Process Name
| Process ID
| Protocol
| Local Port
| Local Port Name
| Local Address
| Remote Port
| Remote Port Name
| Remote Address
| Remote Host Name
| State
| Process Path
| Product Name
| File Description
| File Version
| Company
| Process Created On
| User Name
| Process Services
| Process Attributes
| Added On
| Module Filename
| Remote IP Country
| Window Title
|
Unknown | 0 | TCP | 49205 | | 192.168.25.101 | 49155 | | 192.168.25.100 | PATATADC | Time Wait | | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
Unknown | 0 | TCP | 49204 | | 192.168.25.101 | 135 | epmap | 192.168.25.100 | PATATADC | Time Wait | | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 47001 | | :: | | | :: | | Listening | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 445 | microsoft-ds | :: | | | :: | | Listening | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 445 | microsoft-ds | 192.168.25.101 | 49365 | | 192.168.25.11 | NABO2 | Established | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 445 | microsoft-ds | 192.168.25.101 | 49576 | | 192.168.25.10 | BONIATO1 | Established | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 47001 | | 0.0.0.0 | | | 0.0.0.0 | | Listening | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 445 | microsoft-ds | 0.0.0.0 | | | 0.0.0.0 | | Listening | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | TCP | 139 | netbios-ssn | 192.168.25.101 | | | 0.0.0.0 | | Listening | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | UDP | 138 | netbios-dgm | 192.168.25.101 | | | | | | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
System | 4 | UDP | 137 | netbios-ns | 192.168.25.101 | | | | | | System | | | | | N/A | | | | 20/05/2017 17:43:10 | | |
|
wininit.exe | 376 | TCP | 49152 | | :: | | | :: | | Listening | C:\Windows\system32\wininit.exe | Microsoft® Windows® Operating System | Windows Start-Up Application | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:54 | NT AUTHORITY\SYSTEM | | A | 20/05/2017 17:43:10 | | |
|
wininit.exe | 376 | TCP | 49152 | | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\wininit.exe | Microsoft® Windows® Operating System | Windows Start-Up Application | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:54 | NT AUTHORITY\SYSTEM | | A | 20/05/2017 17:43:10 | | |
|
services.exe | 484 | TCP | 49155 | | :: | | | :: | | Listening | C:\Windows\system32\services.exe | Microsoft® Windows® Operating System | Services and Controller app | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:55 | NT AUTHORITY\SYSTEM | | A | 20/05/2017 17:43:10 | | |
|
services.exe | 484 | TCP | 49155 | | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\services.exe | Microsoft® Windows® Operating System | Services and Controller app | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:55 | NT AUTHORITY\SYSTEM | | A | 20/05/2017 17:43:10 | | |
|
lsass.exe | 496 | TCP | 49156 | | :: | | | :: | | Listening | C:\Windows\system32\lsass.exe | Microsoft® Windows® Operating System | Local Security Authority Process | 6.1.7601.18270 (win7sp1_gdr.130924-1532) | Microsoft Corporation | 20/05/2017 17:02:55 | NT AUTHORITY\SYSTEM | Netlogon, SamSs | A | 20/05/2017 17:43:10 | | |
|
lsass.exe | 496 | TCP | 49156 | | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\lsass.exe | Microsoft® Windows® Operating System | Local Security Authority Process | 6.1.7601.18270 (win7sp1_gdr.130924-1532) | Microsoft Corporation | 20/05/2017 17:02:55 | NT AUTHORITY\SYSTEM | Netlogon, SamSs | A | 20/05/2017 17:43:10 | | |
|
lsass.exe | 496 | UDP | 58737 | | 127.0.0.1 | | | | | | C:\Windows\system32\lsass.exe | Microsoft® Windows® Operating System | Local Security Authority Process | 6.1.7601.18270 (win7sp1_gdr.130924-1532) | Microsoft Corporation | 20/05/2017 17:02:55 | NT AUTHORITY\SYSTEM | Netlogon, SamSs | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 660 | TCP | 135 | epmap | :: | | | :: | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:56 | NT AUTHORITY\NETWORK SERVICE | RpcEptMapper, RpcSs | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 660 | TCP | 135 | epmap | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:56 | NT AUTHORITY\NETWORK SERVICE | RpcEptMapper, RpcSs | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 716 | TCP | 49153 | | :: | | | :: | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:56 | NT AUTHORITY\LOCAL SERVICE | Dhcp, eventlog, lmhosts | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 716 | TCP | 49153 | | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:56 | NT AUTHORITY\LOCAL SERVICE | Dhcp, eventlog, lmhosts | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 832 | TCP | 49154 | | :: | | | :: | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:57 | NT AUTHORITY\SYSTEM | AeLookupSvc, Appinfo, CertPropSvc, gpsvc, iphlpsvc, LanmanServer, ProfSvc, Schedule, SENS, SessionEnv, ShellHWDetection, Winmgmt, wuauserv | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 832 | TCP | 49154 | | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:57 | NT AUTHORITY\SYSTEM | AeLookupSvc, Appinfo, CertPropSvc, gpsvc, iphlpsvc, LanmanServer, ProfSvc, Schedule, SENS, SessionEnv, ShellHWDetection, Winmgmt, wuauserv | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 904 | UDP | 123 | ntp | 0.0.0.0 | | | | | | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:58 | NT AUTHORITY\LOCAL SERVICE | EventSystem, FontCache, netprofm, nsi, sppuinotify, W32Time | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 904 | UDP | 123 | ntp | :: | | | | | | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:58 | NT AUTHORITY\LOCAL SERVICE | EventSystem, FontCache, netprofm, nsi, sppuinotify, W32Time | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 984 | UDP | 5355 | llmnr | 0.0.0.0 | | | | | | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:58 | NT AUTHORITY\NETWORK SERVICE | CryptSvc, Dnscache, LanmanWorkstation, NlaSvc, WinRM | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 984 | UDP | 5355 | llmnr | :: | | | | | | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:02:58 | NT AUTHORITY\NETWORK SERVICE | CryptSvc, Dnscache, LanmanWorkstation, NlaSvc, WinRM | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 1656 | TCP | 3389 | ms-wbt-server | :: | | | :: | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:03:01 | NT AUTHORITY\NETWORK SERVICE | TermService | A | 20/05/2017 17:43:10 | | |
|
svchost.exe | 1656 | TCP | 3389 | ms-wbt-server | 0.0.0.0 | | | 0.0.0.0 | | Listening | C:\Windows\system32\svchost.exe | Microsoft® Windows® Operating System | Host Process for Windows Services | 6.1.7600.16385 (win7_rtm.090713-1255) | Microsoft Corporation | 20/05/2017 17:03:01 | NT AUTHORITY\NETWORK SERVICE | TermService | A | 20/05/2017 17:43:10 | | |
|