CLQD.html |
File size: | 304 bytes |
MD5: | b064ef31a404a35c12eeb6c53fd4301d |
SHA1: | 3c447b2b491ecd54f82c610b8e8fd0bd29d69179 |
SHA256: | c2ee64b861eeff72bf882d57d48f799874c76502dd3afaf1bb93f0877e0157f5 |
SHA512: | e9c97fe963dfdfcabd161499e344a8a4c9933d70ad393c9978b854fcce5acb2e9d72fffd42c398abb302e5a00702b13e463cdf231cde691e5835594b31c9abc8 |
SSDEEP: | 6:q43tWuJG+6SN0MFpROUsJKKK+vGFjioC16ziSZchZNkQfGb:TsB9SNLFHOUsJs+AiQzchZNk8Gb |
TLSH: | 93E07DF653008C567975427610A3BD91F27761181585C084C219C093158612CCACB784 |
File Content Preview: | <html>..<head>..<title>Detail notification for www.ctvnews.ca</title>..</head>..<body>..<SCRIPT LANGUAGE="JavaScript">.. ..self.location = 'https://118fix.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9WVVORWFrcz0mdWlkPVVTRVIxMTA5MjAyNFU1NzA5MTEwMQ==#nilgesb@cbeq |
Icon Hash: | 173149cccc490307 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 3, 2024 21:42:34.199019909 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:34.502784967 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:35.109807014 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:36.320688009 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:36.873861074 CEST | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:42:37.262902021 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:37.262957096 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:37.263034105 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:37.263297081 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:37.263305902 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:37.263360023 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:37.263492107 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:37.263504982 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:37.263703108 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:37.263711929 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.084934950 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.096995115 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.097021103 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.098139048 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.098206043 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.105196953 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.105305910 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.105545998 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.134264946 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.135782957 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.135812044 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.136893988 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.136957884 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.139353037 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.139452934 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.147408009 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.158659935 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.158684969 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.190673113 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.190700054 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:38.206688881 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.238802910 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:38.734780073 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:39.124000072 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:39.124070883 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:39.124128103 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:39.126027107 CEST | 49710 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:39.126045942 CEST | 443 | 49710 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:39.135303020 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.135343075 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.135410070 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.135600090 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.135607004 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.790016890 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.790307999 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.790334940 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.790761948 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.790833950 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.791521072 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.791579962 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.792463064 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.792534113 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.792613029 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:39.792622089 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:39.834719896 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:40.168173075 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:40.168235064 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:40.168299913 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:40.168304920 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:40.168359995 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:40.169455051 CEST | 49712 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:40.169461966 CEST | 443 | 49712 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:40.216695070 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.216722965 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.216799974 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.217004061 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.217019081 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.430912971 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:40.430963993 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:40.431060076 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:40.433137894 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:40.433155060 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:40.518110037 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.518158913 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.518271923 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.518469095 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.518485069 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.870543957 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.871043921 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.871079922 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.872121096 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.872189999 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.873192072 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.873265982 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.873369932 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:40.873384953 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:40.913721085 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.086055040 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.086134911 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.089337111 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.089345932 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.089628935 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.128097057 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.153640032 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.153681993 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.153729916 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.153753042 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.153786898 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.153804064 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.153933048 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.153933048 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.154906034 CEST | 49713 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.154922009 CEST | 443 | 49713 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.166560888 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.166589975 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.166677952 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.166877031 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.166891098 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.175407887 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.184192896 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.184422016 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.184446096 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.185508013 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.185569048 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.185914993 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.185981035 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.186058044 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.186069012 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.228677034 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.357543945 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.357610941 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.357664108 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.357754946 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.357779026 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.357795954 CEST | 49714 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.357804060 CEST | 443 | 49714 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.392797947 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.392832041 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.393032074 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.393383980 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:41.393393993 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:41.459768057 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.459810019 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.459856987 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.459886074 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.459963083 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.460005045 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.460009098 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.460016012 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.460052967 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.460057974 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.462418079 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.462457895 CEST | 443 | 49715 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.462515116 CEST | 49715 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.466927052 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:41.466968060 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:41.467036963 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:41.467327118 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:41.467341900 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:41.480148077 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.480190992 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.480339050 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.480489016 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.480504990 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.798878908 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.799282074 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.799300909 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.800350904 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.800407887 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.800854921 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.800915003 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.800966978 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.843410969 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.849657059 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:41.849678993 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:41.850769997 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.850822926 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.850903988 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.851139069 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:41.851156950 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:41.896749020 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.068620920 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.069746971 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:42.070388079 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:42.070394039 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.070909977 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.072051048 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:42.079047918 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.079190016 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.079459906 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.079638958 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.079648972 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.080621004 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.080770016 CEST | 49716 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.080787897 CEST | 443 | 49716 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.096592903 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.097021103 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.097038984 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.097445965 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.097927094 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.097927094 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.097940922 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.097995996 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.115412951 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.121248007 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.121531963 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.121551991 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.122664928 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.122867107 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.123049974 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.123120070 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.123694897 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.152529001 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.167404890 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.167857885 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.167866945 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.213824034 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.350528002 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.350692034 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.350781918 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:42.351528883 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:42.351545095 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.351574898 CEST | 49717 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 3, 2024 21:42:42.351581097 CEST | 443 | 49717 | 184.28.90.27 | 192.168.2.16 |
Oct 3, 2024 21:42:42.358243942 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:42:42.366635084 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.367014885 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.367110014 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.367151022 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.367151022 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.367163897 CEST | 443 | 49718 | 142.250.186.174 | 192.168.2.16 |
Oct 3, 2024 21:42:42.367328882 CEST | 49718 | 443 | 192.168.2.16 | 142.250.186.174 |
Oct 3, 2024 21:42:42.393799067 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.393831015 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.393862963 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.393904924 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.393959999 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.393971920 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.394126892 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.394196987 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.394403934 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.394409895 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.396542072 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.396585941 CEST | 443 | 49719 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.396687984 CEST | 49719 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.488409042 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.489515066 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.489542007 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.490730047 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.490814924 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.491238117 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.491312027 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.491520882 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.533792019 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.533813953 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.581687927 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.660684109 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:42:42.774158955 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.774239063 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.774291039 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.774326086 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.774424076 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.774452925 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.774473906 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.774482012 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.774842024 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.775367022 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.775420904 CEST | 443 | 49720 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:42:42.775568962 CEST | 49720 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:42:42.780513048 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.780543089 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:42.780635118 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.781090021 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:42.781110048 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.265773058 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:42:43.441324949 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.441828012 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.441849947 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.442986012 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.443093061 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.443397045 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.443479061 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.443795919 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.443808079 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.488698006 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.535691977 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:43.713900089 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.713937998 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.713967085 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.713984013 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.713999033 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.714019060 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.714036942 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.714045048 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.714106083 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.714333057 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.714385033 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.714447021 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.715174913 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.715190887 CEST | 443 | 49723 | 142.250.186.36 | 192.168.2.16 |
Oct 3, 2024 21:42:43.715202093 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:43.715257883 CEST | 49723 | 443 | 192.168.2.16 | 142.250.186.36 |
Oct 3, 2024 21:42:44.471693039 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:42:45.746675968 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:45.746718884 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:45.747175932 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:45.747992039 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:45.748002052 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:46.720918894 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:46.721035957 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:46.723706007 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:46.723716974 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:46.723990917 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:46.767057896 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:46.775306940 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:46.819411993 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:46.829217911 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:42:46.874674082 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:42:47.051879883 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.051906109 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.051914930 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.051923990 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.051954031 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.052026987 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.052047014 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.052067995 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.052099943 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.052829981 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.052949905 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.052963018 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.053198099 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.053280115 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.062227964 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.062227964 CEST | 49724 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:42:47.062251091 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.062263012 CEST | 443 | 49724 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:42:47.143692970 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:42:47.747750998 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:42:48.963176966 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:42:49.852468967 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:49.852535009 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:49.852683067 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:51.263248920 CEST | 49709 | 443 | 192.168.2.16 | 185.213.11.22 |
Oct 3, 2024 21:42:51.263277054 CEST | 443 | 49709 | 185.213.11.22 | 192.168.2.16 |
Oct 3, 2024 21:42:51.373716116 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:42:51.682713032 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:42:53.145739079 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 3, 2024 21:42:56.174773932 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:43:01.296771049 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 3, 2024 21:43:05.779825926 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 3, 2024 21:43:23.326406956 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:23.326502085 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:23.326620102 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:23.327094078 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:23.327130079 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:23.921006918 CEST | 49697 | 80 | 192.168.2.16 | 93.184.221.240 |
Oct 3, 2024 21:43:23.921097994 CEST | 49698 | 80 | 192.168.2.16 | 93.184.221.240 |
Oct 3, 2024 21:43:23.926320076 CEST | 80 | 49697 | 93.184.221.240 | 192.168.2.16 |
Oct 3, 2024 21:43:23.926430941 CEST | 49697 | 80 | 192.168.2.16 | 93.184.221.240 |
Oct 3, 2024 21:43:23.926873922 CEST | 80 | 49698 | 93.184.221.240 | 192.168.2.16 |
Oct 3, 2024 21:43:23.926939011 CEST | 49698 | 80 | 192.168.2.16 | 93.184.221.240 |
Oct 3, 2024 21:43:24.149574041 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.149658918 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.151470900 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.151496887 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.151849031 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.153556108 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.199407101 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.434232950 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.434299946 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.434345007 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.434405088 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.434438944 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.434458017 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.434484959 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.435350895 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.435450077 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.435451031 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.435477972 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.435511112 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.435776949 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.435832977 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.438529968 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.438549995 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:24.438563108 CEST | 49725 | 443 | 192.168.2.16 | 4.175.87.197 |
Oct 3, 2024 21:43:24.438570023 CEST | 443 | 49725 | 4.175.87.197 | 192.168.2.16 |
Oct 3, 2024 21:43:41.909209967 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:41.909274101 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:41.909363985 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:41.909550905 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:41.909565926 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:42.541033030 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:42.541342020 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:42.541373014 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:42.542220116 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:42.542282104 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:42.542558908 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:42.542597055 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:42.593832970 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:42.593847036 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:42.641834021 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:52.460684061 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:52.460783958 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Oct 3, 2024 21:43:52.461016893 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:53.265646935 CEST | 49727 | 443 | 192.168.2.16 | 142.250.186.132 |
Oct 3, 2024 21:43:53.265688896 CEST | 443 | 49727 | 142.250.186.132 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 3, 2024 21:42:37.007164001 CEST | 53 | 62441 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:37.087033033 CEST | 58240 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:37.087410927 CEST | 60431 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:37.130475044 CEST | 53 | 63976 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:37.131431103 CEST | 53 | 60431 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:37.262216091 CEST | 53 | 58240 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:38.233814955 CEST | 53 | 62372 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:39.126878023 CEST | 59094 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:39.127130985 CEST | 61486 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:39.134712934 CEST | 53 | 61486 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:39.134776115 CEST | 53 | 59094 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:40.209021091 CEST | 52362 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:40.209197998 CEST | 63429 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:40.216136932 CEST | 53 | 63429 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:40.216252089 CEST | 53 | 52362 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:41.158643007 CEST | 52127 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:41.158864975 CEST | 49201 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 3, 2024 21:42:41.165927887 CEST | 53 | 49201 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:41.166182995 CEST | 53 | 52127 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:42:55.346457958 CEST | 53 | 58384 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:43:14.135935068 CEST | 53 | 59205 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:43:36.764710903 CEST | 53 | 51484 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:43:37.000564098 CEST | 53 | 59514 | 1.1.1.1 | 192.168.2.16 |
Oct 3, 2024 21:43:38.534822941 CEST | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 3, 2024 21:42:37.087033033 CEST | 192.168.2.16 | 1.1.1.1 | 0xf7ba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 21:42:37.087410927 CEST | 192.168.2.16 | 1.1.1.1 | 0xd401 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 3, 2024 21:42:39.126878023 CEST | 192.168.2.16 | 1.1.1.1 | 0x118d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 21:42:39.127130985 CEST | 192.168.2.16 | 1.1.1.1 | 0x722b | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 3, 2024 21:42:40.209021091 CEST | 192.168.2.16 | 1.1.1.1 | 0xde38 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 21:42:40.209197998 CEST | 192.168.2.16 | 1.1.1.1 | 0xb803 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 3, 2024 21:42:41.158643007 CEST | 192.168.2.16 | 1.1.1.1 | 0x965b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 3, 2024 21:42:41.158864975 CEST | 192.168.2.16 | 1.1.1.1 | 0xdb75 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 3, 2024 21:42:37.262216091 CEST | 1.1.1.1 | 192.168.2.16 | 0xf7ba | No error (0) | 185.213.11.22 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 21:42:39.134712934 CEST | 1.1.1.1 | 192.168.2.16 | 0x722b | No error (0) | 65 | IN (0x0001) | false | |||
Oct 3, 2024 21:42:39.134776115 CEST | 1.1.1.1 | 192.168.2.16 | 0x118d | No error (0) | 142.250.186.174 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 21:42:40.216136932 CEST | 1.1.1.1 | 192.168.2.16 | 0xb803 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 3, 2024 21:42:40.216252089 CEST | 1.1.1.1 | 192.168.2.16 | 0xde38 | No error (0) | 142.250.186.132 | A (IP address) | IN (0x0001) | false | ||
Oct 3, 2024 21:42:41.165927887 CEST | 1.1.1.1 | 192.168.2.16 | 0xdb75 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 3, 2024 21:42:41.166182995 CEST | 1.1.1.1 | 192.168.2.16 | 0x965b | No error (0) | 142.250.186.36 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49710 | 185.213.11.22 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:38 UTC | 718 | OUT | |
2024-10-03 19:42:39 UTC | 439 | IN | |
2024-10-03 19:42:39 UTC | 1 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49712 | 142.250.186.174 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:39 UTC | 643 | OUT | |
2024-10-03 19:42:40 UTC | 231 | IN | |
2024-10-03 19:42:40 UTC | 1159 | IN | |
2024-10-03 19:42:40 UTC | 406 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49713 | 142.250.186.132 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:40 UTC | 783 | OUT | |
2024-10-03 19:42:41 UTC | 671 | IN | |
2024-10-03 19:42:41 UTC | 719 | IN | |
2024-10-03 19:42:41 UTC | 1390 | IN | |
2024-10-03 19:42:41 UTC | 1061 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49714 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:41 UTC | 161 | OUT | |
2024-10-03 19:42:41 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49715 | 142.250.186.132 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:41 UTC | 747 | OUT | |
2024-10-03 19:42:41 UTC | 683 | IN | |
2024-10-03 19:42:41 UTC | 707 | IN | |
2024-10-03 19:42:41 UTC | 1390 | IN | |
2024-10-03 19:42:41 UTC | 1390 | IN | |
2024-10-03 19:42:41 UTC | 1390 | IN | |
2024-10-03 19:42:41 UTC | 1390 | IN | |
2024-10-03 19:42:41 UTC | 60 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49716 | 142.250.186.36 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:41 UTC | 490 | OUT | |
2024-10-03 19:42:42 UTC | 671 | IN | |
2024-10-03 19:42:42 UTC | 719 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 1061 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49717 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:42 UTC | 239 | OUT | |
2024-10-03 19:42:42 UTC | 515 | IN | |
2024-10-03 19:42:42 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49718 | 142.250.186.174 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:42 UTC | 703 | OUT | |
2024-10-03 19:42:42 UTC | 453 | IN | |
2024-10-03 19:42:42 UTC | 231 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49719 | 142.250.186.36 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:42 UTC | 454 | OUT | |
2024-10-03 19:42:42 UTC | 683 | IN | |
2024-10-03 19:42:42 UTC | 707 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 60 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49720 | 142.250.186.132 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:42 UTC | 705 | OUT | |
2024-10-03 19:42:42 UTC | 706 | IN | |
2024-10-03 19:42:42 UTC | 684 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 1390 | IN | |
2024-10-03 19:42:42 UTC | 576 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.16 | 49723 | 142.250.186.36 | 443 | 3940 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:43 UTC | 442 | OUT | |
2024-10-03 19:42:43 UTC | 706 | IN | |
2024-10-03 19:42:43 UTC | 684 | IN | |
2024-10-03 19:42:43 UTC | 1390 | IN | |
2024-10-03 19:42:43 UTC | 1390 | IN | |
2024-10-03 19:42:43 UTC | 1390 | IN | |
2024-10-03 19:42:43 UTC | 576 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.16 | 49724 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:42:46 UTC | 306 | OUT | |
2024-10-03 19:42:47 UTC | 560 | IN | |
2024-10-03 19:42:47 UTC | 15824 | IN | |
2024-10-03 19:42:47 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.16 | 49725 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-03 19:43:24 UTC | 306 | OUT | |
2024-10-03 19:43:24 UTC | 560 | IN | |
2024-10-03 19:43:24 UTC | 15824 | IN | |
2024-10-03 19:43:24 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 15:42:35 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 15:42:36 |
Start date: | 03/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |