Network Analysis
IP Address | Status | Action |
---|---|---|
107.180.58.44 | Active | Moloch |
108.167.181.248 | Active | Moloch |
148.66.138.194 | Active | Moloch |
164.124.101.2 | Active | Moloch |
173.230.252.50 | Active | Moloch |
192.185.16.122 | Active | Moloch |
192.185.32.234 | Active | Moloch |
192.185.79.55 | Active | Moloch |
208.91.198.106 | Active | Moloch |
209.188.15.214 | Active | Moloch |
23.212.13.232 | Active | Moloch |
23.40.44.112 | Active | Moloch |
35.155.6.125 | Active | Moloch |
83.150.213.154 | Active | Moloch |
- TCP Requests
-
-
192.168.56.101:49194 192.168.56.103:2869
-
192.168.56.101:49196 192.168.56.103:5357
-
192.168.56.102:49802 192.168.56.103:2869
-
192.168.56.102:49804 192.168.56.103:5357
-
192.168.56.103:49605 107.180.58.44:443bellaloveboutique.com
-
192.168.56.103:49606 107.180.58.44:443bellaloveboutique.com
-
192.168.56.103:49607 107.180.58.44:443bellaloveboutique.com
-
192.168.56.103:49638 108.167.181.248:443alpax.elcanotradingcorp.com
-
192.168.56.103:49639 108.167.181.248:443alpax.elcanotradingcorp.com
-
192.168.56.103:49640 108.167.181.248:443alpax.elcanotradingcorp.com
-
192.168.56.103:49626 148.66.138.194:443houzzlink.com
-
192.168.56.103:49627 148.66.138.194:443houzzlink.com
-
192.168.56.103:49628 148.66.138.194:443houzzlink.com
-
192.168.56.103:49630 173.230.252.50:443labrie-sabette.com
-
192.168.56.103:49631 173.230.252.50:443labrie-sabette.com
-
192.168.56.103:49632 173.230.252.50:443labrie-sabette.com
-
192.168.56.103:49601 192.185.16.122:443vitiligomatch.com
-
192.168.56.103:49602 192.185.16.122:443vitiligomatch.com
-
192.168.56.103:49603 192.185.16.122:443vitiligomatch.com
-
192.168.56.103:49617 192.185.32.234:443ntf.gov.sb
-
192.168.56.103:49618 192.185.32.234:443ntf.gov.sb
-
192.168.56.103:49619 192.185.32.234:443ntf.gov.sb
-
192.168.56.103:49613 192.185.79.55:443marcoislandguidebook.com
-
192.168.56.103:49614 192.185.79.55:443marcoislandguidebook.com
-
192.168.56.103:49615 192.185.79.55:443marcoislandguidebook.com
-
192.168.56.103:49621 208.91.198.106:443bycec.in
-
192.168.56.103:49623 208.91.198.106:443bycec.in
-
192.168.56.103:49624 208.91.198.106:443bycec.in
-
192.168.56.103:49609 209.188.15.214:443ppml.com.kh
-
192.168.56.103:49610 209.188.15.214:443ppml.com.kh
-
192.168.56.103:49611 209.188.15.214:443ppml.com.kh
-
192.168.56.103:49592 23.197.161.201:80
-
192.168.56.103:49593 23.212.13.232:443www.microsoft.com
-
192.168.56.103:49594 23.40.44.112:443definitionupdates.microsoft.com
-
192.168.56.103:49591 35.155.6.125:443incoming.telemetry.mozilla.org
-
192.168.56.103:49634 83.150.213.154:443www.akseral.com
-
192.168.56.103:49635 83.150.213.154:443www.akseral.com
-
192.168.56.103:49636 83.150.213.154:443www.akseral.com
-
- UDP Requests
-
-
192.168.56.103:50825 164.124.101.2:53
-
192.168.56.103:54288 164.124.101.2:53
-
192.168.56.103:55444 164.124.101.2:53
-
192.168.56.103:56376 164.124.101.2:53
-
192.168.56.103:56508 164.124.101.2:53
-
192.168.56.103:57259 164.124.101.2:53
-
192.168.56.103:58285 164.124.101.2:53
-
192.168.56.103:58575 164.124.101.2:53
-
192.168.56.103:58935 164.124.101.2:53
-
192.168.56.103:59012 164.124.101.2:53
-
192.168.56.103:62079 164.124.101.2:53
-
192.168.56.103:62494 164.124.101.2:53
-
192.168.56.103:64714 164.124.101.2:53
-
192.168.56.103:65511 164.124.101.2:53
-
192.168.56.103:1900 192.168.56.101:62445
-
192.168.56.103:3702 192.168.56.101:62447
-
192.168.56.103:1900 192.168.56.102:56752
-
192.168.56.103:3702 192.168.56.102:56756
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:1900 239.255.255.250:1900
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:50368 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:58575
-
GET
302
http://go.microsoft.com/fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=0.0.0.0&asdelta=0.0.0.0&prod=925A3ACA-C353-458A-AC8D-A7E5EB378092
REQUEST
RESPONSE
BODY
GET /fwlink/?LinkID=121721&clcid=0x409&arch=x86&eng=0.0.0.0&asdelta=0.0.0.0&prod=925A3ACA-C353-458A-AC8D-A7E5EB378092 HTTP/1.1
Connection: Keep-Alive
Accept-Charset: utf-8
User-Agent: MpCommunication
Host: go.microsoft.com
HTTP/1.1 302 Moved Temporarily
Location: https://www.microsoft.com/security/encyclopedia/adlpackages.aspx?arch=x86&eng=0.0.0.0&asdelta=0.0.0.0&prod=925A3ACA-C353-458A-AC8D-A7E5EB378092
Server: Kestrel
Request-Context: appId=cid-v1:7d63747b-487e-492a-872d-762362f77974
X-Response-Cache-Status: True
X-Powered-By: ASP.NET
Content-Length: 0
Expires: Thu, 27 May 2021 00:34:02 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 27 May 2021 00:34:02 GMT
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49591 35.155.6.125:443 |
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA | C=US, ST=California, L=Mountain View, O=Mozilla Corporation, OU=Cloud Services, CN=*.telemetry.mozilla.org | 6d:3c:6a:a4:5f:46:eb:8b:b6:fb:8f:08:44:02:01:61:a0:25:c3:c8 |
TLSv1 192.168.56.103:49594 23.40.44.112:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=download.microsoft.com | e7:01:d1:e2:a1:0e:a1:84:0b:d0:c6:2e:a2:42:7a:f4:7b:40:91:c5 |
TLSv1 192.168.56.103:49593 23.212.13.232:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=www.microsoft.com | 9b:2b:8a:e6:51:69:aa:47:7c:57:83:d6:48:0f:29:6e:f4:8c:f1:4d |
Snort Alerts
No Snort Alerts