Windows
Analysis Report
https://iyu59.com/
Overview
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 180 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5144 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1900 --fi eld-trial- handle=199 6,i,420531 5775780067 847,878141 8941483147 223,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 3224 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t http:/// MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5856 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1972 --fi eld-trial- handle=203 6,i,958864 5296810091 784,914029 8293887751 568,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6520 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://iyu59 .com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 172.217.4.196 | true | false | high | |
fp2e7a.wpc.phicdn.net | 192.229.211.108 | true | false |
| unknown |
iyu59.com | 107.172.87.11 | true | false |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
true | unknown | ||
false | high | ||
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.172.87.11 | iyu59.com | United States | 36352 | AS-COLOCROSSINGUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
172.217.4.196 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1433043 |
Start date and time: | 2024-04-29 01:35:25 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://iyu59.com/ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@23/13@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 172.217.4.195, 142.250.111.84, 142.250.191.238, 34.104.35.123, 72.21.81.240, 199.232.210.172, 192.229.211.108, 13.85.23.206, 52.165.164.15, 142.250.190.3, 104.102.249.211, 104.102.249.139, 104.102.249.192, 104.102.249.202, 104.102.249.200, 104.102.249.147
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtSetInformationFile calls found.
Source | URL |
---|---|
Screenshot | http://<UNKNOWNECI:000103>System.Byte[]</UNKNOWNECI> |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.98682331827081 |
Encrypted: | false |
SSDEEP: | 48:8hwdpTxR2dHfidAKZdA19ehwiZUklqeh1y+3:8h+XAmy |
MD5: | A880D700DEE3946155EE7CBEB58132F3 |
SHA1: | F8BDC68667D361211BF3D48150CC1078FB676C64 |
SHA-256: | D2B4ECAA7B000464537A3FC7E59EC6ACE0488157473AD14E08ACA675C695372C |
SHA-512: | 3CA638E88009F47B03E950335E8055705EBC96744030D0D5E1D694A37599871335F1CD223CDA7790970B36766E8DD3D981E7035F0FEE8CAD63AD3C558B12CCFE |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.003663887540904 |
Encrypted: | false |
SSDEEP: | 48:81sZwdpTxR2dHfidAKZdA1weh/iZUkAQkqehWy+2:8M+X69QLy |
MD5: | 0DAA5CBDC36B4727F99F4A5B65426195 |
SHA1: | AF311ED8576AAF40986FF54AF6DA7F33371FF012 |
SHA-256: | 732B8E27ECDB7A319C7F54C1578395984556A1568FB95A8006B96E77D42578F4 |
SHA-512: | CA14DF7EF1047863E5A607EA78F5D3532E9BF551E21767B84A387BBC5E34ED5D04E4FB15FA7103A3289659DB4E552CD45EDFD18D7E70BFF45E41FE076B097C82 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.011648512415294 |
Encrypted: | false |
SSDEEP: | 48:8xZwdpTxRsHfidAKZdA14tseh7sFiZUkmgqeh7sEy+BX:8xZ+XOnqy |
MD5: | D21500752C39211F01DDD6EAFFFE6664 |
SHA1: | 6CA64E617FE8E8970E2671FBB20461F60E218A10 |
SHA-256: | 3BCB0BD402AF5878B5C877787A6DFDD56C328F0355C28B0877EDCF9355990305 |
SHA-512: | 52F70562640F5E849CCE525B1B8B955F78C13FE4B219BADD946B73166EDCA213C678C1F9B84824211C9FA89424CCD09822271D01D784840FB34DBCDFF82D525F |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 4.001656222029042 |
Encrypted: | false |
SSDEEP: | 48:8KwdpTxR2dHfidAKZdA1vehDiZUkwqehCy+R:8K+Xh8y |
MD5: | A85A7F6C55D7471C7541C10A37D98502 |
SHA1: | 1131760CF5929A73CD6A667FC613FBCB81269BC7 |
SHA-256: | B68C14C027CBA18737BE952DF371AE5AB0BDEACC5B6DCD1FAC1F9A9BF93CA525 |
SHA-512: | 69A8B0645A8BDCA6924B38DFE1902127382765930A58F6E6B11632335E8CFF3EC61510A57F6A6B4F97163325A4BDB699CF531FB4D9EC7AB58A8D45776729A3B4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9901284502378354 |
Encrypted: | false |
SSDEEP: | 48:8AwdpTxR2dHfidAKZdA1hehBiZUk1W1qehIy+C:8A+Xh9oy |
MD5: | C0D4FA1FB630B6C65E763C8395A6A703 |
SHA1: | E0C3B4460DDA86D302917B4387B558774E9BC69A |
SHA-256: | F983F41CFB696A66F7341EBCD8EEDEEDB31F512420D542FA7618B19F3FC1DABF |
SHA-512: | C333A0CE225DD18456CD9F08356908447CFDD2EFEBE5657335B39E491EA9EA9C6D662D60FA80A8554747B08586DCBCC20FECA417C81CBC35EA42E9BD48C4E8A7 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 4.00128094872614 |
Encrypted: | false |
SSDEEP: | 48:8UwdpTxR2dHfidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbqy+yT+:8U+XdT/TbxWOvTbqy7T |
MD5: | 8D3180E90540B551F463CA2621BD82F4 |
SHA1: | 3CFF7D4AEBEF3DE14A3A68B1CB06EBAF2A805C3D |
SHA-256: | EB988F459EB5C76673FE3B7786B8F1850AADB37EF42427BA0A7B17753C26A345 |
SHA-512: | 28D056E2C411176117A08742D802A4805782AE6E2617A0C9721DA45625F43CF16C8E4FFAFE50B46ADC4D62B968056502C9B045B193DEC6703EF5A170A1616998 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3245 |
Entropy (8bit): | 5.81740788221127 |
Encrypted: | false |
SSDEEP: | 96:JlkliAUIN6666VUBOGXeKKO+g8+hbzFl9nf8nXhfQfffo:iTN6666VWXeKagPhbxXnEp |
MD5: | 610129F8D0EECBB18946CDF8775DE191 |
SHA1: | FCD487C220B4DA7CA98DAB273ACC8F868D6A6F36 |
SHA-256: | 7FDB9368D14619F7F14DEE6C9F6B1F7100A6905737A5C6142CEF2FA8CBDCD30D |
SHA-512: | 2C5F5E83C37B2C178CAF5EED46E0B8595F0921A2C5563111676D7EE08169A4838BCDFE5F64AEB0477422B9A73BB571AB84550B47E489706384221EE7725549CF |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4981 |
Entropy (8bit): | 5.113240961469081 |
Encrypted: | false |
SSDEEP: | 96:zDEqwrbv1+GtJ8VuCDJwSUZ+pO8/npbKdHR9BweSW5WRq1EB6eOkkCGomn:zDlMzkGf8VuCJpO8ktRoeSWoq1Ece39m |
MD5: | 48DE24BB73AF029E4812C12060509B28 |
SHA1: | E715A83CBF612971F0275FFDFBA2E45604BE742A |
SHA-256: | AE9DA3C9A568A7B3602DC54E10C324166DB3ABE1D3A6892770D6CE6A7CC8C1C6 |
SHA-512: | FFE85C26D576B7FFBB6052BE6D26E8D48D354FC927D05A2395B0C88F0D87A56E7A5077CDBAEB905F10B17895ACA49353ED4E46B01D5061ECB514617069AA9900 |
Malicious: | false |
Reputation: | low |
URL: | https://iyu59.com/vendor/vendor.23238u92u82.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 22382 |
Entropy (8bit): | 2.2117771924639604 |
Encrypted: | false |
SSDEEP: | 48:nq/LDQsHmq5crBEQB+PLH4euMerTHb+qvceiJqIsxOOBfHiqcfzO58Vpnh:qXQomseyHc7b+qvcHsxNwqcfzR |
MD5: | 576287A38D00E198B1E8B4881932BE10 |
SHA1: | 8401D5110333717C59E4165D34DCE913EB117697 |
SHA-256: | 3850A133BFE3AC48100036A9452F60BFC74538BD94CED9AA53DB40B5654749E5 |
SHA-512: | 7EABF7ABF5A0655E714A7EA7B55D124A33B82246C0AD932099348CE5FF92A4FFB25106719DD2C3A6E56BEB856D1C1368D89234CFC68D89997BA35BEF26577B98 |
Malicious: | false |
Reputation: | low |
URL: | https://iyu59.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 22382 |
Entropy (8bit): | 2.2117771924639604 |
Encrypted: | false |
SSDEEP: | 48:nq/LDQsHmq5crBEQB+PLH4euMerTHb+qvceiJqIsxOOBfHiqcfzO58Vpnh:qXQomseyHc7b+qvcHsxNwqcfzR |
MD5: | 576287A38D00E198B1E8B4881932BE10 |
SHA1: | 8401D5110333717C59E4165D34DCE913EB117697 |
SHA-256: | 3850A133BFE3AC48100036A9452F60BFC74538BD94CED9AA53DB40B5654749E5 |
SHA-512: | 7EABF7ABF5A0655E714A7EA7B55D124A33B82246C0AD932099348CE5FF92A4FFB25106719DD2C3A6E56BEB856D1C1368D89234CFC68D89997BA35BEF26577B98 |
Malicious: | false |
Reputation: | low |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 29, 2024 01:36:10.909002066 CEST | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:10.909357071 CEST | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:11.033967972 CEST | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:20.565936089 CEST | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:20.592216969 CEST | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:20.693948984 CEST | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:20.791328907 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.791376114 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.791429996 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.791548967 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.791598082 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.791771889 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.792032957 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.792047977 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.792373896 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.792387009 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.850383043 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.850451946 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.850513935 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.850737095 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.850754976 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.851411104 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.851438999 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:20.851500034 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.851752043 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:20.851757050 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.030760050 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.031116009 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.031147003 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.032130957 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.032207966 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.032588005 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.033329010 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.033337116 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.033462048 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.033525944 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.033868074 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.033875942 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.034786940 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.034862041 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.035751104 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.035826921 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.035912991 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.035919905 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.083688021 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.084518909 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.084542036 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.086070061 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.086127996 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.086544037 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.086620092 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.086710930 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.087565899 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.087941885 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.087948084 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.089271069 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.089385986 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.089732885 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.089826107 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.132114887 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.162925959 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.162933111 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.162935972 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.162947893 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.180994034 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.181021929 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.263633966 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.281977892 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.282113075 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.282181978 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.282207012 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.282237053 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.282274008 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.286066055 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.286206961 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.286225080 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.286263943 CEST | 443 | 49707 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.286314964 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.286333084 CEST | 49707 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.287828922 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.434722900 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.434775114 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.434973001 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.435153961 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.435204029 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.435256958 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.435370922 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.435384989 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.435673952 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.435693979 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.581033945 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.581120014 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.581197023 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.581370115 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.581438065 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.582405090 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.582426071 CEST | 443 | 49708 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.582434893 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.582477093 CEST | 49708 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.584671021 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.614244938 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.614306927 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.614325047 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.614415884 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.614458084 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.616173029 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.616197109 CEST | 443 | 49709 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.616209030 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.616245031 CEST | 49709 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.619231939 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.619255066 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.619333982 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.619556904 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.619569063 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.628117085 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709021091 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709065914 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709103107 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709152937 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.709158897 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709264040 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.709289074 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709341049 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.709419966 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.709965944 CEST | 49710 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.709979057 CEST | 443 | 49710 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.762792110 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.765595913 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.765633106 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.766746998 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.766809940 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.768256903 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.768318892 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.768459082 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.768465042 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.772300005 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.772497892 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.772521973 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.773638010 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.773699999 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.774676085 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.774732113 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.853506088 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.853790998 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.853809118 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.854258060 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.854638100 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.854729891 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.854767084 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.863408089 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.900115967 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:21.964529037 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:21.964548111 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:21.980724096 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:21.999361038 CEST | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:21.999448061 CEST | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:22.079806089 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.079896927 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.079962969 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:22.089035988 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.089093924 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.089122057 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.089164019 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:22.089186907 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.089231968 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:22.089319944 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.089378119 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.089421988 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:22.105614901 CEST | 49713 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:22.105657101 CEST | 443 | 49713 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.108072042 CEST | 49715 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:22.108095884 CEST | 443 | 49715 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:22.114156008 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:22.160120964 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.273638964 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.273663044 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.273675919 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.273741961 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:22.277502060 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.205733061 CEST | 49714 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.205770016 CEST | 443 | 49714 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.225708008 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.225748062 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.225804090 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.226001978 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.226042032 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.226094961 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.226360083 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.226372004 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.226845980 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.226862907 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.445954084 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:24.445996046 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:24.446048021 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:24.446397066 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:24.446407080 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:24.548386097 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.549444914 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.549462080 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.549797058 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.553845882 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.559088945 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.559159040 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.559298038 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.559310913 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.559787989 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.560457945 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.570420027 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.570591927 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.604110003 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:24.632967949 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:24.681586981 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:24.725673914 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:24.725692034 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:24.726238012 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:24.727169037 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:24.727252007 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:24.886723042 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:29.800884962 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:29.800930023 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:29.800991058 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:29.807576895 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:29.807591915 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.045988083 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.046061039 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.065393925 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.065418005 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.066365004 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.255179882 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.296118975 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.367676973 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.367845058 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.368104935 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.388154984 CEST | 49721 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.388175011 CEST | 443 | 49721 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.435878038 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.435930014 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.436016083 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.437937021 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.437956095 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.670248032 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.670373917 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.682682991 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.682717085 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.683609962 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.685137987 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.732115984 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.887845039 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.888036013 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.890053988 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.890227079 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.890227079 CEST | 49722 | 443 | 192.168.2.5 | 23.11.208.106 |
Apr 29, 2024 01:36:30.890260935 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:30.890274048 CEST | 443 | 49722 | 23.11.208.106 | 192.168.2.5 |
Apr 29, 2024 01:36:31.005290031 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.005389929 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.005711079 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.006191015 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.006207943 CEST | 443 | 49717 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.006237030 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.006381035 CEST | 49717 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.057897091 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.100125074 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.123945951 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:31.124026060 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:31.124350071 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:31.128305912 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:31.128350973 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:31.217808962 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.217832088 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.217838049 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.217916965 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.217931032 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.217981100 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.217994928 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.277039051 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.376422882 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.376435995 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.376507044 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.376528978 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.376579046 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.376607895 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.376610994 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.376625061 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:31.376626015 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.376642942 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.376663923 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:31.785288095 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:31.785391092 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:32.828282118 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:32.828339100 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:32.828679085 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:32.896305084 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:32.958744049 CEST | 49718 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:32.958776951 CEST | 443 | 49718 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:33.819323063 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:33.819353104 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:33.819477081 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:33.819645882 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:33.819653988 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:33.934146881 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:33.976152897 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.141880989 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.142323971 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.142338037 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.143322945 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.143384933 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.144228935 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.144293070 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.144398928 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.144403934 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.271037102 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.310394049 CEST | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.310496092 CEST | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.311239004 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.311307907 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.311436892 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.311773062 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.311805964 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361270905 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361289978 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361295938 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361308098 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361314058 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361335039 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361377001 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:34.361413002 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361435890 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361468077 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:34.361469030 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:34.361495972 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.361506939 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:34.361546993 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:34.460944891 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.460983992 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.460992098 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.461004019 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.461061001 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.461070061 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.461092949 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.462229967 CEST | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.462352037 CEST | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.567914963 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.621299982 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.621315002 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.621339083 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.621351957 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.621370077 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.621393919 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.621426105 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.621469021 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.621469021 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.629738092 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.629823923 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.659439087 CEST | 49726 | 443 | 192.168.2.5 | 107.172.87.11 |
Apr 29, 2024 01:36:34.659456968 CEST | 443 | 49726 | 107.172.87.11 | 192.168.2.5 |
Apr 29, 2024 01:36:34.679924011 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:34.680066109 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:34.680125952 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:34.681873083 CEST | 49723 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:36:34.681899071 CEST | 443 | 49723 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:36:34.955476999 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.955524921 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.956610918 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.956675053 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.957545996 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.957607985 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:34.957915068 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:34.957927942 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:35.133284092 CEST | 49720 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:36:35.133312941 CEST | 443 | 49720 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:36:35.310369968 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:35.311039925 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:35.311135054 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:35.397516966 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:35.397516966 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:36:35.397573948 CEST | 443 | 49729 | 23.1.237.91 | 192.168.2.5 |
Apr 29, 2024 01:36:35.397630930 CEST | 49729 | 443 | 192.168.2.5 | 23.1.237.91 |
Apr 29, 2024 01:37:11.516676903 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:11.516760111 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:11.516860962 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:11.517755985 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:11.517795086 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.166229010 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.166322947 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:12.240504026 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:12.240546942 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.240859032 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.268594027 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:12.316148996 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.805166960 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.805188894 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.805203915 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.805269003 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:12.805315971 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.805341959 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:12.805414915 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:12.812675953 CEST | 49732 | 443 | 192.168.2.5 | 40.68.123.157 |
Apr 29, 2024 01:37:12.812704086 CEST | 443 | 49732 | 40.68.123.157 | 192.168.2.5 |
Apr 29, 2024 01:37:24.506414890 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:24.506454945 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:24.506608963 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:24.507051945 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:24.507064104 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:24.740071058 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:24.740478039 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:24.740495920 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:24.740818024 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:24.741142988 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:24.741199970 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:24.786267996 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:34.744025946 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:34.744107962 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Apr 29, 2024 01:37:34.744328976 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:35.136853933 CEST | 49734 | 443 | 192.168.2.5 | 172.217.4.196 |
Apr 29, 2024 01:37:35.136871099 CEST | 443 | 49734 | 172.217.4.196 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 29, 2024 01:36:20.328973055 CEST | 53 | 56078 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:20.344211102 CEST | 53 | 62930 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:20.679202080 CEST | 59461 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 29, 2024 01:36:20.679743052 CEST | 58536 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 29, 2024 01:36:20.790591955 CEST | 53 | 59461 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:20.790863991 CEST | 53 | 58536 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:21.057341099 CEST | 53 | 51194 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:21.214734077 CEST | 55555 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 29, 2024 01:36:21.215138912 CEST | 60617 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 29, 2024 01:36:21.406187057 CEST | 53 | 55555 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:21.434097052 CEST | 53 | 60617 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:33.626127958 CEST | 51865 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 29, 2024 01:36:33.626669884 CEST | 62442 | 53 | 192.168.2.5 | 1.1.1.1 |
Apr 29, 2024 01:36:33.801336050 CEST | 53 | 62442 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:33.818416119 CEST | 53 | 51865 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:36:41.600656986 CEST | 53 | 51550 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:37:00.570450068 CEST | 53 | 51134 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:37:20.177176952 CEST | 53 | 55653 | 1.1.1.1 | 192.168.2.5 |
Apr 29, 2024 01:37:23.617542028 CEST | 53 | 54018 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 29, 2024 01:36:20.679202080 CEST | 192.168.2.5 | 1.1.1.1 | 0x3d05 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 29, 2024 01:36:20.679743052 CEST | 192.168.2.5 | 1.1.1.1 | 0x9071 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 29, 2024 01:36:21.214734077 CEST | 192.168.2.5 | 1.1.1.1 | 0xb65d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 29, 2024 01:36:21.215138912 CEST | 192.168.2.5 | 1.1.1.1 | 0xd198 | Standard query (0) | 65 | IN (0x0001) | false | |
Apr 29, 2024 01:36:33.626127958 CEST | 192.168.2.5 | 1.1.1.1 | 0x9c8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 29, 2024 01:36:33.626669884 CEST | 192.168.2.5 | 1.1.1.1 | 0xd3b9 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 29, 2024 01:36:20.790591955 CEST | 1.1.1.1 | 192.168.2.5 | 0x3d05 | No error (0) | 172.217.4.196 | A (IP address) | IN (0x0001) | false | ||
Apr 29, 2024 01:36:20.790863991 CEST | 1.1.1.1 | 192.168.2.5 | 0x9071 | No error (0) | 65 | IN (0x0001) | false | |||
Apr 29, 2024 01:36:21.406187057 CEST | 1.1.1.1 | 192.168.2.5 | 0xb65d | No error (0) | 107.172.87.11 | A (IP address) | IN (0x0001) | false | ||
Apr 29, 2024 01:36:33.818416119 CEST | 1.1.1.1 | 192.168.2.5 | 0x9c8b | No error (0) | 107.172.87.11 | A (IP address) | IN (0x0001) | false | ||
Apr 29, 2024 01:36:34.063812971 CEST | 1.1.1.1 | 192.168.2.5 | 0xa58a | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 29, 2024 01:36:34.063812971 CEST | 1.1.1.1 | 192.168.2.5 | 0xa58a | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Apr 29, 2024 01:36:47.382684946 CEST | 1.1.1.1 | 192.168.2.5 | 0x9865 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 29, 2024 01:36:47.382684946 CEST | 1.1.1.1 | 192.168.2.5 | 0x9865 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Apr 29, 2024 01:37:15.667896986 CEST | 1.1.1.1 | 192.168.2.5 | 0x1716 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 29, 2024 01:37:15.667896986 CEST | 1.1.1.1 | 192.168.2.5 | 0x1716 | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false | ||
Apr 29, 2024 01:37:32.960200071 CEST | 1.1.1.1 | 192.168.2.5 | 0xcdae | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Apr 29, 2024 01:37:32.960200071 CEST | 1.1.1.1 | 192.168.2.5 | 0xcdae | No error (0) | 192.229.211.108 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49707 | 172.217.4.196 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:21 UTC | 615 | OUT | |
2024-04-28 23:36:21 UTC | 1703 | IN | |
2024-04-28 23:36:21 UTC | 1703 | IN | |
2024-04-28 23:36:21 UTC | 1549 | IN | |
2024-04-28 23:36:21 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49708 | 172.217.4.196 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:21 UTC | 518 | OUT | |
2024-04-28 23:36:21 UTC | 1843 | IN | |
2024-04-28 23:36:21 UTC | 458 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49709 | 172.217.4.196 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:21 UTC | 353 | OUT | |
2024-04-28 23:36:21 UTC | 1761 | IN | |
2024-04-28 23:36:21 UTC | 417 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49710 | 172.217.4.196 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:21 UTC | 920 | OUT | |
2024-04-28 23:36:21 UTC | 356 | IN | |
2024-04-28 23:36:21 UTC | 899 | IN | |
2024-04-28 23:36:21 UTC | 1255 | IN | |
2024-04-28 23:36:21 UTC | 1029 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49713 | 107.172.87.11 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:21 UTC | 652 | OUT | |
2024-04-28 23:36:22 UTC | 669 | IN | |
2024-04-28 23:36:22 UTC | 1105 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49715 | 172.217.4.196 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:21 UTC | 738 | OUT | |
2024-04-28 23:36:22 UTC | 356 | IN | |
2024-04-28 23:36:22 UTC | 899 | IN | |
2024-04-28 23:36:22 UTC | 1255 | IN | |
2024-04-28 23:36:22 UTC | 957 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49714 | 107.172.87.11 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:22 UTC | 692 | OUT | |
2024-04-28 23:36:22 UTC | 292 | IN | |
2024-04-28 23:36:22 UTC | 4981 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49717 | 107.172.87.11 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:24 UTC | 905 | OUT | |
2024-04-28 23:36:31 UTC | 184 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49721 | 23.11.208.106 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:30 UTC | 161 | OUT | |
2024-04-28 23:36:30 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.5 | 49722 | 23.11.208.106 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:30 UTC | 239 | OUT | |
2024-04-28 23:36:30 UTC | 530 | IN | |
2024-04-28 23:36:30 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.5 | 49718 | 107.172.87.11 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:31 UTC | 811 | OUT | |
2024-04-28 23:36:31 UTC | 283 | IN | |
2024-04-28 23:36:31 UTC | 7909 | IN | |
2024-04-28 23:36:31 UTC | 14473 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.5 | 49723 | 40.68.123.157 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:33 UTC | 306 | OUT | |
2024-04-28 23:36:34 UTC | 560 | IN | |
2024-04-28 23:36:34 UTC | 15824 | IN | |
2024-04-28 23:36:34 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.5 | 49726 | 107.172.87.11 | 443 | 5144 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:34 UTC | 505 | OUT | |
2024-04-28 23:36:34 UTC | 283 | IN | |
2024-04-28 23:36:34 UTC | 7909 | IN | |
2024-04-28 23:36:34 UTC | 14473 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
13 | 192.168.2.5 | 49729 | 23.1.237.91 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:36:34 UTC | 2148 | OUT | |
2024-04-28 23:36:34 UTC | 1 | OUT | |
2024-04-28 23:36:34 UTC | 2483 | OUT | |
2024-04-28 23:36:35 UTC | 480 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.5 | 49732 | 40.68.123.157 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-28 23:37:12 UTC | 306 | OUT | |
2024-04-28 23:37:12 UTC | 560 | IN | |
2024-04-28 23:37:12 UTC | 15824 | IN | |
2024-04-28 23:37:12 UTC | 9633 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 01:36:10 |
Start date: | 29/04/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 01:36:18 |
Start date: | 29/04/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 01:36:19 |
Start date: | 29/04/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 01:36:20 |
Start date: | 29/04/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 01:36:20 |
Start date: | 29/04/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |