Windows
Analysis Report
https://www.flysascomonlineclaimer.mywire.org/WELCOME/
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6840 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7028 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2212 --fi eld-trial- handle=194 4,i,140118 8024050709 3823,14102 7418566082 83169,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6524 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://www.f lysascomon lineclaime r.mywire.o rg/WELCOME /" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
google.com | 142.250.184.206 | true | false | unknown | |
www.google.com | 142.250.186.100 | true | false | unknown | |
www.flysascomonlineclaimer.mywire.org | unknown | unknown | false | unknown | |
wwwflysascomonlineclaimer.mywire.org | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.186.100 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1543678 |
Start date and time: | 2024-10-28 08:59:51 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 19s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://www.flysascomonlineclaimer.mywire.org/WELCOME/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@25/8@34/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.186.46, 74.125.71.84, 34.104.35.123, 199.232.210.172, 172.217.18.3, 172.217.16.142
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://www.flysascomonlineclaimer.mywire.org/WELCOME/
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9825823650942422 |
Encrypted: | false |
SSDEEP: | 48:8TOr0dbQT706b8HMTidAKZdA1FehwiZUklqehHMy+3:8yyQXjbJmMy |
MD5: | 3D9ED6BB0FC0EDD004F78D6307FBD4CD |
SHA1: | ADDDE882DA6A9991450AE248824AC43B80D88DB7 |
SHA-256: | 66BD2951558A204BDB6F0FF6D57FC27DF8BC2BF43A36C3880EBCD6F3C2D894E8 |
SHA-512: | 12CF5663118036669E55DC9F69B96E269CE11073F588962A1BE2AC3C77288D73F9EAB2C97B1F07B82A9FF966596A017D2CFE08AEAF525D61BB1182EFE3440087 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9986278669823676 |
Encrypted: | false |
SSDEEP: | 48:8Mi0dbQT706b8HMTidAKZdA1seh/iZUkAQkqehWMy+2:8SQXjb/9QBMy |
MD5: | 1FAA3A4105CCEDE9D787783D23AFF2C4 |
SHA1: | E28B4A74E6207EB7F16956180B500852502767CC |
SHA-256: | A59207020DA00FB5A3AF289FA06C1AFAF52B471CD7EBB1FC28CD53C0D666C20A |
SHA-512: | A24A50D27B3AB8B8E303BB000E5F6A4513585215CDBE9751D1C01DFC733B870A39551DF038C9B9948D443099F045270D2CD039BAD7182417828976516AC48A91 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.0071551438089905 |
Encrypted: | false |
SSDEEP: | 48:860dbQT706bAHMTidAKZdA14meh7sFiZUkmgqeh7sgMy+BX:89QXjb/nqMy |
MD5: | 41EB99561DCE4E4B0B7E83E7514DD758 |
SHA1: | FF3442357BEC8FDA780D5D4008EB69254BE20149 |
SHA-256: | 8BFB3D998DE2FAB5E0696038EBE50DA8E7E4EA51D836FF491757AB1B77B224C8 |
SHA-512: | 56F0761290EAD411E18DC5707F54FA6FBA827B31AAE7B09C448DFB1338CF37A8C87580CE2053D4FEA152711C627C77836A732CB4525DE1E62C4D42628CC6B4AC |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9970984852711964 |
Encrypted: | false |
SSDEEP: | 48:8P0dbQT706b8HMTidAKZdA1TehDiZUkwqehyMy+R:8+QXjbMIMy |
MD5: | 6CB1BB5DCEE5DCF6818FDEBC57865F2E |
SHA1: | 17EF519AC558C55524612E2E58087DED10A5EA34 |
SHA-256: | CD02B94D7FCEA95032E2EFDEBD0A610A66E5D9F90162DB42ADEA6FD4535FD1FD |
SHA-512: | 0A0180DF70A9D157AA96EA6F1B34D2E6C0FCEBD39D67FA627D4B221000B96BF61C74B5AAB78F2308636D0273669062BA066A5AE992CD217B6ED5EDA00D6A2D9D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.984273763410692 |
Encrypted: | false |
SSDEEP: | 48:8gr0dbQT706b8HMTidAKZdA1dehBiZUk1W1qeh0My+C:8gyQXjbc9UMy |
MD5: | 7988F48CB158921CCE023F00A7B6CB3F |
SHA1: | E1A528B820DE200026C60A010B8F1DB974ED67AB |
SHA-256: | C650E7CA766D392B35EF8417D3D287EB614DE7AF694EA28FC1D0E3468469E3B8 |
SHA-512: | 28F9739D135951E5534F9A355219B150663471D4341635894E4654E4641DCEE0C3D6B418CFC4B633BA4FCA59CA7CF2E77196637753A51A26197C0EB96C4A0D73 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9918047154628624 |
Encrypted: | false |
SSDEEP: | 48:820dbQT706b8HMTidAKZdA1duTeehOuTbbiZUk5OjqehOuTbqMy+yT+:8xQXjbuTfTbxWOvTbqMy7T |
MD5: | D44854B3D01FE77A96241A902C684BF9 |
SHA1: | 7AF9E4AB0C39A68A48822B9A58992B803A26C946 |
SHA-256: | DFFAD7F326186E9B6FFDE5433CCEC74AC3DB9386C1BFCE018FBCEB35A5004E3E |
SHA-512: | 2AB6FF3363B562ACE8F981AFE62888F768D1A29F62AB3CB1D1402A6FC9F8AFC235AF2AF8798FCFF70409BE215B602E770406A9394547CE7B9DDB498C0889AA2E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 799 |
Entropy (8bit): | 5.128164791379477 |
Encrypted: | false |
SSDEEP: | 24:j4ZjwLdWGgCJBHslgT9lCuABurz7HHHHHHHYqmffffffo:EqLyCJKlgZ01Bu/Eqmffffffo |
MD5: | 272541DCD74719BEC5DDFAD2254EDD02 |
SHA1: | EA17DB2ADBD5A5AC35E6AE42444801B804549E67 |
SHA-256: | B523963848432C0BE5D7169FDDA7BFA12CC48FD3519CD6D4E2C8990727545E95 |
SHA-512: | 42FB3EAC5B142C5095829170221539B296FAC2FBCCED6D6165D601C4FCE340C809CC33E9161F639835E794BDC12BF32C86528D8A754B70AAAF1F6036033BBC1A |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 28, 2024 09:00:21.539361000 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:21.846633911 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:22.451643944 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:23.666639090 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:25.457330942 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:26.075648069 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:26.324767113 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:26.324836969 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:26.324942112 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:26.325186014 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:26.325213909 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.218184948 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.218524933 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.218592882 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.220099926 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.220216036 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.221241951 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.221335888 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.273696899 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.273720026 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.321670055 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.627216101 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.671360016 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.832061052 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:27.832112074 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:27.832207918 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:27.834265947 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:27.834284067 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:27.918224096 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.975662947 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.975699902 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.976809025 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:27.976865053 CET | 443 | 49705 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:00:27.976953030 CET | 49705 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:00:29.185555935 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:29.185683012 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:29.190321922 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:29.190332890 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:29.190728903 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:29.228686094 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:29.275343895 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:29.689196110 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:29.992674112 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:30.598656893 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:30.700706959 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:30.700932980 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:30.700963974 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:30.700978041 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:30.701108932 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:30.701138973 CET | 443 | 49706 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:30.701185942 CET | 49706 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:30.730659008 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:30.730725050 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:30.730806112 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:30.731097937 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:30.731116056 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:30.883660078 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:31.574726105 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.574816942 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:31.576539993 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:31.576554060 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.577157021 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.578578949 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:31.619348049 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.806673050 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:31.824188948 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.824273109 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.824438095 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:31.825277090 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:31.825303078 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:31.825315952 CET | 49707 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 28, 2024 09:00:31.825323105 CET | 443 | 49707 | 184.28.90.27 | 192.168.2.16 |
Oct 28, 2024 09:00:34.158929110 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:34.207973957 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:34.318789959 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:34.318818092 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:34.318939924 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:34.319994926 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:34.320004940 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:34.460686922 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:35.066732883 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:35.149313927 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.149405003 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.152414083 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.152420044 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.152679920 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.193686962 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.204425097 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.247375965 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475649118 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475672960 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475682020 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475691080 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475718021 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475771904 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.475781918 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.475847006 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.475915909 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.475966930 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.476042032 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.476048946 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.476716995 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.476774931 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.487770081 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.487783909 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:35.487824917 CET | 49708 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:00:35.487831116 CET | 443 | 49708 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:00:36.270703077 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:38.682674885 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:39.017359972 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:40.498688936 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 28, 2024 09:00:43.482726097 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:00:48.624718904 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 28, 2024 09:00:53.093805075 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 28, 2024 09:01:11.920968056 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:11.921005011 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:11.921201944 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:11.921720028 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:11.921729088 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.729036093 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.729168892 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:12.730428934 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:12.730463028 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.730967999 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.732598066 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:12.775372982 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.996762037 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.996892929 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.996953011 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.997014999 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:12.997081041 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:12.997123957 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:12.997147083 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:13.114064932 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:13.114137888 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:13.114217997 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:13.114280939 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:13.114315033 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:13.114327908 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:13.114373922 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:13.114434004 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:13.114487886 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:13.114522934 CET | 49709 | 443 | 192.168.2.16 | 20.109.210.53 |
Oct 28, 2024 09:01:13.114537954 CET | 443 | 49709 | 20.109.210.53 | 192.168.2.16 |
Oct 28, 2024 09:01:26.377511024 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:26.377595901 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:26.377687931 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:26.377958059 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:26.377993107 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:27.228471994 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:27.228781939 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:27.228843927 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:27.229882002 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:27.229962111 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:27.230238914 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:27.230308056 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:27.270889997 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:27.270947933 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:27.318811893 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:37.221177101 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:37.221270084 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:01:37.221349955 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:37.749581099 CET | 49711 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:01:37.749645948 CET | 443 | 49711 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:02:26.453262091 CET | 49713 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:02:26.453306913 CET | 443 | 49713 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:02:26.453406096 CET | 49713 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:02:26.453742027 CET | 49713 | 443 | 192.168.2.16 | 142.250.186.100 |
Oct 28, 2024 09:02:26.453758001 CET | 443 | 49713 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:02:27.302598000 CET | 443 | 49713 | 142.250.186.100 | 192.168.2.16 |
Oct 28, 2024 09:02:27.345944881 CET | 49713 | 443 | 192.168.2.16 | 142.250.186.100 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 28, 2024 09:00:21.530689001 CET | 53 | 53663 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:21.564311028 CET | 53 | 64943 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:22.421080112 CET | 58674 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:22.421206951 CET | 56751 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:22.713740110 CET | 53 | 58674 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:22.723339081 CET | 53 | 56751 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:22.724059105 CET | 55684 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:22.794645071 CET | 53 | 57075 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:22.920423985 CET | 53 | 55684 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:22.942981005 CET | 53201 | 53 | 192.168.2.16 | 8.8.8.8 |
Oct 28, 2024 09:00:22.943484068 CET | 49771 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:22.951565981 CET | 53 | 49771 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:23.948965073 CET | 60804 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:23.949227095 CET | 50660 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:23.955934048 CET | 63706 | 53 | 192.168.2.16 | 8.8.4.4 |
Oct 28, 2024 09:00:24.016283035 CET | 53 | 63706 | 8.8.4.4 | 192.168.2.16 |
Oct 28, 2024 09:00:24.197120905 CET | 53 | 50660 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:24.291615963 CET | 53 | 60804 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:26.316431999 CET | 52007 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:26.316579103 CET | 56991 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:26.323642969 CET | 53 | 52007 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:26.324116945 CET | 53 | 56991 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:27.285707951 CET | 53 | 53201 | 8.8.8.8 | 192.168.2.16 |
Oct 28, 2024 09:00:29.311135054 CET | 50756 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:29.311330080 CET | 54619 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:30.328015089 CET | 64359 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:30.328208923 CET | 54147 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:30.638189077 CET | 53 | 50756 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:30.695547104 CET | 49808 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:30.710042953 CET | 53 | 54619 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:30.729664087 CET | 53 | 64359 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:30.741203070 CET | 53 | 54147 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:30.885473967 CET | 53 | 49808 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:39.836074114 CET | 53 | 51907 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:42.495981932 CET | 50438 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:42.496223927 CET | 58971 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:42.658885002 CET | 53 | 50438 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:42.702560902 CET | 63584 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:42.711282969 CET | 53 | 58971 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:42.824265957 CET | 53 | 63584 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:42.835661888 CET | 61231 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:42.836324930 CET | 55657 | 53 | 192.168.2.16 | 8.8.4.4 |
Oct 28, 2024 09:00:42.843044996 CET | 53 | 61231 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:42.844309092 CET | 53 | 55657 | 8.8.4.4 | 192.168.2.16 |
Oct 28, 2024 09:00:43.843516111 CET | 57980 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:43.843782902 CET | 49571 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:43.851130962 CET | 53 | 57980 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:43.990318060 CET | 53 | 49571 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:48.887280941 CET | 63669 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:48.887454033 CET | 63089 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:49.008980989 CET | 53 | 63669 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:49.034132004 CET | 53 | 63089 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:49.034908056 CET | 62781 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:00:49.136464119 CET | 53 | 62781 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:00:58.719397068 CET | 53 | 55495 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:13.799653053 CET | 54804 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:01:13.947074890 CET | 53 | 54804 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:19.151273966 CET | 54344 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:01:19.151432991 CET | 64597 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:01:19.274029970 CET | 53 | 54344 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:19.303524017 CET | 52843 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:01:19.558324099 CET | 53 | 64597 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:19.558363914 CET | 53 | 52843 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:21.727267027 CET | 53 | 57379 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:21.756120920 CET | 53 | 56994 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:25.872262955 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Oct 28, 2024 09:01:35.131412029 CET | 61119 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:01:35.278776884 CET | 53 | 61119 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:01:50.506102085 CET | 53 | 61006 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:02:05.584486008 CET | 61328 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:02:05.731600046 CET | 53 | 61328 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:02:19.582314014 CET | 64414 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:02:19.582429886 CET | 53149 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:02:19.685486078 CET | 53 | 53149 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:02:19.729954958 CET | 53 | 64414 | 1.1.1.1 | 192.168.2.16 |
Oct 28, 2024 09:02:19.730818033 CET | 59572 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 28, 2024 09:02:19.739615917 CET | 53 | 59572 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Oct 28, 2024 09:00:27.285794973 CET | 192.168.2.16 | 8.8.8.8 | d00a | (Port unreachable) | Destination Unreachable |
Oct 28, 2024 09:00:30.710140944 CET | 192.168.2.16 | 1.1.1.1 | c245 | (Port unreachable) | Destination Unreachable |
Oct 28, 2024 09:00:42.711389065 CET | 192.168.2.16 | 1.1.1.1 | c244 | (Port unreachable) | Destination Unreachable |
Oct 28, 2024 09:00:43.990437031 CET | 192.168.2.16 | 1.1.1.1 | c244 | (Port unreachable) | Destination Unreachable |
Oct 28, 2024 09:01:19.558528900 CET | 192.168.2.16 | 1.1.1.1 | c244 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 28, 2024 09:00:22.421080112 CET | 192.168.2.16 | 1.1.1.1 | 0xea5f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.421206951 CET | 192.168.2.16 | 1.1.1.1 | 0xcf4c | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.724059105 CET | 192.168.2.16 | 1.1.1.1 | 0x8f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.942981005 CET | 192.168.2.16 | 8.8.8.8 | 0xb55d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.943484068 CET | 192.168.2.16 | 1.1.1.1 | 0x7a9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:23.948965073 CET | 192.168.2.16 | 1.1.1.1 | 0x5b9a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:23.949227095 CET | 192.168.2.16 | 1.1.1.1 | 0xc104 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:23.955934048 CET | 192.168.2.16 | 8.8.4.4 | 0xafae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:26.316431999 CET | 192.168.2.16 | 1.1.1.1 | 0x954c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:26.316579103 CET | 192.168.2.16 | 1.1.1.1 | 0x1ef1 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:29.311135054 CET | 192.168.2.16 | 1.1.1.1 | 0xca4f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:29.311330080 CET | 192.168.2.16 | 1.1.1.1 | 0xe2e7 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.328015089 CET | 192.168.2.16 | 1.1.1.1 | 0x9cc4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.328208923 CET | 192.168.2.16 | 1.1.1.1 | 0x9b1 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.695547104 CET | 192.168.2.16 | 1.1.1.1 | 0xe6c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.495981932 CET | 192.168.2.16 | 1.1.1.1 | 0x2665 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.496223927 CET | 192.168.2.16 | 1.1.1.1 | 0xdb0 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.702560902 CET | 192.168.2.16 | 1.1.1.1 | 0x502b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.835661888 CET | 192.168.2.16 | 1.1.1.1 | 0x1974 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.836324930 CET | 192.168.2.16 | 8.8.4.4 | 0xa589 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:43.843516111 CET | 192.168.2.16 | 1.1.1.1 | 0xf0bb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:43.843782902 CET | 192.168.2.16 | 1.1.1.1 | 0x3824 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:48.887280941 CET | 192.168.2.16 | 1.1.1.1 | 0xea9a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:48.887454033 CET | 192.168.2.16 | 1.1.1.1 | 0xc8af | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:49.034908056 CET | 192.168.2.16 | 1.1.1.1 | 0x8554 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:13.799653053 CET | 192.168.2.16 | 1.1.1.1 | 0xd623 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:19.151273966 CET | 192.168.2.16 | 1.1.1.1 | 0x78c2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:19.151432991 CET | 192.168.2.16 | 1.1.1.1 | 0x3681 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:01:19.303524017 CET | 192.168.2.16 | 1.1.1.1 | 0x7508 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:35.131412029 CET | 192.168.2.16 | 1.1.1.1 | 0xc892 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:02:05.584486008 CET | 192.168.2.16 | 1.1.1.1 | 0x5a0c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:02:19.582314014 CET | 192.168.2.16 | 1.1.1.1 | 0xf24 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:02:19.582429886 CET | 192.168.2.16 | 1.1.1.1 | 0x35b8 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:02:19.730818033 CET | 192.168.2.16 | 1.1.1.1 | 0xd204 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 28, 2024 09:00:22.713740110 CET | 1.1.1.1 | 192.168.2.16 | 0xea5f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.723339081 CET | 1.1.1.1 | 192.168.2.16 | 0xcf4c | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.920423985 CET | 1.1.1.1 | 192.168.2.16 | 0x8f4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:22.951565981 CET | 1.1.1.1 | 192.168.2.16 | 0x7a9f | No error (0) | 142.250.184.206 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 09:00:24.016283035 CET | 8.8.4.4 | 192.168.2.16 | 0xafae | No error (0) | 142.250.184.238 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 09:00:24.197120905 CET | 1.1.1.1 | 192.168.2.16 | 0xc104 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:24.291615963 CET | 1.1.1.1 | 192.168.2.16 | 0x5b9a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:26.323642969 CET | 1.1.1.1 | 192.168.2.16 | 0x954c | No error (0) | 142.250.186.100 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 09:00:26.324116945 CET | 1.1.1.1 | 192.168.2.16 | 0x1ef1 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 28, 2024 09:00:27.285707951 CET | 8.8.8.8 | 192.168.2.16 | 0xb55d | No error (0) | 142.250.186.78 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 09:00:30.638189077 CET | 1.1.1.1 | 192.168.2.16 | 0xca4f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.710042953 CET | 1.1.1.1 | 192.168.2.16 | 0xe2e7 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.729664087 CET | 1.1.1.1 | 192.168.2.16 | 0x9cc4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.741203070 CET | 1.1.1.1 | 192.168.2.16 | 0x9b1 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:30.885473967 CET | 1.1.1.1 | 192.168.2.16 | 0xe6c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.658885002 CET | 1.1.1.1 | 192.168.2.16 | 0x2665 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.711282969 CET | 1.1.1.1 | 192.168.2.16 | 0xdb0 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.824265957 CET | 1.1.1.1 | 192.168.2.16 | 0x502b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:42.843044996 CET | 1.1.1.1 | 192.168.2.16 | 0x1974 | No error (0) | 172.217.18.14 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 09:00:42.844309092 CET | 8.8.4.4 | 192.168.2.16 | 0xa589 | No error (0) | 142.250.184.238 | A (IP address) | IN (0x0001) | false | ||
Oct 28, 2024 09:00:43.851130962 CET | 1.1.1.1 | 192.168.2.16 | 0xf0bb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:43.990318060 CET | 1.1.1.1 | 192.168.2.16 | 0x3824 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:49.008980989 CET | 1.1.1.1 | 192.168.2.16 | 0xea9a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:00:49.034132004 CET | 1.1.1.1 | 192.168.2.16 | 0xc8af | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:00:49.136464119 CET | 1.1.1.1 | 192.168.2.16 | 0x8554 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:13.947074890 CET | 1.1.1.1 | 192.168.2.16 | 0xd623 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:19.274029970 CET | 1.1.1.1 | 192.168.2.16 | 0x78c2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:19.558324099 CET | 1.1.1.1 | 192.168.2.16 | 0x3681 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:01:19.558363914 CET | 1.1.1.1 | 192.168.2.16 | 0x7508 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:01:35.278776884 CET | 1.1.1.1 | 192.168.2.16 | 0xc892 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:02:05.731600046 CET | 1.1.1.1 | 192.168.2.16 | 0x5a0c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:02:19.685486078 CET | 1.1.1.1 | 192.168.2.16 | 0x35b8 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Oct 28, 2024 09:02:19.729954958 CET | 1.1.1.1 | 192.168.2.16 | 0xf24 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 28, 2024 09:02:19.739615917 CET | 1.1.1.1 | 192.168.2.16 | 0xd204 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49705 | 142.250.186.100 | 443 | 7028 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 08:00:27 UTC | 613 | OUT | |
2024-10-28 08:00:27 UTC | 1266 | IN | |
2024-10-28 08:00:27 UTC | 112 | IN | |
2024-10-28 08:00:27 UTC | 694 | IN | |
2024-10-28 08:00:27 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49706 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 08:00:29 UTC | 161 | OUT | |
2024-10-28 08:00:30 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49707 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 08:00:31 UTC | 239 | OUT | |
2024-10-28 08:00:31 UTC | 515 | IN | |
2024-10-28 08:00:31 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49708 | 20.109.210.53 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 08:00:35 UTC | 306 | OUT | |
2024-10-28 08:00:35 UTC | 560 | IN | |
2024-10-28 08:00:35 UTC | 15824 | IN | |
2024-10-28 08:00:35 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49709 | 20.109.210.53 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 08:01:12 UTC | 306 | OUT | |
2024-10-28 08:01:12 UTC | 560 | IN | |
2024-10-28 08:01:12 UTC | 15824 | IN | |
2024-10-28 08:01:13 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 04:00:19 |
Start date: | 28/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 04:00:20 |
Start date: | 28/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 04:00:21 |
Start date: | 28/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |