Windows
Analysis Report
https://t.ly/B1XqO
Overview
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6284 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6904 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2068 --fi eld-trial- handle=198 8,i,960398 8098196996 310,130233 4079381304 2613,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6216 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://t.ly/ B1XqO" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | HTTP traffic: | ||
Source: | HTTP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
homevaluefla.com | 172.67.186.149 | true | false | unknown | |
t.ly | 104.20.7.133 | true | false | unknown | |
google.com | 172.217.23.110 | true | false | unknown | |
www.google.com | 142.250.185.196 | true | false | unknown | |
206.23.85.13.in-addr.arpa | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.185.68 | unknown | United States | 15169 | GOOGLEUS | false | |
172.217.23.110 | google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.196 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.67.186.149 | homevaluefla.com | United States | 13335 | CLOUDFLARENETUS | false | |
104.20.7.133 | t.ly | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1529336 |
Start date and time: | 2024-10-08 21:38:02 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://t.ly/B1XqO |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@18/17@12/7 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 216.58.206.35, 142.250.184.206, 64.233.167.84, 34.104.35.123, 217.20.57.20, 4.175.87.197, 13.95.31.18, 40.69.42.241, 4.245.163.56, 13.85.23.206, 20.12.23.50, 142.250.186.35, 142.250.186.174
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://t.ly/B1XqO
Input | Output |
---|---|
URL: https://google.com/404/ Model: jbxai | { "brand":["Google"], "contains_trigger_text":false, "trigger_text":"", "prominent_button_name":"unknown", "text_input_field_labels":"unknown", "pdf_icon_visible":false, "has_visible_captcha":false, "has_urgent_text":false, "text":"404. That's an error. The requested URL /404/ was not found on this server. That's all we know.", "has_visible_qrcode":false} |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.991380299658959 |
Encrypted: | false |
SSDEEP: | 48:8IdkQTE0VblHdZidAKZdA1FehwiZUklqehty+3:8eHnDay |
MD5: | 3911562C1E1CC05D14CEB7244B677170 |
SHA1: | 5671C9303392A9104B37813D779A78B016F9D405 |
SHA-256: | 178E30C5B147743F37D035431CFF9F4790E4D1166AD2C4127CCD51AD6E7F93D7 |
SHA-512: | BC8B233F04599159BB91AD5E64D5E8A7AB6D18D473F2174E5CA44F8C8AE8D21AA1147B37E935312D2076791DCE7DED3BA472F5CFA51DF0D5025C82E0AA1AE37B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.005378559068571 |
Encrypted: | false |
SSDEEP: | 48:8/HdkQTE0VblHdZidAKZdA1seh/iZUkAQkqehKy+2:83HnN9QLy |
MD5: | 1B19486D5A81001E0EF17B91072AE99F |
SHA1: | 86B4CA3FA687ECE5F493B431D1E5D0926E70F720 |
SHA-256: | 6DAFF1F0A5B8F878AD6C24AD10CAB421B7A9901353D8AB4695CEDF6B683ED8EC |
SHA-512: | 27CF9A2771CF4262A121168FAC9B8E8B8CFB347A208A215983DAE76FA637FBB9D67B0592FD593E7AE6C6AAEC37F4D49B5CEAB86FE313B051A94C0E651F27B1C5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.012374168617675 |
Encrypted: | false |
SSDEEP: | 48:8JdkQTE0VbAHdZidAKZdA14meh7sFiZUkmgqeh7sAy+BX:8hH6RnWy |
MD5: | 951F7A0ABBD69F06FBC4289EC3A5248C |
SHA1: | 9E4E535D0BF7BFF1A521AB94C42AD0EAE6195998 |
SHA-256: | 4505ACCB19E5A68C0F5394126B933EBA070757471E8EDF7981837121AC0F09DE |
SHA-512: | 5B9CF40862F5E9E35CEFCE7F6EF81D8EF066C84950729420590DEDC27AF4A92C7FDB366FB3729D79D8A147D9A7064AFF411547020CAA7382047369E5B8C104A4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.006929559428961 |
Encrypted: | false |
SSDEEP: | 48:8pdkQTE0VblHdZidAKZdA1TehDiZUkwqehOy+R:8BHn+Yy |
MD5: | 9E1722766F47AB7A659BD1BD42F50A95 |
SHA1: | FC4830F21FE5D366E7DBE9CC767D657E187D72F9 |
SHA-256: | 2455BEEDFE8CB946AA9D1113795EA5639B5D80F0803E3CFBF6BEFB966590EA9D |
SHA-512: | D79F08355A48C1783F4AF21042332B643C90FDADF18C533FD85EA41FCC246DB9B315D927D991D475A3801F550760FA8729FB6C21A98F2FE5E0CBC87B96A4415A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9903235564745816 |
Encrypted: | false |
SSDEEP: | 48:8pdkQTE0VblHdZidAKZdA1dehBiZUk1W1qeh8y+C:8BHnu9cy |
MD5: | 5055387AD40AD5D5072B1648332FE9B9 |
SHA1: | 52169B06EB8378CDA971F4DAFD23F7DF6AAC1FE0 |
SHA-256: | CDD38454172B89810CC3538567763631CE5B6AFB15BDF28243DAD715678658F3 |
SHA-512: | 43D31781C04BE7351DFD99AEE28BBBC5FF9192DD52244521AF9C1D799219CB6D4E4E9C5EED5E9DEFA2C3A8278BE71904E8B4BF1D2B555075E508A094DCE16908 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.001114283201027 |
Encrypted: | false |
SSDEEP: | 48:8PdkQTE0VblHdZidAKZdA1duTeehOuTbbiZUk5OjqehOuTbWy+yT+:8HHnETfTbxWOvTbWy7T |
MD5: | 0A1A81B19444605C812D49A122AFF3E0 |
SHA1: | EFA2B1B4624F1B3E274CE6EC01CF29DC69BCA6DB |
SHA-256: | 4887515FAE2E3B07C528AD4E3E83A9881C5278FA95546043DC409D9C36D02AED |
SHA-512: | 2EB30AC7E1E63602108399A38D9BF46DE466CE6880CF4BBA7656BE74F6CDFBBE91E4946A89E762D8B5A7EBE4C4D2ADD117C0E2856032CAB3826729900F5C2F2F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6327 |
Entropy (8bit): | 7.917392761938663 |
Encrypted: | false |
SSDEEP: | 192:fqjwqVtaVHyEy9BWc2AwJ+3qg1f6WUBIT8mIKPNc93Y8Nm:Yk3WBkAkg1CWUCwmIKS93O |
MD5: | 4C9ACF280B47CEF7DEF3FC91A34C7FFE |
SHA1: | C32BB847DAF52117AB93B723D7C57D8B1E75D36B |
SHA-256: | 5F9FC5B3FBDDF0E72C5C56CDCFC81C6E10C617D70B1B93FBE1E4679A8797BFF7 |
SHA-512: | 369D5888E0D19B46CB998EA166D421F98703AEC7D82A02DC7AE10409AEC253A7CE099D208500B4E39779526219301C66C2FD59FE92170B324E70CF63CE2B429C |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/images/errors/robot.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3170 |
Entropy (8bit): | 7.934630496764965 |
Encrypted: | false |
SSDEEP: | 96:c2ZEPhMXQnPkVrTEnGD9c4vnrmBYBaSfS18:c2/XQnPGroGD9vvnXVaq |
MD5: | 9D73B3AA30BCE9D8F166DE5178AE4338 |
SHA1: | D0CBC46850D8ED54625A3B2B01A2C31F37977E75 |
SHA-256: | DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139 |
SHA-512: | 8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1565 |
Entropy (8bit): | 5.2675078899224985 |
Encrypted: | false |
SSDEEP: | 24:hY6svD+6zSU6pedQf3Zvcn1BZdAe1nCr1LTHI5z8xKdS8f:3qD+2+pUAew85zsKQA |
MD5: | BC0AD2DB3272298238C3933EA0D944D1 |
SHA1: | CCB1767CAF616C73513DC921CD3F5DA072582A77 |
SHA-256: | 0A6AD5109827EFF80F61F2106F29D9FB38CE486FA397551E506BF5B6ED861F36 |
SHA-512: | 064388FD474E86ECB2D17082C79F6C9232DB605F62979598D9EA525600B8F9786716B758220D7C3ECC116E8E84AF8BB6AB6297C4005BCEF26E69DD64F4D61A72 |
Malicious: | false |
Reputation: | low |
URL: | https://google.com/404/ |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 21:38:28.929774046 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:28.929826021 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:28.929903984 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:28.930243969 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:28.930274010 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:28.930494070 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:28.930524111 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:28.930582047 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:28.930751085 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:28.930762053 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.431143999 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.431509018 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.431533098 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.432987928 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.433059931 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.433496952 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.433712959 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.433743000 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.434142113 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.434310913 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.434320927 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.434962988 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.435060024 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.435902119 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.435980082 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.479398012 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.479783058 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.479792118 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.479794025 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.479814053 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.526515007 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.526611090 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.561465979 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.561614037 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.561683893 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.563746929 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.563764095 CEST | 443 | 49700 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:29.563774109 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.563828945 CEST | 49700 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:29.588574886 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:29.588676929 CEST | 443 | 49701 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:29.588795900 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:29.589059114 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:29.589081049 CEST | 443 | 49701 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.105731010 CEST | 443 | 49701 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.106025934 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.106051922 CEST | 443 | 49701 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.107669115 CEST | 443 | 49701 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.107739925 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.108583927 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.108616114 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.108679056 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.108756065 CEST | 443 | 49701 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.108995914 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.109030008 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.109045982 CEST | 49701 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.109100103 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.109277964 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.109294891 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.593085051 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.593367100 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.593415022 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.594453096 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.594538927 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.595367908 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.595454931 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.595565081 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.639425039 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.641501904 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.641521931 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.689495087 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.969813108 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.969909906 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.970014095 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.971498966 CEST | 49702 | 443 | 192.168.2.16 | 172.67.186.149 |
Oct 8, 2024 21:38:30.971537113 CEST | 443 | 49702 | 172.67.186.149 | 192.168.2.16 |
Oct 8, 2024 21:38:30.980853081 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:30.980948925 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:30.981069088 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:30.981261969 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:30.981292009 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.649136066 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.649478912 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:31.649528980 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.650213003 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.650295973 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:31.651211977 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.651276112 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:31.652275085 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:31.652367115 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.652456045 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:31.652472019 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:31.706955910 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:32.022872925 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:32.023130894 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:32.023298025 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:32.023338079 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:32.023411989 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:32.036849022 CEST | 49704 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:32.036886930 CEST | 443 | 49704 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:32.123895884 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.123991966 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.124088049 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.124378920 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.124406099 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.425360918 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.425460100 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.425574064 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.425832987 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.425863981 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.786714077 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.787060022 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.787091970 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.788722038 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.788817883 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.789829016 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.789900064 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.790016890 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:32.790024996 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:32.839533091 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.059336901 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.059408903 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.059463024 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.059479952 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.059670925 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.059724092 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.060522079 CEST | 49705 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.060537100 CEST | 443 | 49705 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.061150074 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.061784983 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.061794996 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.062824965 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.062891960 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.063381910 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.063457966 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.063766003 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.063774109 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.074732065 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.074805021 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.074894905 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.075083971 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.075103045 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.111505985 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.342781067 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.342905998 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.342978001 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.343009949 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.343095064 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.343157053 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.343169928 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.343240976 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.343300104 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.343312025 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.343564987 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.343662977 CEST | 443 | 49706 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:33.343733072 CEST | 49706 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:33.346555948 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.346621990 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.346721888 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.346918106 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.346939087 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.348845959 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:33.348911047 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:33.349004984 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:33.349216938 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:33.349247932 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:33.725312948 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.725661993 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.725717068 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.729274988 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.729374886 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.729655027 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.729785919 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.729805946 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.775403023 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.780504942 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.780530930 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.828522921 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.925414085 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:33.988548040 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.989936113 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.989970922 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.991015911 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.991102934 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.991522074 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:33.991589069 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:33.992316961 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.000794888 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.003113985 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:34.003176928 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.003603935 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.005135059 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:34.005218029 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.005377054 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:34.005841017 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.005956888 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.006042004 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.006072044 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.006757021 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.008800983 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.008910894 CEST | 49707 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.008940935 CEST | 443 | 49707 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.037528992 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.037547112 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.051410913 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.052645922 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:34.088613033 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.228559971 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:34.263204098 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.263329983 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.263439894 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.263514996 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.263544083 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.263628006 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.263690948 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.263705015 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.263761044 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.265017986 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.265109062 CEST | 443 | 49708 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:34.265189886 CEST | 49708 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:34.274524927 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.275705099 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.275806904 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:34.276259899 CEST | 49709 | 443 | 192.168.2.16 | 172.217.23.110 |
Oct 8, 2024 21:38:34.276305914 CEST | 443 | 49709 | 172.217.23.110 | 192.168.2.16 |
Oct 8, 2024 21:38:34.278855085 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.278906107 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.279093981 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.279604912 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.279681921 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.835529089 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:34.922974110 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.923248053 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.923280954 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.924762011 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.924843073 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.925157070 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.925246000 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.925291061 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.971402884 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:34.979532957 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:34.979592085 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.027704954 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:35.204255104 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.204377890 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.204655886 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:35.204719067 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.204829931 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.204962015 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.205049038 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:35.205111980 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.205154896 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.205158949 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:35.205197096 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:35.205396891 CEST | 49712 | 443 | 192.168.2.16 | 142.250.185.196 |
Oct 8, 2024 21:38:35.205426931 CEST | 443 | 49712 | 142.250.185.196 | 192.168.2.16 |
Oct 8, 2024 21:38:35.207798958 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.207887888 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.208132982 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.208245039 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.208276987 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.853893042 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.854192019 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.854216099 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.858098984 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.858176947 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.858468056 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.858606100 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.858642101 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.898514986 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:35.898525000 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:35.946516991 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:36.041531086 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:36.132078886 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:36.132616997 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:36.132707119 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:36.132765055 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:36.132790089 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:36.132817984 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:36.132846117 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:36.133661032 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:36.133724928 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:36.133841038 CEST | 49714 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:38:36.133867979 CEST | 443 | 49714 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:38:37.592649937 CEST | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:38:38.450582981 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:40.153358936 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:40.153429031 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:40.153558016 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:40.155635118 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:40.155653954 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:40.793911934 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:40.794019938 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:40.798744917 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:40.798773050 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:40.799110889 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:40.836678982 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:40.883410931 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.060625076 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.060808897 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.060884953 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.060980082 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.061016083 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.061017036 CEST | 49720 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.061038971 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.061057091 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.105287075 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.105334044 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.105421066 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.105673075 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.105685949 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.972848892 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.972937107 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.974283934 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:41.974292994 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.974600077 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:41.978806019 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:42.019433022 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:42.100089073 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:38:42.243918896 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:42.244012117 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:42.248895884 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:42.248977900 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:42.248979092 CEST | 49722 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 8, 2024 21:38:42.248997927 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:42.249011993 CEST | 443 | 49722 | 184.28.90.27 | 192.168.2.16 |
Oct 8, 2024 21:38:42.401618004 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:38:43.005587101 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:38:43.261569023 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:44.218676090 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:38:44.330461025 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:44.330532074 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:44.330739975 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:46.279450893 CEST | 49699 | 443 | 192.168.2.16 | 104.20.7.133 |
Oct 8, 2024 21:38:46.279520035 CEST | 443 | 49699 | 104.20.7.133 | 192.168.2.16 |
Oct 8, 2024 21:38:46.566802979 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:38:46.630707026 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:38:46.868594885 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:38:47.476644039 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:38:48.689589977 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:38:51.099622011 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:38:51.435662985 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:38:52.873639107 CEST | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 8, 2024 21:38:55.310497999 CEST | 56305 | 53 | 192.168.2.16 | 162.159.36.2 |
Oct 8, 2024 21:38:55.315834999 CEST | 53 | 56305 | 162.159.36.2 | 192.168.2.16 |
Oct 8, 2024 21:38:55.316057920 CEST | 56305 | 53 | 192.168.2.16 | 162.159.36.2 |
Oct 8, 2024 21:38:55.316057920 CEST | 56305 | 53 | 192.168.2.16 | 162.159.36.2 |
Oct 8, 2024 21:38:55.321983099 CEST | 53 | 56305 | 162.159.36.2 | 192.168.2.16 |
Oct 8, 2024 21:38:55.772511005 CEST | 53 | 56305 | 162.159.36.2 | 192.168.2.16 |
Oct 8, 2024 21:38:55.773355961 CEST | 56305 | 53 | 192.168.2.16 | 162.159.36.2 |
Oct 8, 2024 21:38:55.779129982 CEST | 53 | 56305 | 162.159.36.2 | 192.168.2.16 |
Oct 8, 2024 21:38:55.779217958 CEST | 56305 | 53 | 192.168.2.16 | 162.159.36.2 |
Oct 8, 2024 21:38:55.909662008 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:39:01.036685944 CEST | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 8, 2024 21:39:05.520766020 CEST | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 8, 2024 21:39:32.895347118 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:32.895409107 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:32.895514011 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:32.895840883 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:32.895875931 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:33.551302910 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:33.551697969 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:33.551765919 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:33.552877903 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:33.553281069 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:33.553456068 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:33.603954077 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:43.449781895 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:43.449845076 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Oct 8, 2024 21:39:43.450005054 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:44.272665024 CEST | 56311 | 443 | 192.168.2.16 | 142.250.185.68 |
Oct 8, 2024 21:39:44.272725105 CEST | 443 | 56311 | 142.250.185.68 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 8, 2024 21:38:28.091531992 CEST | 53 | 59419 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:28.161149979 CEST | 53 | 63032 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:28.915364981 CEST | 52120 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:28.915646076 CEST | 56852 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:28.923466921 CEST | 53 | 52120 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:28.924834967 CEST | 53 | 56852 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:29.211158037 CEST | 53 | 49861 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:29.564532995 CEST | 55574 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:29.564718962 CEST | 63197 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:29.583858013 CEST | 53 | 55574 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:29.585836887 CEST | 53 | 63197 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:30.972091913 CEST | 62872 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:30.972219944 CEST | 58999 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:30.980220079 CEST | 53 | 62872 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:30.980259895 CEST | 53 | 58999 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:32.115816116 CEST | 55644 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:32.116233110 CEST | 64882 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:32.123147964 CEST | 53 | 55644 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:32.123209953 CEST | 53 | 64882 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:33.066339016 CEST | 65362 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:33.066559076 CEST | 56028 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:33.073196888 CEST | 53 | 65362 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:33.074299097 CEST | 53 | 56028 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:46.287535906 CEST | 53 | 65207 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:38:55.309704065 CEST | 53 | 56335 | 162.159.36.2 | 192.168.2.16 |
Oct 8, 2024 21:38:55.819866896 CEST | 51543 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:38:55.830020905 CEST | 53 | 51543 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:39:32.886168957 CEST | 60214 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 8, 2024 21:39:32.894130945 CEST | 53 | 60214 | 1.1.1.1 | 192.168.2.16 |
Oct 8, 2024 21:39:38.278791904 CEST | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 8, 2024 21:38:28.915364981 CEST | 192.168.2.16 | 1.1.1.1 | 0x542d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 21:38:28.915646076 CEST | 192.168.2.16 | 1.1.1.1 | 0x2b25 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 8, 2024 21:38:29.564532995 CEST | 192.168.2.16 | 1.1.1.1 | 0x52ce | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 21:38:29.564718962 CEST | 192.168.2.16 | 1.1.1.1 | 0xb8af | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 8, 2024 21:38:30.972091913 CEST | 192.168.2.16 | 1.1.1.1 | 0xb49d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 21:38:30.972219944 CEST | 192.168.2.16 | 1.1.1.1 | 0x504 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 8, 2024 21:38:32.115816116 CEST | 192.168.2.16 | 1.1.1.1 | 0x8335 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 21:38:32.116233110 CEST | 192.168.2.16 | 1.1.1.1 | 0x7107 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 8, 2024 21:38:33.066339016 CEST | 192.168.2.16 | 1.1.1.1 | 0x4905 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 8, 2024 21:38:33.066559076 CEST | 192.168.2.16 | 1.1.1.1 | 0x76a7 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 8, 2024 21:38:55.819866896 CEST | 192.168.2.16 | 1.1.1.1 | 0xf552 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Oct 8, 2024 21:39:32.886168957 CEST | 192.168.2.16 | 1.1.1.1 | 0xc250 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 8, 2024 21:38:28.923466921 CEST | 1.1.1.1 | 192.168.2.16 | 0x542d | No error (0) | 104.20.7.133 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:28.923466921 CEST | 1.1.1.1 | 192.168.2.16 | 0x542d | No error (0) | 104.20.6.133 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:28.924834967 CEST | 1.1.1.1 | 192.168.2.16 | 0x2b25 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 8, 2024 21:38:29.583858013 CEST | 1.1.1.1 | 192.168.2.16 | 0x52ce | No error (0) | 172.67.186.149 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:29.583858013 CEST | 1.1.1.1 | 192.168.2.16 | 0x52ce | No error (0) | 104.21.84.54 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:29.585836887 CEST | 1.1.1.1 | 192.168.2.16 | 0xb8af | No error (0) | 65 | IN (0x0001) | false | |||
Oct 8, 2024 21:38:30.980220079 CEST | 1.1.1.1 | 192.168.2.16 | 0xb49d | No error (0) | 172.217.23.110 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:30.980259895 CEST | 1.1.1.1 | 192.168.2.16 | 0x504 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 8, 2024 21:38:32.123147964 CEST | 1.1.1.1 | 192.168.2.16 | 0x8335 | No error (0) | 142.250.185.196 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:32.123209953 CEST | 1.1.1.1 | 192.168.2.16 | 0x7107 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 8, 2024 21:38:33.073196888 CEST | 1.1.1.1 | 192.168.2.16 | 0x4905 | No error (0) | 142.250.185.68 | A (IP address) | IN (0x0001) | false | ||
Oct 8, 2024 21:38:33.074299097 CEST | 1.1.1.1 | 192.168.2.16 | 0x76a7 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 8, 2024 21:38:55.830020905 CEST | 1.1.1.1 | 192.168.2.16 | 0xf552 | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false | |
Oct 8, 2024 21:39:32.894130945 CEST | 1.1.1.1 | 192.168.2.16 | 0xc250 | No error (0) | 142.250.185.68 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49700 | 104.20.7.133 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:29 UTC | 652 | OUT | |
2024-10-08 19:38:29 UTC | 739 | IN | |
2024-10-08 19:38:29 UTC | 630 | IN | |
2024-10-08 19:38:29 UTC | 473 | IN | |
2024-10-08 19:38:29 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49702 | 172.67.186.149 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:30 UTC | 751 | OUT | |
2024-10-08 19:38:30 UTC | 669 | IN | |
2024-10-08 19:38:30 UTC | 6 | IN | |
2024-10-08 19:38:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49704 | 172.217.23.110 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:31 UTC | 657 | OUT | |
2024-10-08 19:38:32 UTC | 231 | IN | |
2024-10-08 19:38:32 UTC | 1159 | IN | |
2024-10-08 19:38:32 UTC | 406 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49705 | 142.250.185.196 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:32 UTC | 783 | OUT | |
2024-10-08 19:38:33 UTC | 671 | IN | |
2024-10-08 19:38:33 UTC | 719 | IN | |
2024-10-08 19:38:33 UTC | 1390 | IN | |
2024-10-08 19:38:33 UTC | 1061 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49706 | 142.250.185.196 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:33 UTC | 747 | OUT | |
2024-10-08 19:38:33 UTC | 682 | IN | |
2024-10-08 19:38:33 UTC | 708 | IN | |
2024-10-08 19:38:33 UTC | 1390 | IN | |
2024-10-08 19:38:33 UTC | 1390 | IN | |
2024-10-08 19:38:33 UTC | 1390 | IN | |
2024-10-08 19:38:33 UTC | 1390 | IN | |
2024-10-08 19:38:33 UTC | 59 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49707 | 142.250.185.68 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:33 UTC | 490 | OUT | |
2024-10-08 19:38:33 UTC | 671 | IN | |
2024-10-08 19:38:33 UTC | 719 | IN | |
2024-10-08 19:38:33 UTC | 1390 | IN | |
2024-10-08 19:38:33 UTC | 1061 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49708 | 142.250.185.68 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:33 UTC | 454 | OUT | |
2024-10-08 19:38:34 UTC | 682 | IN | |
2024-10-08 19:38:34 UTC | 708 | IN | |
2024-10-08 19:38:34 UTC | 1390 | IN | |
2024-10-08 19:38:34 UTC | 1390 | IN | |
2024-10-08 19:38:34 UTC | 1390 | IN | |
2024-10-08 19:38:34 UTC | 1390 | IN | |
2024-10-08 19:38:34 UTC | 59 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49709 | 172.217.23.110 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:33 UTC | 703 | OUT | |
2024-10-08 19:38:34 UTC | 454 | IN | |
2024-10-08 19:38:34 UTC | 231 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.16 | 49712 | 142.250.185.196 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:34 UTC | 705 | OUT | |
2024-10-08 19:38:35 UTC | 706 | IN | |
2024-10-08 19:38:35 UTC | 684 | IN | |
2024-10-08 19:38:35 UTC | 1390 | IN | |
2024-10-08 19:38:35 UTC | 1390 | IN | |
2024-10-08 19:38:35 UTC | 1390 | IN | |
2024-10-08 19:38:35 UTC | 576 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.16 | 49714 | 142.250.185.68 | 443 | 6904 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:35 UTC | 442 | OUT | |
2024-10-08 19:38:36 UTC | 706 | IN | |
2024-10-08 19:38:36 UTC | 684 | IN | |
2024-10-08 19:38:36 UTC | 1390 | IN | |
2024-10-08 19:38:36 UTC | 1390 | IN | |
2024-10-08 19:38:36 UTC | 1390 | IN | |
2024-10-08 19:38:36 UTC | 576 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.16 | 49720 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:40 UTC | 161 | OUT | |
2024-10-08 19:38:41 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.16 | 49722 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-08 19:38:41 UTC | 239 | OUT | |
2024-10-08 19:38:42 UTC | 514 | IN | |
2024-10-08 19:38:42 UTC | 55 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 15:38:25 |
Start date: | 08/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 15:38:26 |
Start date: | 08/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 15:38:27 |
Start date: | 08/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |