Windows
Analysis Report
https://check.xemyrai6.icu/gkcxv.google?i=3755074e-f8fb-4a7a-b690-776492d909a4%20#%20''I%20am%20not%20a%20robot%20-%20%D0%A1%D0%90%D0%A0%D0%A2%D0%A1%D0%9D%D0%90%20Verification%20ID:738948''
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
chrome.exe (PID: 1272 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: DBE43C1D0092437B88CFF7BD9ABC336C) chrome.exe (PID: 5228 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1844,i ,577010779 7414074847 ,104683192 0253140096 8,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250316- 180048.776 000 --mojo -platform- channel-ha ndle=2100 /prefetch: 11 MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
chrome.exe (PID: 6172 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://check .xemyrai6. icu/gkcxv. google?i=3 755074e-f8 fb-4a7a-b6 90-776492d 909a4%20#% 20''I%20am %20not%20a %20robot%2 0-%20????? ??%20Verif ication%20 ID:738948' '" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
check.xemyrai6.icu | 188.114.96.3 | true | false | unknown | |
www.google.com | 142.250.186.68 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false |
| unknown | |
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.68 | www.google.com | United States | 15169 | GOOGLEUS | false | |
188.114.96.3 | check.xemyrai6.icu | European Union | 13335 | CLOUDFLARENETUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.24 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1640905 |
Start date and time: | 2025-03-17 21:01:21 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 52s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://check.xemyrai6.icu/gkcxv.google?i=3755074e-f8fb-4a7a-b690-776492d909a4%20#%20''I%20am%20not%20a%20robot%20-%20%D0%A1%D0%90%D0%A0%D0%A2%D0%A1%D0%9D%D0%90%20Verification%20ID:738948'' |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal56.win@24/0@6/4 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): SystemSettingsBroker.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.206, 142.250.184.227, 216.58.206.46, 74.125.206.84, 142.250.185.142, 142.250.185.238, 131.107.255.255, 142.250.185.174, 142.250.186.110, 142.250.185.110, 216.58.206.67, 216.58.206.78, 172.217.16.206, 142.251.32.110, 173.194.7.38, 142.250.185.78
- Excluded domains from analysis (whitelisted): clients2.google.com, edgedl.me.gvt1.com, accounts.google.com, redirector.gvt1.com, r1.sn-p5qddn76.gvt1.com, r1---sn-p5qddn76.gvt1.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com, dns.msftncsi.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- VT rate limit hit for: https://check.xemyrai6.icu/gkcxv.google?i=3755074e-f8fb-4a7a-b690-776492d909a4%20#%20''I%20am%20not%20a%20robot%20-%20%20Verification%20ID:738948''
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 17, 2025 21:02:19.085863113 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:19.085896969 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:19.086111069 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:19.086111069 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:19.086141109 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:19.719037056 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:19.719115019 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:19.720580101 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:19.720588923 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:19.720812082 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:19.763358116 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:20.142021894 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.142047882 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.142122984 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.142337084 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.142360926 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.142416000 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.142566919 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.142580986 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.142693043 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.142709017 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.674247980 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.674321890 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.675882101 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.675892115 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.676085949 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.676747084 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.695065975 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.695133924 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.695700884 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:20.695708036 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.695931911 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.720333099 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:20.737430096 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:21.029786110 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:21.029846907 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:21.029921055 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:21.031352043 CET | 60830 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:21.031367064 CET | 443 | 60830 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:21.083077908 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.083098888 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.083169937 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.083522081 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.083534002 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.551244974 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.551317930 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.552336931 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.552340984 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.552572966 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.552828074 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.596327066 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.676911116 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.676992893 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.677074909 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.677211046 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.677217960 CET | 443 | 60831 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.677227020 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.677262068 CET | 60831 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.677859068 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.677898884 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.677962065 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.678111076 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:21.678124905 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:22.151472092 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:22.151844025 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:22.151873112 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:22.152004004 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:22.152009964 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:22.283121109 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:22.283164978 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:22.283227921 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:22.283566952 CET | 60833 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:02:22.283582926 CET | 443 | 60833 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:02:29.618496895 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:29.618551016 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:29.618598938 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:30.991012096 CET | 60828 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:02:30.991034031 CET | 443 | 60828 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:02:35.513916969 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.513955116 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.514022112 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.514596939 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.514611006 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.520348072 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.564321041 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.583914042 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.583972931 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.584115028 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.584162951 CET | 60829 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.584175110 CET | 443 | 60829 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.977847099 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.978262901 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.978286028 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:35.978332043 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:35.978337049 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:36.331825018 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:36.331888914 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:36.331943989 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:36.332756996 CET | 60834 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:36.332771063 CET | 443 | 60834 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.481807947 CET | 60836 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.481858015 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.481987000 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.481990099 CET | 60836 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.482017994 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.482366085 CET | 60836 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.482384920 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.482409000 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.482692003 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.482705116 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.953754902 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.954190969 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.954190969 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.954205990 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.954221010 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.956059933 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:47.956425905 CET | 60836 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:47.956435919 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:48.329628944 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:48.329715014 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:02:48.329780102 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:48.330488920 CET | 60837 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:02:48.330504894 CET | 443 | 60837 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:03:02.858321905 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:03:02.858376026 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:03:02.858424902 CET | 60836 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:03:02.991914988 CET | 60836 | 443 | 192.168.2.24 | 188.114.96.3 |
Mar 17, 2025 21:03:02.991940975 CET | 443 | 60836 | 188.114.96.3 | 192.168.2.24 |
Mar 17, 2025 21:03:19.131997108 CET | 60845 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:03:19.132035017 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:03:19.132103920 CET | 60845 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:03:19.132333040 CET | 60845 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:03:19.132349968 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:03:20.085809946 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:03:20.086327076 CET | 60845 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:03:20.086338997 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:03:20.372900009 CET | 50311 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:03:20.377612114 CET | 53 | 50311 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:20.377672911 CET | 50311 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:03:20.378735065 CET | 50311 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:03:20.383407116 CET | 53 | 50311 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:20.819883108 CET | 53 | 50311 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:20.820144892 CET | 50311 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:03:20.825118065 CET | 53 | 50311 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:20.825191975 CET | 50311 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:03:21.036987066 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.037009954 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.037065983 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.037184000 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.037194967 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.496499062 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.496885061 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.496897936 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.496957064 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.496961117 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.631398916 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.631608009 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.631756067 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.631768942 CET | 443 | 50313 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.631963015 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.631963015 CET | 50313 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.632330894 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.632364035 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:21.632431030 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.632577896 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:21.632591963 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.105262041 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.105693102 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:22.105720043 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.105746031 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:22.105746031 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:22.105752945 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.105762005 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.237947941 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.238095045 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.238235950 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:22.238296032 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:22.238318920 CET | 443 | 50314 | 35.190.80.1 | 192.168.2.24 |
Mar 17, 2025 21:03:22.238328934 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:22.238364935 CET | 50314 | 443 | 192.168.2.24 | 35.190.80.1 |
Mar 17, 2025 21:03:30.006082058 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:03:30.006136894 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Mar 17, 2025 21:03:30.006194115 CET | 60845 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:03:30.990988970 CET | 60845 | 443 | 192.168.2.24 | 142.250.186.68 |
Mar 17, 2025 21:03:30.991003036 CET | 443 | 60845 | 142.250.186.68 | 192.168.2.24 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 17, 2025 21:02:14.819432974 CET | 53 | 53358 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:14.884975910 CET | 53 | 59564 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:16.473522902 CET | 53 | 63456 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:19.077682018 CET | 54214 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:02:19.077682018 CET | 57810 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:02:19.084716082 CET | 53 | 54214 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:19.084932089 CET | 53 | 57810 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:20.125653028 CET | 57943 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:02:20.125994921 CET | 59100 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:02:20.137206078 CET | 53 | 59100 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:20.141484022 CET | 53 | 57943 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.059103012 CET | 63665 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:02:21.059305906 CET | 57572 | 53 | 192.168.2.24 | 1.1.1.1 |
Mar 17, 2025 21:02:21.066044092 CET | 53 | 63665 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:21.066601038 CET | 53 | 57572 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:33.545407057 CET | 53 | 60949 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:02:44.937850952 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Mar 17, 2025 21:02:45.678180933 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Mar 17, 2025 21:02:46.431224108 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Mar 17, 2025 21:02:52.295535088 CET | 53 | 60795 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:14.422386885 CET | 53 | 52362 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:15.328470945 CET | 53 | 61777 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:17.842227936 CET | 53 | 63459 | 1.1.1.1 | 192.168.2.24 |
Mar 17, 2025 21:03:20.372559071 CET | 53 | 58305 | 1.1.1.1 | 192.168.2.24 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 17, 2025 21:02:19.077682018 CET | 192.168.2.24 | 1.1.1.1 | 0x3ae4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 21:02:19.077682018 CET | 192.168.2.24 | 1.1.1.1 | 0x9ed2 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 17, 2025 21:02:20.125653028 CET | 192.168.2.24 | 1.1.1.1 | 0xdc12 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 21:02:20.125994921 CET | 192.168.2.24 | 1.1.1.1 | 0x5588 | Standard query (0) | 65 | IN (0x0001) | false | |
Mar 17, 2025 21:02:21.059103012 CET | 192.168.2.24 | 1.1.1.1 | 0x48a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Mar 17, 2025 21:02:21.059305906 CET | 192.168.2.24 | 1.1.1.1 | 0x3d21 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 17, 2025 21:02:19.084716082 CET | 1.1.1.1 | 192.168.2.24 | 0x3ae4 | No error (0) | 142.250.186.68 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 21:02:19.084932089 CET | 1.1.1.1 | 192.168.2.24 | 0x9ed2 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 17, 2025 21:02:20.137206078 CET | 1.1.1.1 | 192.168.2.24 | 0x5588 | No error (0) | 65 | IN (0x0001) | false | |||
Mar 17, 2025 21:02:20.141484022 CET | 1.1.1.1 | 192.168.2.24 | 0xdc12 | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 21:02:20.141484022 CET | 1.1.1.1 | 192.168.2.24 | 0xdc12 | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Mar 17, 2025 21:02:21.066044092 CET | 1.1.1.1 | 192.168.2.24 | 0x48a6 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.24 | 60830 | 188.114.96.3 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:02:20 UTC | 722 | OUT | |
2025-03-17 20:02:21 UTC | 856 | IN | |
2025-03-17 20:02:21 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 60831 | 35.190.80.1 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:02:21 UTC | 551 | OUT | |
2025-03-17 20:02:21 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.24 | 60833 | 35.190.80.1 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:02:22 UTC | 526 | OUT | |
2025-03-17 20:02:22 UTC | 442 | OUT | |
2025-03-17 20:02:22 UTC | 214 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.24 | 60829 | 188.114.96.3 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:02:35 UTC | 754 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.24 | 60834 | 188.114.96.3 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:02:35 UTC | 754 | OUT | |
2025-03-17 20:02:36 UTC | 855 | IN | |
2025-03-17 20:02:36 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.24 | 60837 | 188.114.96.3 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:02:47 UTC | 754 | OUT | |
2025-03-17 20:02:48 UTC | 855 | IN | |
2025-03-17 20:02:48 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.24 | 50313 | 35.190.80.1 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:03:21 UTC | 551 | OUT | |
2025-03-17 20:03:21 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.24 | 50314 | 35.190.80.1 | 443 | 5228 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-17 20:03:22 UTC | 527 | OUT | |
2025-03-17 20:03:22 UTC | 1347 | OUT | |
2025-03-17 20:03:22 UTC | 214 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 16:02:11 |
Start date: | 17/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d9110000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 16:02:12 |
Start date: | 17/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d9110000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 16:02:18 |
Start date: | 17/03/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d9110000 |
File size: | 3'384'928 bytes |
MD5 hash: | DBE43C1D0092437B88CFF7BD9ABC336C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |