Windows
Analysis Report
https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5716 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 2412 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2004,i ,153563354 5978631493 4,56951365 6973427986 3,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2032 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7048 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://intim idadcondio sgt.com/fg hjwssxhj/2 pIU6hxd/Y2 l0eXRpdGxl QGNpdHl0aX RsZWFnZW5j eS5jb20N" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
office.a8a.shop | 172.67.136.69 | true | false | unknown | |
intimidadcondiosgt.com | 162.210.98.14 | true | false | unknown | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
www.google.com | 142.250.186.36 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | high | ||
false |
| unknown | |
false | unknown | ||
false |
| unknown | |
false | high | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.67.136.69 | office.a8a.shop | United States | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
162.210.98.14 | intimidadcondiosgt.com | United States | 32748 | STEADFASTUS | false |
IP |
---|
192.168.2.4 |
192.168.2.23 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1638529 |
Start date and time: | 2025-03-14 13:46:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@22/2@8/6 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.184.206, 142.250.186.131, 64.233.184.84, 142.250.186.35, 216.58.206.46, 142.250.186.78, 142.250.184.238, 172.217.16.206, 184.30.131.245, 142.250.185.174, 142.250.185.238, 142.250.186.174, 142.250.185.195, 142.250.185.78, 142.250.185.227, 216.58.206.78, 23.60.203.209, 20.12.23.50
- Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, www.gstatic.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- VT rate limit hit for: https://intimidadcondiosgt.com/fghjwssxhj/2pIU6hxd/Y2l0eXRpdGxlQGNpdHl0aXRsZWFnZW5jeS5jb20N
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 884 |
Entropy (8bit): | 5.175091821968257 |
Encrypted: | false |
SSDEEP: | 24:t/ImaejK2SBHslgT1d1uawBATT3uoBN2t2t2t2t2t2t2tomffffffo:CoyKlgJXwBAP3uSNYYYYYYYomffffffo |
MD5: | A44BC707A290913978B8CA2411F858F2 |
SHA1: | D4C9C6B181281F129FD6640651FFC093EA44AF8F |
SHA-256: | F843E57C52DCBEEBAEA805142B30AC5FB1572482BE7949A0BBCAAB218F880BCE |
SHA-512: | EFAFA39B4F5B9B27A366006567A6352BCA940386B9A05942C90EAB383082501AFEC32B82EEF3C711EF133E2F5E8D519D06404545EC8C6CF1AD3FA8F5762F1127 |
Malicious: | false |
Reputation: | low |
URL: | https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 14, 2025 13:47:08.163425922 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:08.471491098 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:09.174604893 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:10.377485037 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:11.636569977 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:11.636616945 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:11.636714935 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:11.636893988 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:11.636912107 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:12.304099083 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:12.304600954 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:12.305541992 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:12.305556059 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:12.305820942 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:12.346270084 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:12.783776999 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:13.825817108 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:13.825843096 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:13.826004982 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:13.826072931 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:13.826078892 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:13.826448917 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:13.826503992 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:13.826558113 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:13.826710939 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:13.826728106 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.353490114 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.353494883 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.353579998 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.354722023 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.354722023 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.354737043 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.354957104 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.355086088 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.355098963 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.355299950 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.355323076 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.398921967 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.400319099 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.574599981 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.574671030 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.574723959 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.575247049 CET | 49734 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.575258017 CET | 443 | 49734 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.683368921 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.690920115 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:14.690967083 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:14.691023111 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:14.691406965 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:14.691437006 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:14.691499949 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:14.692296028 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:14.692313910 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:14.692322016 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:14.692334890 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:14.728318930 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.801382065 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.802467108 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:14.802515984 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.803431988 CET | 49735 | 443 | 192.168.2.4 | 162.210.98.14 |
Mar 14, 2025 13:47:14.803453922 CET | 443 | 49735 | 162.210.98.14 | 192.168.2.4 |
Mar 14, 2025 13:47:15.194720030 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.194820881 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.194912910 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:15.194912910 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:15.205874920 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:15.205892086 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.206126928 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.206760883 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:15.206787109 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.206907034 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:15.207024097 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.252332926 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:15.260355949 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:16.941525936 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:17.251279116 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:17.436934948 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:17.484323025 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:17.587023973 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:17.639477015 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:17.642222881 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:17.642291069 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:17.654577971 CET | 49732 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:47:17.654593945 CET | 443 | 49732 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:47:17.858292103 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:18.182629108 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:18.490923882 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:18.881694078 CET | 49709 | 443 | 192.168.2.4 | 52.113.196.254 |
Mar 14, 2025 13:47:18.882447958 CET | 49709 | 443 | 192.168.2.4 | 52.113.196.254 |
Mar 14, 2025 13:47:18.882477999 CET | 49709 | 443 | 192.168.2.4 | 52.113.196.254 |
Mar 14, 2025 13:47:18.886358976 CET | 443 | 49709 | 52.113.196.254 | 192.168.2.4 |
Mar 14, 2025 13:47:18.887145996 CET | 443 | 49709 | 52.113.196.254 | 192.168.2.4 |
Mar 14, 2025 13:47:18.887156010 CET | 443 | 49709 | 52.113.196.254 | 192.168.2.4 |
Mar 14, 2025 13:47:18.976655006 CET | 443 | 49709 | 52.113.196.254 | 192.168.2.4 |
Mar 14, 2025 13:47:18.976711988 CET | 49709 | 443 | 192.168.2.4 | 52.113.196.254 |
Mar 14, 2025 13:47:18.977319002 CET | 49709 | 443 | 192.168.2.4 | 52.113.196.254 |
Mar 14, 2025 13:47:18.981950045 CET | 443 | 49709 | 52.113.196.254 | 192.168.2.4 |
Mar 14, 2025 13:47:19.068763018 CET | 443 | 49709 | 52.113.196.254 | 192.168.2.4 |
Mar 14, 2025 13:47:19.068820953 CET | 49709 | 443 | 192.168.2.4 | 52.113.196.254 |
Mar 14, 2025 13:47:19.072191000 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:19.102777958 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:20.315624952 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:21.473743916 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:22.723824024 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:26.279476881 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:27.194056988 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 13:47:27.532887936 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:30.055438995 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:30.055520058 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:30.055588961 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:30.145082951 CET | 49737 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:30.145109892 CET | 443 | 49737 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:35.883757114 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 13:47:37.134535074 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 13:47:54.033153057 CET | 49715 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 13:47:54.033241987 CET | 49717 | 80 | 192.168.2.4 | 199.232.214.172 |
Mar 14, 2025 13:47:54.033303022 CET | 49719 | 80 | 192.168.2.4 | 199.232.214.172 |
Mar 14, 2025 13:47:54.039325953 CET | 80 | 49715 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 13:47:54.039402962 CET | 49715 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 13:47:54.039927959 CET | 80 | 49717 | 199.232.214.172 | 192.168.2.4 |
Mar 14, 2025 13:47:54.039974928 CET | 80 | 49719 | 199.232.214.172 | 192.168.2.4 |
Mar 14, 2025 13:47:54.039978027 CET | 49717 | 80 | 192.168.2.4 | 199.232.214.172 |
Mar 14, 2025 13:47:54.040024996 CET | 49719 | 80 | 192.168.2.4 | 199.232.214.172 |
Mar 14, 2025 13:47:54.515621901 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:54.515698910 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:54.515767097 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:54.517616987 CET | 49736 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:54.517637968 CET | 443 | 49736 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:54.526556015 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:54.526593924 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:54.526660919 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:54.541285038 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:54.541305065 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:54.580425024 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:54.580471992 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:54.580610991 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:54.580946922 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:54.580964088 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:54.759614944 CET | 49716 | 443 | 192.168.2.4 | 2.19.96.81 |
Mar 14, 2025 13:47:54.759919882 CET | 49718 | 80 | 192.168.2.4 | 199.232.214.172 |
Mar 14, 2025 13:47:55.035985947 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.036082983 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.041121960 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.041129112 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.041379929 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.042391062 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.084146023 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:55.084330082 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.108041048 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:55.108062983 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:55.145302057 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:47:55.145315886 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:47:55.164850950 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.164922953 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.164984941 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.195207119 CET | 49743 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.195218086 CET | 443 | 49743 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.196012974 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.196059942 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.196125031 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.196254015 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.196264982 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.757443905 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.757767916 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.757787943 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.758009911 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.758018017 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.890511990 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.890666962 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.890707016 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.890832901 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.890845060 CET | 443 | 49745 | 35.190.80.1 | 192.168.2.4 |
Mar 14, 2025 13:47:55.890856028 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:47:55.890897036 CET | 49745 | 443 | 192.168.2.4 | 35.190.80.1 |
Mar 14, 2025 13:48:11.691780090 CET | 49750 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:48:11.691838026 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:48:11.691952944 CET | 49750 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:48:11.692138910 CET | 49750 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:48:11.692154884 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:48:12.353619099 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:48:12.353996992 CET | 49750 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:48:12.354018927 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:48:14.582652092 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:48:14.582720041 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:48:14.582911015 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:48:14.583421946 CET | 49744 | 443 | 192.168.2.4 | 172.67.136.69 |
Mar 14, 2025 13:48:14.583441019 CET | 443 | 49744 | 172.67.136.69 | 192.168.2.4 |
Mar 14, 2025 13:48:22.255953074 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:48:22.256019115 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Mar 14, 2025 13:48:22.256078959 CET | 49750 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:48:24.144486904 CET | 49750 | 443 | 192.168.2.4 | 142.250.186.36 |
Mar 14, 2025 13:48:24.144524097 CET | 443 | 49750 | 142.250.186.36 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 14, 2025 13:47:08.099586964 CET | 53 | 52712 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:08.795367956 CET | 53 | 60398 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:09.835558891 CET | 53 | 58923 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:09.943046093 CET | 53 | 58787 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:11.628418922 CET | 59403 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:11.628659010 CET | 61513 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:11.635360003 CET | 53 | 59403 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:11.635854959 CET | 53 | 61513 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:13.702570915 CET | 60865 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:13.702609062 CET | 64376 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:13.747795105 CET | 53 | 64376 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:13.825083017 CET | 53 | 60865 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:14.673263073 CET | 58681 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:14.673629999 CET | 49324 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:14.686547041 CET | 53 | 49324 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:14.689357996 CET | 53 | 58681 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:26.927177906 CET | 53 | 55418 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:44.682929993 CET | 53 | 51720 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:45.731013060 CET | 53 | 49419 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:54.517330885 CET | 49791 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:54.517510891 CET | 51562 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 13:47:54.524367094 CET | 53 | 49791 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:47:54.524420977 CET | 53 | 51562 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:48:07.558911085 CET | 53 | 61618 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:48:08.163665056 CET | 53 | 58800 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:48:10.214771986 CET | 53 | 61982 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 13:48:16.414477110 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 14, 2025 13:47:11.628418922 CET | 192.168.2.4 | 1.1.1.1 | 0xd31b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 14, 2025 13:47:11.628659010 CET | 192.168.2.4 | 1.1.1.1 | 0x5af6 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 14, 2025 13:47:13.702570915 CET | 192.168.2.4 | 1.1.1.1 | 0xbae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 14, 2025 13:47:13.702609062 CET | 192.168.2.4 | 1.1.1.1 | 0x5a66 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 14, 2025 13:47:14.673263073 CET | 192.168.2.4 | 1.1.1.1 | 0x4850 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 14, 2025 13:47:14.673629999 CET | 192.168.2.4 | 1.1.1.1 | 0x50d9 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 14, 2025 13:47:54.517330885 CET | 192.168.2.4 | 1.1.1.1 | 0xbaf9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 14, 2025 13:47:54.517510891 CET | 192.168.2.4 | 1.1.1.1 | 0x1451 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 14, 2025 13:47:11.635360003 CET | 1.1.1.1 | 192.168.2.4 | 0xd31b | No error (0) | 142.250.186.36 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 13:47:11.635854959 CET | 1.1.1.1 | 192.168.2.4 | 0x5af6 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 14, 2025 13:47:13.825083017 CET | 1.1.1.1 | 192.168.2.4 | 0xbae | No error (0) | 162.210.98.14 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 13:47:14.686547041 CET | 1.1.1.1 | 192.168.2.4 | 0x50d9 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 14, 2025 13:47:14.689357996 CET | 1.1.1.1 | 192.168.2.4 | 0x4850 | No error (0) | 172.67.136.69 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 13:47:14.689357996 CET | 1.1.1.1 | 192.168.2.4 | 0x4850 | No error (0) | 104.21.26.128 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 13:47:54.524367094 CET | 1.1.1.1 | 192.168.2.4 | 0xbaf9 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49734 | 162.210.98.14 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:14 UTC | 732 | OUT | |
2025-03-14 12:47:14 UTC | 410 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49735 | 162.210.98.14 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:14 UTC | 667 | OUT | |
2025-03-14 12:47:14 UTC | 416 | IN | |
2025-03-14 12:47:14 UTC | 952 | IN | |
2025-03-14 12:47:14 UTC | 299 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49736 | 172.67.136.69 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:15 UTC | 701 | OUT | |
2025-03-14 12:47:54 UTC | 952 | IN | |
2025-03-14 12:47:54 UTC | 15 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49732 | 142.250.186.36 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:17 UTC | 579 | OUT | |
2025-03-14 12:47:17 UTC | 1303 | IN | |
2025-03-14 12:47:17 UTC | 87 | IN | |
2025-03-14 12:47:17 UTC | 804 | IN | |
2025-03-14 12:47:17 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49743 | 35.190.80.1 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:55 UTC | 542 | OUT | |
2025-03-14 12:47:55 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49744 | 172.67.136.69 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:55 UTC | 601 | OUT | |
2025-03-14 12:48:14 UTC | 960 | IN | |
2025-03-14 12:48:14 UTC | 15 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49745 | 35.190.80.1 | 443 | 2412 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 12:47:55 UTC | 517 | OUT | |
2025-03-14 12:47:55 UTC | 426 | OUT | |
2025-03-14 12:47:55 UTC | 214 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 08:47:02 |
Start date: | 14/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:47:06 |
Start date: | 14/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff659320000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 08:47:12 |
Start date: | 14/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |