Windows
Analysis Report
https://roberthood.net/me/young/quak/bizmail.php/
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 5008 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 6228 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2216 --fi eld-trial- handle=214 8,i,146841 9583963318 0778,14619 9217076178 28709,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- chrome.exe (PID: 6872 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://rober thood.net/ me/young/q uak/bizmai l.php/" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-16T00:53:56.108269+0100 | 2812237 | 1 | Successful Credential Theft Detected | 192.168.2.6 | 49856 | 72.18.194.32 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Directory created: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Directory created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 2 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
roberthood.net | 72.18.194.32 | true | true | unknown | |
www.google.com | 142.250.185.132 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true |
| unknown | |
true | unknown | ||
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
72.18.194.32 | roberthood.net | United States | 26277 | PREMIANETUS | true |
IP |
---|
192.168.2.6 |
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1592308 |
Start date and time: | 2025-01-16 00:52:37 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://roberthood.net/me/young/quak/bizmail.php/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal60.win@16/12@6/5 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.99, 142.250.186.142, 142.250.110.84, 216.58.212.174, 142.250.186.110, 142.250.185.170, 142.250.186.170, 172.217.18.10, 142.250.185.106, 142.250.186.42, 142.250.184.234, 216.58.206.74, 172.217.16.202, 142.250.185.138, 172.217.18.106, 142.250.74.202, 216.58.212.138, 142.250.185.74, 142.250.185.202, 142.250.186.74, 142.250.185.234, 184.30.131.245, 199.232.210.172, 172.217.23.110, 142.250.181.238, 142.250.185.110, 142.250.186.46, 142.250.184.238, 172.217.16.206, 142.250.185.78, 142.250.185.142, 216.58.206.46, 13.107.246.45, 184.28.90.27, 4.245.163.56
- Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://roberthood.net/me/young/quak/bizmail.php/
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2194 |
Entropy (8bit): | 5.7899045267699165 |
Encrypted: | false |
SSDEEP: | 48:K1wim4yNLK5sLZxDOg4zwz0kyBDu4zwASLrx/9yTGjYssssssssssssssssssssj:5imvhIMO7Vk0dYPx/9KP |
MD5: | D06ABFB359AC6C91C986759370559251 |
SHA1: | 496BE551E13C4BCBDC7DE87F9B75DF5CD8CAB05E |
SHA-256: | FD2469CEC0BF5A2D632FDDE8BA2106E938D013A91D2DCBD8F476F4B90894A503 |
SHA-512: | FC83C23FC0AC2B7A08AA549328CB8CE13F0FCA47F28CD8DB815983094CE861988B3D8E92A1873971F7850B69965415D2E3A75973D866B496B8F95EAE185D9438 |
Malicious: | false |
Reputation: | low |
URL: | https://roberthood.net/me/young/quak/bizmail.php/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2194 |
Entropy (8bit): | 5.7899045267699165 |
Encrypted: | false |
SSDEEP: | 48:K1wim4yNLK5sLZxDOg4zwz0kyBDu4zwASLrx/9yTGjYssssssssssssssssssssj:5imvhIMO7Vk0dYPx/9KP |
MD5: | D06ABFB359AC6C91C986759370559251 |
SHA1: | 496BE551E13C4BCBDC7DE87F9B75DF5CD8CAB05E |
SHA-256: | FD2469CEC0BF5A2D632FDDE8BA2106E938D013A91D2DCBD8F476F4B90894A503 |
SHA-512: | FC83C23FC0AC2B7A08AA549328CB8CE13F0FCA47F28CD8DB815983094CE861988B3D8E92A1873971F7850B69965415D2E3A75973D866B496B8F95EAE185D9438 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 28 |
Entropy (8bit): | 4.378783493486175 |
Encrypted: | false |
SSDEEP: | 3:qinPt:qyPt |
MD5: | 4C42AB4890733A2B01B1B3269C4855E7 |
SHA1: | 5B68BFE664DCBC629042EA45C23954EEF1A9F698 |
SHA-256: | F69E8FC1414A82F108CFA0725E5211AF1865A9CEA342A5F01E6B2B5ABE47E010 |
SHA-512: | 0631C6EFD555699CB2273107FE5AF565FEC2234344E2D412C23E4EE43C6D721CB2B058764622E44FD544D840FF64D7C866565E280127C701CAAB0A48C35D4F5C |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzQSFwn84getxWcRPRIFDYOoWz0SBQ3OQUx6?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2194 |
Entropy (8bit): | 5.7899045267699165 |
Encrypted: | false |
SSDEEP: | 48:K1wim4yNLK5sLZxDOg4zwz0kyBDu4zwASLrx/9yTGjYssssssssssssssssssssj:5imvhIMO7Vk0dYPx/9KP |
MD5: | D06ABFB359AC6C91C986759370559251 |
SHA1: | 496BE551E13C4BCBDC7DE87F9B75DF5CD8CAB05E |
SHA-256: | FD2469CEC0BF5A2D632FDDE8BA2106E938D013A91D2DCBD8F476F4B90894A503 |
SHA-512: | FC83C23FC0AC2B7A08AA549328CB8CE13F0FCA47F28CD8DB815983094CE861988B3D8E92A1873971F7850B69965415D2E3A75973D866B496B8F95EAE185D9438 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2194 |
Entropy (8bit): | 5.7899045267699165 |
Encrypted: | false |
SSDEEP: | 48:K1wim4yNLK5sLZxDOg4zwz0kyBDu4zwASLrx/9yTGjYssssssssssssssssssssj:5imvhIMO7Vk0dYPx/9KP |
MD5: | D06ABFB359AC6C91C986759370559251 |
SHA1: | 496BE551E13C4BCBDC7DE87F9B75DF5CD8CAB05E |
SHA-256: | FD2469CEC0BF5A2D632FDDE8BA2106E938D013A91D2DCBD8F476F4B90894A503 |
SHA-512: | FC83C23FC0AC2B7A08AA549328CB8CE13F0FCA47F28CD8DB815983094CE861988B3D8E92A1873971F7850B69965415D2E3A75973D866B496B8F95EAE185D9438 |
Malicious: | false |
Reputation: | low |
URL: | https://roberthood.net/me/young/quak/bizmail.php/img/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2204 |
Entropy (8bit): | 5.806332564455325 |
Encrypted: | false |
SSDEEP: | 48:K1wim4yNLK5sLZxDOg4zwz0kyBeu4zwASLrx/9yTGjYssssssssssssssssssssj:5imvhIMO7Vk0kYPx/9KP |
MD5: | CC05AEF39AE05AB4DBBE8E641989714B |
SHA1: | CA5EE7BA10D28B291A32B5B734ABD8899F48F169 |
SHA-256: | CBE25C132CF80F4CCCA7816B78C36C478EF3DB521D35CE02F084A47D0B4C0F9D |
SHA-512: | A6B47F21B1025589664BCEF6E320DAF5A55650BA0FDC5BB9EFD62B84D442040B23FD38A0B24366329173A14E757557C66C8FF4FE633E7157151BD0BA303B5D06 |
Malicious: | false |
Reputation: | low |
URL: | https://roberthood.net/me/young/quak/bizmail.php/next.php |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2194 |
Entropy (8bit): | 5.7899045267699165 |
Encrypted: | false |
SSDEEP: | 48:K1wim4yNLK5sLZxDOg4zwz0kyBDu4zwASLrx/9yTGjYssssssssssssssssssssj:5imvhIMO7Vk0dYPx/9KP |
MD5: | D06ABFB359AC6C91C986759370559251 |
SHA1: | 496BE551E13C4BCBDC7DE87F9B75DF5CD8CAB05E |
SHA-256: | FD2469CEC0BF5A2D632FDDE8BA2106E938D013A91D2DCBD8F476F4B90894A503 |
SHA-512: | FC83C23FC0AC2B7A08AA549328CB8CE13F0FCA47F28CD8DB815983094CE861988B3D8E92A1873971F7850B69965415D2E3A75973D866B496B8F95EAE185D9438 |
Malicious: | false |
Reputation: | low |
URL: | https://roberthood.net/me/young/quak/bizmail.php/img/qiye.png |
Preview: |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-16T00:53:56.108269+0100 | 2812237 | ETPRO PHISHING Possible Successful Generic Phish July 28 | 1 | 192.168.2.6 | 49856 | 72.18.194.32 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 16, 2025 00:53:27.566466093 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:27.566483021 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:27.894632101 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:33.469106913 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:33.469209909 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:33.469295025 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:33.470164061 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:33.470184088 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.278351068 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.278426886 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.284085989 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.284109116 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.284312010 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.286078930 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.286145926 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.286150932 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.286283016 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.331322908 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.460398912 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.460478067 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:34.460659027 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.460851908 CET | 49712 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:34.460872889 CET | 443 | 49712 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:37.174640894 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:37.174643040 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:37.481765032 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:37.481786966 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:37.481929064 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:37.482158899 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:37.482177019 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:37.502619982 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:38.145724058 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:38.146004915 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:38.146013021 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:38.146944046 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:38.147017002 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:38.151849985 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:38.151922941 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:38.205763102 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:38.205848932 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:38.252610922 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:39.137644053 CET | 443 | 49708 | 173.222.162.64 | 192.168.2.6 |
Jan 16, 2025 00:53:39.137747049 CET | 49708 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 16, 2025 00:53:39.785494089 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:39.785535097 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:39.785607100 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:39.786488056 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:39.786528111 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:39.786597013 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:39.786892891 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:39.786906004 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:39.787034988 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:39.787050962 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.369730949 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.370060921 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.370090008 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.371157885 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.371246099 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.372586966 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.372701883 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.372754097 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.419327974 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.424566031 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.424593925 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.451107025 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.451375961 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.451414108 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.452414989 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.452488899 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.453043938 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.453109026 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.474303007 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.493662119 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.493695021 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.536039114 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.615722895 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.615871906 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.615933895 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.616010904 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.617362022 CET | 49746 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.617378950 CET | 443 | 49746 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.751324892 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.795356989 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.904344082 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.904484034 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.904544115 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.904557943 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.904608011 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.905322075 CET | 49747 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.905340910 CET | 443 | 49747 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.972712994 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.972791910 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:40.972883940 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.975507975 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:40.975537062 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.275775909 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.275850058 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.275990963 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.276954889 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.276967049 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.569183111 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.588491917 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.588502884 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.590425968 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.591108084 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.591293097 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.591296911 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.591370106 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.658289909 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.821348906 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.821664095 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.821732044 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.821746111 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.821818113 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.822051048 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.822428942 CET | 49753 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.822438955 CET | 443 | 49753 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.826014042 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.826062918 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.826138973 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.826338053 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.826354027 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.862838030 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.863388062 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.863408089 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.866974115 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.867058039 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.867440939 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.867592096 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.867605925 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.908586979 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:41.908605099 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:41.955504894 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.114378929 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.114496946 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.114550114 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.114602089 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.114641905 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.122422934 CET | 49758 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.122443914 CET | 443 | 49758 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.484724045 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:42.484770060 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:42.484838009 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:42.485455036 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:42.485466957 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:42.499610901 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.499907017 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.499937057 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.501003981 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.501066923 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.501382113 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.501444101 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.501507044 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.501516104 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.543880939 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.754874945 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.755227089 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.755290985 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.755327940 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.755383968 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:42.755431890 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.756318092 CET | 49762 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:42.756329060 CET | 443 | 49762 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:43.277595997 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.277771950 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.279124022 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.279158115 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.279974937 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.281584978 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.281637907 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.281667948 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.281764984 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.327328920 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.461347103 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.461554050 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:43.461846113 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.487483025 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.487483025 CET | 49769 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:43.487514019 CET | 443 | 49769 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:48.069752932 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:48.069801092 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:48.069854975 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:49.754523993 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:53:49.754571915 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:53:55.136614084 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.136657000 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.136722088 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.138792992 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.138853073 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.138910055 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.140633106 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.140678883 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.140876055 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.140891075 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.758105040 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.758359909 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.758393049 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.759552956 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.759906054 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.760088921 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.760126114 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.789299011 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.789577961 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.789623022 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.790112972 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.790534973 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.790638924 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.802465916 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:55.802510023 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:55.834713936 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.108268023 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.108544111 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.108603954 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.108638048 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.108690977 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.108742952 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.109276056 CET | 49856 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.109288931 CET | 443 | 49856 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.128329039 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.175332069 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.288048983 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.288187981 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.288252115 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.288269043 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.288312912 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.291100979 CET | 49857 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.291140079 CET | 443 | 49857 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.296777964 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.296817064 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.296886921 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.297110081 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.297123909 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.894217014 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.894598961 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.894622087 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.895803928 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.896126032 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.896295071 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:56.896543026 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:56.939347029 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.160460949 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.160742998 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.160814047 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.160844088 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.160907030 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.160959005 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.244172096 CET | 49864 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.244200945 CET | 443 | 49864 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.250916958 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.250999928 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.251090050 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.251322031 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.251351118 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.849812031 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.850265026 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.850343943 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.851738930 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.852225065 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.852382898 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.852442026 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:57.892599106 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:57.995151997 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:57.995196104 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:57.995331049 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:57.995865107 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:57.995887041 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.110528946 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:58.110786915 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:58.110865116 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:58.110898972 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:58.111041069 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:58.111105919 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:58.112721920 CET | 49871 | 443 | 192.168.2.6 | 72.18.194.32 |
Jan 16, 2025 00:53:58.112751007 CET | 443 | 49871 | 72.18.194.32 | 192.168.2.6 |
Jan 16, 2025 00:53:58.780050993 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.780132055 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.785756111 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.785769939 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.786113024 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.787976027 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.788045883 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.788052082 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.788307905 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.831341028 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.960118055 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.960254908 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:53:58.960320950 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.960438013 CET | 49876 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:53:58.960462093 CET | 443 | 49876 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:15.448313951 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:15.448349953 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:15.448421001 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:15.448918104 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:15.448934078 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.241101980 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.241221905 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.243005037 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.243011951 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.243798971 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.245167971 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.245213032 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.245234966 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.245321989 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.287343979 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.416049957 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.416259050 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.416331053 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.416579962 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:16.416595936 CET | 443 | 49984 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:16.416605949 CET | 49984 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:37.535932064 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:37.536042929 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:37.536169052 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:37.536375999 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:37.536402941 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:38.192867041 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:38.193250895 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:38.193285942 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:38.193865061 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:38.194267988 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:38.194335938 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:38.237294912 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:42.400485039 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:42.400511980 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:42.400585890 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:42.401087999 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:42.401103973 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.275532007 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.275691986 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.277463913 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.277479887 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.277892113 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.279721975 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.279804945 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.279810905 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.279947042 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.323338032 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.453222036 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.453358889 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:43.453457117 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.453654051 CET | 50006 | 443 | 192.168.2.6 | 40.115.3.253 |
Jan 16, 2025 00:54:43.453680038 CET | 443 | 50006 | 40.115.3.253 | 192.168.2.6 |
Jan 16, 2025 00:54:48.158334017 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:48.158498049 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Jan 16, 2025 00:54:48.158623934 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:49.755003929 CET | 50005 | 443 | 192.168.2.6 | 142.250.185.132 |
Jan 16, 2025 00:54:49.755039930 CET | 443 | 50005 | 142.250.185.132 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 16, 2025 00:53:33.363111019 CET | 53 | 51977 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:33.390003920 CET | 53 | 51396 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:34.438709974 CET | 53 | 62241 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:37.474127054 CET | 50020 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 16, 2025 00:53:37.474272966 CET | 57877 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 16, 2025 00:53:37.480854034 CET | 53 | 57877 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:37.480866909 CET | 53 | 50020 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:39.373924017 CET | 62038 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 16, 2025 00:53:39.374412060 CET | 50819 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 16, 2025 00:53:39.721698046 CET | 53 | 62038 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:39.938833952 CET | 53 | 50819 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:40.980173111 CET | 56239 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 16, 2025 00:53:40.980329037 CET | 57864 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 16, 2025 00:53:40.992574930 CET | 53 | 58853 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:40.992630005 CET | 53 | 57864 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:41.275060892 CET | 53 | 56239 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:53:51.419364929 CET | 53 | 60489 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:54:03.159487009 CET | 53 | 63783 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:54:10.449820042 CET | 53 | 62859 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:54:32.980279922 CET | 53 | 60370 | 1.1.1.1 | 192.168.2.6 |
Jan 16, 2025 00:54:33.124475002 CET | 53 | 49582 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 16, 2025 00:53:39.938935995 CET | 192.168.2.6 | 1.1.1.1 | c21f | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 16, 2025 00:53:37.474127054 CET | 192.168.2.6 | 1.1.1.1 | 0xe2b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 16, 2025 00:53:37.474272966 CET | 192.168.2.6 | 1.1.1.1 | 0x3bec | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 16, 2025 00:53:39.373924017 CET | 192.168.2.6 | 1.1.1.1 | 0x3a74 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 16, 2025 00:53:39.374412060 CET | 192.168.2.6 | 1.1.1.1 | 0x54cc | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 16, 2025 00:53:40.980173111 CET | 192.168.2.6 | 1.1.1.1 | 0x1790 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 16, 2025 00:53:40.980329037 CET | 192.168.2.6 | 1.1.1.1 | 0xcc41 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 16, 2025 00:53:37.480854034 CET | 1.1.1.1 | 192.168.2.6 | 0x3bec | No error (0) | 65 | IN (0x0001) | false | |||
Jan 16, 2025 00:53:37.480866909 CET | 1.1.1.1 | 192.168.2.6 | 0xe2b7 | No error (0) | 142.250.185.132 | A (IP address) | IN (0x0001) | false | ||
Jan 16, 2025 00:53:39.721698046 CET | 1.1.1.1 | 192.168.2.6 | 0x3a74 | No error (0) | 72.18.194.32 | A (IP address) | IN (0x0001) | false | ||
Jan 16, 2025 00:53:41.275060892 CET | 1.1.1.1 | 192.168.2.6 | 0x1790 | No error (0) | 72.18.194.32 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49712 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:34 UTC | 71 | OUT | |
2025-01-15 23:53:34 UTC | 249 | OUT | |
2025-01-15 23:53:34 UTC | 1084 | OUT | |
2025-01-15 23:53:34 UTC | 218 | OUT | |
2025-01-15 23:53:34 UTC | 14 | IN | |
2025-01-15 23:53:34 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49746 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:40 UTC | 683 | OUT | |
2025-01-15 23:53:40 UTC | 360 | IN | |
2025-01-15 23:53:40 UTC | 1008 | IN | |
2025-01-15 23:53:40 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49747 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:40 UTC | 637 | OUT | |
2025-01-15 23:53:40 UTC | 360 | IN | |
2025-01-15 23:53:40 UTC | 1008 | IN | |
2025-01-15 23:53:40 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49753 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:41 UTC | 640 | OUT | |
2025-01-15 23:53:41 UTC | 360 | IN | |
2025-01-15 23:53:41 UTC | 1008 | IN | |
2025-01-15 23:53:41 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49758 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:41 UTC | 376 | OUT | |
2025-01-15 23:53:42 UTC | 360 | IN | |
2025-01-15 23:53:42 UTC | 1008 | IN | |
2025-01-15 23:53:42 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49762 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:42 UTC | 379 | OUT | |
2025-01-15 23:53:42 UTC | 360 | IN | |
2025-01-15 23:53:42 UTC | 1008 | IN | |
2025-01-15 23:53:42 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
6 | 192.168.2.6 | 49769 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:43 UTC | 71 | OUT | |
2025-01-15 23:53:43 UTC | 249 | OUT | |
2025-01-15 23:53:43 UTC | 1084 | OUT | |
2025-01-15 23:53:43 UTC | 218 | OUT | |
2025-01-15 23:53:43 UTC | 14 | IN | |
2025-01-15 23:53:43 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49856 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:55 UTC | 886 | OUT | |
2025-01-15 23:53:55 UTC | 51 | OUT | |
2025-01-15 23:53:56 UTC | 360 | IN | |
2025-01-15 23:53:56 UTC | 1008 | IN | |
2025-01-15 23:53:56 UTC | 1196 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49857 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:56 UTC | 645 | OUT | |
2025-01-15 23:53:56 UTC | 360 | IN | |
2025-01-15 23:53:56 UTC | 1008 | IN | |
2025-01-15 23:53:56 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.6 | 49864 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:56 UTC | 648 | OUT | |
2025-01-15 23:53:57 UTC | 360 | IN | |
2025-01-15 23:53:57 UTC | 1008 | IN | |
2025-01-15 23:53:57 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.6 | 49871 | 72.18.194.32 | 443 | 6228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:57 UTC | 379 | OUT | |
2025-01-15 23:53:58 UTC | 360 | IN | |
2025-01-15 23:53:58 UTC | 1008 | IN | |
2025-01-15 23:53:58 UTC | 1186 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
11 | 192.168.2.6 | 49876 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:53:58 UTC | 71 | OUT | |
2025-01-15 23:53:58 UTC | 249 | OUT | |
2025-01-15 23:53:58 UTC | 1084 | OUT | |
2025-01-15 23:53:58 UTC | 218 | OUT | |
2025-01-15 23:53:58 UTC | 14 | IN | |
2025-01-15 23:53:58 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
12 | 192.168.2.6 | 49984 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:54:16 UTC | 71 | OUT | |
2025-01-15 23:54:16 UTC | 249 | OUT | |
2025-01-15 23:54:16 UTC | 1084 | OUT | |
2025-01-15 23:54:16 UTC | 218 | OUT | |
2025-01-15 23:54:16 UTC | 14 | IN | |
2025-01-15 23:54:16 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
13 | 192.168.2.6 | 50006 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 23:54:43 UTC | 71 | OUT | |
2025-01-15 23:54:43 UTC | 249 | OUT | |
2025-01-15 23:54:43 UTC | 1084 | OUT | |
2025-01-15 23:54:43 UTC | 218 | OUT | |
2025-01-15 23:54:43 UTC | 14 | IN | |
2025-01-15 23:54:43 UTC | 58 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 18:53:29 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 18:53:32 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 18:53:38 |
Start date: | 15/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |