Windows
Analysis Report
http://s.ksrndkehqnwntyxlhgto.com
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6472 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 7004 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2200 --fi eld-trial- handle=193 6,i,139788 1381798873 5767,11448 8086751290 81722,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6536 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://s.ksrn dkehqnwnty xlhgto.com " MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s.ksrndkehqnwntyxlhgto.com | 18.245.60.90 | true | false | high | |
www.google.com | 142.250.181.68 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.245.60.9 | unknown | United States | 16509 | AMAZON-02US | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
18.245.60.90 | s.ksrndkehqnwntyxlhgto.com | United States | 16509 | AMAZON-02US | false | |
142.250.181.68 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.17 |
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1562621 |
Start date and time: | 2024-11-25 19:34:24 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://s.ksrndkehqnwntyxlhgto.com |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@19/12@6/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.19.227, 172.217.17.46, 74.125.205.84, 34.104.35.123, 172.217.17.67
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: http://s.ksrndkehqnwntyxlhgto.com
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.99002199649846 |
Encrypted: | false |
SSDEEP: | 48:85dqOTKKrXH8idAKZdA1FehwiZUklqeh1y+3:8zHSyy |
MD5: | E7CA2937474500F159C74940C37BC00D |
SHA1: | 4204B788D72CB171C762C5F023964AB74426AB0D |
SHA-256: | 4B6EB3C15C09103876A63508038D0E77BBF1509C7CEB66BDD81CD3D27B1428D5 |
SHA-512: | 7714336E2DD4A1DFA97331AFBC8013957E812C3FB2BC883C73905939A15E9CEAC42A3F52AD1CDA9CA240776CBE02FCD9A0B25A141F3185FF3740725CDC2EB455 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.007002883969792 |
Encrypted: | false |
SSDEEP: | 48:8HbdqOTKKrXH8idAKZdA1seh/iZUkAQkqehiy+2:8HhHM9Qvy |
MD5: | 84ED3009EFA6923FB215AFD1AD60BC6D |
SHA1: | 5CF8BC59646B90393BCA708CEE10A3A4B659B912 |
SHA-256: | D3A8E95872BCB1A420923052965FF70AA86BD2FE41AE5BEFCAC167519C5322AE |
SHA-512: | 6301762E153191FCC4D9E64D32B8FA0C003A0511961596A6CFFA0DF02C873564B7422B0707C0433A6816692CE06AB5E93127DDDCE6F28F5795C75CC3AD0B4A4E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.015746705247201 |
Encrypted: | false |
SSDEEP: | 48:8jdqOTKKrAH8idAKZdA14meh7sFiZUkmgqeh7s8y+BX:8JH9ney |
MD5: | 6A45107D4C287C36E6B668BC998681A3 |
SHA1: | B1A3B78471BC405392006C6862742AED41A52112 |
SHA-256: | BF897AFE6F8B0B8A23FFA9E470E9A24B34D2BB4ABD7AA6CF7F17A26A447104E4 |
SHA-512: | 4007FFF64064070E506AC4A9A26E55BDF0B9DCDAF0563CB67985EECBAEAE6C7CA632BD77BEADF23B613AB055FD0CDEA53D80DFA3AB33D640ED1F7EF5F9EF6B5B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.002439739251875 |
Encrypted: | false |
SSDEEP: | 48:8PzdqOTKKrXH8idAKZdA1TehDiZUkwqehWy+R:8PZHHUy |
MD5: | F7E40993FEB82F4891EFAFF1F3E9AC93 |
SHA1: | 089163E2ACB1228BC6398ACD8AC100711E6BF39B |
SHA-256: | F60EC24C0D0B8DC1A292576804A8D1532284B95448F2EA0FBDD6A6A3DCC2052F |
SHA-512: | 8AB2BCD56B20C8547BCB497D36538A300C0FF96C4FA302017BDB7038D24563D0382604FD263CE446FEFBDA834E7C71AA705603A8E09CEA41FE20BAEDF4FDE9DB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9947027869695675 |
Encrypted: | false |
SSDEEP: | 48:8JdqOTKKrXH8idAKZdA1dehBiZUk1W1qehYy+C:8DHX94y |
MD5: | 61F051365587159A20CFDA8F90652C0E |
SHA1: | 9FC23F752059C3217E82690A569CCA6CA2CDA67A |
SHA-256: | 35E26B700AC7B0ED604F381A4AD7B98F9F81878B19B28CDBF22CDF7400A98B2E |
SHA-512: | A9B6C054D141A6733AAD879334CCF5FBF1ABD199B405FEC607B4C80487BADD43579DCE8480E730B6A91D6136C129BDD07CE4B0805D087BC8041A6D9A83CE74EC |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.002826053735063 |
Encrypted: | false |
SSDEEP: | 48:8NdqOTKKrXH8idAKZdA1duTeehOuTbbiZUk5OjqehOuTbey+yT+:8PHbTfTbxWOvTbey7T |
MD5: | D011DCEC837895C090F456A9F4E08D4C |
SHA1: | E9C00EEB223BE1F9FE1AEC56AAA32468C5FFE31F |
SHA-256: | C2F59FA143A831D23F15254DF828EFF0BA95E467AC988BF88987870785E617F0 |
SHA-512: | 233E81CEDC5F7FAB4FF4736904AE2D2A231A3CA8BAF2D8AA93806195386D07540C21C00D0BBB2CC5BF68158459B5F9F18BA81900FFE581E74CB513F8F31BF5A9 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 243 |
Entropy (8bit): | 5.590088876555848 |
Encrypted: | false |
SSDEEP: | 6:TMVBd/ZbZjZvKtWRVzji8fhHyIFFezUan:TMHd9BZKtWR8A5FFUUa |
MD5: | E7D35F1B3FCAF8545E0D480DE15824F6 |
SHA1: | D452DD86BB1475E7E82DE163D46A84782F2A63B1 |
SHA-256: | D0D07995D036BDB3E5875A6FF5CF99DDDCF2DFEC3E029C806D041DA449A24EF3 |
SHA-512: | 0309A42186DD6D55436838025392BCDBCF5DDEA5381C066E5D20D25D609161572864BCD7781779CA17BE0FB725A0274AC37D62820993CF738D22994DE4E8C1A9 |
Malicious: | false |
Reputation: | low |
URL: | https://s.ksrndkehqnwntyxlhgto.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 20 |
Entropy (8bit): | 3.3841837197791884 |
Encrypted: | false |
SSDEEP: | 3:OHKW3Ae:OqOAe |
MD5: | DC5BCBF7F9372CCC9AEDB581FE88EDFE |
SHA1: | 79097FE77C29B4CA590114BDD0331431A1EFC470 |
SHA-256: | D872E8E4176213EA84EBC76D8FB621C31B4CA116FD0A51258813E804FE110CA4 |
SHA-512: | 1EA2F632E9647FBDE1DA45DB3F295620E3B8228E48C237134DE7ADCE74121F9F12B0A647D27A574B4172A93A4E86B9C1B5868C24ABA5F48253E6283EAB35F6F0 |
Malicious: | false |
Reputation: | low |
URL: | https://s.ksrndkehqnwntyxlhgto.com/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 154 |
Entropy (8bit): | 4.835928340972722 |
Encrypted: | false |
SSDEEP: | 3:Vw/KN6WlOoh3wwBHsLpYJWriFGWjLwWkzXFETH1u4:VwCpVV5BHsL2YriFGAwWeXFEL13 |
MD5: | 6B13A3BBFDDCEED69F437879BE8EC4ED |
SHA1: | 0D40F17D32466F7FAF2683FA5F8484AD2A6B5D7F |
SHA-256: | 29D3BE350A8AB75A8F36EDB7AB255DDAB8F7EB5F7936C7F72C8F7950C0730440 |
SHA-512: | DFE2A9B6E54ECF7EA6A62CDB7A7F5BD4EC43A960BA9B2D0DDBDE9FC118D75E1E8EB7D20E1A105282F4CC88C4D54E3A5D2032EDDCC4B059006FEEFC66149047DD |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=http%3A%2F%2Fs.ksrndkehqnwntyxlhgto.com&oit=3&cp=4&pgcl=4&gs_rn=42&psi=iSR4VaPXe_50Me9V&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 25, 2024 19:34:48.174381971 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.174400091 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.174415112 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.174424887 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.174432039 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.174438000 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.174582005 CET | 49699 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:34:48.182697058 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.182755947 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.182816982 CET | 49699 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:34:48.191135883 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.191282988 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.191342115 CET | 49699 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:34:48.199619055 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:34:48.244977951 CET | 49699 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:34:54.593945026 CET | 49704 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:34:54.594291925 CET | 49705 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:34:54.719995022 CET | 80 | 49704 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:34:54.720113993 CET | 49704 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:34:54.720215082 CET | 80 | 49705 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:34:54.720271111 CET | 49705 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:34:54.720396996 CET | 49704 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:34:54.847245932 CET | 80 | 49704 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:34:55.460501909 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:34:55.761692047 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:34:56.032711983 CET | 80 | 49704 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:34:56.081687927 CET | 49704 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:34:56.182605982 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:56.182660103 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:56.182729959 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:56.182997942 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:56.183027983 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:56.365678072 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:34:57.572724104 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:34:57.764997005 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:57.765300035 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:57.765335083 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:57.766318083 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:57.766395092 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:57.767281055 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:57.767350912 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:57.767436028 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:57.767443895 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:57.810662031 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:58.268033981 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:34:58.268080950 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:34:58.268155098 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:34:58.268382072 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:34:58.268394947 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:34:58.294164896 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:58.294271946 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:58.294331074 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:58.294785976 CET | 49707 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:58.294806004 CET | 443 | 49707 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:58.359189987 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:58.359239101 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:58.359318018 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:58.359508038 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:34:58.359519958 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:34:59.980679989 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:35:00.026030064 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:00.026344061 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:00.026395082 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:00.028269053 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:00.028345108 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:00.029469967 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:00.029563904 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:00.057427883 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:00.057701111 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:00.057730913 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:00.058193922 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:00.058542967 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:00.058614969 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:00.058623075 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:00.058634043 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:00.075692892 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:00.075728893 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:00.107672930 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:00.123677015 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:00.143737078 CET | 49690 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:01.001692057 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:01.001864910 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:01.001918077 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:01.002692938 CET | 49711 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:01.002717018 CET | 443 | 49711 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:01.870754004 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:01.870805025 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:01.870883942 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:01.872786045 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:01.872802973 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:02.828257084 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:02.828310013 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:02.829015017 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:02.830037117 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:02.830050945 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:03.272159100 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.272243977 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.276101112 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.276119947 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.276525974 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.314531088 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.355359077 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.622028112 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:03.898207903 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.898277998 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.898344994 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.898387909 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.898406982 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.898417950 CET | 49713 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.898423910 CET | 443 | 49713 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.923686028 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:03.928839922 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.928862095 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:03.928926945 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.929227114 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:03.929239988 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:04.524837017 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:04.587549925 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:04.587646008 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:04.590121984 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:04.590132952 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:04.590370893 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:04.636652946 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:04.639832020 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:04.683335066 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:04.780742884 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:35:05.279057980 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.279149055 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:05.281018019 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:05.281028032 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.281929970 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.283329010 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:05.285264015 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.285291910 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.285300016 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.285310030 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.285329103 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.285363913 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.285391092 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.285402060 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.285442114 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.307488918 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.307559967 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.307586908 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.307598114 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.307663918 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.307712078 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.307724953 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.307742119 CET | 49714 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:05.307746887 CET | 443 | 49714 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:05.327331066 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.737683058 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:05.780121088 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.780328035 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.780395031 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:05.781003952 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:05.781033039 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:05.781045914 CET | 49715 | 443 | 192.168.2.16 | 2.18.109.164 |
Nov 25, 2024 19:35:05.781053066 CET | 443 | 49715 | 2.18.109.164 | 192.168.2.16 |
Nov 25, 2024 19:35:08.102850914 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:08.150688887 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:08.406709909 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:09.014731884 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:09.704977036 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:09.705041885 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:09.705149889 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:10.228725910 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:11.509258032 CET | 49710 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:11.509306908 CET | 443 | 49710 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:12.641788006 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:12.964792013 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:14.381903887 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 19:35:17.445744991 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:22.575810909 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 19:35:25.870428085 CET | 80 | 49705 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:35:25.870518923 CET | 49705 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:35:27.046746969 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 19:35:27.512228012 CET | 49705 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:35:27.634025097 CET | 80 | 49705 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:35:39.260421991 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:39.260489941 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:39.260570049 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:39.260796070 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:39.260816097 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:41.005521059 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:41.005825043 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:41.005881071 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:41.006211042 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:41.006503105 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:41.006572962 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:41.043771029 CET | 49704 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:35:41.059761047 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:41.169354916 CET | 80 | 49704 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:35:41.655662060 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:41.655730963 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:41.655824900 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:41.656152964 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:41.656167030 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:43.477581024 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:43.477670908 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:43.478925943 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:43.478938103 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:43.479435921 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:43.480707884 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:43.523332119 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.196536064 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.196594000 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.196634054 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.196677923 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.196705103 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.196734905 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.196757078 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.237631083 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.237693071 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.237725973 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.237744093 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.237744093 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.237849951 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.237860918 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.237873077 CET | 49717 | 443 | 192.168.2.16 | 4.245.163.56 |
Nov 25, 2024 19:35:44.237879992 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:44.237890005 CET | 443 | 49717 | 4.245.163.56 | 192.168.2.16 |
Nov 25, 2024 19:35:47.431948900 CET | 49698 | 80 | 192.168.2.16 | 178.79.238.128 |
Nov 25, 2024 19:35:47.431966066 CET | 49700 | 80 | 192.168.2.16 | 178.79.238.128 |
Nov 25, 2024 19:35:47.560334921 CET | 80 | 49698 | 178.79.238.128 | 192.168.2.16 |
Nov 25, 2024 19:35:47.560400963 CET | 49698 | 80 | 192.168.2.16 | 178.79.238.128 |
Nov 25, 2024 19:35:47.561467886 CET | 80 | 49700 | 178.79.238.128 | 192.168.2.16 |
Nov 25, 2024 19:35:47.561543941 CET | 49700 | 80 | 192.168.2.16 | 178.79.238.128 |
Nov 25, 2024 19:35:50.040312052 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:50.083343029 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:50.722115993 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:50.724452972 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:50.724533081 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:50.731174946 CET | 49716 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:50.731221914 CET | 443 | 49716 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:51.106910944 CET | 49718 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:35:51.130043030 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:51.130137920 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:51.130248070 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:51.130568027 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:51.130616903 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:51.227205038 CET | 80 | 49718 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:35:51.227300882 CET | 49718 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:35:52.764951944 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:52.765398026 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:52.765460968 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:52.765822887 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:52.766141891 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:52.766216993 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:52.766264915 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:52.807336092 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:52.817805052 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:53.704761028 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:53.705359936 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:53.705421925 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:53.705624104 CET | 49719 | 443 | 192.168.2.16 | 18.245.60.9 |
Nov 25, 2024 19:35:53.705676079 CET | 443 | 49719 | 18.245.60.9 | 192.168.2.16 |
Nov 25, 2024 19:35:58.192820072 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:58.192862988 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:58.192974091 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:58.193181038 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:58.193196058 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:59.893016100 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:59.893335104 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:59.893363953 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:59.893687010 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:59.894095898 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:35:59.894196987 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:35:59.949897051 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:36:09.603405952 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:36:09.603475094 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:36:09.603682041 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:36:11.504230976 CET | 49721 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:36:11.504265070 CET | 443 | 49721 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:36:22.371903896 CET | 80 | 49718 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:36:22.372112989 CET | 49718 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:36:23.203733921 CET | 49718 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:36:23.329447031 CET | 80 | 49718 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:36:26.172931910 CET | 49704 | 80 | 192.168.2.16 | 18.245.60.90 |
Nov 25, 2024 19:36:26.295331955 CET | 80 | 49704 | 18.245.60.90 | 192.168.2.16 |
Nov 25, 2024 19:36:30.876152039 CET | 49696 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:36:30.876359940 CET | 49697 | 80 | 192.168.2.16 | 192.229.221.95 |
Nov 25, 2024 19:36:30.997884035 CET | 443 | 49696 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:36:30.998090982 CET | 49696 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:36:30.998325109 CET | 80 | 49697 | 192.229.221.95 | 192.168.2.16 |
Nov 25, 2024 19:36:30.998404026 CET | 49697 | 80 | 192.168.2.16 | 192.229.221.95 |
Nov 25, 2024 19:36:35.816201925 CET | 49699 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:36:35.941663980 CET | 443 | 49699 | 20.190.147.0 | 192.168.2.16 |
Nov 25, 2024 19:36:35.941864967 CET | 49699 | 443 | 192.168.2.16 | 20.190.147.0 |
Nov 25, 2024 19:36:58.249037027 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:36:58.249079943 CET | 443 | 49723 | 142.250.181.68 | 192.168.2.16 |
Nov 25, 2024 19:36:58.249181986 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:36:58.249521017 CET | 49723 | 443 | 192.168.2.16 | 142.250.181.68 |
Nov 25, 2024 19:36:58.249535084 CET | 443 | 49723 | 142.250.181.68 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 25, 2024 19:34:53.453252077 CET | 53 | 52384 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:53.468729973 CET | 53 | 63145 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:54.267447948 CET | 53445 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 19:34:54.267792940 CET | 50616 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 19:34:54.406770945 CET | 53 | 50616 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:54.593180895 CET | 53 | 53445 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:56.036570072 CET | 51113 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 19:34:56.036751986 CET | 58203 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 19:34:56.179882050 CET | 53 | 51113 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:56.182096004 CET | 53 | 58203 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:56.414354086 CET | 53 | 57204 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:58.128523111 CET | 52025 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 19:34:58.128675938 CET | 64880 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 19:34:58.267038107 CET | 53 | 52025 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:34:58.267057896 CET | 53 | 64880 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:35:13.421895027 CET | 53 | 64229 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:35:32.469012976 CET | 53 | 65345 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:35:53.390532970 CET | 53 | 52218 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:35:55.284250975 CET | 53 | 52758 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 19:35:59.796555042 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Nov 25, 2024 19:36:23.347421885 CET | 53 | 58917 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 25, 2024 19:34:54.267447948 CET | 192.168.2.16 | 1.1.1.1 | 0x22f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 19:34:54.267792940 CET | 192.168.2.16 | 1.1.1.1 | 0xc76b | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 19:34:56.036570072 CET | 192.168.2.16 | 1.1.1.1 | 0xed1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 19:34:56.036751986 CET | 192.168.2.16 | 1.1.1.1 | 0x51bd | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 19:34:58.128523111 CET | 192.168.2.16 | 1.1.1.1 | 0x1977 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 19:34:58.128675938 CET | 192.168.2.16 | 1.1.1.1 | 0xaea0 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 25, 2024 19:34:54.593180895 CET | 1.1.1.1 | 192.168.2.16 | 0x22f9 | No error (0) | 18.245.60.90 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:54.593180895 CET | 1.1.1.1 | 192.168.2.16 | 0x22f9 | No error (0) | 18.245.60.77 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:54.593180895 CET | 1.1.1.1 | 192.168.2.16 | 0x22f9 | No error (0) | 18.245.60.3 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:54.593180895 CET | 1.1.1.1 | 192.168.2.16 | 0x22f9 | No error (0) | 18.245.60.9 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:56.179882050 CET | 1.1.1.1 | 192.168.2.16 | 0xed1f | No error (0) | 18.245.60.9 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:56.179882050 CET | 1.1.1.1 | 192.168.2.16 | 0xed1f | No error (0) | 18.245.60.77 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:56.179882050 CET | 1.1.1.1 | 192.168.2.16 | 0xed1f | No error (0) | 18.245.60.3 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:56.179882050 CET | 1.1.1.1 | 192.168.2.16 | 0xed1f | No error (0) | 18.245.60.90 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:58.267038107 CET | 1.1.1.1 | 192.168.2.16 | 0x1977 | No error (0) | 142.250.181.68 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 19:34:58.267057896 CET | 1.1.1.1 | 192.168.2.16 | 0xaea0 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49704 | 18.245.60.90 | 80 | 7004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 25, 2024 19:34:54.720396996 CET | 441 | OUT | |
Nov 25, 2024 19:34:56.032711983 CET | 576 | IN | |
Nov 25, 2024 19:35:41.043771029 CET | 6 | OUT | |
Nov 25, 2024 19:36:26.172931910 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49707 | 18.245.60.9 | 443 | 7004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:34:57 UTC | 669 | OUT | |
2024-11-25 18:34:58 UTC | 481 | IN | |
2024-11-25 18:34:58 UTC | 20 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49711 | 18.245.60.9 | 443 | 7004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:00 UTC | 608 | OUT | |
2024-11-25 18:35:00 UTC | 357 | IN | |
2024-11-25 18:35:00 UTC | 282 | IN | |
2024-11-25 18:35:00 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49713 | 2.18.109.164 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:03 UTC | 161 | OUT | |
2024-11-25 18:35:03 UTC | 478 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49714 | 4.245.163.56 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:04 UTC | 306 | OUT | |
2024-11-25 18:35:05 UTC | 560 | IN | |
2024-11-25 18:35:05 UTC | 15824 | IN | |
2024-11-25 18:35:05 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49715 | 2.18.109.164 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:05 UTC | 239 | OUT | |
2024-11-25 18:35:05 UTC | 534 | IN | |
2024-11-25 18:35:05 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.16 | 49717 | 4.245.163.56 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:43 UTC | 306 | OUT | |
2024-11-25 18:35:44 UTC | 560 | IN | |
2024-11-25 18:35:44 UTC | 15824 | IN | |
2024-11-25 18:35:44 UTC | 14181 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.16 | 49716 | 142.250.181.68 | 443 | 7004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:50 UTC | 685 | OUT | |
2024-11-25 18:35:50 UTC | 1266 | IN | |
2024-11-25 18:35:50 UTC | 124 | IN | |
2024-11-25 18:35:50 UTC | 36 | IN | |
2024-11-25 18:35:50 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.16 | 49719 | 18.245.60.9 | 443 | 7004 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 18:35:52 UTC | 608 | OUT | |
2024-11-25 18:35:53 UTC | 357 | IN | |
2024-11-25 18:35:53 UTC | 249 | IN | |
2024-11-25 18:35:53 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 13:34:51 |
Start date: | 25/11/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 13:34:51 |
Start date: | 25/11/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 13:34:52 |
Start date: | 25/11/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |