Windows
Analysis Report
http://klopotenko.com/wp-content/uploads/2023/08/knedli-img-1000x600.jpg?v=1720543094
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Confidence: | 80% |
Signatures
Classification
- System is w10x64
chrome.exe (PID: 516 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 3368 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2120,i ,512368388 479169648, 8015906001 973249642, 262144 --d isable-fea tures=Opti mizationGu ideModelDo wnloading, Optimizati onHints,Op timization HintsFetch ing,Optimi zationTarg etPredicti on --varia tions-seed -version - -mojo-plat form-chann el-handle= 2148 /pref etch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7072 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://klopot enko.com/w p-content/ uploads/20 23/08/kned li-img-100 0x600.jpg? v=17205430 94" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Process Injection | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
klopotenko.com | 104.26.5.5 | true | false | high | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
beacons-handoff.gcp.gvt2.com | 142.250.112.94 | true | false | high | |
www.google.com | 142.250.81.228 | true | false | high | |
e2c33.gcp.gvt2.com | 35.213.86.143 | true | false | high | |
beacons.gcp.gvt2.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
104.26.5.5 | klopotenko.com | United States | 13335 | CLOUDFLARENETUS | false | |
142.250.81.228 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.6 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1711300 |
Start date and time: | 2025-06-10 19:10:32 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://klopotenko.com/wp-content/uploads/2023/08/knedli-img-1000x600.jpg?v=1720543094 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@24/4@24/4 |
- Exclude process from analysis (whitelisted): MpCmdRun.exe, sppsvc.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe, TextInputHost.exe
- Excluded IPs from analysis (whitelisted): 142.251.40.238, 142.251.35.163, 142.250.80.46, 142.251.179.84, 142.250.80.78, 142.250.72.110, 142.250.176.206, 199.232.214.172, 142.250.65.174, 142.251.41.3, 34.104.35.123, 142.250.64.110, 64.233.180.84, 142.250.80.14, 23.204.23.20
- Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, c.pki.goog, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 564 |
Entropy (8bit): | 4.775290370533887 |
Encrypted: | false |
SSDEEP: | 12:TjeRHVIdtklI5rRCNGlTF5TF5TF5TF5TF5TFK:neRH688lTPTPTPTPTPTc |
MD5: | 5DA4C1420F84EC727D1B6BDD0D46E62E |
SHA1: | 280D08D142F7386283F420444EC48E1CDBFD61BB |
SHA-256: | 3C8CC37A98346BD0123B35E5CCD87BD07D69914DAE04F8B49F61C150D96E9D1F |
SHA-512: | 7C51A628831D0236E8D314C71732B8A62E06334431D10F7C293C49B23665B2A6A1DDBC4772009010955B5228EA4A5CD97FB93581CE391EE1792E8A198B76111A |
Malicious: | false |
Reputation: | low |
URL: | https://klopotenko.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 92272 |
Entropy (8bit): | 7.943701404270104 |
Encrypted: | false |
SSDEEP: | 1536:Tg7vX0a6t1cZ+0jdr4zhDBY8hMwrM6oNynlkgMNcMOnztxAh7hAERg9c:sDKtE+GoVD2Id3nb5APAEW9c |
MD5: | 7A19EE52DAE6A724E4A034B70D9C7A47 |
SHA1: | 41B952C835F57C81E94E617784F7801084F00923 |
SHA-256: | 1885465578A2132690950CF120E43E2A22FB026869B6283C5927146B4129BACA |
SHA-512: | 788A18673ECF1517174E441103B869635D3133774DC477D9F92986E2D0AC1D8513110705078D408A639ABB75F321603EA6D8F2CCA2662F0A5A4D564D018CDDA4 |
Malicious: | false |
Reputation: | low |
URL: | https://klopotenko.com/wp-content/uploads/2023/08/knedli-img-1000x600.jpg?v=1720543094 |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 10, 2025 19:11:24.991962910 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Jun 10, 2025 19:11:26.193710089 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Jun 10, 2025 19:11:28.600070000 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Jun 10, 2025 19:11:33.412472963 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Jun 10, 2025 19:11:35.468137980 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:11:35.847096920 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:11:36.543504953 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:11:37.760962963 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:11:40.258793116 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:11:42.008872032 CEST | 49696 | 80 | 192.168.2.6 | 142.250.176.195 |
Jun 10, 2025 19:11:42.034630060 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:11:42.034673929 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:11:42.034737110 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:11:42.035140991 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:11:42.035152912 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:11:42.094460011 CEST | 80 | 49696 | 142.250.176.195 | 192.168.2.6 |
Jun 10, 2025 19:11:42.094660044 CEST | 49696 | 80 | 192.168.2.6 | 142.250.176.195 |
Jun 10, 2025 19:11:42.094800949 CEST | 49696 | 80 | 192.168.2.6 | 142.250.176.195 |
Jun 10, 2025 19:11:42.180288076 CEST | 80 | 49696 | 142.250.176.195 | 192.168.2.6 |
Jun 10, 2025 19:11:42.181323051 CEST | 80 | 49696 | 142.250.176.195 | 192.168.2.6 |
Jun 10, 2025 19:11:42.226500988 CEST | 49696 | 80 | 192.168.2.6 | 142.250.176.195 |
Jun 10, 2025 19:11:42.235631943 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:11:42.235697985 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:11:42.237164974 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:11:42.237184048 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:11:42.237662077 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:11:42.289236069 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:11:43.023370981 CEST | 49672 | 443 | 192.168.2.6 | 204.79.197.203 |
Jun 10, 2025 19:11:43.939735889 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:43.939795017 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:43.939877987 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:43.941730022 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:43.941739082 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.454267979 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.454349041 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.459116936 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.459132910 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.459846973 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.500097990 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.500154018 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.500282049 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.500729084 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.500740051 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.512932062 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.537960052 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.537986994 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.538086891 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.539968014 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.542517900 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.542853117 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.589050055 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.706506968 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.706579924 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.707777023 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.707787037 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.707890987 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.707967043 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.707973957 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.708177090 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.708185911 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.708599091 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.709069014 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.709168911 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.709233046 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.709302902 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.751918077 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.756278992 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.827076912 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.828037977 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.828115940 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.829457045 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.829485893 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.829550982 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.829607964 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.829786062 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.829862118 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.830100060 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.830173969 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.830332994 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.830396891 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.831804037 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.831897974 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.832108974 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.832178116 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.832360983 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.832428932 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.868282080 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868319035 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868338108 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868355036 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868366957 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.868372917 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868402958 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868434906 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.868457079 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.868788004 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868808031 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.868839979 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.868854046 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.869087934 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.874875069 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:44.874967098 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:44.908674002 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.908759117 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.911994934 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.912065983 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.912746906 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.912823915 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.913609982 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.913674116 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.913842916 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.913892984 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.914045095 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.914232969 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:44.916615009 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:44.962100029 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:45.071368933 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:11:45.289721012 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:45.289748907 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:45.362857103 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:45.363398075 CEST | 443 | 49698 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:11:45.363471985 CEST | 49698 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:11:45.706837893 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:45.707093000 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:45.707135916 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:45.707156897 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:45.708312988 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:11:45.708491087 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:11:45.798556089 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:45.798589945 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:45.798667908 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:45.799030066 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:45.799037933 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.005348921 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.005431890 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.006575108 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.006603003 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.006794930 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.006813049 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.006964922 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.006979942 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.007299900 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.007842064 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.007905960 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.008013010 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.008791924 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.058597088 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.125442982 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.126270056 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.126574993 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.126601934 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.126787901 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.260961056 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:46.261404037 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:11:46.308273077 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:11:54.680370092 CEST | 49678 | 443 | 192.168.2.6 | 20.42.65.91 |
Jun 10, 2025 19:12:21.962438107 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:21.962491035 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:21.962555885 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:21.963473082 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:21.963481903 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.468189955 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.468300104 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.470753908 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.470767021 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.471417904 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.480667114 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.480781078 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.481476068 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.481679916 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.481708050 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.524060011 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.648483038 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.695936918 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.806838036 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806858063 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806879044 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806890965 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806900978 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806912899 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.806937933 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806962967 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.806982994 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.806983948 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.806993008 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.807003975 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.807039022 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.807069063 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.807092905 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.809319973 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.809384108 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.826493979 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:22.826714993 CEST | 443 | 49701 | 4.175.87.197 | 192.168.2.6 |
Jun 10, 2025 19:12:22.826781034 CEST | 49701 | 443 | 192.168.2.6 | 4.175.87.197 |
Jun 10, 2025 19:12:27.242655039 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:12:27.242674112 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:12:30.711396933 CEST | 49699 | 443 | 192.168.2.6 | 104.26.5.5 |
Jun 10, 2025 19:12:30.711426973 CEST | 443 | 49699 | 104.26.5.5 | 192.168.2.6 |
Jun 10, 2025 19:12:31.320775986 CEST | 49700 | 443 | 192.168.2.6 | 35.190.80.1 |
Jun 10, 2025 19:12:31.320811033 CEST | 443 | 49700 | 35.190.80.1 | 192.168.2.6 |
Jun 10, 2025 19:12:42.274491072 CEST | 49696 | 80 | 192.168.2.6 | 142.250.176.195 |
Jun 10, 2025 19:12:42.360276937 CEST | 80 | 49696 | 142.250.176.195 | 192.168.2.6 |
Jun 10, 2025 19:12:42.360354900 CEST | 49696 | 80 | 192.168.2.6 | 142.250.176.195 |
Jun 10, 2025 19:12:42.621125937 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Jun 10, 2025 19:12:42.621486902 CEST | 443 | 49697 | 142.250.81.228 | 192.168.2.6 |
Jun 10, 2025 19:12:42.621547937 CEST | 49697 | 443 | 192.168.2.6 | 142.250.81.228 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 10, 2025 19:11:37.449115038 CEST | 53 | 54909 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:37.469055891 CEST | 53 | 62895 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:38.057012081 CEST | 53 | 53971 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:38.587786913 CEST | 53 | 51353 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:41.946602106 CEST | 61727 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:41.946980953 CEST | 54024 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:42.032458067 CEST | 53 | 61727 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:42.033428907 CEST | 53 | 54024 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:44.378252029 CEST | 63039 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:44.379029989 CEST | 60831 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:44.388792992 CEST | 57116 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:44.388928890 CEST | 61701 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:44.479007006 CEST | 53 | 61701 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:44.482937098 CEST | 53 | 60831 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:44.486846924 CEST | 53 | 63039 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:44.496331930 CEST | 53 | 57116 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:45.708993912 CEST | 57957 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:45.709580898 CEST | 60154 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:11:45.797826052 CEST | 53 | 60154 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:45.797858953 CEST | 53 | 57957 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:11:55.659265041 CEST | 53 | 50210 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:14.596112967 CEST | 53 | 63885 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:30.718597889 CEST | 138 | 138 | 192.168.2.6 | 192.168.2.255 |
Jun 10, 2025 19:12:37.032347918 CEST | 53 | 55734 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:37.348639011 CEST | 53 | 50513 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:38.709253073 CEST | 53 | 64995 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:39.030674934 CEST | 61293 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:39.030992031 CEST | 60555 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:39.118249893 CEST | 53 | 61293 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:39.118797064 CEST | 53 | 60555 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:40.056191921 CEST | 64690 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:40.144906044 CEST | 53 | 64690 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:42.088268042 CEST | 55609 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:42.174191952 CEST | 53 | 55609 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:43.102710009 CEST | 55609 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:43.188502073 CEST | 53 | 55609 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:44.102648020 CEST | 55609 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:44.188538074 CEST | 53 | 55609 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:46.103049040 CEST | 55609 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:46.189050913 CEST | 53 | 55609 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:50.109257936 CEST | 55609 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:50.195549011 CEST | 53 | 55609 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:55.143667936 CEST | 54728 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:55.144093037 CEST | 59478 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:55.230307102 CEST | 53 | 54728 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:55.230346918 CEST | 53 | 59478 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:56.156266928 CEST | 52804 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:56.156414986 CEST | 59347 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:56.242367983 CEST | 53 | 59347 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:56.242727041 CEST | 53 | 52804 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:58.189058065 CEST | 50583 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:58.275552034 CEST | 53 | 50583 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:12:59.202991962 CEST | 50583 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:12:59.289387941 CEST | 53 | 50583 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:13:00.211549997 CEST | 50583 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:13:00.298356056 CEST | 53 | 50583 | 1.1.1.1 | 192.168.2.6 |
Jun 10, 2025 19:13:02.227493048 CEST | 50583 | 53 | 192.168.2.6 | 1.1.1.1 |
Jun 10, 2025 19:13:02.314043999 CEST | 53 | 50583 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jun 10, 2025 19:11:44.486918926 CEST | 192.168.2.6 | 1.1.1.1 | c216 | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jun 10, 2025 19:11:41.946602106 CEST | 192.168.2.6 | 1.1.1.1 | 0x536f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:11:41.946980953 CEST | 192.168.2.6 | 1.1.1.1 | 0x7341 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:11:44.378252029 CEST | 192.168.2.6 | 1.1.1.1 | 0x168d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:11:44.379029989 CEST | 192.168.2.6 | 1.1.1.1 | 0xa115 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:11:44.388792992 CEST | 192.168.2.6 | 1.1.1.1 | 0xef68 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:11:44.388928890 CEST | 192.168.2.6 | 1.1.1.1 | 0x5646 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:11:45.708993912 CEST | 192.168.2.6 | 1.1.1.1 | 0xc927 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:11:45.709580898 CEST | 192.168.2.6 | 1.1.1.1 | 0x2552 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:12:39.030674934 CEST | 192.168.2.6 | 1.1.1.1 | 0xfac2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:39.030992031 CEST | 192.168.2.6 | 1.1.1.1 | 0xcfe1 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:12:40.056191921 CEST | 192.168.2.6 | 1.1.1.1 | 0x136d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:42.088268042 CEST | 192.168.2.6 | 1.1.1.1 | 0xd936 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:43.102710009 CEST | 192.168.2.6 | 1.1.1.1 | 0xd936 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:44.102648020 CEST | 192.168.2.6 | 1.1.1.1 | 0xd936 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:46.103049040 CEST | 192.168.2.6 | 1.1.1.1 | 0xd936 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:50.109257936 CEST | 192.168.2.6 | 1.1.1.1 | 0xd936 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:55.143667936 CEST | 192.168.2.6 | 1.1.1.1 | 0x1537 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:55.144093037 CEST | 192.168.2.6 | 1.1.1.1 | 0xcb | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:12:56.156266928 CEST | 192.168.2.6 | 1.1.1.1 | 0xf9e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:56.156414986 CEST | 192.168.2.6 | 1.1.1.1 | 0xc648 | Standard query (0) | 65 | IN (0x0001) | false | |
Jun 10, 2025 19:12:58.189058065 CEST | 192.168.2.6 | 1.1.1.1 | 0xa51d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:12:59.202991962 CEST | 192.168.2.6 | 1.1.1.1 | 0xa51d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:13:00.211549997 CEST | 192.168.2.6 | 1.1.1.1 | 0xa51d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jun 10, 2025 19:13:02.227493048 CEST | 192.168.2.6 | 1.1.1.1 | 0xa51d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jun 10, 2025 19:11:42.032458067 CEST | 1.1.1.1 | 192.168.2.6 | 0x536f | No error (0) | 142.250.81.228 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:42.033428907 CEST | 1.1.1.1 | 192.168.2.6 | 0x7341 | No error (0) | 65 | IN (0x0001) | false | |||
Jun 10, 2025 19:11:44.479007006 CEST | 1.1.1.1 | 192.168.2.6 | 0x5646 | No error (0) | 65 | IN (0x0001) | false | |||
Jun 10, 2025 19:11:44.482937098 CEST | 1.1.1.1 | 192.168.2.6 | 0xa115 | No error (0) | 65 | IN (0x0001) | false | |||
Jun 10, 2025 19:11:44.486846924 CEST | 1.1.1.1 | 192.168.2.6 | 0x168d | No error (0) | 104.26.5.5 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:44.486846924 CEST | 1.1.1.1 | 192.168.2.6 | 0x168d | No error (0) | 172.67.70.147 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:44.486846924 CEST | 1.1.1.1 | 192.168.2.6 | 0x168d | No error (0) | 104.26.4.5 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:44.496331930 CEST | 1.1.1.1 | 192.168.2.6 | 0xef68 | No error (0) | 104.26.5.5 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:44.496331930 CEST | 1.1.1.1 | 192.168.2.6 | 0xef68 | No error (0) | 104.26.4.5 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:44.496331930 CEST | 1.1.1.1 | 192.168.2.6 | 0xef68 | No error (0) | 172.67.70.147 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:11:45.797858953 CEST | 1.1.1.1 | 192.168.2.6 | 0xc927 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:39.118249893 CEST | 1.1.1.1 | 192.168.2.6 | 0xfac2 | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:40.144906044 CEST | 1.1.1.1 | 192.168.2.6 | 0x136d | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:42.174191952 CEST | 1.1.1.1 | 192.168.2.6 | 0xd936 | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:43.188502073 CEST | 1.1.1.1 | 192.168.2.6 | 0xd936 | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:44.188538074 CEST | 1.1.1.1 | 192.168.2.6 | 0xd936 | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:46.189050913 CEST | 1.1.1.1 | 192.168.2.6 | 0xd936 | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:50.195549011 CEST | 1.1.1.1 | 192.168.2.6 | 0xd936 | No error (0) | 35.213.86.143 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:55.230307102 CEST | 1.1.1.1 | 192.168.2.6 | 0x1537 | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:55.230307102 CEST | 1.1.1.1 | 192.168.2.6 | 0x1537 | No error (0) | 142.250.112.94 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:55.230346918 CEST | 1.1.1.1 | 192.168.2.6 | 0xcb | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:56.242367983 CEST | 1.1.1.1 | 192.168.2.6 | 0xc648 | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:56.242727041 CEST | 1.1.1.1 | 192.168.2.6 | 0xf9e6 | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:56.242727041 CEST | 1.1.1.1 | 192.168.2.6 | 0xf9e6 | No error (0) | 142.250.112.94 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:58.275552034 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:58.275552034 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | 142.250.112.94 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:59.289387941 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:12:59.289387941 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | 142.250.112.94 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:13:00.298356056 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:13:00.298356056 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | 142.250.112.94 | A (IP address) | IN (0x0001) | false | ||
Jun 10, 2025 19:13:02.314043999 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | beacons-handoff.gcp.gvt2.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jun 10, 2025 19:13:02.314043999 CEST | 1.1.1.1 | 192.168.2.6 | 0xa51d | No error (0) | 142.250.112.94 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49696 | 142.250.176.195 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jun 10, 2025 19:11:42.094800949 CEST | 200 | OUT | |
Jun 10, 2025 19:11:42.181323051 CEST | 1242 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49698 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-10 17:11:44 UTC | 309 | OUT | |
2025-06-10 17:11:44 UTC | 558 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49699 | 104.26.5.5 | 443 | 3368 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-10 17:11:44 UTC | 706 | OUT | |
2025-06-10 17:11:44 UTC | 973 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:44 UTC | 1460 | IN | |
2025-06-10 17:11:45 UTC | 633 | OUT | |
2025-06-10 17:11:45 UTC | 795 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49700 | 35.190.80.1 | 443 | 3368 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-10 17:11:46 UTC | 516 | OUT | |
2025-06-10 17:11:46 UTC | 317 | IN | |
2025-06-10 17:11:46 UTC | 491 | OUT | |
2025-06-10 17:11:46 UTC | 472 | OUT | |
2025-06-10 17:11:46 UTC | 195 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49701 | 4.175.87.197 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-06-10 17:12:22 UTC | 309 | OUT | |
2025-06-10 17:12:22 UTC | 558 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN | |
2025-06-10 17:12:22 UTC | 1460 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 1 |
Start time: | 13:11:30 |
Start date: | 10/06/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 13:11:36 |
Start date: | 10/06/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 13 |
Start time: | 13:11:43 |
Start date: | 10/06/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63b000000 |
File size: | 3'388'000 bytes |
MD5 hash: | E81F54E6C1129887AEA47E7D092680BF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |