Windows
Analysis Report
http://oneamerica.ws
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 5556 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6780 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2152 --fi eld-trial- handle=192 8,i,976209 5352043587 412,148685 4254752582 8690,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6332 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://oneame rica.ws" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
oneamerica.ws | 104.37.175.156 | true | false | unknown | |
www.google.com | 142.250.185.164 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.37.175.156 | oneamerica.ws | United States | 396073 | MAJESTIC-HOSTING-01US | false |
IP |
---|
192.168.2.16 |
192.168.2.6 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1544491 |
Start date and time: | 2024-10-29 14:00:37 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 18s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://oneamerica.ws |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@17/10@4/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.186.142, 173.194.76.84, 34.104.35.123, 93.184.221.240, 172.217.16.195, 142.250.186.46
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: http://oneamerica.ws
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9823374871777126 |
Encrypted: | false |
SSDEEP: | 48:8YdBTpVoHEidAKZdA1FehwiZUklqehWy+3:8iPPJy |
MD5: | 729601A9AD4382BA67608A1709507B9B |
SHA1: | E94798F9F9766BB49DF110C9028480D126C6D11C |
SHA-256: | 1E75D2B794DD9702BC87D8878BCAAB43B4090E2F8EB618D61497C3E573B0C3C3 |
SHA-512: | D548A6222A798E62E1CB7BD89D92AF42D7BDD556DD4741D52520EB7E54FAC8DE8CA41C59DEE4AE558D7D7553758F55B9FAA120A7F081DD854BB017DDE897E8E2 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.9992310389940084 |
Encrypted: | false |
SSDEEP: | 48:8tdBTpVoHEidAKZdA1seh/iZUkAQkqeh5y+2:8hP59Q0y |
MD5: | 5AE4F0B02FBA23B022E333987BE52E06 |
SHA1: | 67DC0382CD052C18DB40FE83BBE7AA8BF2C480C3 |
SHA-256: | 1F10F6D89B92D241AFDE200265FA792880F3EDB952C8030C939EF559244D960D |
SHA-512: | B259E69C06892389B321865CEECD409DBA109970A1CE18F8FE21785C1FD9255E9315A7077BCE47000F6D4BF571745ED22F656EE1EB87C6FD903AC7A14EE5326A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.006403792373883 |
Encrypted: | false |
SSDEEP: | 48:8DdBTpVAHEidAKZdA14meh7sFiZUkmgqeh7s3y+BX:8HPNnNy |
MD5: | BEBA485475C4F6C6C08A530BF8795D89 |
SHA1: | 70F004CAB14D2278096C2BD0927289F1C61E44AA |
SHA-256: | 62EAC92381029C201A3D5829DDE60C75F86574497D46B8D59BA0E0696B59338F |
SHA-512: | FD24BCCE0715F623D2DD2AC7522F24A6FE41031333940590799689EC66E85719AF1304F599F46E35735FFF2093D8712409BE4A9BE66438983F4131F600641DE3 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9947487915256175 |
Encrypted: | false |
SSDEEP: | 48:8NdBTpVoHEidAKZdA1TehDiZUkwqehVy+R:8BPq/y |
MD5: | CFFBA84D6A97418067AAFADBC68796B8 |
SHA1: | F34AA2D675E16901A7AF370FDB3611D9D304F026 |
SHA-256: | D1FB439C215B189181A31C7B7BCA12CFD28BB57812DFD3402417B3698663C1E5 |
SHA-512: | 83CB5ACCED8F7336356D1F674B1361DF5939373EA85A233EF0B7B9F9F40008E72961B0A83DB6106942D52B22CAC080F5C8A8118BFEFA52242583B0ADFB1518AB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9855144037190056 |
Encrypted: | false |
SSDEEP: | 48:8HdBTpVoHEidAKZdA1dehBiZUk1W1qehry+C:87Pq9Ly |
MD5: | 2CF5A273096A8498E2D015DDF335027D |
SHA1: | 5C8C94668B0CD0FDA9C6A6E263423BFFF7C7D1AD |
SHA-256: | 43954389A8A178096342BF07C667DF5E6B04B9F694E7A93A1E7F1E6C7E90596C |
SHA-512: | F8767743030B530C0120A4499755443F9F31A5CA59D4C5AF00CDBF7A71C41B7CCF38B18C798A8A2BC655E63DE1543B8F1EB42C6E135096AF9D26805AB229E128 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9932604741989386 |
Encrypted: | false |
SSDEEP: | 48:8AdBTpVoHEidAKZdA1duTeehOuTbbiZUk5OjqehOuTbNy+yT+:8qPgTfTbxWOvTbNy7T |
MD5: | BCC2D2985D1F3AFA4F6A6764AD2760BD |
SHA1: | 6AAA03330DB44AA0EF4B7AD6D4179C71A88520BF |
SHA-256: | EFD8EF5B6AAE37C763E1680C16EB2D9484B4C0886C98052951256FD3F3EFBD65 |
SHA-512: | 64937F1672BF2384EE9CC7B04C112DAA2997F7FE14317B6704A82D6EF573521CFAF7FA66581BBF074B7F82985B91957B098B905F306C200D9808C9850C24C1EC |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 315 |
Entropy (8bit): | 5.0572271090563765 |
Encrypted: | false |
SSDEEP: | 6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR |
MD5: | A34AC19F4AFAE63ADC5D2F7BC970C07F |
SHA1: | A82190FC530C265AA40A045C21770D967F4767B8 |
SHA-256: | D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3 |
SHA-512: | 42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765 |
Malicious: | false |
Reputation: | low |
URL: | http://oneamerica.ws/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 10 |
Entropy (8bit): | 3.1219280948873624 |
Encrypted: | false |
SSDEEP: | 3:h2V:h4 |
MD5: | 0C5A1E92F0C9947556E036D125C7E1CD |
SHA1: | E16A2CA2AAD91694E7B62330C08C735C772D74C6 |
SHA-256: | 6881A4A575ED257C893AD0A870178D069B72F8713714C21F46317A187B919048 |
SHA-512: | A86FF07E52E2F40D532CBEA3350BA4FE155E4ED2AB6769D784EBDFC551B08E9DCBD9471A8067694593135ED3705227AE8E1D2CD5B5105FB9E2B6857DC525C30A |
Malicious: | false |
Reputation: | low |
URL: | http://oneamerica.ws/ |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 29, 2024 14:01:09.866996050 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:09.867496014 CET | 49701 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:09.872689962 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:09.872792006 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:09.872848034 CET | 80 | 49701 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:09.872905016 CET | 49701 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:09.872992039 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:09.878511906 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:10.008323908 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:10.311799049 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:10.484417915 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:10.531980038 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:10.559129953 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:10.564913034 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:10.689738989 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:10.737770081 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:10.912816048 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:12.126775980 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:13.265489101 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:13.540277958 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:13.540323973 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:13.540405035 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:13.540714025 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:13.540733099 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:14.420151949 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:14.420483112 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:14.420506001 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:14.421556950 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:14.421637058 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:14.422883987 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:14.423019886 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:14.473763943 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:14.473794937 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:14.521766901 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:14.537775993 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:15.696719885 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:15.696942091 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:16.275995970 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:16.276052952 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:16.276146889 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:16.278429031 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:16.278448105 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.002470016 CET | 49700 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:17.008040905 CET | 80 | 49700 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:17.133687973 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.133980989 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.142405033 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.142431021 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.142822027 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.186072111 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.231339931 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.431062937 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.431138039 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.431221962 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.431617022 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.431652069 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.431679010 CET | 49709 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.431685925 CET | 443 | 49709 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.513348103 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.513401031 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:17.513565063 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.513839960 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:17.513850927 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.167134047 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:18.362904072 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.363070965 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:18.364670992 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:18.364692926 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.365668058 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.367105007 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:18.407339096 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.469815016 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:18.616561890 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.616673946 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.616764069 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:18.617561102 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:18.617583990 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:18.617594957 CET | 49710 | 443 | 192.168.2.16 | 184.28.90.27 |
Oct 29, 2024 14:01:18.617602110 CET | 443 | 49710 | 184.28.90.27 | 192.168.2.16 |
Oct 29, 2024 14:01:19.071810007 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:19.341804028 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:19.748518944 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:19.748564959 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:19.748668909 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:19.749742985 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:19.749756098 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.277811050 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:20.613956928 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.614059925 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.617245913 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.617258072 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.617592096 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.659781933 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.682085991 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.723335028 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966037989 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966109037 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966129065 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966178894 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966233015 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966394901 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.966434956 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.966492891 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.967350960 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.967427015 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.967442989 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.967494011 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.986980915 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.987020016 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:20.987035990 CET | 49711 | 443 | 192.168.2.16 | 20.12.23.50 |
Oct 29, 2024 14:01:20.987045050 CET | 443 | 49711 | 20.12.23.50 | 192.168.2.16 |
Oct 29, 2024 14:01:22.640981913 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:22.688779116 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:22.943901062 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:23.549810886 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:24.422575951 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:24.422648907 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:24.422792912 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:24.761795044 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:25.005902052 CET | 49707 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:01:25.005940914 CET | 443 | 49707 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:01:27.171808958 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:27.490828991 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:28.954368114 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Oct 29, 2024 14:01:31.986841917 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:37.104887962 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Oct 29, 2024 14:01:41.587831974 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Oct 29, 2024 14:01:49.021097898 CET | 80 | 49701 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:49.021210909 CET | 49701 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:51.008795977 CET | 49701 | 80 | 192.168.2.16 | 104.37.175.156 |
Oct 29, 2024 14:01:51.014414072 CET | 80 | 49701 | 104.37.175.156 | 192.168.2.16 |
Oct 29, 2024 14:01:57.566169977 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:57.566265106 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:57.566410065 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:57.567425966 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:57.567444086 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.489224911 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.489376068 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.491266966 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.491300106 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.491739988 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.493535042 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.539344072 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.789820910 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.789851904 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.789870977 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.790186882 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.790263891 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.790370941 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.792608976 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.792670012 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.792685032 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.792706013 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.792728901 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.792738914 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.792793036 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.793526888 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.793566942 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:01:58.793596029 CET | 49712 | 443 | 192.168.2.16 | 52.149.20.212 |
Oct 29, 2024 14:01:58.793611050 CET | 443 | 49712 | 52.149.20.212 | 192.168.2.16 |
Oct 29, 2024 14:02:13.598222017 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:13.598274946 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:13.598368883 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:13.598650932 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:13.598675013 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:14.459069014 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:14.459428072 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:14.459461927 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:14.459810972 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:14.460115910 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:14.460186005 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:14.507920980 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:24.451236963 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:24.451307058 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Oct 29, 2024 14:02:24.451597929 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:25.008748055 CET | 49714 | 443 | 192.168.2.16 | 142.250.185.164 |
Oct 29, 2024 14:02:25.008758068 CET | 443 | 49714 | 142.250.185.164 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 29, 2024 14:01:08.854022026 CET | 53 | 50564 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:08.910015106 CET | 53 | 54224 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:09.579545021 CET | 57335 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 29, 2024 14:01:09.579921961 CET | 58014 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 29, 2024 14:01:09.838144064 CET | 53 | 58014 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:09.866131067 CET | 53 | 57335 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:10.298007011 CET | 53 | 58514 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:13.531857014 CET | 53700 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 29, 2024 14:01:13.532064915 CET | 61178 | 53 | 192.168.2.16 | 1.1.1.1 |
Oct 29, 2024 14:01:13.539252043 CET | 53 | 61178 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:13.539464951 CET | 53 | 53700 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:27.340677023 CET | 53 | 55728 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:01:46.289530039 CET | 53 | 54576 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:02:08.610850096 CET | 53 | 60590 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:02:08.692404985 CET | 53 | 62659 | 1.1.1.1 | 192.168.2.16 |
Oct 29, 2024 14:02:14.338325024 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Oct 29, 2024 14:02:37.894341946 CET | 53 | 49937 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 29, 2024 14:01:09.579545021 CET | 192.168.2.16 | 1.1.1.1 | 0x85c8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 29, 2024 14:01:09.579921961 CET | 192.168.2.16 | 1.1.1.1 | 0xb54f | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 29, 2024 14:01:13.531857014 CET | 192.168.2.16 | 1.1.1.1 | 0x561f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 29, 2024 14:01:13.532064915 CET | 192.168.2.16 | 1.1.1.1 | 0x254a | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 29, 2024 14:01:09.866131067 CET | 1.1.1.1 | 192.168.2.16 | 0x85c8 | No error (0) | 104.37.175.156 | A (IP address) | IN (0x0001) | false | ||
Oct 29, 2024 14:01:13.539252043 CET | 1.1.1.1 | 192.168.2.16 | 0x254a | No error (0) | 65 | IN (0x0001) | false | |||
Oct 29, 2024 14:01:13.539464951 CET | 1.1.1.1 | 192.168.2.16 | 0x561f | No error (0) | 142.250.185.164 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49700 | 104.37.175.156 | 80 | 6780 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 29, 2024 14:01:09.872992039 CET | 428 | OUT | |
Oct 29, 2024 14:01:10.484417915 CET | 333 | IN | |
Oct 29, 2024 14:01:10.559129953 CET | 370 | OUT | |
Oct 29, 2024 14:01:10.689738989 CET | 515 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49709 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-29 13:01:17 UTC | 161 | OUT | |
2024-10-29 13:01:17 UTC | 466 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49710 | 184.28.90.27 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-29 13:01:18 UTC | 239 | OUT | |
2024-10-29 13:01:18 UTC | 514 | IN | |
2024-10-29 13:01:18 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49711 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-29 13:01:20 UTC | 306 | OUT | |
2024-10-29 13:01:20 UTC | 560 | IN | |
2024-10-29 13:01:20 UTC | 15824 | IN | |
2024-10-29 13:01:20 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49712 | 52.149.20.212 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-29 13:01:58 UTC | 306 | OUT | |
2024-10-29 13:01:58 UTC | 560 | IN | |
2024-10-29 13:01:58 UTC | 15824 | IN | |
2024-10-29 13:01:58 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 09:01:06 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 09:01:07 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 09:01:08 |
Start date: | 29/10/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |