Network Analysis
IP Address | Status | Action |
---|---|---|
157.240.215.35 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.161.142 | Active | Moloch |
172.217.25.14 | Active | Moloch |
175.208.134.150 | Active | Moloch |
18.200.206.178 | Active | Moloch |
34.250.171.60 | Active | Moloch |
34.255.131.204 | Active | Moloch |
52.218.52.233 | Active | Moloch |
54.171.169.161 | Active | Moloch |
62.113.216.169 | Active | Moloch |
74.6.231.21 | Active | Moloch |
- TCP Requests
-
-
192.168.56.102:49797 172.217.25.14:443
-
192.168.56.102:49820 34.250.171.60:443mlb.giraffic.com
-
192.168.56.102:49825 34.250.171.60:443mlb.giraffic.com
-
192.168.56.102:49855 34.250.171.60:443mlb.giraffic.com
-
192.168.56.102:49857 34.250.171.60:8443mlb.giraffic.com
-
192.168.56.102:49858 34.250.171.60:8443mlb.giraffic.com
-
192.168.56.102:49861 34.250.171.60:80mlb.giraffic.com
-
192.168.56.102:49863 34.250.171.60:80mlb.giraffic.com
-
192.168.56.102:49864 34.250.171.60:80mlb.giraffic.com
-
192.168.56.102:49865 34.250.171.60:80mlb.giraffic.com
-
192.168.56.102:49859 52.218.52.233:80chromodoris.s3.amazonaws.com
-
192.168.56.102:49827 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49832 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49833 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49834 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49835 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49836 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49837 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49838 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49839 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49840 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49841 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49842 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49843 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49844 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49845 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49846 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49847 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49848 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49849 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49850 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49851 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49852 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49853 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49854 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49856 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49860 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49866 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49867 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49868 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49869 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49870 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49871 54.171.169.161:443mseed.giraffic.com
-
192.168.56.102:49874 54.171.169.161:443mseed.giraffic.com
-
- UDP Requests
-
-
192.168.56.102:52053 10.0.5.111:3478
-
192.168.56.102:52614 10.0.5.111:3479
-
192.168.56.102:50538 164.124.101.2:53
-
192.168.56.102:50839 164.124.101.2:53
-
192.168.56.102:51857 164.124.101.2:53
-
192.168.56.102:51983 164.124.101.2:53
-
192.168.56.102:54221 164.124.101.2:53
-
192.168.56.102:54660 164.124.101.2:53
-
192.168.56.102:55957 164.124.101.2:53
-
192.168.56.102:57660 164.124.101.2:53
-
192.168.56.102:59367 164.124.101.2:53
-
192.168.56.102:61459 164.124.101.2:53
-
192.168.56.102:61998 164.124.101.2:53
-
192.168.56.102:62039 164.124.101.2:53
-
192.168.56.102:62262 164.124.101.2:53
-
192.168.56.102:62461 164.124.101.2:53
-
192.168.56.102:63574 164.124.101.2:53
-
192.168.56.102:52053 175.208.134.150:52053
-
192.168.56.102:43261 18.200.206.178:3478rendezvous5.giraffic.com
-
192.168.56.102:52053 18.200.206.178:3478rendezvous5.giraffic.com
-
192.168.56.102:52614 18.200.206.178:3478rendezvous5.giraffic.com
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:51984 239.255.255.250:1900
-
192.168.56.102:56752 239.255.255.250:1900
-
192.168.56.102:56754 239.255.255.250:3702
-
192.168.56.102:56756 239.255.255.250:3702
-
192.168.56.102:62462 239.255.255.250:1900
-
192.168.56.102:52053 34.255.131.204:59727
-
192.168.56.102:52053 62.113.216.169:53593
-
GET
200
http://chromodoris.s3.amazonaws.com/GirafficInstall1.0.0.25.exe
REQUEST
RESPONSE
BODY
GET /GirafficInstall1.0.0.25.exe HTTP/1.1
Host: chromodoris.s3.amazonaws.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.72 Safari/537.36
Accept: */*
HTTP/1.1 200 OK
x-amz-id-2: Nu/rAHcYBSWSbgsDYoUnfnryQ2xOYCdlNKmtYWB8fZai5P8kiHjoCMo7XePBYSQT0F957Pf/Hik=
x-amz-request-id: 4DT7N0841KSDH11T
Date: Sat, 05 Jun 2021 12:41:12 GMT
Last-Modified: Fri, 05 Mar 2021 16:24:41 GMT
ETag: "86d6eb83d2d0914e8a50a43b580dbf23"
x-amz-version-id: LPFa6N.bXMmciMwW_HBpM7A99T_LVRoI
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Content-Length: 5038672
Server: AmazonS3
GET
200
http://mlb.giraffic.com/inst_report.php?op=15549906_1.0.0.25_Watchdog_Silent_Install&msg=Init
REQUEST
RESPONSE
BODY
GET /inst_report.php?op=15549906_1.0.0.25_Watchdog_Silent_Install&msg=Init HTTP/1.0
Host: mlb.giraffic.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sat, 05 Jun 2021 12:41:17 GMT
Server: Apache/2.4.46 (Ubuntu)
Strict-Transport-Security: max-age=63072000; includeSubdomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Content-Length: 2
Connection: Close
GET
200
http://mlb.giraffic.com/inst_report.php?op=15569187_1.0.0.25_Agent_Silent_Install&msg=Init
REQUEST
RESPONSE
BODY
GET /inst_report.php?op=15569187_1.0.0.25_Agent_Silent_Install&msg=Init HTTP/1.0
Host: mlb.giraffic.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sat, 05 Jun 2021 12:41:36 GMT
Server: Apache/2.4.46 (Ubuntu)
Strict-Transport-Security: max-age=63072000; includeSubdomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Content-Length: 2
Connection: Close
GET
200
http://mlb.giraffic.com/inst_report.php?op=15569187_1.0.0.25_Agent_Silent_Install&msg=Installation_Complete
REQUEST
RESPONSE
BODY
GET /inst_report.php?op=15569187_1.0.0.25_Agent_Silent_Install&msg=Installation_Complete HTTP/1.0
Host: mlb.giraffic.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sat, 05 Jun 2021 12:41:37 GMT
Server: Apache/2.4.46 (Ubuntu)
Strict-Transport-Security: max-age=63072000; includeSubdomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Content-Length: 2
Connection: Close
GET
200
http://mlb.giraffic.com/inst_report.php?op=15549906_1.0.0.25_Watchdog_Silent_Install&msg=Installation_Complete
REQUEST
RESPONSE
BODY
GET /inst_report.php?op=15549906_1.0.0.25_Watchdog_Silent_Install&msg=Installation_Complete HTTP/1.0
Host: mlb.giraffic.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Date: Sat, 05 Jun 2021 12:41:40 GMT
Server: Apache/2.4.46 (Ubuntu)
Strict-Transport-Security: max-age=63072000; includeSubdomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Content-Length: 2
Connection: Close
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 34.255.131.204 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 | |
192.168.56.102 | 62.113.216.169 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.102:49820 34.250.171.60:443 |
CN=ip-10-226-5-106.eu-west-1.compute.internal | CN=ip-10-226-5-106.eu-west-1.compute.internal | c4:ac:9f:36:1f:de:3c:54:da:16:e7:91:eb:d3:f8:b1:d8:87:3f:0d |
TLS 1.2 192.168.56.102:49825 34.250.171.60:443 |
CN=ip-10-226-5-106.eu-west-1.compute.internal | CN=ip-10-226-5-106.eu-west-1.compute.internal | c4:ac:9f:36:1f:de:3c:54:da:16:e7:91:eb:d3:f8:b1:d8:87:3f:0d |
TLS 1.2 192.168.56.102:49827 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49832 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49834 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49836 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49835 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49839 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49840 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49853 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49849 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49838 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49851 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49841 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49844 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49852 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49846 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49837 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49843 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49848 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49857 34.250.171.60:8443 |
CN=ip-10-226-5-106.eu-west-1.compute.internal | CN=ip-10-226-5-106.eu-west-1.compute.internal | c4:ac:9f:36:1f:de:3c:54:da:16:e7:91:eb:d3:f8:b1:d8:87:3f:0d |
TLS 1.2 192.168.56.102:49850 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49854 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49833 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49842 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49845 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49847 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49858 34.250.171.60:8443 |
CN=ip-10-226-5-106.eu-west-1.compute.internal | CN=ip-10-226-5-106.eu-west-1.compute.internal | c4:ac:9f:36:1f:de:3c:54:da:16:e7:91:eb:d3:f8:b1:d8:87:3f:0d |
TLS 1.2 192.168.56.102:49855 34.250.171.60:443 |
CN=ip-10-226-5-106.eu-west-1.compute.internal | CN=ip-10-226-5-106.eu-west-1.compute.internal | c4:ac:9f:36:1f:de:3c:54:da:16:e7:91:eb:d3:f8:b1:d8:87:3f:0d |
TLS 1.2 192.168.56.102:49856 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49860 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49866 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49870 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49867 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49868 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49874 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49869 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
TLS 1.2 192.168.56.102:49871 54.171.169.161:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=mseed.giraffic.com | a5:8f:e5:6a:2f:0c:78:88:a6:7a:12:ec:be:59:27:bc:ec:3f:7b:c8 |
Snort Alerts
No Snort Alerts