Windows
Analysis Report
http://details.co
Overview
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 6256 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA) - chrome.exe (PID: 6864 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2200 --fi eld-trial- handle=192 8,i,152931 1758305639 5098,12545 6459469667 39969,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- chrome.exe (PID: 6628 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://detail s.co" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
details.co | 35.243.228.36 | true | false | high | |
code.jquery.com | 151.101.2.137 | true | false | high | |
www.google.com | 216.58.206.36 | true | false | high | |
www.godaddy.com | unknown | unknown | false | high | |
img6.wsimg.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
151.101.2.137 | code.jquery.com | United States | 54113 | FASTLYUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
35.243.228.36 | details.co | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.17 |
192.168.2.18 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1592160 |
Start date and time: | 2025-01-15 20:57:15 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://details.co |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@19/15@18/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, TextInputHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.18.3, 142.251.168.84, 142.250.186.78, 142.250.185.110, 2.23.196.52, 95.100.110.86, 95.100.110.77, 142.250.181.238, 2.21.65.216, 2.21.65.215, 2.23.77.188, 172.217.18.110, 142.250.186.46, 142.250.185.238, 142.250.186.163, 142.250.185.174, 142.250.185.78, 142.250.184.238, 142.250.185.206, 172.202.163.200, 88.221.168.226, 23.219.128.174, 40.126.31.67, 13.107.5.88, 2.23.227.215
- Excluded domains from analysis (whitelisted): www.bing.com, clients1.google.com, e40258.g.akamaiedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, e6001.dscx.akamaiedge.net, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, wildcard-ipv6.godaddy.com.edgekey.net, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, login.live.com, evoke-windowsservices-tas.msedge.net, update.googleapis.com, clients.l.google.com, global-wildcard.wsimg.com.sni-only.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: http://details.co
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9928846322468083 |
Encrypted: | false |
SSDEEP: | 48:8Opd3Tw7lFHOidAKZdA1JehwiZUklqehLy+3:8OzQuky |
MD5: | 80E32579D42239339D60FE5E2F7ADF3F |
SHA1: | 38578CC04D5CB39ACD21578AB1749B89F9E7FA33 |
SHA-256: | ECD05C974299F29D3978249CB504EF52614AA267AF33C73EB139AF692BEEEA19 |
SHA-512: | 3BEAFC5DF83E9B87FC191FBC87ED193288F2830F1685477C8ACB668E8E944952309DB9C4F2B4FCEA9099A61E314449E1CD69BC16E4B5FD299FC55BB3A1BFACEE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.0076429935122615 |
Encrypted: | false |
SSDEEP: | 48:8pkpd3Tw7lFHOidAKZdA10eh/iZUkAQkqehUy+2:8uzQc9QBy |
MD5: | AFA7CFC577A9D6FD85FECAE35A07C2B7 |
SHA1: | D817EB64BCBD171115D4359FBB9B2AC0EF117408 |
SHA-256: | E96508FD6E27156AFF74F47F67FA28EF21F888016BC4351247610CE56B0D34DB |
SHA-512: | 0B99EDBD0C6BC0E1D422A0EC7F54AFF8D794311D069F26A6BB918BC45E1A8AB763DC44837BF34CA0A8E38A2314FF8B42BE6EC06F93E985C0877DEFB02AAF2F9C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.017574118608054 |
Encrypted: | false |
SSDEEP: | 48:8epd3Tw7ljHOidAKZdA14tIeh7sFiZUkmgqeh7sSy+BX:8ezQenoy |
MD5: | 6AFEA298874EB08340211BC06FD66442 |
SHA1: | 89146747D6B20F307D39CDF677D629BF716B883A |
SHA-256: | 2F563D0AEBE236D85205B8B3A74B071D93E17D0469B063FE18EE2D5C6BCC03F9 |
SHA-512: | 8CAA6EB19B3E4AB72335F10F028313978411D62CF7FBB716D75A6D56B361A63B02BF84C6E3968B41397A0A0E7C7B4F59A185F7196B5DBD9596F43436301E5ECE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 4.00572814540714 |
Encrypted: | false |
SSDEEP: | 48:80pd3Tw7lFHOidAKZdA1behDiZUkwqehAy+R:80zQXKy |
MD5: | 98272DEC1C9A964E0F29A2B5C3EF9793 |
SHA1: | 049793466C6964324BC5DABE0FB21E5A4FEB1AC0 |
SHA-256: | E15083517D7F002C274C12FB1CD9B34D239C52FC6869264B38A9B9454FCB4245 |
SHA-512: | ED64DF26A9D49A6F9066F8D33D929A0C60100ECBE0FC19C4831C1B3D74A425ACAD6D030A812E69C980E22A45136963F4E138A971EB0625B954FA82B9347A9D7C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9955221793120406 |
Encrypted: | false |
SSDEEP: | 48:8rpd3Tw7lFHOidAKZdA1VehBiZUk1W1qehWy+C:8rzQn92y |
MD5: | C7121264AC905016D1BA921A37A5448D |
SHA1: | 4F1006FDD37BFBC3ED321B489A4966CFC4242089 |
SHA-256: | 9B532FB8B4F3272653AE87672C7187EAF361FE87A56CC62DE085BB482200CC38 |
SHA-512: | BCCB9B396A42BBD9B6001DA79340A3701E75C3E96DCF3D6F4AE2F4385535E08DB4585C1B200255AFB3FB1B5E6CB0EEC881D2802D6DBD8F53C3CB49BF77DC5629 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 4.007811282566865 |
Encrypted: | false |
SSDEEP: | 48:8Mjpd3Tw7lFHOidAKZdA1duT6ehOuTbbiZUk5OjqehOuTboy+yT+:8QzQjTTTbxWOvTboy7T |
MD5: | 71DA560752B63EE467A69E61ECB892D1 |
SHA1: | 41734C4B24936EEE47F0C2BB0D2839D1CF1529CB |
SHA-256: | 5977BBC6015597D71638620E08F08BBE166FC10A9E4478D7F3AF8B380B449DCD |
SHA-512: | F8B46716EE0D061F31B985107898FB763F92691100BA36AC3A6B382CF6271A3EA9960E37BD74B44BEC355EF1749DF0A5CEFA48F966C4E8471247C5CC59DD150D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 89476 |
Entropy (8bit): | 5.2896589255084425 |
Encrypted: | false |
SSDEEP: | 1536:AjExXUqrnxDjoXEZxkMV4SYSt0zvDD6ip3h8cApwEjOPrBeU6QLiTFbc0QlQvakF:AYh8eip3huuf6IidlrvakdtQ47GK1 |
MD5: | DC5E7F18C8D36AC1D3D4753A87C98D0A |
SHA1: | C8E1C8B386DC5B7A9184C763C88D19A346EB3342 |
SHA-256: | F7F6A5894F1D19DDAD6FA392B2ECE2C5E578CBF7DA4EA805B6885EB6985B6E3D |
SHA-512: | 6CB4F4426F559C06190DF97229C05A436820D21498350AC9F118A5625758435171418A022ED523BAE46E668F9F8EA871FEAB6AFF58AD2740B67A30F196D65516 |
Malicious: | false |
Reputation: | low |
URL: | https://code.jquery.com/jquery-3.5.1.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89476 |
Entropy (8bit): | 5.2896589255084425 |
Encrypted: | false |
SSDEEP: | 1536:AjExXUqrnxDjoXEZxkMV4SYSt0zvDD6ip3h8cApwEjOPrBeU6QLiTFbc0QlQvakF:AYh8eip3huuf6IidlrvakdtQ47GK1 |
MD5: | DC5E7F18C8D36AC1D3D4753A87C98D0A |
SHA1: | C8E1C8B386DC5B7A9184C763C88D19A346EB3342 |
SHA-256: | F7F6A5894F1D19DDAD6FA392B2ECE2C5E578CBF7DA4EA805B6885EB6985B6E3D |
SHA-512: | 6CB4F4426F559C06190DF97229C05A436820D21498350AC9F118A5625758435171418A022ED523BAE46E668F9F8EA871FEAB6AFF58AD2740B67A30F196D65516 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15086 |
Entropy (8bit): | 2.958559883129887 |
Encrypted: | false |
SSDEEP: | 96:jqpSLDaGwTNg6TlxKLBge3le1xAWdT6pzN3JdxcbP9w:j/LDaJT+QQBgKsxAiGDJdxG1w |
MD5: | E7158D9A3E45E62B33B2F0DEF91F4E53 |
SHA1: | DEE20D866774F939FB784EE74EFE47480F83F97F |
SHA-256: | FCB1491FDAE7ED692CD88A483DACF6D0457AD72AC1BE93C95B6BC5CF122B925A |
SHA-512: | 8B528A3BF4FCDBEF7CCBD863743703F904BC754C8205864B386B73F44A70F8E7CD126ECD402C8B082AF79B84B950A07CC6128AAAEB7B89EEBFE87E7E3F3EA82F |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 862 |
Entropy (8bit): | 5.468327554319824 |
Encrypted: | false |
SSDEEP: | 12:hnMEwuiuX4wpBdZrJ4xk3qJmWG4XGS1kAAqJmntTgrHhD5CQtvsEykAAqJm7+xRQ:hMNmlBDJvMi4Xt1vP5D5NMvPHr1okrC |
MD5: | 0D0330D08668FB92310C1766EFB13E65 |
SHA1: | 8507C1D7A03E90080663D26136B02FFA90E21B95 |
SHA-256: | B7B471B6B49847B4A1E51B4ECF86D1C5FA405A7AAD8A22F077077D47AB04485F |
SHA-512: | EA36273DF0DE1976075FB1B2D7BCC318E71F6D386EA8C08D4A1FC0BF920181F227379AB31802DE5F398D64D0F38BD8E3463C581EF92B9582299C5F3D55E98D7D |
Malicious: | false |
Reputation: | low |
URL: | https://details.co/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4981 |
Entropy (8bit): | 4.99103897898732 |
Encrypted: | false |
SSDEEP: | 96:T+3sq2ixgj/BH6qwxSFS+6k2ZGbLafRuBKowE:a3sqLxgj/tUxSFS+VbLafRuBKor |
MD5: | 07F76B7A656C97CB7F72E0C9F50894F4 |
SHA1: | 1F5CDE6AC9C12CCB7B7A52A5EA85627DA50D1B96 |
SHA-256: | 0235CB5FD5C3EBC72E25EA090C1B1867ED6535303916A841F4C1B6DCCE0F651F |
SHA-512: | F7144C5D1F53D5FF6F45FA66AE3FD4F7F358077656C09AB633E25B65F791A4CB47CE47634EDE3A75A94657930049218938D2575D7288873D3BD4B96DF2F6267A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 15086 |
Entropy (8bit): | 2.958559883129887 |
Encrypted: | false |
SSDEEP: | 96:jqpSLDaGwTNg6TlxKLBge3le1xAWdT6pzN3JdxcbP9w:j/LDaJT+QQBgKsxAiGDJdxG1w |
MD5: | E7158D9A3E45E62B33B2F0DEF91F4E53 |
SHA1: | DEE20D866774F939FB784EE74EFE47480F83F97F |
SHA-256: | FCB1491FDAE7ED692CD88A483DACF6D0457AD72AC1BE93C95B6BC5CF122B925A |
SHA-512: | 8B528A3BF4FCDBEF7CCBD863743703F904BC754C8205864B386B73F44A70F8E7CD126ECD402C8B082AF79B84B950A07CC6128AAAEB7B89EEBFE87E7E3F3EA82F |
Malicious: | false |
Reputation: | low |
URL: | https://img6.wsimg.com/ux/favicon/favicon.ico |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 20:57:46.950386047 CET | 49677 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:57:46.950519085 CET | 49676 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:57:46.950520039 CET | 49678 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:57:50.549981117 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:50.550023079 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:50.550093889 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:50.550367117 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:50.550388098 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:50.699136972 CET | 49707 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:50.699345112 CET | 49708 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:50.704104900 CET | 80 | 49707 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:50.704159975 CET | 80 | 49708 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:50.704209089 CET | 49707 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:50.704246044 CET | 49708 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.189032078 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.189376116 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.189403057 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.190496922 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.190568924 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.191679001 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.191754103 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.191915989 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.191927910 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.241786003 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.316421032 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.316548109 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.316605091 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.320266962 CET | 49706 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:51.320292950 CET | 443 | 49706 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:51.370942116 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.371057987 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.371149063 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.371428013 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.371453047 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.831461906 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.831825972 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.831861019 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.833278894 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.833370924 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.835081100 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.835172892 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.835361958 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.835371971 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.881242037 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.929678917 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.929971933 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930013895 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930048943 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930068970 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.930135965 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930156946 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.930310011 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930358887 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930378914 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.930389881 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.930452108 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.930460930 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.931157112 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.931190968 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.931220055 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.931231022 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.931528091 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:51.951267004 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:51.993243933 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.016666889 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.016751051 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.016886950 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.016951084 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.016987085 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.017080069 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.017124891 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.017210960 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.017246962 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.017261982 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.017271042 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.017385960 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.017986059 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.018095970 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.018127918 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.018151999 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.018160105 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.018201113 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.018250942 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.018259048 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.018311024 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.018908978 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.019068956 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.019104958 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.019130945 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.019140959 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.019186020 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.019192934 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.020499945 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.020538092 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.020562887 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.020570040 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.020617962 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.020626068 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.020633936 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.020679951 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.103980064 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.103995085 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.104089022 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.104096889 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.104140043 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.104182959 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.104212999 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.105521917 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.105541945 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.105582952 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.105592012 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.105626106 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.105645895 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.105710030 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.105773926 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.105782032 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.105808020 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.105859995 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.106393099 CET | 49709 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.106412888 CET | 443 | 49709 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.121660948 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.121731997 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.121942997 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.123235941 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.123255014 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.123696089 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.123756886 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.123842955 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.124279976 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.124293089 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.601264954 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.601658106 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.601691961 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.603100061 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.603188992 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.603640079 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.603712082 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.603861094 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.622509003 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.622857094 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.622903109 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.623395920 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.623754978 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.623842001 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.623924971 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.645276070 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.645329952 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.667351961 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.693367004 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.701683044 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.701776028 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.701817989 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.701854944 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.701900005 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.701900959 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.701921940 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.701946974 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.701975107 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.702013016 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.704499006 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.704567909 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.704574108 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.707473993 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.707516909 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.707532883 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.707540989 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.707859039 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.707864046 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.756246090 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.791873932 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.791889906 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.791939974 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.791956902 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.791973114 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.791989088 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.792021036 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.792037964 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.792047024 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.792062998 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.794250965 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.794272900 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.794325113 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.794348001 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.794367075 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.794394016 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.818598032 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.818692923 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.819830894 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.819951057 CET | 49710 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:52.819972038 CET | 443 | 49710 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:52.875453949 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.875490904 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.875735998 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.875765085 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.875822067 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.877660990 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.877682924 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.877734900 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.877748013 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.877768993 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.877785921 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.878515005 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.878582954 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.878592968 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.878618002 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:52.878664017 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.878921986 CET | 49711 | 443 | 192.168.2.17 | 151.101.2.137 |
Jan 15, 2025 20:57:52.878940105 CET | 443 | 49711 | 151.101.2.137 | 192.168.2.17 |
Jan 15, 2025 20:57:53.037210941 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.037278891 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.037425995 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.037744045 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.037763119 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.533700943 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.534094095 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.534137964 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.535615921 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.535741091 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.536012888 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.536169052 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.536170006 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.583342075 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.598315001 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:53.598350048 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:53.649343967 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:54.421847105 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:54.421907902 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:54.421998024 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:54.422193050 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:54.422204971 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:55.111707926 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:55.111927986 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:55.111957073 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:55.113416910 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:55.113492966 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:55.114790916 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:55.114921093 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:55.157248020 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:55.157279015 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:57:55.205241919 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:57:56.073487043 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:56.073513985 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:56.073523998 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:56.073576927 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:56.073606968 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:56.073623896 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:57:56.073671103 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:56.074625969 CET | 49714 | 443 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:57:56.074640036 CET | 443 | 49714 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:58:04.978703976 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:04.978790045 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:04.979029894 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:05.908839941 CET | 49717 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:05.908876896 CET | 443 | 49717 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:06.298896074 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:06.599543095 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:07.206486940 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:08.419343948 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:10.445750952 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:10.749495029 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:10.829379082 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:11.355427027 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:12.569538116 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:14.974427938 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:15.630423069 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:18.908678055 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:19.211493015 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:19.786453009 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:19.818468094 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:21.031502962 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:23.439445019 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:25.242543936 CET | 49675 | 443 | 192.168.2.17 | 204.79.197.203 |
Jan 15, 2025 20:58:28.243459940 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:29.395495892 CET | 49680 | 443 | 192.168.2.17 | 20.189.173.13 |
Jan 15, 2025 20:58:29.841806889 CET | 49694 | 80 | 192.168.2.17 | 199.232.214.172 |
Jan 15, 2025 20:58:29.846937895 CET | 80 | 49694 | 199.232.214.172 | 192.168.2.17 |
Jan 15, 2025 20:58:29.847073078 CET | 49694 | 80 | 192.168.2.17 | 199.232.214.172 |
Jan 15, 2025 20:58:35.718488932 CET | 49708 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:58:35.718491077 CET | 49707 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:58:35.723372936 CET | 80 | 49708 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:58:35.723397017 CET | 80 | 49707 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:58:37.857705116 CET | 49682 | 80 | 192.168.2.17 | 192.229.211.108 |
Jan 15, 2025 20:58:39.407638073 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.412862062 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.504767895 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.504839897 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.507774115 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.507924080 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.508198977 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.508476973 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.512645960 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.512887955 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.512917995 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.513125896 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.513283014 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.601679087 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.601733923 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:39.730901003 CET | 443 | 49691 | 204.79.197.200 | 192.168.2.17 |
Jan 15, 2025 20:58:39.730962038 CET | 49691 | 443 | 192.168.2.17 | 204.79.197.200 |
Jan 15, 2025 20:58:51.899102926 CET | 49708 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:58:51.899183035 CET | 49707 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:58:51.904198885 CET | 80 | 49708 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:58:51.904270887 CET | 49708 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:58:51.905297995 CET | 80 | 49707 | 35.243.228.36 | 192.168.2.17 |
Jan 15, 2025 20:58:51.905349016 CET | 49707 | 80 | 192.168.2.17 | 35.243.228.36 |
Jan 15, 2025 20:58:54.468704939 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:54.468729973 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:54.468832016 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:54.469059944 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:54.469072104 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:55.119678974 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:55.120070934 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:55.120095015 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:55.120460987 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:55.120769978 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:58:55.120831966 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:58:55.170608997 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:59:05.020908117 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:59:05.021080971 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:59:05.021200895 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:59:05.909543991 CET | 49730 | 443 | 192.168.2.17 | 216.58.206.36 |
Jan 15, 2025 20:59:05.909574986 CET | 443 | 49730 | 216.58.206.36 | 192.168.2.17 |
Jan 15, 2025 20:59:17.436029911 CET | 49692 | 80 | 192.168.2.17 | 199.232.214.172 |
Jan 15, 2025 20:59:17.443686008 CET | 80 | 49692 | 199.232.214.172 | 192.168.2.17 |
Jan 15, 2025 20:59:17.443785906 CET | 49692 | 80 | 192.168.2.17 | 199.232.214.172 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 20:57:49.601573944 CET | 53 | 54628 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:49.623686075 CET | 53 | 64150 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:50.319911957 CET | 53627 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:50.320173025 CET | 64052 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:50.329049110 CET | 65346 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:50.329426050 CET | 64764 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:50.538110018 CET | 53 | 64052 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:50.542438984 CET | 53 | 64764 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:50.549416065 CET | 53 | 65346 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:50.620122910 CET | 53 | 56475 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:50.698105097 CET | 53 | 53627 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:51.362587929 CET | 51122 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:51.362871885 CET | 55412 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:51.369652033 CET | 53 | 51122 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:51.370210886 CET | 53 | 55412 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:52.111716032 CET | 50549 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:52.111884117 CET | 54642 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:52.118623972 CET | 53 | 54642 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:52.121371031 CET | 53 | 50549 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:52.127923012 CET | 59893 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:52.128582954 CET | 65146 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:52.823115110 CET | 60452 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:52.823412895 CET | 54156 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:53.034724951 CET | 53 | 54156 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:53.036551952 CET | 53 | 60452 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:53.362874985 CET | 59152 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:53.363157034 CET | 59201 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:54.376184940 CET | 49825 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:54.376322031 CET | 60142 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:54.413249969 CET | 60291 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:54.413408041 CET | 52931 | 53 | 192.168.2.17 | 1.1.1.1 |
Jan 15, 2025 20:57:54.420581102 CET | 53 | 60291 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:57:54.421030998 CET | 53 | 52931 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:58:07.613707066 CET | 53 | 54580 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:58:26.403942108 CET | 53 | 56420 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:58:48.824862957 CET | 53 | 63389 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:58:49.576556921 CET | 53 | 55941 | 1.1.1.1 | 192.168.2.17 |
Jan 15, 2025 20:59:07.670553923 CET | 138 | 138 | 192.168.2.17 | 192.168.2.255 |
Jan 15, 2025 20:59:19.312239885 CET | 53 | 50882 | 1.1.1.1 | 192.168.2.17 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 20:57:50.319911957 CET | 192.168.2.17 | 1.1.1.1 | 0xb55e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:50.320173025 CET | 192.168.2.17 | 1.1.1.1 | 0x7934 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:50.329049110 CET | 192.168.2.17 | 1.1.1.1 | 0xfa8d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:50.329426050 CET | 192.168.2.17 | 1.1.1.1 | 0x3c4c | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:51.362587929 CET | 192.168.2.17 | 1.1.1.1 | 0x5d1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:51.362871885 CET | 192.168.2.17 | 1.1.1.1 | 0xe271 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:52.111716032 CET | 192.168.2.17 | 1.1.1.1 | 0x2ff4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:52.111884117 CET | 192.168.2.17 | 1.1.1.1 | 0x8199 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:52.127923012 CET | 192.168.2.17 | 1.1.1.1 | 0x2ee0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:52.128582954 CET | 192.168.2.17 | 1.1.1.1 | 0xcc3f | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:52.823115110 CET | 192.168.2.17 | 1.1.1.1 | 0x4862 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:52.823412895 CET | 192.168.2.17 | 1.1.1.1 | 0xe44a | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:53.362874985 CET | 192.168.2.17 | 1.1.1.1 | 0x4b92 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:53.363157034 CET | 192.168.2.17 | 1.1.1.1 | 0xac3a | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:54.376184940 CET | 192.168.2.17 | 1.1.1.1 | 0x622 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:54.376322031 CET | 192.168.2.17 | 1.1.1.1 | 0x6e3d | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 20:57:54.413249969 CET | 192.168.2.17 | 1.1.1.1 | 0xf413 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 20:57:54.413408041 CET | 192.168.2.17 | 1.1.1.1 | 0x1dcc | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 20:57:50.549416065 CET | 1.1.1.1 | 192.168.2.17 | 0xfa8d | No error (0) | 35.243.228.36 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:50.698105097 CET | 1.1.1.1 | 192.168.2.17 | 0xb55e | No error (0) | 35.243.228.36 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:51.369652033 CET | 1.1.1.1 | 192.168.2.17 | 0x5d1 | No error (0) | 151.101.2.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:51.369652033 CET | 1.1.1.1 | 192.168.2.17 | 0x5d1 | No error (0) | 151.101.66.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:51.369652033 CET | 1.1.1.1 | 192.168.2.17 | 0x5d1 | No error (0) | 151.101.194.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:51.369652033 CET | 1.1.1.1 | 192.168.2.17 | 0x5d1 | No error (0) | 151.101.130.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:52.121371031 CET | 1.1.1.1 | 192.168.2.17 | 0x2ff4 | No error (0) | 151.101.2.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:52.121371031 CET | 1.1.1.1 | 192.168.2.17 | 0x2ff4 | No error (0) | 151.101.66.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:52.121371031 CET | 1.1.1.1 | 192.168.2.17 | 0x2ff4 | No error (0) | 151.101.130.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:52.121371031 CET | 1.1.1.1 | 192.168.2.17 | 0x2ff4 | No error (0) | 151.101.194.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:52.135612965 CET | 1.1.1.1 | 192.168.2.17 | 0x2ee0 | No error (0) | wildcard-ipv6.godaddy.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:52.135900021 CET | 1.1.1.1 | 192.168.2.17 | 0xcc3f | No error (0) | wildcard-ipv6.godaddy.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:53.036551952 CET | 1.1.1.1 | 192.168.2.17 | 0x4862 | No error (0) | 35.243.228.36 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:53.370969057 CET | 1.1.1.1 | 192.168.2.17 | 0xac3a | No error (0) | global-wildcard.wsimg.com.sni-only.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:53.372126102 CET | 1.1.1.1 | 192.168.2.17 | 0x4b92 | No error (0) | global-wildcard.wsimg.com.sni-only.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:54.383702993 CET | 1.1.1.1 | 192.168.2.17 | 0x6e3d | No error (0) | global-wildcard.wsimg.com.sni-only.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:54.387895107 CET | 1.1.1.1 | 192.168.2.17 | 0x622 | No error (0) | global-wildcard.wsimg.com.sni-only.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:54.420581102 CET | 1.1.1.1 | 192.168.2.17 | 0xf413 | No error (0) | 216.58.206.36 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 20:57:54.421030998 CET | 1.1.1.1 | 192.168.2.17 | 0x1dcc | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.17 | 49708 | 35.243.228.36 | 80 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 15, 2025 20:58:35.718488932 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.17 | 49707 | 35.243.228.36 | 80 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 15, 2025 20:58:35.718491077 CET | 6 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.17 | 49706 | 35.243.228.36 | 443 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:57:51 UTC | 653 | OUT | |
2025-01-15 19:57:51 UTC | 240 | IN | |
2025-01-15 19:57:51 UTC | 862 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.17 | 49709 | 151.101.2.137 | 443 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:57:51 UTC | 553 | OUT | |
2025-01-15 19:57:51 UTC | 613 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN | |
2025-01-15 19:57:51 UTC | 1378 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.17 | 49711 | 151.101.2.137 | 443 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:57:52 UTC | 358 | OUT | |
2025-01-15 19:57:52 UTC | 613 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN | |
2025-01-15 19:57:52 UTC | 1378 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.17 | 49710 | 35.243.228.36 | 443 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:57:52 UTC | 663 | OUT | |
2025-01-15 19:57:52 UTC | 64 | OUT | |
2025-01-15 19:57:52 UTC | 240 | IN | |
2025-01-15 19:57:52 UTC | 134 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.17 | 49714 | 35.243.228.36 | 443 | 6864 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 19:57:53 UTC | 349 | OUT | |
2025-01-15 19:57:56 UTC | 260 | IN | |
2025-01-15 19:57:56 UTC | 4981 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 14:57:47 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d6f10000 |
File size: | 3'242'272 bytes |
MD5 hash: | 83395EAB5B03DEA9720F8D7AC0D15CAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 14:57:48 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d6f10000 |
File size: | 3'242'272 bytes |
MD5 hash: | 83395EAB5B03DEA9720F8D7AC0D15CAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 14:57:49 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d6f10000 |
File size: | 3'242'272 bytes |
MD5 hash: | 83395EAB5B03DEA9720F8D7AC0D15CAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |