Windows
Analysis Report
https://infector.sh/index
Overview
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 5956 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 1952 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2044,i ,159484815 3030529683 1,52049827 8735251730 7,262144 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onHintsFet ching,Opti mizationTa rgetPredic tion --var iations-se ed-version =20250306- 183004.429 000 --mojo -platform- channel-ha ndle=2108 /prefetch: 3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 6224 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://infec tor.sh/ind ex" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
# Phishing Threat Analysis: Microsoft Brand Impersonation
## Threat Overview
A sophisticated phishing attempt targeting Microsoft users has been detected, using a deceptive login page to harvest user credentials through brand impersonation.
## Key Findings
### Brand Impersonation Tactics
- The attacker has created a pixel-perfect replica of a legitimate Microsoft sign-in page
- Leverages the official Microsoft logo and login interface design to appear authentic
- Hosted on a suspicious domain 'infector.sh', which is unrelated to Microsoft
### Credential Harvesting Mechanism
- Presents a familiar login interface requesting:
- Email, phone, or Skype credentials
- Includes "No account? Create one!" and "Sign in with a security key" options to mimic genuine Microsoft login flow
- Strategic placement of input fields designed to trick users into voluntarily submitting sensitive authentication information
### Technical Red Flags
- Domain mismatch: 'infector.sh' vs legitimate 'microsoft.com'
- Unusual top-level domain '.sh' signals potential malicious infrastructure
- High risk score of 9/10 indicating a high-confidence phishing attempt
## Conclusion
This phishing site represents a carefully crafted impersonation of Microsoft's login page, engineered to deceive users and capture their credentials through visual mimicry and social engineering techniques.
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CAPTCHAScam | Yara detected CAPTCHA Scam/ ClickFix | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CAPTCHAScam | Yara detected CAPTCHA Scam/ ClickFix | Joe Security |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-06-03T19:17:17.391580+0200 | 2058473 | 1 | A Network Trojan was detected | 130.51.23.140 | 443 | 192.168.2.9 | 49697 | TCP |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | File source: | ||
Source: | File source: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Drive-by Compromise | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.138.99 | true | false | high | |
infector.sh | 130.51.23.140 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown | ||
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.138.99 | www.google.com | United States | 15169 | GOOGLEUS | false | |
130.51.23.140 | infector.sh | Reserved | 15601 | BaringInvestmentServicesGB | true |
IP |
---|
192.168.2.9 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1705195 |
Start date and time: | 2025-06-03 19:15:51 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 28s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | https://infector.sh/index |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal64.phis.win@21/8@4/3 |
EGA Information: | Failed |
HCA Information: |
|
- Exclude process from analysis (whitelisted): sppsvc.exe, SIHClient.exe, SgrmBroker.exe, TextInputHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.251.116.94, 142.250.138.101, 142.250.138.113, 142.250.138.100, 142.250.138.102, 142.250.138.138, 142.250.138.139, 142.250.114.113, 142.250.114.102, 142.250.114.100, 142.250.114.138, 142.250.114.101, 142.250.114.139, 173.194.208.84, 142.251.186.139, 142.251.186.138, 142.251.186.102, 142.251.186.113, 142.251.186.100, 142.251.186.101, 142.251.116.113, 142.251.116.138, 142.251.116.139, 142.251.116.102, 142.251.116.100, 142.251.116.101, 172.253.58.138, 172.253.58.139, 172.253.58.102, 172.253.58.100, 172.253.58.113, 172.253.58.101, 173.194.208.102, 173.194.208.138, 173.194.208.113, 173.194.208.139, 173.194.208.100, 173.194.208.101, 142.251.186.95, 173.194.208.95, 142.250.115.95, 142.250.113.95, 142.250.114.95, 142.250.138.95, 142.251.116.95, 23.53.127.231, 209.85.235.139, 209.85.235.102, 209.85.235.113, 209.85.235.101, 209.85.235.100, 209.85.235.138, 173.194.78.94, 142.251.187.138, 142.251.187.139, 142.251.187.101, 142.251.187.100, 142.251.187.102, 142.251.187.113, 104.
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 36 |
Entropy (8bit): | 4.321888195526177 |
Encrypted: | false |
SSDEEP: | 3:Ftt113Spye0n:XtfS47 |
MD5: | 8F5D1BCD40FE2D360819C01A59AB7A56 |
SHA1: | 04EF4B3654056DB95992A8E4F4E6FF1FD584F309 |
SHA-256: | EB36CCBA07BEB1EF1EACD8E48A783C557483DD8C27033A19BEEC96F86459BD89 |
SHA-512: | 8BC2291E5ED8034D62116A7E06D963DA170A8009C4930E154279B98B618A814F596D7593AE1C548B548E9D49667D73A9964CD636D9B1CAA011E4AD20F0ABD0DA |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCQ7GeYUnJB1FEgUNzyMq_yGgnSzOtkyjVA==?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 52 |
Entropy (8bit): | 4.844106544814539 |
Encrypted: | false |
SSDEEP: | 3:Ftt113Sp1prxphv2G/:XtfSbpjVB/ |
MD5: | 822B3E1C9A80D38A21B1CA72FBB405FF |
SHA1: | 4A95D57B3B54B7AF8B7306A8A93A30FB633469C6 |
SHA-256: | BA0847E6558E8D342496B3B2A9E97BE84F93DE9D03E098D3F33AED95AFC53E4E |
SHA-512: | 5BEF5C6358BC978FB16070952BCB38EC9308D3A4B96D83864E6EE51715E7076230AAAA868903AA65968A0FE721637FEB10A3DEF1376BCFC40CA9298CD6FD8666 |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCQ7GeYUnJB1FEgUNzyMq_yGgnSzOtkyjVBIZCfEZNMISFONBEgUNxZPEJCGTmIglQgZ5eQ==?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 187447 |
Entropy (8bit): | 5.759143887511641 |
Encrypted: | false |
SSDEEP: | 3072:XU6X2h/+arh7d3JrggynSSOw6lxxLLiPix1Isk9/9FSCagTY5sc:XU6Gr33yTSSdOiPix7k1i4lc |
MD5: | 8E0F5963C61608C54D661F7E91C9A522 |
SHA1: | 475447E64F59F908ABD77DAB7A313B906E692D8F |
SHA-256: | 788F1733F0A80F3566E7518F36DA75BFB21298FC493D4951B77C132FE2B228ED |
SHA-512: | FB0F85DF1667EF8B2D2E66690ED342C3B5DFEE6777311E6E6646085AB668682C0D695592CDA4842AC461E4E4D06E760B8BBFD1AABAB6B8D5F8EE84A5EED5612F |
Malicious: | false |
Reputation: | low |
URL: | https://infector.sh/clickfix |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 21787 |
Entropy (8bit): | 5.63805974421119 |
Encrypted: | false |
SSDEEP: | 384:efF9F+e4JEsEH3Us4T3swSqxsEH3UhsEH3UNaaw:efF9F+e4esEEX9SqxsEEhsEENaaw |
MD5: | 43CDDC41A8139D36D2F096EEB30E65FC |
SHA1: | 7BA09DCD33739409920C92A9C0D20503CB2CED41 |
SHA-256: | 5F09D3F10EEB12CEA71CD0727F99247217995D6A0B57D523B4CDCD47C38CDB6C |
SHA-512: | A2D0406D715B2B28E8E80CFC5057CC835D335A3B2206D6ADCF35A92B5742A61EDCAC25871A64EAED02FAF89A60B4DCEE34B1CD7BF2F8E4880FDC9D420FE41FB7 |
Malicious: | false |
Reputation: | low |
URL: | https://infector.sh/index |
Preview: |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-06-03T19:17:17.391580+0200 | 2058473 | ET MALWARE Observed ClickFix Powershell Delivery Page Inbound | 1 | 130.51.23.140 | 443 | 192.168.2.9 | 49697 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 3, 2025 19:16:45.247529030 CEST | 49675 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:16:45.247528076 CEST | 49673 | 443 | 192.168.2.9 | 2.23.227.215 |
Jun 3, 2025 19:16:45.247558117 CEST | 49674 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:16:51.611567020 CEST | 49676 | 80 | 192.168.2.9 | 2.23.73.143 |
Jun 3, 2025 19:16:51.611638069 CEST | 49677 | 443 | 192.168.2.9 | 2.19.104.63 |
Jun 3, 2025 19:16:54.862317085 CEST | 49675 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:16:54.862338066 CEST | 49674 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:16:54.862338066 CEST | 49673 | 443 | 192.168.2.9 | 2.23.227.215 |
Jun 3, 2025 19:16:55.129051924 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:16:55.129090071 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:16:55.129198074 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:16:55.129551888 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:16:55.129561901 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:16:55.407329082 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:16:55.407402039 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:16:55.408658028 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:16:55.408668995 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:16:55.409236908 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:16:55.456079960 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:16:56.642589092 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:56.642637014 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:56.642700911 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:56.643106937 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:56.643115044 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:56.644280910 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:56.644325018 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:56.644999981 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:56.644999981 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:56.645030022 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.090528011 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.090687990 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.091892004 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.091902018 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.092138052 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.092144966 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.100521088 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.100671053 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.101114035 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.101155043 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.101166964 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.104326963 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.146473885 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.146497965 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.393099070 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.393712997 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.393723965 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.393754959 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.393785954 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.393798113 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.393857002 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.393888950 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.413719893 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.460272074 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.560179949 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.602695942 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.604935884 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:16:57.604948044 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.751440048 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:16:57.801539898 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:03.296210051 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:03.296251059 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:03.296374083 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:03.300116062 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:03.300129890 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.095196962 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.095314980 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.098862886 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.098875999 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.099541903 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.143141031 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.566416979 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.566446066 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.566556931 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.567549944 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.568583012 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.568655014 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.569428921 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.612277031 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.731815100 CEST | 49703 | 80 | 192.168.2.9 | 142.250.114.94 |
Jun 3, 2025 19:17:04.830770969 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:04.854351997 CEST | 80 | 49703 | 142.250.114.94 | 192.168.2.9 |
Jun 3, 2025 19:17:04.854430914 CEST | 49703 | 80 | 192.168.2.9 | 142.250.114.94 |
Jun 3, 2025 19:17:04.854583979 CEST | 49703 | 80 | 192.168.2.9 | 142.250.114.94 |
Jun 3, 2025 19:17:04.877525091 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:04.977088928 CEST | 80 | 49703 | 142.250.114.94 | 192.168.2.9 |
Jun 3, 2025 19:17:04.978570938 CEST | 80 | 49703 | 142.250.114.94 | 192.168.2.9 |
Jun 3, 2025 19:17:05.033787012 CEST | 49703 | 80 | 192.168.2.9 | 142.250.114.94 |
Jun 3, 2025 19:17:05.089283943 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089303017 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089382887 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.089396954 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089406967 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089438915 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089451075 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089453936 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.089510918 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089523077 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.089543104 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.089554071 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.089582920 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.091185093 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.091243982 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.172337055 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.172621012 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:05.172693968 CEST | 49701 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:05.945393085 CEST | 49672 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:05.945393085 CEST | 49672 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:05.945462942 CEST | 443 | 49672 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:05.945482016 CEST | 443 | 49672 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:05.946041107 CEST | 49672 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:05.946062088 CEST | 443 | 49672 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:05.946968079 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:05.947021008 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:05.947110891 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:05.947350025 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:05.947360992 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.440510988 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.440673113 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.473045111 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.473083973 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.473972082 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.474031925 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.476650000 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.476720095 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.476881981 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.476929903 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.477219105 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.477569103 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.477622986 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.477696896 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.477745056 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.477788925 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.754264116 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.754405022 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.754580975 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.754635096 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:06.755783081 CEST | 443 | 49706 | 2.23.227.208 | 192.168.2.9 |
Jun 3, 2025 19:17:06.755825996 CEST | 49706 | 443 | 192.168.2.9 | 2.23.227.208 |
Jun 3, 2025 19:17:16.814184904 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:16.814217091 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.105246067 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.105818033 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.105829954 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.105935097 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.105957031 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.105967045 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.106005907 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.106009960 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.106019020 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.106024027 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.106050014 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.106338024 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.106348991 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.106369019 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.106394053 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.106427908 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.246715069 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.246731997 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.246984005 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.247879982 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.247898102 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.247939110 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.247968912 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.248176098 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.389138937 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.389328957 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.391091108 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.391163111 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.391237974 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.391360998 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.391695976 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:17.391797066 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:17.397936106 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:18.471721888 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:18.783766031 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:19.393457890 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:20.596596003 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:23.002996922 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:27.020268917 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:27.331290960 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:27.714433908 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:27.816088915 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:27.941385031 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:28.019201994 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:28.628598928 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:29.144237995 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:29.831723928 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:31.332138062 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:31.553883076 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:31.642266989 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:32.237346888 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:32.252986908 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:33.456041098 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:35.861979961 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:36.362024069 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:37.049531937 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:37.424386024 CEST | 49671 | 443 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:40.424288988 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:17:40.424308062 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:17:40.674309969 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:41.621932983 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:41.621998072 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:41.622121096 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:41.622534990 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:41.622554064 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.111771107 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:42.111788034 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:42.392313957 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.392478943 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.394469976 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.394489050 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.395051956 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.402096033 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.402137041 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.402190924 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.402992010 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.403162956 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.404084921 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.455579042 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.658663034 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.705663919 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.909832001 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.909853935 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.909873009 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.909888029 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.909898043 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.909945965 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.909975052 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.909991026 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.910026073 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.910166025 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.910176039 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.910242081 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.910263062 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.911988974 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.912157059 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.931579113 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:42.931974888 CEST | 443 | 49712 | 4.175.87.197 | 192.168.2.9 |
Jun 3, 2025 19:17:42.932043076 CEST | 49712 | 443 | 192.168.2.9 | 4.175.87.197 |
Jun 3, 2025 19:17:45.972081900 CEST | 49678 | 443 | 192.168.2.9 | 52.182.141.63 |
Jun 3, 2025 19:17:46.659780979 CEST | 49679 | 80 | 192.168.2.9 | 2.17.190.73 |
Jun 3, 2025 19:17:50.284321070 CEST | 49681 | 80 | 192.168.2.9 | 204.79.197.203 |
Jun 3, 2025 19:17:55.739948034 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:17:55.740354061 CEST | 443 | 49696 | 142.250.138.99 | 192.168.2.9 |
Jun 3, 2025 19:17:55.740441084 CEST | 49696 | 443 | 192.168.2.9 | 142.250.138.99 |
Jun 3, 2025 19:17:57.740478992 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:17:57.740864038 CEST | 443 | 49698 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:17:57.740962982 CEST | 49698 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:18:02.393732071 CEST | 49697 | 443 | 192.168.2.9 | 130.51.23.140 |
Jun 3, 2025 19:18:02.393750906 CEST | 443 | 49697 | 130.51.23.140 | 192.168.2.9 |
Jun 3, 2025 19:18:05.253530025 CEST | 49703 | 80 | 192.168.2.9 | 142.250.114.94 |
Jun 3, 2025 19:18:05.378936052 CEST | 80 | 49703 | 142.250.114.94 | 192.168.2.9 |
Jun 3, 2025 19:18:05.378998041 CEST | 49703 | 80 | 192.168.2.9 | 142.250.114.94 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 3, 2025 19:16:50.652620077 CEST | 53 | 54898 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:50.797353983 CEST | 53 | 58598 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:51.621234894 CEST | 53 | 54246 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:51.750674963 CEST | 53 | 53338 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:55.004266977 CEST | 61617 | 53 | 192.168.2.9 | 1.1.1.1 |
Jun 3, 2025 19:16:55.004422903 CEST | 58327 | 53 | 192.168.2.9 | 1.1.1.1 |
Jun 3, 2025 19:16:55.127654076 CEST | 53 | 58327 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:55.128160954 CEST | 53 | 61617 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:56.340287924 CEST | 50777 | 53 | 192.168.2.9 | 1.1.1.1 |
Jun 3, 2025 19:16:56.340384007 CEST | 65332 | 53 | 192.168.2.9 | 1.1.1.1 |
Jun 3, 2025 19:16:56.576685905 CEST | 53 | 65332 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:56.641833067 CEST | 53 | 50777 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:16:57.706805944 CEST | 53 | 54540 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:17:08.658690929 CEST | 53 | 63088 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:17:27.525255919 CEST | 53 | 61031 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:17:50.423155069 CEST | 53 | 50142 | 1.1.1.1 | 192.168.2.9 |
Jun 3, 2025 19:17:50.576015949 CEST | 53 | 49472 | 1.1.1.1 | 192.168.2.9 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jun 3, 2025 19:16:55.004266977 CEST | 192.168.2.9 | 1.1.1.1 | 0xc039 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 3, 2025 19:16:55.004422903 CEST | 192.168.2.9 | 1.1.1.1 | 0x843f | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 3, 2025 19:16:56.340287924 CEST | 192.168.2.9 | 1.1.1.1 | 0x71b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 3, 2025 19:16:56.340384007 CEST | 192.168.2.9 | 1.1.1.1 | 0xed8d | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jun 3, 2025 19:16:55.127654076 CEST | 1.1.1.1 | 192.168.2.9 | 0x843f | No error (0) | 65 | IN (0x0001) | false | |||
Jun 3, 2025 19:16:55.128160954 CEST | 1.1.1.1 | 192.168.2.9 | 0xc039 | No error (0) | 142.250.138.99 | A (IP address) | IN (0x0001) | false | ||
Jun 3, 2025 19:16:55.128160954 CEST | 1.1.1.1 | 192.168.2.9 | 0xc039 | No error (0) | 142.250.138.105 | A (IP address) | IN (0x0001) | false | ||
Jun 3, 2025 19:16:55.128160954 CEST | 1.1.1.1 | 192.168.2.9 | 0xc039 | No error (0) | 142.250.138.104 | A (IP address) | IN (0x0001) | false | ||
Jun 3, 2025 19:16:55.128160954 CEST | 1.1.1.1 | 192.168.2.9 | 0xc039 | No error (0) | 142.250.138.103 | A (IP address) | IN (0x0001) | false | ||
Jun 3, 2025 19:16:55.128160954 CEST | 1.1.1.1 | 192.168.2.9 | 0xc039 | No error (0) | 142.250.138.106 | A (IP address) | IN (0x0001) | false | ||
Jun 3, 2025 19:16:55.128160954 CEST | 1.1.1.1 | 192.168.2.9 | 0xc039 | No error (0) | 142.250.138.147 | A (IP address) | IN (0x0001) | false | ||
Jun 3, 2025 19:16:56.641833067 CEST | 1.1.1.1 | 192.168.2.9 | 0x71b4 | No error (0) | 130.51.23.140 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.9 | 49703 | 142.250.114.94 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jun 3, 2025 19:17:04.854583979 CEST | 200 | OUT | |
Jun 3, 2025 19:17:04.978570938 CEST | 1242 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.9 | 49697 | 130.51.23.140 | 443 | 1952 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-03 17:16:57 UTC | 666 | OUT | |
2025-06-03 17:16:57 UTC | 119 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 1460 | IN | |
2025-06-03 17:16:57 UTC | 532 | OUT | |
2025-06-03 17:16:57 UTC | 82 | IN | |
2025-06-03 17:16:57 UTC | 597 | OUT | |
2025-06-03 17:16:57 UTC | 82 | IN | |
2025-06-03 17:17:16 UTC | 710 | OUT | |
2025-06-03 17:17:17 UTC | 120 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.9 | 49701 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-03 17:17:05 UTC | 282 | OUT | |
2025-06-03 17:17:05 UTC | 558 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN | |
2025-06-03 17:17:05 UTC | 1460 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.9 | 49706 | 2.23.227.208 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-03 17:17:06 UTC | 1460 | OUT | |
2025-06-03 17:17:06 UTC | 890 | OUT | |
2025-06-03 17:17:06 UTC | 511 | OUT | |
2025-06-03 17:17:06 UTC | 567 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.9 | 49712 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-03 17:17:42 UTC | 282 | OUT | |
2025-06-03 17:17:42 UTC | 558 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN | |
2025-06-03 17:17:42 UTC | 1460 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 13:16:48 |
Start date: | 03/06/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff735640000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 13:16:49 |
Start date: | 03/06/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff735640000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 5 |
Start time: | 13:16:55 |
Start date: | 03/06/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff735640000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |