Windows
Analysis Report
3661627172.svg
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 7552 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 7740 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1924,i ,104949822 3650960210 8,77605369 0028913160 2,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version --mojo-pl atform-cha nnel-handl e=2092 /pr efetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 1536 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "C:\ Users\user \Desktop\3 661627172. svg" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_JavaScriptembeddedinSVG | Yara detected JavaScript embedded in SVG | Joe Security | ||
JoeSecurity_HtmlPhish_80 | Yara detected HtmlPhish_80 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_44 | Yara detected HtmlPhish_44 | Joe Security |
Click to jump to signature section
Phishing |
---|
Source: | File source: |
Source: | File source: |
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | File source: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
tonygraham.pwswrp.ru | 104.21.32.1 | true | true | unknown | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
kakhuy07co.woofradio.cfd | 104.21.2.147 | true | true | unknown | |
www.google.com | 142.250.185.132 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
true |
| unknown | |
false | high | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.32.1 | tonygraham.pwswrp.ru | United States | 13335 | CLOUDFLARENETUS | true | |
142.250.185.132 | www.google.com | United States | 15169 | GOOGLEUS | false | |
172.67.129.81 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
192.168.2.6 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1640783 |
Start date and time: | 2025-03-17 18:17:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 25s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 3661627172.svg |
Detection: | MAL |
Classification: | mal64.phis.winSVG@27/4@10/6 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, TextInputHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.163, 142.250.186.78, 142.250.181.238, 74.125.71.84, 142.250.184.238, 142.250.185.238, 142.250.186.174, 142.250.185.110, 199.232.210.172, 142.250.185.206, 172.217.18.14, 142.250.185.174, 142.250.184.195, 142.250.185.78, 142.250.186.142, 172.217.16.195, 172.217.16.206, 23.199.214.10, 4.175.87.197
- Excluded domains from analysis (whitelisted): clients1.google.com, clients2.google.com, fs.microsoft.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.21.32.1 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2064 |
Entropy (8bit): | 4.688062995007013 |
Encrypted: | false |
SSDEEP: | 24:hPRCqdsseeK+C6uSf7p9Nai7iI/bZoL0WDC9TZYUIWZ4+vQWRBG+542uMCO:tTV1CTip9NwI/JFZEQRQO48CO |
MD5: | 2582548B3B57FD2B0FCE6A65318B0D93 |
SHA1: | 657841AAD6B2033FBE66072D8AA0C9D145129516 |
SHA-256: | B33890B04578D07E428534DAB2094ED4CB0FC9F2F54C4C0F79D2896BC6F81B27 |
SHA-512: | 0CEE5E2BC3ED0EEC27C40343FF0F3991ED9CA92943EA3AB6F89DF2E5750977A1AC4742607616660D00B33F42BB8FEAA9ECE776D55A337289396F6979A6EF95C8 |
Malicious: | false |
Reputation: | low |
URL: | https://kakhuy07co.woofradio.cfd/3IgjcDhi7bbLzyqNi74Dxtc1XOq0HV69zuTXLXqnhnYexhMqaslCucBcrtlUAvSaQSHXMHYR05jmstE6iCIFE9U9189WjNjjz6aD13nD5x0ol5cOZZSgb1syufIVGxpC2vKAj025i7NnVFZ9WFKa4eQvR2G4GQlt0NUGhxzukbWwHVKybFjbIYtqNcss36hvXYTTWP3N/YbDwc0zBR3huOXy35f8itseSalgK7rTTlIvJq1ijGxpNl40QvAaRigeNv9w4WgQtfwqU0MZf0ZjFmo6q1zQTQ4McS3cwVqHVdgJViZ0qzMmzR113GzSYhuROL0CvhNuzfR8MwDRER9IzVQyErpcLEotUxoDX7vUphdcT8zYuYxxljaaSPR7ffLs4A1GIZ6QkHtGNWsGY/ddimaano@tonygraham.com |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 183763 |
Entropy (8bit): | 4.584753819517689 |
Encrypted: | false |
SSDEEP: | 1536:ALXHmdOGNqXn1GXNMs1r9jmnUnX3iq4tLXHmdOGNqXn1GXNMs1r9jmnUnX3iq4Pr:zISpNMs1wyISpNMs1w7Qi |
MD5: | F4D015E2C3EB747D4D4F35E25B987704 |
SHA1: | 148C6AA47B07142A2D88251C206CAA5206C009C3 |
SHA-256: | 9FD0B569FB1F0E3DC7E4CD04B14A3AB60D7FAA66E6B65F1DD25117BE6F7AAD8D |
SHA-512: | B9A3A53B93F9EEB0B61BC5C0D2DEF47665DC94533193987ABA8E3CFFA2CE5155F27DCE8C8C9FC384ABB4B789E0A84D668C6A97651F145C632372C898A867A699 |
Malicious: | false |
Reputation: | low |
URL: | https://tonygraham.pwswrp.ru/8T8x6LF1E/ |
Preview: |
File type: | |
Entropy (8bit): | 5.646290552847957 |
TrID: | |
File name: | 3661627172.svg |
File size: | 4'110 bytes |
MD5: | b6a88357b2e5cd6ced7d126e00b43081 |
SHA1: | d10bc9ec13b8f1366af43eb1a7c6b1e382c52d6e |
SHA256: | a24d4b69a5ce681a4ad85800aaaaf900ef55c38970c4c0ccf09036d45f1aa975 |
SHA512: | 3ec14f2bc020907f5c25113759c7a9574c46aacedde62d5fd48c53232f6fd80b252691a83b1aa4105c3f3ac08b47ca58ed4fb0ca4a3fec8056c5392733786073 |
SSDEEP: | 96:A451Zh5qEvEEd4g6nU1GSq23Z/0is9UmYhHqIhY15u:AkewEuTro94ht |
TLSH: | 758164A00C5F0E1C133151D3DCDD18CA878ED3976F81E68C728FD9A4A79653A06CA8CB |
File Content Preview: | The explorer composed a beautiful painting in the desert. -->.<svg xmlns="http://www.w3.org/2000/svg" width="100%" height="100%">. The child painted a curious thought while sailing across the seas. -->. <foreignObject width="100%" heig |
Icon Hash: | 173149cccc490307 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 17, 2025 18:18:07.142832041 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:07.452042103 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:07.889568090 CET | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Mar 17, 2025 18:18:08.061391115 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:09.264518023 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:11.670785904 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:16.483519077 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:16.945957899 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:16.946002960 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:16.947675943 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:16.947767019 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:16.947774887 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:17.498997927 CET | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Mar 17, 2025 18:18:17.593162060 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:17.593259096 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:17.595315933 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:17.595325947 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:17.595565081 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:17.639611959 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:19.236804962 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.236851931 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.236933947 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.241688967 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.241702080 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.717091084 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.717159033 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.718565941 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.718578100 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.718895912 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.719223022 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.760320902 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.996264935 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.996330023 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.996463060 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:19.996540070 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.998043060 CET | 49702 | 443 | 192.168.2.6 | 172.67.129.81 |
Mar 17, 2025 18:18:19.998064041 CET | 443 | 49702 | 172.67.129.81 | 192.168.2.6 |
Mar 17, 2025 18:18:20.098185062 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.098257065 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.098340988 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.098773003 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.098813057 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.098887920 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.099383116 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.099395037 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.099536896 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.099560022 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.562123060 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.562241077 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.563635111 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.563643932 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.563879967 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.564377069 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.582515955 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.582711935 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.583115101 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:20.583123922 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.583358049 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.612318993 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.625338078 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.259327888 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259423018 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259449005 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259475946 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259489059 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.259505033 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259517908 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.259535074 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259558916 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259601116 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.259607077 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259639025 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.259643078 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.259951115 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.260008097 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.260013103 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.313519001 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.313544989 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.361516953 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.363213062 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363265991 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363298893 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363327980 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363343000 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.363353014 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363369942 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.363521099 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363605022 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363647938 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363665104 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.363670111 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.363686085 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.364356041 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.364387035 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.364428043 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.364455938 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.364516973 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.364710093 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.364717007 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.365286112 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.365314007 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.365331888 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.365336895 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.365376949 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.365395069 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.365400076 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.365684986 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.379889011 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.423815966 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.449835062 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.449899912 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.449942112 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.449945927 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.449956894 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450090885 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450114965 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450123072 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.450133085 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450149059 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.450743914 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450889111 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450906992 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.450911999 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.450928926 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.450959921 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.451524973 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.451625109 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.451642990 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.451647043 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.451663017 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.451690912 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.451733112 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.452529907 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.452565908 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.452570915 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.452620983 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.452658892 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.452697992 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.525984049 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.526204109 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.536514997 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.536740065 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.536789894 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.536838055 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.536988974 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.537035942 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.537106991 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.537161112 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.537354946 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.537419081 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.537452936 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.537492990 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.537837029 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.537882090 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.537952900 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.537993908 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.538054943 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.538095951 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.538228035 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.538270950 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.538830042 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.538866043 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.538882971 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.538889885 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.538902998 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.539036989 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.539055109 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.539058924 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.539081097 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.539613962 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.539654970 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.539659023 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.539695024 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.539788961 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.539840937 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.540000916 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.540041924 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.540046930 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.540081978 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.540621996 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.540733099 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.540811062 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.540853977 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.560704947 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.612710953 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.612793922 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624315023 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624353886 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624370098 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624377966 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624397039 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624428988 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624449015 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624449015 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624454021 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624464035 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624468088 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624511003 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624520063 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624550104 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.624564886 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.624623060 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.625396967 CET | 49705 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.625413895 CET | 443 | 49705 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:21.696939945 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:21.744323969 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.123099089 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.123173952 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.123215914 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:22.126045942 CET | 49704 | 443 | 192.168.2.6 | 104.21.32.1 |
Mar 17, 2025 18:18:22.126061916 CET | 443 | 49704 | 104.21.32.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.134262085 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.134294033 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.134360075 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.134509087 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.134522915 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.599880934 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.599977970 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.601126909 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.601134062 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.601428986 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.601738930 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.644318104 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.726521015 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.726602077 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.726664066 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.726902008 CET | 49706 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.726917982 CET | 443 | 49706 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.727847099 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.727884054 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.727946997 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.728092909 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:22.728102922 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.180198908 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.180502892 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:23.180521011 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.180655956 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:23.180664062 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.311337948 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.311517000 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.311604977 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:23.311794043 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:23.311794043 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:23.311815023 CET | 443 | 49707 | 35.190.80.1 | 192.168.2.6 |
Mar 17, 2025 18:18:23.311906099 CET | 49707 | 443 | 192.168.2.6 | 35.190.80.1 |
Mar 17, 2025 18:18:26.092849970 CET | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Mar 17, 2025 18:18:27.489006042 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:27.489070892 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:27.489545107 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:28.953963041 CET | 49701 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:18:28.953994989 CET | 443 | 49701 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:18:29.730216980 CET | 80 | 49685 | 142.250.186.99 | 192.168.2.6 |
Mar 17, 2025 18:18:29.730341911 CET | 49685 | 80 | 192.168.2.6 | 142.250.186.99 |
Mar 17, 2025 18:18:29.730397940 CET | 49685 | 80 | 192.168.2.6 | 142.250.186.99 |
Mar 17, 2025 18:18:29.735079050 CET | 80 | 49685 | 142.250.186.99 | 192.168.2.6 |
Mar 17, 2025 18:18:58.367266893 CET | 80 | 49683 | 217.20.57.35 | 192.168.2.6 |
Mar 17, 2025 18:18:58.367466927 CET | 49683 | 80 | 192.168.2.6 | 217.20.57.35 |
Mar 17, 2025 18:18:58.367512941 CET | 49683 | 80 | 192.168.2.6 | 217.20.57.35 |
Mar 17, 2025 18:18:58.372195959 CET | 80 | 49683 | 217.20.57.35 | 192.168.2.6 |
Mar 17, 2025 18:19:00.572740078 CET | 80 | 49687 | 217.20.57.35 | 192.168.2.6 |
Mar 17, 2025 18:19:00.572904110 CET | 49687 | 80 | 192.168.2.6 | 217.20.57.35 |
Mar 17, 2025 18:19:00.572985888 CET | 49687 | 80 | 192.168.2.6 | 217.20.57.35 |
Mar 17, 2025 18:19:00.577661991 CET | 80 | 49687 | 217.20.57.35 | 192.168.2.6 |
Mar 17, 2025 18:19:00.812510967 CET | 80 | 49690 | 217.20.57.35 | 192.168.2.6 |
Mar 17, 2025 18:19:00.812659025 CET | 49690 | 80 | 192.168.2.6 | 217.20.57.35 |
Mar 17, 2025 18:19:01.847043037 CET | 49686 | 443 | 192.168.2.6 | 2.23.227.208 |
Mar 17, 2025 18:19:01.847150087 CET | 49691 | 80 | 192.168.2.6 | 2.23.77.188 |
Mar 17, 2025 18:19:01.847491980 CET | 49690 | 80 | 192.168.2.6 | 217.20.57.35 |
Mar 17, 2025 18:19:17.001266003 CET | 49715 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:19:17.001310110 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:17.001380920 CET | 49715 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:19:17.001638889 CET | 49715 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:19:17.001652002 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:17.639189959 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:17.639641047 CET | 49715 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:19:17.639661074 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:20.629611969 CET | 443 | 49681 | 2.23.227.215 | 192.168.2.6 |
Mar 17, 2025 18:19:20.629640102 CET | 443 | 49681 | 2.23.227.215 | 192.168.2.6 |
Mar 17, 2025 18:19:20.629712105 CET | 49681 | 443 | 192.168.2.6 | 2.23.227.215 |
Mar 17, 2025 18:19:20.629750967 CET | 49681 | 443 | 192.168.2.6 | 2.23.227.215 |
Mar 17, 2025 18:19:27.547512054 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:27.547576904 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:27.547645092 CET | 49715 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:19:28.938836098 CET | 49715 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:19:28.938874960 CET | 443 | 49715 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:19:47.031133890 CET | 49684 | 80 | 192.168.2.6 | 2.23.77.188 |
Mar 17, 2025 18:19:47.031132936 CET | 49682 | 443 | 192.168.2.6 | 20.190.159.68 |
Mar 17, 2025 18:19:47.037705898 CET | 80 | 49684 | 2.23.77.188 | 192.168.2.6 |
Mar 17, 2025 18:19:47.037813902 CET | 49684 | 80 | 192.168.2.6 | 2.23.77.188 |
Mar 17, 2025 18:19:47.037837029 CET | 443 | 49682 | 20.190.159.68 | 192.168.2.6 |
Mar 17, 2025 18:19:47.037878990 CET | 49682 | 443 | 192.168.2.6 | 20.190.159.68 |
Mar 17, 2025 18:20:17.063615084 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:20:17.063663006 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:20:17.063743114 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:20:17.063939095 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:20:17.063949108 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:20:17.717447042 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:20:17.717878103 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:20:17.717920065 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:20:27.620508909 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:20:27.620580912 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:20:27.620702982 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:20:28.047629118 CET | 49728 | 443 | 192.168.2.6 | 142.250.185.132 |
Mar 17, 2025 18:20:28.047657013 CET | 443 | 49728 | 142.250.185.132 | 192.168.2.6 |
Mar 17, 2025 18:21:21.961847067 CET | 49679 | 443 | 192.168.2.6 | 20.191.45.158 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 17, 2025 18:18:12.646330118 CET | 53 | 57177 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:12.654006004 CET | 53 | 60091 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:13.669454098 CET | 53 | 58893 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:13.788252115 CET | 53 | 65001 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:16.937943935 CET | 52306 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:16.937943935 CET | 61488 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:16.944602013 CET | 53 | 61488 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:16.944977999 CET | 53 | 52306 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:19.178857088 CET | 58020 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:19.179019928 CET | 51304 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:19.194576025 CET | 59515 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:19.194737911 CET | 62899 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:19.202934027 CET | 53 | 51304 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:19.209530115 CET | 53 | 58020 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:19.210643053 CET | 53 | 62899 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:19.217864990 CET | 53 | 59515 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.062896967 CET | 62987 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:20.063168049 CET | 50910 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:20.072746992 CET | 53 | 62987 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:20.118278027 CET | 53 | 50910 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.124623060 CET | 60647 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:22.125144958 CET | 62864 | 53 | 192.168.2.6 | 1.1.1.1 |
Mar 17, 2025 18:18:22.131661892 CET | 53 | 60647 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:22.133883953 CET | 53 | 62864 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:30.806556940 CET | 53 | 50335 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:18:49.886334896 CET | 53 | 60430 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:19:05.209328890 CET | 138 | 138 | 192.168.2.6 | 192.168.2.255 |
Mar 17, 2025 18:19:12.249156952 CET | 53 | 64174 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:19:12.273211002 CET | 53 | 59434 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:19:15.805259943 CET | 53 | 56698 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:19:42.069550991 CET | 53 | 64654 | 1.1.1.1 | 192.168.2.6 |
Mar 17, 2025 18:20:28.055969954 CET | 53 | 59795 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Mar 17, 2025 18:18:20.118415117 CET | 192.168.2.6 | 1.1.1.1 | c2e4 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 17, 2025 18:18:16.937943935 CET | 192.168.2.6 | 1.1.1.1 | 0x7685 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 17, 2025 18:18:16.937943935 CET | 192.168.2.6 | 1.1.1.1 | 0xb46 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 18:18:19.178857088 CET | 192.168.2.6 | 1.1.1.1 | 0x2039 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 18:18:19.179019928 CET | 192.168.2.6 | 1.1.1.1 | 0x1964 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 17, 2025 18:18:19.194576025 CET | 192.168.2.6 | 1.1.1.1 | 0x409a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 18:18:19.194737911 CET | 192.168.2.6 | 1.1.1.1 | 0x912e | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 17, 2025 18:18:20.062896967 CET | 192.168.2.6 | 1.1.1.1 | 0x1f62 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 18:18:20.063168049 CET | 192.168.2.6 | 1.1.1.1 | 0xfc87 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 17, 2025 18:18:22.124623060 CET | 192.168.2.6 | 1.1.1.1 | 0x45b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 18:18:22.125144958 CET | 192.168.2.6 | 1.1.1.1 | 0xed69 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 17, 2025 18:18:16.944602013 CET | 1.1.1.1 | 192.168.2.6 | 0xb46 | No error (0) | 142.250.185.132 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:16.944977999 CET | 1.1.1.1 | 192.168.2.6 | 0x7685 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 17, 2025 18:18:19.202934027 CET | 1.1.1.1 | 192.168.2.6 | 0x1964 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 17, 2025 18:18:19.209530115 CET | 1.1.1.1 | 192.168.2.6 | 0x2039 | No error (0) | 104.21.2.147 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:19.209530115 CET | 1.1.1.1 | 192.168.2.6 | 0x2039 | No error (0) | 172.67.129.81 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:19.210643053 CET | 1.1.1.1 | 192.168.2.6 | 0x912e | No error (0) | 65 | IN (0x0001) | false | |||
Mar 17, 2025 18:18:19.217864990 CET | 1.1.1.1 | 192.168.2.6 | 0x409a | No error (0) | 172.67.129.81 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:19.217864990 CET | 1.1.1.1 | 192.168.2.6 | 0x409a | No error (0) | 104.21.2.147 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.072746992 CET | 1.1.1.1 | 192.168.2.6 | 0x1f62 | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 18:18:20.118278027 CET | 1.1.1.1 | 192.168.2.6 | 0xfc87 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 17, 2025 18:18:22.131661892 CET | 1.1.1.1 | 192.168.2.6 | 0x45b7 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49702 | 172.67.129.81 | 443 | 7740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 17:18:19 UTC | 1085 | OUT | |
2025-03-17 17:18:19 UTC | 853 | IN | |
2025-03-17 17:18:19 UTC | 516 | IN | |
2025-03-17 17:18:19 UTC | 1369 | IN | |
2025-03-17 17:18:19 UTC | 186 | IN | |
2025-03-17 17:18:19 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49705 | 104.21.32.1 | 443 | 7740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 17:18:20 UTC | 710 | OUT | |
2025-03-17 17:18:21 UTC | 1216 | IN | |
2025-03-17 17:18:21 UTC | 762 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN | |
2025-03-17 17:18:21 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49704 | 104.21.32.1 | 443 | 7740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 17:18:21 UTC | 1336 | OUT | |
2025-03-17 17:18:22 UTC | 844 | IN | |
2025-03-17 17:18:22 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49706 | 35.190.80.1 | 443 | 7740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 17:18:22 UTC | 547 | OUT | |
2025-03-17 17:18:22 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49707 | 35.190.80.1 | 443 | 7740 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 17:18:23 UTC | 522 | OUT | |
2025-03-17 17:18:23 UTC | 438 | OUT | |
2025-03-17 17:18:23 UTC | 214 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 13:18:10 |
Start date: | 17/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 1 |
Start time: | 13:18:11 |
Start date: | 17/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 13:18:18 |
Start date: | 17/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |