Windows
Analysis Report
https://Saic.exposuppllesusa.com/enlooxjhfkgdrsl/kdulaemkojkzf/Zbfarruvjxihnwe89g0xmaersk/kkjszejwukhwbm/bbxljzmmavz/random.bby/yantadlfmev/gmail.com/nwklvpyezrmf8
Overview
General Information
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 5992 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6632 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2164 --fi eld-trial- handle=198 4,i,667385 4912136990 476,165232 8717916580 8227,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 5892 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://Saic. exposuppll esusa.com/ enlooxjhfk gdrsl/kdul aemkojkzf/ Zbfarruvjx ihnwe89g0x maersk/kkj szejwukhwb m/bbxljzmm avz/random .bby/yanta dlfmev/gma il.com/nwk lvpyezrmf8 " MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
google.com | 142.250.181.142 | true | false | high | |
www.google.com | 142.250.181.100 | true | false | high | |
saic.exposuppllesusa.com | unknown | unknown | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.181.100 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1562668 |
Start date and time: | 2024-11-25 21:01:37 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://Saic.exposuppllesusa.com/enlooxjhfkgdrsl/kdulaemkojkzf/Zbfarruvjxihnwe89g0xmaersk/kkjszejwukhwbm/bbxljzmmavz/random.bby/yantadlfmev/gmail.com/nwklvpyezrmf8 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.win@22/6@20/3 |
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 216.58.208.227, 172.217.17.46, 64.233.165.84, 34.104.35.123, 199.232.210.172, 172.217.17.67, 172.217.19.206
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://Saic.exposuppllesusa.com/enlooxjhfkgdrsl/kdulaemkojkzf/Zbfarruvjxihnwe89g0xmaersk/kkjszejwukhwbm/bbxljzmmavz/random.bby/yantadlfmev/gmail.com/nwklvpyezrmf8
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9832345504868654 |
Encrypted: | false |
SSDEEP: | 48:8sdq6TKm/5EHvidAKZdA1FehwiZUklqehry+3:8Iv5Qky |
MD5: | 75A281C18D3C3E44BBC07EFAE241FE32 |
SHA1: | E072D487675C7399CC3E7186C9027CBF01AEDDBC |
SHA-256: | 933CEB74AC42727E45F9C9D8F6A92C70F3BA848824D43DE67CB8C9791C5A59F8 |
SHA-512: | AC722BE7FB3EC233858976DC9E53B6F367E2987C186DBF3335DD6137FF302795D6461B79B5B02F7AF6DB5DC3A860F31681DC589AF3BA8E818506BC0A8474A157 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.998277431993333 |
Encrypted: | false |
SSDEEP: | 48:8/dq6TKm/5EHvidAKZdA1seh/iZUkAQkqehUy+2:8Bv5G9Qpy |
MD5: | 95B7738EA195746EEDA4D3EDEB91CB7C |
SHA1: | A75882785A49D6AF929CAB786FEB45E02F02F656 |
SHA-256: | 074425C762DE969C5E18C1BD90B9F209F8CF6B8CD3A1C8F37E8745572FFB1052 |
SHA-512: | 869DEF2AC0A6ABCF14B4F3DDFFBD75B5E36D727E48D2234F12B77B3F910C732C19108AF6D7D5F9647A71DD06014F755FD993F9DCF38CDC82A66BA739064DD575 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.008691269137029 |
Encrypted: | false |
SSDEEP: | 48:8ydq6TKm/AHvidAKZdA14meh7sFiZUkmgqeh7siy+BX:8qvWnoy |
MD5: | DEA56DFDBDA3F53B86F2600DA141529A |
SHA1: | EB3F7437E5AD8C67CC58CB146476C0A775B94693 |
SHA-256: | 50513A99F98B97C948579A846464E68899804B3F91E9A6AFB56559DD588FFCA5 |
SHA-512: | C4C5A4365763A1BBE6FA9E9FDE98D68D960409E94FF32805D0C498ED616BAE1D7A88300A3B328C35C5566896152A98EC2EA6C3B7AF0FB1691AB872CB763FAF8F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.997041512073845 |
Encrypted: | false |
SSDEEP: | 48:87dq6TKm/5EHvidAKZdA1TehDiZUkwqehgy+R:8tv5day |
MD5: | 613DD3E1D276863B9128D0324EC2CB8E |
SHA1: | B661E80DBB0E833BB590D45B3548F3B3987E9689 |
SHA-256: | E30B5AE6330648E7413014E0D72320981F2C2BD192C79AB252B7BB7A136BEA5B |
SHA-512: | 2584C8E01CCA407D3C74138CBB5188D09636EEFF9423355055FE826CAD89A0EBB86942C119365B1441630AFB38E7884C9F794F5392A69F06048CE55D282F718F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9851800249815126 |
Encrypted: | false |
SSDEEP: | 48:85dq6TKm/5EHvidAKZdA1dehBiZUk1W1qehmy+C:8Xv5d9Gy |
MD5: | 8440EE26D362CFFFA32237A9ECC24095 |
SHA1: | A3585DD42F886FEB56D1A3A798ED839B9723940C |
SHA-256: | 50A837CE87921FB82F4537BA6C539BC87C2E8B8734A6AB3448B623502A46DC5C |
SHA-512: | E4F7A5FCC12B6D5E3298E0EE58539BB773F2434BB0AF5425651C59578279391B6555A93063B6F5CA9EF96E47B9F860B6359026257A2366BBFAC53D1A836CCFED |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.99663531715915 |
Encrypted: | false |
SSDEEP: | 48:8Rdq6TKm/5EHvidAKZdA1duTeehOuTbbiZUk5OjqehOuTboy+yT+:8fv5lTfTbxWOvTboy7T |
MD5: | 0A3821494DA4BA3A8D7D8DD4BEB875D6 |
SHA1: | C9E2409F766F550A3403B1D88D4DE97F544A07BD |
SHA-256: | B9898167D4932678DC3576D4D44094539FB57B33E49F64CB7AECDBA6A3419302 |
SHA-512: | 7E8097C493185338197DC3805126F98348464359815F015DC880F5934E1920CDE8C4BCAEBCEA38C7B87C51059E30B459C2C22E9E50A5838FFEE11C349D4E11FC |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 25, 2024 21:02:08.442853928 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:08.746001959 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:09.361336946 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:09.527884007 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:09.527940035 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:09.528017044 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:09.528256893 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:09.528278112 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:10.568346024 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:11.322019100 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:11.322405100 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:11.322419882 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:11.323441982 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:11.323535919 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:11.324825048 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:11.324903965 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:11.377346992 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:11.377357006 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:11.425365925 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:12.972384930 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:13.279896021 CET | 49689 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:14.774408102 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:14.774437904 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:14.774630070 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:14.776623011 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:14.776631117 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.249694109 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.249789953 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.254803896 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.254821062 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.255196095 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.306371927 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.312180996 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.359339952 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.610795975 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:16.787326097 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.787408113 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.787559032 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.787698984 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.787725925 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.787744999 CET | 49701 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.787750006 CET | 443 | 49701 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.837094069 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.837141037 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.837248087 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.837599993 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:16.837618113 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:16.912379026 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:17.364983082 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:17.365031004 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:17.365115881 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:17.366348982 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:17.366375923 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:17.519393921 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:17.774378061 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:18.276865959 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.276952028 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:18.278115034 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:18.278134108 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.278412104 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.282181978 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:18.323339939 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.730369091 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:18.806595087 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.806761980 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.806837082 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:18.807539940 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:18.807555914 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.807568073 CET | 49703 | 443 | 192.168.2.16 | 23.52.182.8 |
Nov 25, 2024 21:02:18.807579041 CET | 443 | 49703 | 23.52.182.8 | 192.168.2.16 |
Nov 25, 2024 21:02:18.946821928 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:18.946944952 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:18.950053930 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:18.950062990 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:18.950474977 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.002383947 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.009814024 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.051343918 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585855961 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585885048 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585892916 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585917950 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585928917 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585938931 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.585967064 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.585992098 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.586036921 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.586036921 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.608444929 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.608532906 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.608534098 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.608572960 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.608650923 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.608670950 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:19.608697891 CET | 49704 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:19.608704090 CET | 443 | 49704 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:20.959786892 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:20.959887981 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:20.959989071 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:21.078531981 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:21.142352104 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:21.382388115 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:21.989384890 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:22.820178986 CET | 49696 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:02:22.820213079 CET | 443 | 49696 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:02:23.202383995 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:25.612400055 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:25.947400093 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:27.386393070 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Nov 25, 2024 21:02:30.415448904 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:35.555428982 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Nov 25, 2024 21:02:40.023422956 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Nov 25, 2024 21:02:55.992677927 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:55.992718935 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:55.992877960 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:55.993254900 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:55.993268967 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:57.628015995 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:57.628231049 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:57.629584074 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:57.629594088 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:57.629834890 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:57.631824017 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:57.679333925 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.470788956 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471240997 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471350908 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.471380949 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471405983 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471491098 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.471498966 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471688032 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471726894 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471750975 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.471760988 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471780062 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.471820116 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.471890926 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.473895073 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.473895073 CET | 49705 | 443 | 192.168.2.16 | 20.12.23.50 |
Nov 25, 2024 21:02:58.473912954 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:02:58.473925114 CET | 443 | 49705 | 20.12.23.50 | 192.168.2.16 |
Nov 25, 2024 21:03:09.441874981 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:09.441916943 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:09.442055941 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:09.442306042 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:09.442320108 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:11.234348059 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:11.234719992 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:11.234757900 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:11.235085964 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:11.235382080 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:11.235455990 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:11.276509047 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:20.913871050 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:20.913957119 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:03:20.914192915 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:22.822240114 CET | 49707 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:03:22.822279930 CET | 443 | 49707 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:04:09.500597954 CET | 49709 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:04:09.500652075 CET | 443 | 49709 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:04:09.500807047 CET | 49709 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:04:09.501091957 CET | 49709 | 443 | 192.168.2.16 | 142.250.181.100 |
Nov 25, 2024 21:04:09.501108885 CET | 443 | 49709 | 142.250.181.100 | 192.168.2.16 |
Nov 25, 2024 21:04:11.195815086 CET | 443 | 49709 | 142.250.181.100 | 192.168.2.16 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 25, 2024 21:02:04.737016916 CET | 53 | 49557 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:04.738181114 CET | 53 | 57872 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:05.510354042 CET | 60235 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:05.510699034 CET | 56702 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:05.693280935 CET | 53 | 56702 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:05.694010973 CET | 53 | 60235 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:05.694799900 CET | 59093 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:05.838159084 CET | 53 | 59093 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:05.867557049 CET | 55072 | 53 | 192.168.2.16 | 8.8.8.8 |
Nov 25, 2024 21:02:05.867923021 CET | 58363 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:06.012100935 CET | 53 | 58363 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:06.878777981 CET | 49340 | 53 | 192.168.2.16 | 8.8.4.4 |
Nov 25, 2024 21:02:06.882926941 CET | 54026 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:06.883547068 CET | 60461 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:07.017179966 CET | 53 | 49340 | 8.8.4.4 | 192.168.2.16 |
Nov 25, 2024 21:02:07.023696899 CET | 53 | 60461 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:07.024673939 CET | 53 | 54026 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:07.521225929 CET | 53 | 57444 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:09.378287077 CET | 54591 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:09.378423929 CET | 54074 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:09.525298119 CET | 53 | 54074 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:09.526923895 CET | 53 | 54591 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:12.036222935 CET | 61690 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:12.036336899 CET | 51339 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:12.175463915 CET | 53 | 51339 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:12.175477982 CET | 53 | 61690 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:12.176357031 CET | 58572 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:12.319216967 CET | 53 | 58572 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:24.488146067 CET | 53 | 58666 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:43.296294928 CET | 53 | 51114 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:47.465631962 CET | 54702 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:47.465816021 CET | 55937 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:47.604355097 CET | 53 | 55937 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:47.604818106 CET | 53 | 54702 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:02:47.605562925 CET | 53283 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:02:47.746085882 CET | 53 | 53283 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:04.694612026 CET | 53 | 59179 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:05.904025078 CET | 53 | 51163 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:12.789978981 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Nov 25, 2024 21:03:19.576338053 CET | 51220 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:03:19.717421055 CET | 53 | 51220 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:34.203280926 CET | 53 | 59506 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:47.764652967 CET | 57260 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:03:47.764844894 CET | 55556 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:03:47.903856993 CET | 53 | 57260 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:47.904299021 CET | 53 | 55556 | 1.1.1.1 | 192.168.2.16 |
Nov 25, 2024 21:03:47.905077934 CET | 63998 | 53 | 192.168.2.16 | 1.1.1.1 |
Nov 25, 2024 21:03:48.043387890 CET | 53 | 63998 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 25, 2024 21:02:05.510354042 CET | 192.168.2.16 | 1.1.1.1 | 0xe637 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:05.510699034 CET | 192.168.2.16 | 1.1.1.1 | 0x1468 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:05.694799900 CET | 192.168.2.16 | 1.1.1.1 | 0x2d83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:05.867557049 CET | 192.168.2.16 | 8.8.8.8 | 0x9a43 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:05.867923021 CET | 192.168.2.16 | 1.1.1.1 | 0x8646 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:06.878777981 CET | 192.168.2.16 | 8.8.4.4 | 0xfecd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:06.882926941 CET | 192.168.2.16 | 1.1.1.1 | 0x2119 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:06.883547068 CET | 192.168.2.16 | 1.1.1.1 | 0x81d5 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:09.378287077 CET | 192.168.2.16 | 1.1.1.1 | 0xcb5f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:09.378423929 CET | 192.168.2.16 | 1.1.1.1 | 0xa479 | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:12.036222935 CET | 192.168.2.16 | 1.1.1.1 | 0x174a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:12.036336899 CET | 192.168.2.16 | 1.1.1.1 | 0xd9bd | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:12.176357031 CET | 192.168.2.16 | 1.1.1.1 | 0x45da | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:47.465631962 CET | 192.168.2.16 | 1.1.1.1 | 0xc079 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:47.465816021 CET | 192.168.2.16 | 1.1.1.1 | 0x1a9e | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:47.605562925 CET | 192.168.2.16 | 1.1.1.1 | 0x2515 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:03:19.576338053 CET | 192.168.2.16 | 1.1.1.1 | 0xce43 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:03:47.764652967 CET | 192.168.2.16 | 1.1.1.1 | 0x108 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:03:47.764844894 CET | 192.168.2.16 | 1.1.1.1 | 0x65c | Standard query (0) | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:03:47.905077934 CET | 192.168.2.16 | 1.1.1.1 | 0xe225 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 25, 2024 21:02:05.693280935 CET | 1.1.1.1 | 192.168.2.16 | 0x1468 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:05.694010973 CET | 1.1.1.1 | 192.168.2.16 | 0xe637 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:05.838159084 CET | 1.1.1.1 | 192.168.2.16 | 0x2d83 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:06.012100935 CET | 1.1.1.1 | 192.168.2.16 | 0x8646 | No error (0) | 142.250.181.142 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 21:02:07.017179966 CET | 8.8.4.4 | 192.168.2.16 | 0xfecd | No error (0) | 142.250.181.142 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 21:02:07.023696899 CET | 1.1.1.1 | 192.168.2.16 | 0x81d5 | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:07.024673939 CET | 1.1.1.1 | 192.168.2.16 | 0x2119 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:09.525298119 CET | 1.1.1.1 | 192.168.2.16 | 0xa479 | No error (0) | 65 | IN (0x0001) | false | |||
Nov 25, 2024 21:02:09.526923895 CET | 1.1.1.1 | 192.168.2.16 | 0xcb5f | No error (0) | 142.250.181.100 | A (IP address) | IN (0x0001) | false | ||
Nov 25, 2024 21:02:12.175463915 CET | 1.1.1.1 | 192.168.2.16 | 0xd9bd | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:12.175477982 CET | 1.1.1.1 | 192.168.2.16 | 0x174a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:12.319216967 CET | 1.1.1.1 | 192.168.2.16 | 0x45da | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:47.604355097 CET | 1.1.1.1 | 192.168.2.16 | 0x1a9e | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:02:47.604818106 CET | 1.1.1.1 | 192.168.2.16 | 0xc079 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:02:47.746085882 CET | 1.1.1.1 | 192.168.2.16 | 0x2515 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:03:19.717421055 CET | 1.1.1.1 | 192.168.2.16 | 0xce43 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:03:47.903856993 CET | 1.1.1.1 | 192.168.2.16 | 0x108 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 25, 2024 21:03:47.904299021 CET | 1.1.1.1 | 192.168.2.16 | 0x65c | Name error (3) | none | none | 65 | IN (0x0001) | false | |
Nov 25, 2024 21:03:48.043387890 CET | 1.1.1.1 | 192.168.2.16 | 0xe225 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49701 | 23.52.182.8 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 20:02:16 UTC | 161 | OUT | |
2024-11-25 20:02:16 UTC | 478 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49703 | 23.52.182.8 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 20:02:18 UTC | 239 | OUT | |
2024-11-25 20:02:18 UTC | 514 | IN | |
2024-11-25 20:02:18 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49704 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 20:02:19 UTC | 306 | OUT | |
2024-11-25 20:02:19 UTC | 560 | IN | |
2024-11-25 20:02:19 UTC | 15824 | IN | |
2024-11-25 20:02:19 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49705 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-25 20:02:57 UTC | 306 | OUT | |
2024-11-25 20:02:58 UTC | 560 | IN | |
2024-11-25 20:02:58 UTC | 15824 | IN | |
2024-11-25 20:02:58 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 15:02:02 |
Start date: | 25/11/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 15:02:03 |
Start date: | 25/11/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 15:02:04 |
Start date: | 25/11/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |