Windows
Analysis Report
https://cdn.discordapp.com/attachments/1349643885605031967/1349721707249930290/FDHub.exe?ex=67d5734b&is=67d421cb&hm=c44eaa2986e2ceeb64f6e0372961436a9bbbe0e8ed94b08df6ad92b879e007d4&
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 2028 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 1236 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2316,i ,172867921 8306811978 7,58365027 3912575028 3,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2392 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6832 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://cdn.d iscordapp. com/attach ments/1349 6438856050 31967/1349 7217072499 30290/FDHu b.exe?ex=6 7d5734b&is =67d421cb& hm=c44eaa2 986e2ceeb6 4f6e037296 1436a9bbbe 0e8ed94b08 df6ad92b87 9e007d4&" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | |||
Source: | File created: | Jump to dropped file |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 21 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | |||
21% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cdn.discordapp.com | 162.159.133.233 | true | false | high | |
www.google.com | 142.250.181.228 | true | false | high | |
241.42.69.40.in-addr.arpa | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.181.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.185.100 | unknown | United States | 15169 | GOOGLEUS | false | |
162.159.133.233 | cdn.discordapp.com | United States | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1638574 |
Start date and time: | 2025-03-14 14:51:41 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://cdn.discordapp.com/attachments/1349643885605031967/1349721707249930290/FDHub.exe?ex=67d5734b&is=67d421cb&hm=c44eaa2986e2ceeb64f6e0372961436a9bbbe0e8ed94b08df6ad92b879e007d4& |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal48.win@21/3@6/4 |
- Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.110, 142.250.184.227, 142.250.185.206, 142.251.173.84, 142.250.185.174, 142.250.186.174, 172.217.18.14, 2.23.77.188, 199.232.210.172, 20.109.210.53, 13.95.31.18, 142.250.184.238, 20.12.23.50, 40.69.42.241, 4.245.163.56, 172.202.163.200, 52.149.20.212, 142.250.186.142, 142.250.185.163, 142.250.181.227, 23.199.214.10, 204.79.197.222
- Excluded domains from analysis (whitelisted): fp.msedge.net, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, c.pki.goog, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: https://cdn.discordapp.com/attachments/1349643885605031967/1349721707249930290/FDHub.exe?ex=67d5734b&is=67d421cb&hm=c44eaa2986e2ceeb64f6e0372961436a9bbbe0e8ed94b08df6ad92b879e007d4&
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40960 |
Entropy (8bit): | 5.621871376688446 |
Encrypted: | false |
SSDEEP: | 768:tUcy+UfuUpjGjSYzuqGhZG0sWxMlF3xPt3m:Zyz5pjG/zRsCF3+ |
MD5: | 25B8C95CF47E29857579D68F0741EFAC |
SHA1: | C260AC1E98564B22268F4FFB4282BBDC29D522BA |
SHA-256: | 4E3DB0A7CF891967A59B1A1B3FC0301CCFF33EC5B59CB9EDCC818F3B4696F642 |
SHA-512: | B5656E5FF46A7CF73E2617B7DB6D14AA359874C2695B3EE37FDBB53DB1BFEC180C37E1A4ABA5AC6687F04CA0C7E6F340A1732A5CF62172CB31CFED866AC847A2 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 40960 |
Entropy (8bit): | 5.621871376688446 |
Encrypted: | false |
SSDEEP: | 768:tUcy+UfuUpjGjSYzuqGhZG0sWxMlF3xPt3m:Zyz5pjG/zRsCF3+ |
MD5: | 25B8C95CF47E29857579D68F0741EFAC |
SHA1: | C260AC1E98564B22268F4FFB4282BBDC29D522BA |
SHA-256: | 4E3DB0A7CF891967A59B1A1B3FC0301CCFF33EC5B59CB9EDCC818F3B4696F642 |
SHA-512: | B5656E5FF46A7CF73E2617B7DB6D14AA359874C2695B3EE37FDBB53DB1BFEC180C37E1A4ABA5AC6687F04CA0C7E6F340A1732A5CF62172CB31CFED866AC847A2 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
URL: | https://cdn.discordapp.com/attachments/1349643885605031967/1349721707249930290/FDHub.exe?ex=67d5734b&is=67d421cb&hm=c44eaa2986e2ceeb64f6e0372961436a9bbbe0e8ed94b08df6ad92b879e007d4& |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 14, 2025 14:52:34.966916084 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 14:52:41.294162035 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:52:41.631901026 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:52:42.294939041 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:52:43.497694969 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:52:44.575668097 CET | 49681 | 80 | 192.168.2.4 | 2.17.190.73 |
Mar 14, 2025 14:52:45.908375978 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:52:46.881251097 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:46.881293058 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:46.881439924 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:46.881536961 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:46.881546974 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:47.570735931 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:47.570848942 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:47.572911978 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:47.572921038 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:47.573179007 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:47.622323990 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:48.164326906 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.164365053 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.164447069 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.164808989 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.164849043 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.164906979 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.165153980 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.165173054 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.165548086 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.165560961 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.468211889 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:52:48.674841881 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.674947977 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.678528070 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.678625107 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.683728933 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.683763981 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.683993101 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.684279919 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.684287071 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.684560061 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.684655905 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.728368998 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.732255936 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.778739929 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:52:48.976969004 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977030039 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977077007 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977108955 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977127075 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.977140903 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977190971 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977235079 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.977257967 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977262974 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.977277040 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.977333069 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.977407932 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.981529951 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.981556892 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.981618881 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:48.981632948 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:48.984868050 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.070033073 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.070202112 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.070233107 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.070246935 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.070262909 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.070297003 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.070310116 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.070317030 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.070365906 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.070374012 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071067095 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071116924 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.071124077 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071356058 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071389914 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071420908 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071429014 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.071435928 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071491957 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.071499109 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.071537971 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.072042942 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072093010 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072122097 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072150946 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072173119 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.072180033 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072208881 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.072808027 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072864056 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.072886944 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.072915077 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.079344988 CET | 49729 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:52:49.079360008 CET | 443 | 49729 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:52:49.388937950 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:52:50.593115091 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:52:50.712991953 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:52:52.886068106 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:52.886324883 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:52.886485100 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:52.890692949 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:52.890983105 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:52.891081095 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:52.993272066 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:52.993328094 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:52.998203039 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:52:53.155594110 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:53.155705929 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:53.159281015 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:53.163935900 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:53.166383028 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:53.171025038 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:53.267697096 CET | 443 | 49709 | 131.253.33.254 | 192.168.2.4 |
Mar 14, 2025 14:52:53.267749071 CET | 49709 | 443 | 192.168.2.4 | 131.253.33.254 |
Mar 14, 2025 14:52:53.488861084 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:52:53.493580103 CET | 80 | 49733 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 14:52:53.493684053 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:52:53.493752956 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:52:53.498420954 CET | 80 | 49733 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 14:52:54.180210114 CET | 80 | 49733 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 14:52:54.188087940 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:52:54.192768097 CET | 80 | 49733 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 14:52:54.365870953 CET | 80 | 49733 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 14:52:54.407423973 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:52:57.491854906 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:57.491909981 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:52:57.491997957 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:57.808444023 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:52:58.765261889 CET | 49726 | 443 | 192.168.2.4 | 142.250.181.228 |
Mar 14, 2025 14:52:58.765284061 CET | 443 | 49726 | 142.250.181.228 | 192.168.2.4 |
Mar 14, 2025 14:53:00.314238071 CET | 49671 | 443 | 192.168.2.4 | 204.79.197.203 |
Mar 14, 2025 14:53:03.577127934 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:53:03.577204943 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:53:03.577270985 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:53:04.765743017 CET | 49728 | 443 | 192.168.2.4 | 162.159.133.233 |
Mar 14, 2025 14:53:04.765768051 CET | 443 | 49728 | 162.159.133.233 | 192.168.2.4 |
Mar 14, 2025 14:53:07.418298006 CET | 49678 | 443 | 192.168.2.4 | 20.189.173.27 |
Mar 14, 2025 14:53:10.941807985 CET | 59969 | 53 | 192.168.2.4 | 162.159.36.2 |
Mar 14, 2025 14:53:10.946506023 CET | 53 | 59969 | 162.159.36.2 | 192.168.2.4 |
Mar 14, 2025 14:53:10.946602106 CET | 59969 | 53 | 192.168.2.4 | 162.159.36.2 |
Mar 14, 2025 14:53:10.946650028 CET | 59969 | 53 | 192.168.2.4 | 162.159.36.2 |
Mar 14, 2025 14:53:10.951368093 CET | 53 | 59969 | 162.159.36.2 | 192.168.2.4 |
Mar 14, 2025 14:53:11.449980021 CET | 53 | 59969 | 162.159.36.2 | 192.168.2.4 |
Mar 14, 2025 14:53:11.450695038 CET | 59969 | 53 | 192.168.2.4 | 162.159.36.2 |
Mar 14, 2025 14:53:11.455641985 CET | 53 | 59969 | 162.159.36.2 | 192.168.2.4 |
Mar 14, 2025 14:53:11.455773115 CET | 59969 | 53 | 192.168.2.4 | 162.159.36.2 |
Mar 14, 2025 14:53:46.946443081 CET | 59977 | 443 | 192.168.2.4 | 142.250.185.100 |
Mar 14, 2025 14:53:46.946470022 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Mar 14, 2025 14:53:46.946540117 CET | 59977 | 443 | 192.168.2.4 | 142.250.185.100 |
Mar 14, 2025 14:53:46.946672916 CET | 59977 | 443 | 192.168.2.4 | 142.250.185.100 |
Mar 14, 2025 14:53:46.946690083 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Mar 14, 2025 14:53:48.625830889 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Mar 14, 2025 14:53:48.626389027 CET | 59977 | 443 | 192.168.2.4 | 142.250.185.100 |
Mar 14, 2025 14:53:48.626410961 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Mar 14, 2025 14:53:55.045463085 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:53:55.052084923 CET | 80 | 49733 | 172.217.23.99 | 192.168.2.4 |
Mar 14, 2025 14:53:55.052158117 CET | 49733 | 80 | 192.168.2.4 | 172.217.23.99 |
Mar 14, 2025 14:53:57.594926119 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Mar 14, 2025 14:53:57.595000029 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Mar 14, 2025 14:53:57.595053911 CET | 59977 | 443 | 192.168.2.4 | 142.250.185.100 |
Mar 14, 2025 14:53:58.765202045 CET | 59977 | 443 | 192.168.2.4 | 142.250.185.100 |
Mar 14, 2025 14:53:58.765229940 CET | 443 | 59977 | 142.250.185.100 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 14, 2025 14:52:42.737337112 CET | 53 | 63274 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:52:42.761548996 CET | 53 | 56953 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:52:44.865628004 CET | 53 | 52248 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:52:46.873251915 CET | 61892 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 14:52:46.873537064 CET | 57199 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 14:52:46.879978895 CET | 53 | 61892 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:52:46.880484104 CET | 53 | 57199 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:52:48.138993025 CET | 59684 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 14:52:48.139739990 CET | 64836 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 14:52:48.145508051 CET | 53 | 59684 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:52:48.146275043 CET | 53 | 64836 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:53:01.834726095 CET | 53 | 51772 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:53:10.941217899 CET | 53 | 55536 | 162.159.36.2 | 192.168.2.4 |
Mar 14, 2025 14:53:11.460119009 CET | 55337 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 14:53:11.508487940 CET | 53 | 55337 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:53:46.938345909 CET | 65465 | 53 | 192.168.2.4 | 1.1.1.1 |
Mar 14, 2025 14:53:46.945481062 CET | 53 | 65465 | 1.1.1.1 | 192.168.2.4 |
Mar 14, 2025 14:53:47.957890987 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 14, 2025 14:52:46.873251915 CET | 192.168.2.4 | 1.1.1.1 | 0x3e30 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 14, 2025 14:52:46.873537064 CET | 192.168.2.4 | 1.1.1.1 | 0x777c | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 14, 2025 14:52:48.138993025 CET | 192.168.2.4 | 1.1.1.1 | 0xa77e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 14, 2025 14:52:48.139739990 CET | 192.168.2.4 | 1.1.1.1 | 0xe407 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 14, 2025 14:53:11.460119009 CET | 192.168.2.4 | 1.1.1.1 | 0x1a6e | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Mar 14, 2025 14:53:46.938345909 CET | 192.168.2.4 | 1.1.1.1 | 0xff1c | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 14, 2025 14:52:46.879978895 CET | 1.1.1.1 | 192.168.2.4 | 0x3e30 | No error (0) | 142.250.181.228 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 14:52:46.880484104 CET | 1.1.1.1 | 192.168.2.4 | 0x777c | No error (0) | 65 | IN (0x0001) | false | |||
Mar 14, 2025 14:52:48.145508051 CET | 1.1.1.1 | 192.168.2.4 | 0xa77e | No error (0) | 162.159.133.233 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 14:52:48.145508051 CET | 1.1.1.1 | 192.168.2.4 | 0xa77e | No error (0) | 162.159.135.233 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 14:52:48.145508051 CET | 1.1.1.1 | 192.168.2.4 | 0xa77e | No error (0) | 162.159.129.233 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 14:52:48.145508051 CET | 1.1.1.1 | 192.168.2.4 | 0xa77e | No error (0) | 162.159.134.233 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 14:52:48.145508051 CET | 1.1.1.1 | 192.168.2.4 | 0xa77e | No error (0) | 162.159.130.233 | A (IP address) | IN (0x0001) | false | ||
Mar 14, 2025 14:52:48.146275043 CET | 1.1.1.1 | 192.168.2.4 | 0xe407 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 14, 2025 14:53:11.508487940 CET | 1.1.1.1 | 192.168.2.4 | 0x1a6e | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false | |
Mar 14, 2025 14:53:46.945481062 CET | 1.1.1.1 | 192.168.2.4 | 0xff1c | No error (0) | 142.250.185.100 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.4 | 49733 | 172.217.23.99 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Mar 14, 2025 14:52:53.493752956 CET | 202 | OUT | |
Mar 14, 2025 14:52:54.180210114 CET | 222 | IN | |
Mar 14, 2025 14:52:54.188087940 CET | 200 | OUT | |
Mar 14, 2025 14:52:54.365870953 CET | 222 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49729 | 162.159.133.233 | 443 | 1236 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-14 13:52:48 UTC | 822 | OUT | |
2025-03-14 13:52:48 UTC | 1135 | IN | |
2025-03-14 13:52:48 UTC | 589 | IN | |
2025-03-14 13:52:48 UTC | 1014 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN | |
2025-03-14 13:52:48 UTC | 1369 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 09:52:37 |
Start date: | 14/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 09:52:41 |
Start date: | 14/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 09:52:47 |
Start date: | 14/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff786830000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |