Windows
Analysis Report
https://name10-safelinks-protection-outlook-com-url-atp-redirect.details-info.co/XVTNJOTVUdXQzTjgzNUZYMm9meHV6RHZGTnpRWmZlSlRaOGs3QlVKUlVrTmU5SlU5TXExenpsNHdTUnpiSW4xVTgxU0dZK0FnRnpwdnUxVmFzb0NkV3FmejZlb0kxak9KT2poRnI1VE5waTc3Y1dVR2pPOCtHVDZ4QTA5cUNqRHVsVUxrQnNmSU1ZTHZpSnlTWnJmdEx1V0RXampkZ0FHam5PcH
Overview
General Information
Detection
Score: | 20 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6208 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6428 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2032 --fi eld-trial- handle=195 2,i,122330 3242334391 4190,16600 2217496409 21859,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6992 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://name1 0-safelink s-protecti on-outlook -com-url-a tp-redirec t.details- info.co/XV TNJOTVUdXQ zTjgzNUZYM m9meHV6RHZ GTnpRWmZlS lRaOGs3QlV KUlVrTmU5S lU5TXExenp sNHdTUnpiS W4xVTgxU0d ZK0FnRnpwd nUxVmFzb0N kV3FmejZlb 0kxak9KT2p oRnI1VE5wa Tc3Y1dVR2p POCtHVDZ4Q TA5cUNqRHV sVUxrQnNmS U1ZTHZpSnl TWnJmdEx1V 0RXampkZ0F Ham5PcHJ0a Uh4dGgzK0c waGp1a" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 172.217.18.4 | true | false | high | |
name10-safelinks-protection-outlook-com-url-atp-redirect.details-info.co | 3.98.135.159 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | unknown | ||
false | high | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.217.18.4 | www.google.com | United States | 15169 | GOOGLEUS | false | |
3.98.135.159 | name10-safelinks-protection-outlook-com-url-atp-redirect.details-info.co | United States | 16509 | AMAZON-02US | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1592159 |
Start date and time: | 2025-01-15 20:54:12 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://name10-safelinks-protection-outlook-com-url-atp-redirect.details-info.co/XVTNJOTVUdXQzTjgzNUZYMm9meHV6RHZGTnpRWmZlSlRaOGs3QlVKUlVrTmU5SlU5TXExenpsNHdTUnpiSW4xVTgxU0dZK0FnRnpwdnUxVmFzb0NkV3FmejZlb0kxak9KT2poRnI1VE5waTc3Y1dVR2pPOCtHVDZ4QTA5cUNqRHVsVUxrQnNmSU1ZTHZpSnlTWnJmdEx1V0RXampkZ0FHam5PcHJ0aUh4dGgzK0cwaGp1a |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | SUS |
Classification: | sus20.win@18/22@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.99, 172.217.16.206, 142.251.168.84, 142.250.181.238, 172.217.18.110, 142.250.185.110, 199.232.210.172, 172.217.18.14, 142.250.185.238, 142.250.184.206, 142.250.186.78, 142.250.186.163, 88.221.110.91, 142.250.185.174, 142.250.186.174, 2.23.242.162, 20.12.23.50, 40.126.32.134, 2.21.65.154
- Excluded domains from analysis (whitelisted): www.bing.com, clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, encrypted-tbn0.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, login.live.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://name10-safelinks-protection-outlook-com-url-atp-redirect.details-info.co/XVTNJOTVUdXQzTjgzNUZYMm9meHV6RHZGTnpRWmZlSlRaOGs3QlVKUlVrTmU5SlU5TXExenpsNHdTUnpiSW4xVTgxU0dZK0FnRnpwdnUxVmFzb0NkV3FmejZlb0kxak9KT2poRnI1VE5waTc3Y1dVR2pPOCtHVDZ4QTA5cUNqRHVsVUxrQnNmSU1ZTHZpSnlTWnJmdEx1V0RXampkZ0FHam5PcHJ0aUh4dGgzK0cwaGp1a
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.993230560424458 |
Encrypted: | false |
SSDEEP: | 48:8tdqTWaPHQidAKZdA1FehwiZUklqehuy+3:8KrOFy |
MD5: | 36724F66C6EC0F324D8C038F9FE9A22D |
SHA1: | 66131D8B39B3AD28F31DD51859808F6A64DA70B2 |
SHA-256: | CB1FC2BE94C13AB5342BEE1811AE5C27A9B9B661A3E9810FE8944C12CCB59158 |
SHA-512: | 8F9469F52053AF4667F816AF9C4B74D0CF33AB76D699017E22D2DD7A2F91270FF466FE87CFC9CCB61726CF410A2D4D2BB8F926DFC1AEA0A46298C9304D297C81 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.0041308897890175 |
Encrypted: | false |
SSDEEP: | 48:8+dqTWaPHQidAKZdA1seh/iZUkAQkqeh1y+2:8fro9Q8y |
MD5: | F6C22C6474B87E91DA247E3ACA471FB4 |
SHA1: | 4514D90B35C17D2A79156AE627388964C0DC459C |
SHA-256: | ABDF08FBB403F4B15E4BDFE2BA554EB1CE9E84A5B61F096065A0369E3F4AAD73 |
SHA-512: | 876EE839B5867D253DFAD6B7F74C6308C5E4313E0B67CE534CBF64B78642F54095E7EA186F1E6531E7B096129D550C7DFEDE0B8122C0DBE92451A7D4DAC67292 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.015299729108377 |
Encrypted: | false |
SSDEEP: | 48:8ydqTWaAHQidAKZdA14meh7sFiZUkmgqeh7sLy+BX:8LrBnZy |
MD5: | 44DAAECE9BEBF2651D7970C9884250B2 |
SHA1: | 1F9A01F53F0BFD789E85D337A3F2190499214378 |
SHA-256: | 41EEA449D5A770716EC03200E3F9D28161848D6461EF5D743415EE6209200D0F |
SHA-512: | A66F15B735F576933B8D4AD70FDDBEEF433346AB52B7A86CCCE0F427AE8F63C6201C3A761B55BEC77877E479DEC16B41A3161D1E55411A591476A87D2EFFBBF5 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.005888295623677 |
Encrypted: | false |
SSDEEP: | 48:8udqTWaPHQidAKZdA1TehDiZUkwqehBy+R:8vrDTy |
MD5: | 00C109470C63679267775FF588CB2E39 |
SHA1: | C2CE70FD2E77048B618B546BFA3DB99F4676F23F |
SHA-256: | 6BFDCD3613FFC5805822D698177E5B09D1D64E50E1C573CDCEE0D19840B75015 |
SHA-512: | 6C977B750E1A68533A63038EB9796D0541F3915DCFBC700AF0B572AC0EB2CDAFF0EE6AB31606FE9A38CE9DF9CE7B2475AD6850427376476BD51CE97F0EFECA1C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9935299167118194 |
Encrypted: | false |
SSDEEP: | 48:8MdqTWaPHQidAKZdA1dehBiZUk1W1qehPy+C:8prz9vy |
MD5: | 74496C52C3D8085DB92ACB15EE8E28F6 |
SHA1: | 6308FE8228BA5B55569F2F38F0DE306A509BEF9C |
SHA-256: | CA3CB52FE4348B647C7E5D187ACBD44813AFC95E2511233261118CC7252E8520 |
SHA-512: | 091360F019CCDBB94D72709B3CBD7E62FA68A1E8AD819B801E1D13A23D4E398F22715F1B1EE5BF42D533D1814E875FF63835837CDB97C3F303DB978AEC7852E9 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.00348499667328 |
Encrypted: | false |
SSDEEP: | 48:8f0dqTWaPHQidAKZdA1duTeehOuTbbiZUk5OjqehOuTbZy+yT+:8ZrXTfTbxWOvTbZy7T |
MD5: | A4CB1410C3136A1038F883B0F0BE389E |
SHA1: | 7B5D84202BA7502D49214D5FE147F2C5AEB58BC6 |
SHA-256: | 40FF6B3416E2444A4A462EDF645FEA505D8B43409E843A3EF48B8720BD997459 |
SHA-512: | 0EE3C02A40AB7EF4086253B0010962549A10762E09B00A56D3076D0C5D50B97445F8091320F84A73FC83FDBD05B9542E3E0C045701662B868C42BBA95745844C |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 43 |
Entropy (8bit): | 3.0950611313667666 |
Encrypted: | false |
SSDEEP: | 3:CUMllRPQEsJ9pse:Gl3QEsJLse |
MD5: | AD4B0F606E0F8465BC4C4C170B37E1A3 |
SHA1: | 50B30FD5F87C85FE5CBA2635CB83316CA71250D7 |
SHA-256: | CF4724B2F736ED1A0AE6BC28F1EAD963D9CD2C1FD87B6EF32E7799FC1C5C8BDA |
SHA-512: | EBFE0C0DF4BCC167D5CB6EBDD379F9083DF62BEF63A23818E1C6ADF0F64B65467EA58B7CD4D03CF0A1B1A2B07FB7B969BF35F25F1F8538CC65CF3EEBDF8A0910 |
Malicious: | false |
Reputation: | low |
URL: | https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcT36PU2foulIDSrKaxiP1dwGwS-jV6qMAkef2CN_Q4&s=10 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1177 |
Entropy (8bit): | 7.435980615451955 |
Encrypted: | false |
SSDEEP: | 24:rQk6holV+H+EurQdij++cNYTDBmsXzD/qyiE0Qth:rr+olV+H+TMijPcyur+ |
MD5: | 79F3E9D4BA05A9A5A22CF07B98E201F0 |
SHA1: | C5ECCA2803F3C2B77BA00050E80297067A30CC1A |
SHA-256: | E16ADB589C3689CCD55E9CB9980A6C5D1EFD161C795EFB0106B02DB492AAC92B |
SHA-512: | 913A179AFC3196394DF0D0E39F3962DF7BA871C201655E75DF2A9667BF45393A3CDACAB0E564BDAEC4B7A4179665865B36731946F05AC23B723E3433E4B58B1C |
Malicious: | false |
Reputation: | low |
URL: | https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSqKrL3Wpc0B2BWes0EZnZcBMySVOV3-5Wr89DXJ0vLfjPWL3KOEsOj5dGn&s=10 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 825 |
Entropy (8bit): | 5.152197519803491 |
Encrypted: | false |
SSDEEP: | 24:2dfFX5WhWBHslgT9lCuABAT3uoB7HHHHHHHYqmffffffo:2d39KlgZ01BAjuSEqmffffffo |
MD5: | 799BD7A9DE56010EA63C2E74A9845D38 |
SHA1: | 85A1A1538791FAE7875F1D54C62D4162C4A4D703 |
SHA-256: | 9CE40676299274D354C7B80F514944EB23C66B938A7CCC0FA4A2F734C4871ECE |
SHA-512: | C1130BB46048A9E36A2A55EB03373F29EFEB6E71BB4B5D459EA866629FF6D2A6F67D12BC5C7CB827EE40E5036B0D923B1C97592F36E6B3F600C2E7739C7DC1D2 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1686 |
Entropy (8bit): | 7.80243208212236 |
Encrypted: | false |
SSDEEP: | 24:qBq26hXV4EPspkkJ1lpc2OrB+JWYkqXrxcTkRi2U3Y+nOI/fBksVTgC1xXX+PZK3:qBqHKEE2kzDOrsPrnGtleC1xt9ao |
MD5: | 87CBE3536916D37D82FF6948C208A955 |
SHA1: | 622E4B5E3354ABFBD96829FA2237CC144A8BD299 |
SHA-256: | 2E0280B01BC51E106B26BB88618C7D15A948AFAD22A0B6AAEEF48482EF2D5FDA |
SHA-512: | 6005C7415AFEBEAAD76A810777396D3C2CE9ECFA6799CB6489359AABAF49CF7E73053D5665E1FAE4A809A5BC0BCE786EC1DD97E1B434C4B0B82A94700AEBAC50 |
Malicious: | false |
Reputation: | low |
URL: | https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSWJm9N8xvgz-ZtW71z3k63vYZzsssi9v1HKD6xMeY&s=10 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 485 |
Entropy (8bit): | 5.346925395723081 |
Encrypted: | false |
SSDEEP: | 12:BMQtJOo9arYffNJWqFuPhViHHr2WTotMTRLRMA4AHWqFuPeIQL:WCqs9gqF2Vo5DV9PV2qFVj |
MD5: | 2C42775B2A328C445B7122B571378437 |
SHA1: | 1C0EFD0B31BC40AA0BCF66EA226A708E1DF98B70 |
SHA-256: | 01A432B43B929122A2C355002BAF21A439B54020A72BF041B481053E3AF0138B |
SHA-512: | 83C8DE2D7061EF37140D671A32082494CDC28808B93E97350C0D0A5BAC9479F21AA95D1BFE26CAAD5A31BA68CAB4CC598F1F7924EBC1F27BD8CBCE4A96860704 |
Malicious: | false |
Reputation: | low |
URL: | https://name10-safelinks-protection-outlook-com-url-atp-redirect.details-info.co/XVTNJOTVUdXQzTjgzNUZYMm9meHV6RHZGTnpRWmZlSlRaOGs3QlVKUlVrTmU5SlU5TXExenpsNHdTUnpiSW4xVTgxU0dZK0FnRnpwdnUxVmFzb0NkV3FmejZlb0kxak9KT2poRnI1VE5waTc3Y1dVR2pPOCtHVDZ4QTA5cUNqRHVsVUxrQnNmSU1ZTHZpSnlTWnJmdEx1V0RXampkZ0FHam5PcHJ0aUh4dGgzK0cwaGp1a |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1113 |
Entropy (8bit): | 7.776571092556926 |
Encrypted: | false |
SSDEEP: | 24:D+F/CmYKCa7HoUzIfVaRFiRtbR0yB8HEmJlSF0iPmIkkQVxXR:DJmhCLKIfVaRAbRJ8kmM03kQx |
MD5: | 3EFA7757BF6E074387349FA1CA0E509D |
SHA1: | 621911A64296D76080B16067BD83169F236640F9 |
SHA-256: | 47B04349A125B9E1A032CE2154C28D1AD3680D98958B688DDC7376EF62B204D0 |
SHA-512: | 4D4B50D6D5386A69C36EE7932505A7D7AF3933720D8BC391F40195BDAAD683F83108F7954A683BB9CAC812799B096BDC9738AB57DDAE52E5F0D6D58BDCE5371C |
Malicious: | false |
Reputation: | low |
URL: | https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQ9cCpmKbEzxyJ8t6HVomYAceZQid-B31klFyVu1-A&s=10 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 716 |
Entropy (8bit): | 6.9229034003986785 |
Encrypted: | false |
SSDEEP: | 12:7PBpAY53Zx//kWVCDN/lBc29Oa/RSw02PZIg5gQfzv9srV3h3Yb0Pn:rQe7VVCDVlYa/RSwtx7Pb9sV3iS |
MD5: | 2F3910B90A5BAC3872B7FC7EA643575D |
SHA1: | 676B8BD81B18833AC0D403B010A4E9379A2C0F42 |
SHA-256: | 78AEF26DEF8ABAFB325D662D7D054141A3B321997E2C6083F6B4F04CAA43E59F |
SHA-512: | 05504AD82BA2BA06B1A30C5DC42A45F033315080C69A5E2E1479BFE916D588277AA00473A59ACB4D841027C925FF224A20F4FD30FEF3BFB2C565A202590DAA3C |
Malicious: | false |
Reputation: | low |
URL: | https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcSD3r_OShaLpePvehRGPESsAN4se3N1_9I3L1KF7xA&s=10 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2308 |
Entropy (8bit): | 5.887828650031636 |
Encrypted: | false |
SSDEEP: | 48:RJeqKlgT82It9kVVU1Avux/Q8mhhHX/qQ/vThQva0AsQCr6yuZsEFJm5QfQY+:RJeZlHHt9idGy8mDHPvT4+bTsr5QfQp |
MD5: | 8CEABA37CC3F2B538EC1F1EE03BD7700 |
SHA1: | F49461D9F14CDD5DA9438CF257B7D9F4B78FCE3D |
SHA-256: | 5653C049D0450CE7C6A7BB17C0920CC9E4D8A1D6AF4C36461477B52C496C46EF |
SHA-512: | 5878C118D18B32FBE6C52574EE3FE3EF769AA1C708144922860CBA543130D4F8013C15C55ED1F29569B4E6F73A5303849D2490ECC72F8C6C4096345678EDC24A |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=det&oit=1&cp=3&pgcl=4&gs_rn=42&psi=szkXRHhDH0lZPj4w&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 20:54:41.498867989 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:54:41.706420898 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:41.706465006 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:41.706521988 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:41.707355976 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:41.707370996 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:41.707802057 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:41.707840919 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:41.707901955 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:41.708131075 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:41.708148003 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:41.801491022 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:54:42.407627106 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:54:42.444478989 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.446389914 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.446410894 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.447140932 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.447302103 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.448204041 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.448271990 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.450275898 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.452394009 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.452502012 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.452565908 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.452598095 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.452739954 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.452753067 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.453249931 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.453310966 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.454287052 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.455169916 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.457652092 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.457741022 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.503633976 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.503648043 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.503726959 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.551563025 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.597469091 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.597563028 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.599809885 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.601124048 CET | 49701 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.601145983 CET | 443 | 49701 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.634879112 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.675334930 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.751899004 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.751983881 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.752181053 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.752648115 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.752667904 CET | 443 | 49702 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.752680063 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.752721071 CET | 49702 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.775860071 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.775893927 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:42.775960922 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.776191950 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:42.776210070 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.276654005 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.276870966 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.276887894 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.277272940 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.277328014 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.278016090 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.278059006 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.278287888 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.278342962 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.278546095 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.278556108 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.333457947 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.411350012 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.411428928 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.411468983 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.412085056 CET | 49703 | 443 | 192.168.2.16 | 3.98.135.159 |
Jan 15, 2025 20:54:43.412103891 CET | 443 | 49703 | 3.98.135.159 | 192.168.2.16 |
Jan 15, 2025 20:54:43.614783049 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:54:45.568615913 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:45.568660975 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:45.568744898 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:45.568933010 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:45.568949938 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:46.021538973 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:54:46.213723898 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:46.214011908 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:46.214027882 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:46.215090990 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:46.215152979 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:46.216233969 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:46.216300011 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:46.261461973 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:46.261468887 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:46.309540033 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:49.667931080 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:54:49.969621897 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:54:50.573525906 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:54:50.827514887 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:54:51.786521912 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:54:54.134699106 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:54:54.198554993 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:54:54.438544989 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:54:55.043528080 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:54:56.119815111 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:56.119895935 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:56.119971991 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:56.243570089 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:54:56.980150938 CET | 49707 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:54:56.980227947 CET | 443 | 49707 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:54:58.655564070 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:54:59.004545927 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:55:00.441514969 CET | 49673 | 443 | 192.168.2.16 | 204.79.197.203 |
Jan 15, 2025 20:55:03.462560892 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:55:08.616576910 CET | 49678 | 443 | 192.168.2.16 | 20.189.173.10 |
Jan 15, 2025 20:55:13.064807892 CET | 49680 | 80 | 192.168.2.16 | 192.229.211.108 |
Jan 15, 2025 20:55:45.623893023 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:45.623964071 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:45.624061108 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:45.624308109 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:45.624327898 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:46.275137901 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:46.275543928 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:46.275574923 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:46.276046991 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:46.276443005 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:46.276529074 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:46.324685097 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:56.226418018 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:56.226486921 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:55:56.226536036 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:56.976257086 CET | 49720 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:55:56.976281881 CET | 443 | 49720 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.298588037 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:40.298625946 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.298885107 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:40.299076080 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:40.299087048 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.952778101 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.953244925 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:40.953306913 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.954881907 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.955353975 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:40.955353975 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:40.955436945 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.955590963 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:40.998013973 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:41.255269051 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:41.256747961 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:41.256966114 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:41.257977009 CET | 49723 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:41.258040905 CET | 443 | 49723 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:42.536364079 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.536456108 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:42.536551952 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.536951065 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.537033081 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:42.724169970 CET | 49725 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.724221945 CET | 443 | 49725 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:42.724292994 CET | 49725 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.724570036 CET | 49725 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.724582911 CET | 443 | 49725 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:42.899286032 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.899382114 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:42.899508953 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.899696112 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:42.899719954 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.201096058 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.202898026 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.202961922 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.204516888 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.204991102 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.205157042 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.205183983 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.205262899 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.247952938 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.382050991 CET | 443 | 49725 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.382308960 CET | 49725 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.382342100 CET | 443 | 49725 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.382823944 CET | 443 | 49725 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.383115053 CET | 49725 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.383198023 CET | 443 | 49725 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.423871040 CET | 49725 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.552670956 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.552787066 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.552859068 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.552920103 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.556209087 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.556359053 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.556440115 CET | 49724 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.556478977 CET | 443 | 49724 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.569401979 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.570033073 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.570094109 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.574640036 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.574768066 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.575043917 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.575164080 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.615977049 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Jan 15, 2025 20:56:43.616036892 CET | 443 | 49726 | 172.217.18.4 | 192.168.2.16 |
Jan 15, 2025 20:56:43.663933039 CET | 49726 | 443 | 192.168.2.16 | 172.217.18.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 20:54:40.763842106 CET | 53 | 57497 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:40.775151014 CET | 53 | 61193 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:41.679390907 CET | 64055 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 20:54:41.681312084 CET | 60859 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 20:54:41.692346096 CET | 53 | 64055 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:41.711461067 CET | 53 | 60859 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:41.745870113 CET | 53 | 51527 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:42.755233049 CET | 61993 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 20:54:42.755356073 CET | 55549 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 20:54:42.765294075 CET | 53 | 61993 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:42.788516045 CET | 53 | 55549 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:45.559204102 CET | 62919 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 20:54:45.559351921 CET | 51945 | 53 | 192.168.2.16 | 1.1.1.1 |
Jan 15, 2025 20:54:45.567167044 CET | 53 | 51945 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:45.567984104 CET | 53 | 62919 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:54:58.679589987 CET | 53 | 62316 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:55:17.410022020 CET | 53 | 60413 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:55:40.010323048 CET | 53 | 60091 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:55:40.714412928 CET | 53 | 58685 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:55:45.837657928 CET | 138 | 138 | 192.168.2.16 | 192.168.2.255 |
Jan 15, 2025 20:56:10.088087082 CET | 53 | 58995 | 1.1.1.1 | 192.168.2.16 |
Jan 15, 2025 20:56:43.567828894 CET | 53 | 60869 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 15, 2025 20:54:41.711519957 CET | 192.168.2.16 | 1.1.1.1 | c27b | (Port unreachable) | Destination Unreachable |
Jan 15, 2025 20:54:42.788580894 CET | 192.168.2.16 | 1.1.1.1 | c27b | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 20:54:41.679390907 CET | 192.168.2.16 | 1.1.1.1 | 0x2e6e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:54:41.681312084 CET | 192.168.2.16 | 1.1.1.1 | 0x3ecb | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:54:42.755233049 CET | 192.168.2.16 | 1.1.1.1 | 0x6bf6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:54:42.755356073 CET | 192.168.2.16 | 1.1.1.1 | 0x84f4 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:54:45.559204102 CET | 192.168.2.16 | 1.1.1.1 | 0xb310 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:54:45.559351921 CET | 192.168.2.16 | 1.1.1.1 | 0x7db6 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 20:54:41.692346096 CET | 1.1.1.1 | 192.168.2.16 | 0x2e6e | No error (0) | 3.98.135.159 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:54:41.692346096 CET | 1.1.1.1 | 192.168.2.16 | 0x2e6e | No error (0) | 3.98.239.58 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:54:41.692346096 CET | 1.1.1.1 | 192.168.2.16 | 0x2e6e | No error (0) | 35.183.149.148 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:54:42.765294075 CET | 1.1.1.1 | 192.168.2.16 | 0x6bf6 | No error (0) | 3.98.135.159 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:54:42.765294075 CET | 1.1.1.1 | 192.168.2.16 | 0x6bf6 | No error (0) | 35.183.149.148 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:54:42.765294075 CET | 1.1.1.1 | 192.168.2.16 | 0x6bf6 | No error (0) | 3.98.239.58 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:54:45.567167044 CET | 1.1.1.1 | 192.168.2.16 | 0x7db6 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 20:54:45.567984104 CET | 1.1.1.1 | 192.168.2.16 | 0xb310 | No error (0) | 172.217.18.4 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49701 | 3.98.135.159 | 443 | 6428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:54:42 UTC | 953 | OUT | |
2025-01-15 19:54:42 UTC | 574 | IN | |
2025-01-15 19:54:42 UTC | 485 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49702 | 3.98.135.159 | 443 | 6428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:54:42 UTC | 938 | OUT | |
2025-01-15 19:54:42 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.16 | 49703 | 3.98.135.159 | 443 | 6428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:54:43 UTC | 407 | OUT | |
2025-01-15 19:54:43 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.16 | 49723 | 172.217.18.4 | 443 | 6428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:56:40 UTC | 613 | OUT | |
2025-01-15 19:56:41 UTC | 1266 | IN | |
2025-01-15 19:56:41 UTC | 124 | IN | |
2025-01-15 19:56:41 UTC | 708 | IN | |
2025-01-15 19:56:41 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.16 | 49724 | 172.217.18.4 | 443 | 6428 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:56:43 UTC | 649 | OUT | |
2025-01-15 19:56:43 UTC | 1266 | IN | |
2025-01-15 19:56:43 UTC | 124 | IN | |
2025-01-15 19:56:43 UTC | 1390 | IN | |
2025-01-15 19:56:43 UTC | 801 | IN | |
2025-01-15 19:56:43 UTC | 5 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 14:54:38 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 14:54:39 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 14:54:40 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f9810000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |