Windows
Analysis Report
http://www.klinch.ch//WORK/-1
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 5644 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3964 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2128 --fi eld-trial- handle=208 8,i,338735 6910927797 428,188117 8812209797 916,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 1012 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://www.kl inch.ch//W ORK/-1" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | unknown | |
d3fqahajli23b9.cloudfront.net | 108.138.26.35 | true | false | unknown | |
knoppkniel.com | 3.234.189.133 | true | false | unknown | |
klinch.ch | 149.126.4.35 | true | false | unknown | |
www.knoppkniel.com | 3.234.189.133 | true | false | unknown | |
www.google.com | 142.250.185.132 | true | false | unknown | |
d3q7swlkq70mfj.cloudfront.net | 18.66.102.33 | true | false | unknown | |
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | unknown | |
freight.cargo.site | unknown | unknown | false | unknown | |
www.klinch.ch | unknown | unknown | false | unknown | |
static.cargo.site | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.66.102.33 | d3q7swlkq70mfj.cloudfront.net | United States | 3 | MIT-GATEWAYSUS | false | |
142.250.185.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
3.234.189.133 | knoppkniel.com | United States | 14618 | AMAZON-AESUS | false | |
108.138.26.35 | d3fqahajli23b9.cloudfront.net | United States | 16509 | AMAZON-02US | false | |
149.126.4.35 | klinch.ch | Switzerland | 47302 | CYONCH | false |
IP |
---|
192.168.2.8 |
192.168.2.5 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1531968 |
Start date and time: | 2024-10-12 00:54:02 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://www.klinch.ch//WORK/-1 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@17/8@16/8 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.185.174, 173.194.76.84, 34.104.35.123, 199.232.210.172, 40.69.42.241, 192.229.221.95, 52.165.164.15, 142.250.186.163, 93.184.221.240
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, update.googleapis.com, hlb.apr-52dd2-0.edgecastdns.net, clients.l.google.com, wu-b-net.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
- VT rate limit hit for: http://www.klinch.ch//WORK/-1
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9765210574545047 |
Encrypted: | false |
SSDEEP: | 48:860dKT2SKH/idAKZdA1oehwiZUklqehly+3:86p//qy |
MD5: | 018D3A809947FD388EE023DDE251B31C |
SHA1: | 631E97B51C46F3E772644E99647A295AE2141CB8 |
SHA-256: | FECE3064DCABC97A19E2049EB8392137B3F21304600CBD3E8CE159353D8FF45F |
SHA-512: | 5A4D7B3E988E8E231BE6138E1F067719B13F5F971F31FFFD18ABF9BE046DC4EEB338495A5AF129872DC64440B79B3741DA6971E19DF0150E7673D687EE6CE659 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.997119181230565 |
Encrypted: | false |
SSDEEP: | 48:8I0dKT2SKH/idAKZdA1leh/iZUkAQkqehay+2:8Ip/l9Qny |
MD5: | B84A221284A3658AF875F4A9BB5CC97E |
SHA1: | 468E03FF1B8ECF824294D99125AB9E162E157C11 |
SHA-256: | 4279A0BDB14D16355E55D83571608F49FD3CFB6A8B684F6A069E67C4372D1247 |
SHA-512: | 3C03B39915F5645E86E8CFF002B7A42AB9819530BBAF91FB50A235D749D81B7ED5E1FA521FB112BC1B8E4E2B985FEA0548F9EC8593AE6DA220F221906F22E70D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.006375892626877 |
Encrypted: | false |
SSDEEP: | 48:8X0dKT2SbH/idAKZdA14t5eh7sFiZUkmgqeh7sMy+BX:8Xp/2nmy |
MD5: | 9BA34792DD36D8C14D8A8E69E85CA654 |
SHA1: | A1FB836B0B0CC1A6D1EBDD20F1308015130B0553 |
SHA-256: | 5500A497A8742853FBF5599F14B6F98487FBB6D72801184C64F0DB5FDD36156D |
SHA-512: | 6A76837D05142F8F1F07636A56A0EF10C7F8B6C9200EBC9D016D404C3AB06369CB1B130901EFC3F4F5D916BD3DCCF0E69BEB2BC482DB76DF4F84E30046045C86 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.99229171279318 |
Encrypted: | false |
SSDEEP: | 48:8U0dKT2SKH/idAKZdA16ehDiZUkwqehey+R:8Up/2ky |
MD5: | 2A106E2C785972106A88CAF605CEA8B7 |
SHA1: | AFE94917FA3A181405B8B4EAC23DF3088FECED10 |
SHA-256: | 9EC9A9C872235671463AB716339A38CDB9ED89EBBA1263444C1AD4E553483152 |
SHA-512: | F9742F19A3F0297AF120E0030FE6EDF0C9E6262332F537EB33D31C3279F519B02E8609B3C5CCF126F74D746DA4405DB1D68EAA4D0EE141CC6E719FCFBB81FE5B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9835905341838496 |
Encrypted: | false |
SSDEEP: | 48:8C0dKT2SKH/idAKZdA1UehBiZUk1W1qehoy+C:8Cp/W9Iy |
MD5: | D03023E3CFBB715BBFB455068BD92B04 |
SHA1: | 17281188F92FFCB35A76A48C2751C82F74B92061 |
SHA-256: | 4B557DD43EED66837464345671B3508802DE5D4579D503213E809A627FA55350 |
SHA-512: | 28A8FECCD17D937D607ADF637D61DBAD7675D4637C3D01F14D9D5D53D3DBD7C8C28884248528ECD30CC96E43F3038E9449CD641C6A7CBF87A81E3D5395D90D30 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9919072950266763 |
Encrypted: | false |
SSDEEP: | 48:8R0dKT2SKH/idAKZdA1duTrehOuTbbiZUk5OjqehOuTbmy+yT+:8Rp/nTYTbxWOvTbmy7T |
MD5: | F51BF5DBE5E8F3AD18768C79ABB70662 |
SHA1: | 4860C8D72A494A6F03A98A90F8446D997109D877 |
SHA-256: | D7ABB2DB7FD41F799AC6E63ECA414F8AC6FA77AF145F35D46B02066D0D608506 |
SHA-512: | B8CF9662C69F3D932C2F85095F6CD7E02E76EE3B92276A388DB1D499608DCB4A1788FB786D1345993FE896CCF85872F85AF1D6221F41E59213D0621B1CAED555 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 14044 |
Entropy (8bit): | 5.18150597504193 |
Encrypted: | false |
SSDEEP: | 384:RGJ0M4lcK9oJ4jZZyZ5SZD3bZBfm34TZGzZDsAZkrZcLZnw8Zf:RlGK9oJ4j/yPSB3bDfm34TUzBsAurSLz |
MD5: | 31CF5CB03E7E0CB006BD956B7524723E |
SHA1: | 79B9D53B282E1F2F0228639CD4B393C537DF739C |
SHA-256: | 9821487E15808C86D9C7B640218A9229FB745DEB59FDE9595497FF26AB357E85 |
SHA-512: | 1342765745989669814BA5A3227A703E700E7ADB1A89B5155A23A8030D68B70CC3BCBA2ECBD0210195A7A3258E3AE499833C9250AD72BEA7338294DBEDCF389A |
Malicious: | false |
Reputation: | low |
URL: | https://knoppkniel.com/stylesheet?c=3680624028&1667768525 |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 00:54:54.811994076 CEST | 49671 | 443 | 192.168.2.8 | 204.79.197.203 |
Oct 12, 2024 00:54:55.155504942 CEST | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Oct 12, 2024 00:54:57.171027899 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 12, 2024 00:54:57.546020031 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 12, 2024 00:55:03.249104023 CEST | 49676 | 443 | 192.168.2.8 | 52.182.143.211 |
Oct 12, 2024 00:55:05.850331068 CEST | 49677 | 80 | 192.168.2.8 | 192.229.211.108 |
Oct 12, 2024 00:55:06.788115025 CEST | 49673 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 12, 2024 00:55:06.940608025 CEST | 49711 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:06.940612078 CEST | 49710 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:06.945518970 CEST | 80 | 49711 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:06.945533037 CEST | 80 | 49710 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:06.945633888 CEST | 49711 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:06.947125912 CEST | 49710 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.063582897 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.063622952 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.063690901 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.063905954 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.063918114 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.150460958 CEST | 49672 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 12, 2024 00:55:07.718415022 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.718719006 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.718746901 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.719624996 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.719697952 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.720676899 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.720735073 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.720948935 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:07.720957994 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:07.761023045 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:08.034542084 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:08.034729958 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:08.034781933 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:08.034960032 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:08.034980059 CEST | 443 | 49712 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:08.034986973 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:08.035043955 CEST | 49712 | 443 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:08.222664118 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.222704887 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.222771883 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.223036051 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.223047972 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.515563011 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:08.515594006 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:08.515645027 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:08.515880108 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:08.515891075 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:08.794682980 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.794946909 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.794958115 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.796034098 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.796106100 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.797240973 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.797302008 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.797508955 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.797516108 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.813407898 CEST | 443 | 49704 | 23.206.229.226 | 192.168.2.8 |
Oct 12, 2024 00:55:08.813673019 CEST | 49704 | 443 | 192.168.2.8 | 23.206.229.226 |
Oct 12, 2024 00:55:08.836960077 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.900959969 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.901027918 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:08.901271105 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.901627064 CEST | 49715 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:08.901638985 CEST | 443 | 49715 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:09.854379892 CEST | 49710 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:10.054035902 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.054090977 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.054157972 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.054590940 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.054608107 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.068110943 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:10.068530083 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:10.068546057 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:10.075182915 CEST | 80 | 49710 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:10.076646090 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:10.076683044 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:10.076780081 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:10.079497099 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:10.079508066 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:10.079691887 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:10.079765081 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:10.081521988 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:10.081590891 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:10.131541967 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:10.131551027 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:10.173861027 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:10.238778114 CEST | 80 | 49710 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:10.246254921 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.246290922 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.246365070 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.246592999 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.246603966 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.281944990 CEST | 49710 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:10.653826952 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.654095888 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.654120922 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.655545950 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.655611992 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.656721115 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.656852961 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.656961918 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.656969070 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.712272882 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.781785011 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:10.781892061 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:10.784348965 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:10.784382105 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:10.784799099 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:10.822494030 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.822726965 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.822755098 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.823851109 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.823915958 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.824346066 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.824407101 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.825927019 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:10.867407084 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:10.867995024 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:10.868004084 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:10.914712906 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:11.108815908 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:11.108896017 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:11.108967066 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:11.109124899 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:11.109144926 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:11.109160900 CEST | 49718 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:11.109167099 CEST | 443 | 49718 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:11.143201113 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:11.143232107 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:11.143305063 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:11.143631935 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:11.143645048 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164335012 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164361954 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164369106 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164386988 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164395094 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164397955 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164437056 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.164472103 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.164494991 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.164525986 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.173135042 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.173155069 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.173228025 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.173234940 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.181669950 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.181695938 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.181792974 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.181812048 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.185164928 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.185182095 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.185265064 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.185277939 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.185348988 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.188236952 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.188260078 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.188402891 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.188402891 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.188410997 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.191164017 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.191180944 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.191282988 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.191291094 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.191334963 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.193113089 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.193137884 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.193269014 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.193269014 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.193278074 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.194677114 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.194695950 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.194863081 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.194871902 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.195864916 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.196130991 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.207951069 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.227274895 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:12.227329969 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:12.227492094 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:12.229765892 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:12.229800940 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:12.229887009 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:12.230567932 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:12.230578899 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:12.232166052 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:12.232182026 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:12.233225107 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.234291077 CEST | 49717 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.234325886 CEST | 443 | 49717 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.279398918 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340156078 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340184927 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340193033 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340219021 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340231895 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340240002 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340267897 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.340354919 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.340354919 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.340354919 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.341989040 CEST | 49719 | 443 | 192.168.2.8 | 3.234.189.133 |
Oct 12, 2024 00:55:12.342010021 CEST | 443 | 49719 | 3.234.189.133 | 192.168.2.8 |
Oct 12, 2024 00:55:12.854016066 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:12.854131937 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:12.855469942 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:12.855490923 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:12.855731964 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:12.856934071 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:12.899442911 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:12.950784922 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:12.951312065 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:12.951325893 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:12.952439070 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:12.952542067 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:12.957520962 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:12.957623005 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:12.969254017 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:12.969496012 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:12.969513893 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:12.970474958 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:12.970549107 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:12.971381903 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:12.971460104 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:13.006792068 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:13.006803989 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:13.022393942 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:13.022413015 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:13.053634882 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:13.069252014 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:13.185307026 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:13.185384989 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:13.185446978 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:13.186152935 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:13.186186075 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:13.186187029 CEST | 49720 | 443 | 192.168.2.8 | 184.28.90.27 |
Oct 12, 2024 00:55:13.186196089 CEST | 443 | 49720 | 184.28.90.27 | 192.168.2.8 |
Oct 12, 2024 00:55:13.438703060 CEST | 80 | 49711 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:13.442646980 CEST | 49711 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:13.558422089 CEST | 49711 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:13.563329935 CEST | 80 | 49711 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:16.048222065 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:16.048253059 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:16.048343897 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:16.049375057 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:16.049385071 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:16.212223053 CEST | 80 | 49710 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:16.212308884 CEST | 49710 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:16.708920002 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:16.709005117 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:16.715442896 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:16.715454102 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:16.715706110 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:16.756124973 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:17.423163891 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:17.467405081 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.544239044 CEST | 49710 | 80 | 192.168.2.8 | 149.126.4.35 |
Oct 12, 2024 00:55:17.549191952 CEST | 80 | 49710 | 149.126.4.35 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640047073 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640075922 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640083075 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640100956 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640137911 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640162945 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:17.640176058 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640213013 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:17.640234947 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:17.640522003 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640592098 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:17.640599966 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.640891075 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:17.641216040 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:18.159786940 CEST | 49723 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:18.159795046 CEST | 443 | 49723 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:19.083230019 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:19.083286047 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:19.083492041 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:19.539334059 CEST | 49716 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:55:19.539347887 CEST | 443 | 49716 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:55:42.769412994 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:42.769499063 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:42.769620895 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:42.784580946 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:42.784667969 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:42.784722090 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:42.970655918 CEST | 49722 | 443 | 192.168.2.8 | 18.66.102.33 |
Oct 12, 2024 00:55:42.970700026 CEST | 443 | 49722 | 18.66.102.33 | 192.168.2.8 |
Oct 12, 2024 00:55:42.970733881 CEST | 49721 | 443 | 192.168.2.8 | 108.138.26.35 |
Oct 12, 2024 00:55:42.970755100 CEST | 443 | 49721 | 108.138.26.35 | 192.168.2.8 |
Oct 12, 2024 00:55:54.672158957 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:54.672214031 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:54.672276020 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:54.672617912 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:54.672631979 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.330985069 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.331057072 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.333971977 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.333983898 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.335144997 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.339065075 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.383404970 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.581518888 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.581547022 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.581562996 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.581609011 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.581629992 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.581651926 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.581679106 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.582422972 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.582463980 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.582494974 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.582500935 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.582510948 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.583070993 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.583134890 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.584439993 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.584451914 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:55:56.584490061 CEST | 49728 | 443 | 192.168.2.8 | 20.109.210.53 |
Oct 12, 2024 00:55:56.584496021 CEST | 443 | 49728 | 20.109.210.53 | 192.168.2.8 |
Oct 12, 2024 00:56:08.570056915 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:08.570101023 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:08.570157051 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:08.570579052 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:08.570594072 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:09.201657057 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:09.201992035 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:09.202017069 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:09.202474117 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:09.202794075 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:09.202867031 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:09.256006002 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:19.105348110 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:19.105434895 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:19.105493069 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:19.889348030 CEST | 49730 | 443 | 192.168.2.8 | 142.250.185.132 |
Oct 12, 2024 00:56:19.889369965 CEST | 443 | 49730 | 142.250.185.132 | 192.168.2.8 |
Oct 12, 2024 00:56:22.538409948 CEST | 443 | 49703 | 13.107.246.60 | 192.168.2.8 |
Oct 12, 2024 00:56:22.538466930 CEST | 443 | 49703 | 13.107.246.60 | 192.168.2.8 |
Oct 12, 2024 00:56:22.538530111 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.60 |
Oct 12, 2024 00:56:22.539216995 CEST | 49703 | 443 | 192.168.2.8 | 13.107.246.60 |
Oct 12, 2024 00:56:22.544039011 CEST | 443 | 49703 | 13.107.246.60 | 192.168.2.8 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 00:55:05.309674978 CEST | 53 | 51199 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:05.324270010 CEST | 53 | 63894 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:06.254646063 CEST | 53 | 60356 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:06.840135098 CEST | 58198 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:06.840135098 CEST | 55554 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:06.870003939 CEST | 53 | 58198 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:06.879692078 CEST | 53 | 55554 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:06.939616919 CEST | 61682 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:06.939670086 CEST | 57550 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:06.961047888 CEST | 53 | 61682 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:06.961066008 CEST | 53 | 57550 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:08.038721085 CEST | 60826 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:08.039284945 CEST | 51658 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:08.140486956 CEST | 53 | 51658 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:08.222007036 CEST | 53 | 60826 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:08.507787943 CEST | 56814 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:08.508008003 CEST | 58134 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:08.514342070 CEST | 53 | 56814 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:08.514611959 CEST | 53 | 58134 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:08.903680086 CEST | 52673 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:08.903841972 CEST | 56786 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:09.915406942 CEST | 56564 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:09.916002035 CEST | 59626 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:10.052947998 CEST | 53 | 56786 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:10.052968979 CEST | 53 | 52673 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:10.239109039 CEST | 53 | 56564 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:10.268629074 CEST | 53 | 59626 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:12.204787016 CEST | 60885 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:12.205058098 CEST | 56737 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:12.205681086 CEST | 63473 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:12.206116915 CEST | 63155 | 53 | 192.168.2.8 | 1.1.1.1 |
Oct 12, 2024 00:55:12.214292049 CEST | 53 | 63155 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:12.215476990 CEST | 53 | 63473 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:12.215734005 CEST | 53 | 60885 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:12.224349022 CEST | 53 | 56737 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:23.874344110 CEST | 53 | 57718 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:43.177026033 CEST | 53 | 57877 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:55:43.972980022 CEST | 138 | 138 | 192.168.2.8 | 192.168.2.255 |
Oct 12, 2024 00:56:04.766865969 CEST | 53 | 55436 | 1.1.1.1 | 192.168.2.8 |
Oct 12, 2024 00:56:06.920640945 CEST | 53 | 58182 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Oct 12, 2024 00:55:10.239170074 CEST | 192.168.2.8 | 1.1.1.1 | c208 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 12, 2024 00:55:06.840135098 CEST | 192.168.2.8 | 1.1.1.1 | 0x8414 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:06.840135098 CEST | 192.168.2.8 | 1.1.1.1 | 0x8b9b | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:06.939616919 CEST | 192.168.2.8 | 1.1.1.1 | 0x6f15 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:06.939670086 CEST | 192.168.2.8 | 1.1.1.1 | 0x515c | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:08.038721085 CEST | 192.168.2.8 | 1.1.1.1 | 0x7726 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:08.039284945 CEST | 192.168.2.8 | 1.1.1.1 | 0xf8de | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:08.507787943 CEST | 192.168.2.8 | 1.1.1.1 | 0xd42c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:08.508008003 CEST | 192.168.2.8 | 1.1.1.1 | 0xf61b | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:08.903680086 CEST | 192.168.2.8 | 1.1.1.1 | 0x30f8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:08.903841972 CEST | 192.168.2.8 | 1.1.1.1 | 0xd1d4 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:09.915406942 CEST | 192.168.2.8 | 1.1.1.1 | 0x5225 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:09.916002035 CEST | 192.168.2.8 | 1.1.1.1 | 0x550c | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:12.204787016 CEST | 192.168.2.8 | 1.1.1.1 | 0xa6bf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:12.205058098 CEST | 192.168.2.8 | 1.1.1.1 | 0x8670 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 12, 2024 00:55:12.205681086 CEST | 192.168.2.8 | 1.1.1.1 | 0xb9ee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 00:55:12.206116915 CEST | 192.168.2.8 | 1.1.1.1 | 0x35fa | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 12, 2024 00:55:06.870003939 CEST | 1.1.1.1 | 192.168.2.8 | 0x8414 | No error (0) | klinch.ch | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:06.870003939 CEST | 1.1.1.1 | 192.168.2.8 | 0x8414 | No error (0) | 149.126.4.35 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:06.879692078 CEST | 1.1.1.1 | 192.168.2.8 | 0x8b9b | No error (0) | klinch.ch | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:06.961047888 CEST | 1.1.1.1 | 192.168.2.8 | 0x6f15 | No error (0) | klinch.ch | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:06.961047888 CEST | 1.1.1.1 | 192.168.2.8 | 0x6f15 | No error (0) | 149.126.4.35 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:06.961066008 CEST | 1.1.1.1 | 192.168.2.8 | 0x515c | No error (0) | klinch.ch | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:08.222007036 CEST | 1.1.1.1 | 192.168.2.8 | 0x7726 | No error (0) | 3.234.189.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:08.222007036 CEST | 1.1.1.1 | 192.168.2.8 | 0x7726 | No error (0) | 3.215.100.79 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:08.514342070 CEST | 1.1.1.1 | 192.168.2.8 | 0xd42c | No error (0) | 142.250.185.132 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:08.514611959 CEST | 1.1.1.1 | 192.168.2.8 | 0xf61b | No error (0) | 65 | IN (0x0001) | false | |||
Oct 12, 2024 00:55:10.052968979 CEST | 1.1.1.1 | 192.168.2.8 | 0x30f8 | No error (0) | 3.234.189.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:10.052968979 CEST | 1.1.1.1 | 192.168.2.8 | 0x30f8 | No error (0) | 3.215.100.79 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:10.239109039 CEST | 1.1.1.1 | 192.168.2.8 | 0x5225 | No error (0) | 3.234.189.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:10.239109039 CEST | 1.1.1.1 | 192.168.2.8 | 0x5225 | No error (0) | 3.215.100.79 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.214292049 CEST | 1.1.1.1 | 192.168.2.8 | 0x35fa | No error (0) | d3q7swlkq70mfj.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215476990 CEST | 1.1.1.1 | 192.168.2.8 | 0xb9ee | No error (0) | d3q7swlkq70mfj.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215476990 CEST | 1.1.1.1 | 192.168.2.8 | 0xb9ee | No error (0) | 18.66.102.33 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215476990 CEST | 1.1.1.1 | 192.168.2.8 | 0xb9ee | No error (0) | 18.66.102.87 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215476990 CEST | 1.1.1.1 | 192.168.2.8 | 0xb9ee | No error (0) | 18.66.102.32 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215476990 CEST | 1.1.1.1 | 192.168.2.8 | 0xb9ee | No error (0) | 18.66.102.78 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215734005 CEST | 1.1.1.1 | 192.168.2.8 | 0xa6bf | No error (0) | d3fqahajli23b9.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215734005 CEST | 1.1.1.1 | 192.168.2.8 | 0xa6bf | No error (0) | 108.138.26.35 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215734005 CEST | 1.1.1.1 | 192.168.2.8 | 0xa6bf | No error (0) | 108.138.26.24 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215734005 CEST | 1.1.1.1 | 192.168.2.8 | 0xa6bf | No error (0) | 108.138.26.119 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.215734005 CEST | 1.1.1.1 | 192.168.2.8 | 0xa6bf | No error (0) | 108.138.26.115 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:12.224349022 CEST | 1.1.1.1 | 192.168.2.8 | 0x8670 | No error (0) | d3fqahajli23b9.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:16.919173956 CEST | 1.1.1.1 | 192.168.2.8 | 0x9325 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:16.919173956 CEST | 1.1.1.1 | 192.168.2.8 | 0x9325 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:18.496318102 CEST | 1.1.1.1 | 192.168.2.8 | 0x8d24 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:18.496318102 CEST | 1.1.1.1 | 192.168.2.8 | 0x8d24 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:38.732625008 CEST | 1.1.1.1 | 192.168.2.8 | 0x676c | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:38.732625008 CEST | 1.1.1.1 | 192.168.2.8 | 0x676c | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:58.523067951 CEST | 1.1.1.1 | 192.168.2.8 | 0xc6db | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:55:58.523067951 CEST | 1.1.1.1 | 192.168.2.8 | 0xc6db | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 00:56:17.841681957 CEST | 1.1.1.1 | 192.168.2.8 | 0x1688 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 12, 2024 00:56:17.841681957 CEST | 1.1.1.1 | 192.168.2.8 | 0x1688 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49710 | 149.126.4.35 | 80 | 3964 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 00:55:09.854379892 CEST | 436 | OUT | |
Oct 12, 2024 00:55:10.238778114 CEST | 922 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49712 | 149.126.4.35 | 443 | 3964 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:07 UTC | 664 | OUT | |
2024-10-11 22:55:08 UTC | 395 | IN | |
2024-10-11 22:55:08 UTC | 707 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49715 | 3.234.189.133 | 443 | 3964 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:08 UTC | 668 | OUT | |
2024-10-11 22:55:08 UTC | 384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49717 | 3.234.189.133 | 443 | 3964 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:10 UTC | 664 | OUT | |
2024-10-11 22:55:12 UTC | 356 | IN | |
2024-10-11 22:55:12 UTC | 16028 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN | |
2024-10-11 22:55:12 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49718 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:10 UTC | 161 | OUT | |
2024-10-11 22:55:11 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49719 | 3.234.189.133 | 443 | 3964 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:12 UTC | 568 | OUT | |
2024-10-11 22:55:12 UTC | 451 | IN | |
2024-10-11 22:55:12 UTC | 14064 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49720 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:12 UTC | 239 | OUT | |
2024-10-11 22:55:13 UTC | 514 | IN | |
2024-10-11 22:55:13 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.8 | 49723 | 20.109.210.53 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:17 UTC | 306 | OUT | |
2024-10-11 22:55:17 UTC | 560 | IN | |
2024-10-11 22:55:17 UTC | 15824 | IN | |
2024-10-11 22:55:17 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.8 | 49728 | 20.109.210.53 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-11 22:55:56 UTC | 306 | OUT | |
2024-10-11 22:55:56 UTC | 560 | IN | |
2024-10-11 22:55:56 UTC | 15824 | IN | |
2024-10-11 22:55:56 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 18:54:57 |
Start date: | 11/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 18:55:02 |
Start date: | 11/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 18:55:05 |
Start date: | 11/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff678760000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |