Network Analysis
IP Address | Status | Action |
---|---|---|
13.225.134.82 | Active | Moloch |
142.250.196.131 | Active | Moloch |
142.250.199.77 | Active | Moloch |
142.250.207.78 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.223.135 | Active | Moloch |
172.217.161.65 | Active | Moloch |
172.217.26.35 | Active | Moloch |
172.217.31.131 | Active | Moloch |
193.70.47.128 | Active | Moloch |
59.18.30.144 | Active | Moloch |
59.18.44.80 | Active | Moloch |
34.104.35.123 | Active | Moloch |
35.83.118.206 | Active | Moloch |
52.54.193.222 | Active | Moloch |
65.8.17.57 | Active | Moloch |
- TCP Requests
-
-
192.168.56.101:49322 13.225.134.82:443
-
192.168.56.101:49323 13.225.134.82:443
-
192.168.56.101:49319 142.250.196.131:443
-
192.168.56.101:49300 142.250.199.77:443accounts.google.com
-
192.168.56.101:49307 142.250.207.78:443www.google-analytics.com
-
172.67.223.135:80 192.168.56.101:49221
-
192.168.56.101:49321 172.217.161.65:443
-
192.168.56.101:49320 172.217.26.35:443
-
192.168.56.101:49324 172.217.26.35:443
-
192.168.56.101:49325 172.217.31.131:443
-
192.168.56.101:49216 172.67.223.135:443flownetserv.com
-
192.168.56.101:49217 172.67.223.135:443flownetserv.com
-
192.168.56.101:49315 172.67.223.135:443flownetserv.com
-
192.168.56.101:49305 193.70.47.128:443soloyama.com
-
192.168.56.101:49301 216.58.200.78:443
-
192.168.56.101:49302 216.58.200.78:443
-
192.168.56.101:49306 59.18.30.144:443r5---sn-3u-bh2lk.gvt1.com
-
192.168.56.101:49304 59.18.44.80:443r5---sn-3u-bh2d.gvt1.com
-
192.168.56.101:49326 34.104.35.123:80edgedl.me.gvt1.com
-
192.168.56.101:49309 35.83.118.206:443api.mywot.com
-
192.168.56.101:49310 35.83.118.206:443api.mywot.com
-
192.168.56.101:49311 52.54.193.222:443secure.mywot.com
-
192.168.56.101:49308 65.8.17.57:443static.mywot.com
-
8.8.4.4:443 192.168.56.101:49318
-
8.8.8.8:443 192.168.56.101:49317
-
- UDP Requests
-
-
192.168.56.101:62903 142.250.207.78:443www.google-analytics.com
-
192.168.56.101:50851 164.124.101.2:53
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:55450 164.124.101.2:53
-
192.168.56.101:55629 164.124.101.2:53
-
192.168.56.101:56887 164.124.101.2:53
-
192.168.56.101:56977 164.124.101.2:53
-
192.168.56.101:57460 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:60751 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:62430 164.124.101.2:53
-
192.168.56.101:62902 164.124.101.2:53
-
192.168.56.101:65329 164.124.101.2:53
-
192.168.56.101:62436 172.217.26.35:443
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:61481 239.255.255.250:1900
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
192.168.56.101:62331 239.255.255.250:3702
-
192.168.56.101:62333 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
192.168.56.101:56979 59.18.30.144:443r5---sn-3u-bh2lk.gvt1.com
-
192.168.56.101:56978 59.18.44.80:443r5---sn-3u-bh2d.gvt1.com
-
192.168.56.101:5353 224.0.0.251:5353
-
8.8.4.4:443 192.168.56.101:62438
-
8.8.8.8:443 192.168.56.101:62433
-
POST
200
https://flownetserv.com/service/update2
REQUEST
RESPONSE
BODY
POST /service/update2 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.36.71;winhttp
X-Old-UID: age=-1; cnt=1
X-Goog-Update-Updater: Omaha-1.3.36.71
X-Goog-Update-Interactivity: bg
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Content-Length: 749
Host: flownetserv.com
HTTP/1.1 200 OK
Date: Thu, 24 Jun 2021 14:14:08 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 250
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
CF-Cache-Status: DYNAMIC
cf-request-id: 0adff80c380000fcd93c06c000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=qphnmlsCaSszEBIhY%2FTId%2B8%2BMJopiVmuW006G7v5qR%2FN2aa8wMQ1vYkavMedjFP54OmlyHlWS2xNihkNeRhybInuCOIRguzsxKvThkzME%2BlPilgOOJs1JprZ5cBM"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 66468f8d1968fcd9-KIX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
POST
200
https://flownetserv.com/service/update2?cup2key=10:2041637316&cup2hreq=c44ca074fab98820e0ddea4abd5bbe7984d55eefb00cbc75bdb2c1c68dce87ec
REQUEST
RESPONSE
BODY
POST /service/update2?cup2key=10:2041637316&cup2hreq=c44ca074fab98820e0ddea4abd5bbe7984d55eefb00cbc75bdb2c1c68dce87ec HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.36.71;winhttp;cup-ecdsa
X-Old-UID: cnt=1
X-Goog-Update-AppId: {AB01C5D1-7F78-4A4E-A89B-0415F6466BCA}
X-Goog-Update-Updater: Omaha-1.3.36.71
X-Goog-Update-Interactivity: fg
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Content-Length: 664
Host: flownetserv.com
HTTP/1.1 200 OK
Date: Thu, 24 Jun 2021 14:14:08 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 946
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
CF-Cache-Status: DYNAMIC
cf-request-id: 0adff80cf80000fbd82d20f000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=BEs1qPfajN%2BT6dcwZQgE7IEHchsZWVNnfil94DiX9TqXs81SBdC1m85JTNjoUj6zOHICzw%2BHnU29i3tbzq8hUtRxGLQVaO%2BdVrUYi0ftcVZdwKkPvth5o2t%2Bx6IW"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 66468f8e5bc5fbd8-KIX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
https://soloyama.com/app.php?ping=f%3D1%26a%3D3100%26u%3Dfldk-20210619-4126222-fbchff02%26p%3Dpa%26ck%3D430179789257580636%2F
REQUEST
RESPONSE
BODY
GET /app.php?ping=f%3D1%26a%3D3100%26u%3Dfldk-20210619-4126222-fbchff02%26p%3Dpa%26ck%3D430179789257580636%2F HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: soloyama.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 24 Jun 2021 14:14:42 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
P3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"
Set-Cookie: _asd=16245440825417535; expires=Fri, 24-Jun-2022 14:14:42 GMT; Max-Age=31536000; path=/; samesite=none; domain=soloyama.com; secure
POST
200
https://flownetserv.com/service/update2
REQUEST
RESPONSE
BODY
POST /service/update2 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.36.71;winhttp
X-Old-UID: cnt=1
X-Goog-Update-Updater: Omaha-1.3.36.71
X-Goog-Update-Interactivity: bg
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Content-Length: 1402
Host: flownetserv.com
HTTP/1.1 200 OK
Date: Thu, 24 Jun 2021 14:14:43 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 375
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
CF-Cache-Status: DYNAMIC
cf-request-id: 0adff8940200000a4e6cbfb000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=mkCya6hsxcQUy9qhAKhhJfEDOioEDCD7qSuArYfpABRwcUvTpnpbSV1M3s6gVwMm2CY2mcBL9ndQsBRzbIUS4wlNPkUu6maWss1hD19zLkC4MyLHZSdqoIFZLovy"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 664690666f500a4e-KIX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
HEAD
200
http://flownetserv.com/static/media/build/Flow%20Browser%20-%20SearchBip/stable/win/x64/97856822509658/Setup.exe
REQUEST
RESPONSE
BODY
HEAD /static/media/build/Flow%20Browser%20-%20SearchBip/stable/win/x64/97856822509658/Setup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=1
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: flownetserv.com
HTTP/1.1 200 OK
Date: Thu, 24 Jun 2021 14:14:11 GMT
Content-Type: application/octet-stream
Content-Length: 62909168
Connection: keep-alive
Last-Modified: Fri, 09 Apr 2021 19:06:10 GMT
ETag: "6070a5a2-3bfeaf0"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
cf-request-id: 0adff817e40000fbe05c1a5000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=pw%2BVvoG3yMa7nt77mpAGt5tlElNuK5B8TER7olKSc1ocxm4uG9isojjFvDCYOefIlXTnivVVKsPcu1WZhZA1GlttrmZHtjENAYh6qTM73k9qLXTS1lUraEYRxV5L"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 66468f9fdbe6fbe0-KIX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
http://flownetserv.com/static/media/build/Flow%20Browser%20-%20SearchBip/stable/win/x64/97856822509658/Setup.exe
REQUEST
RESPONSE
BODY
GET /static/media/build/Flow%20Browser%20-%20SearchBip/stable/win/x64/97856822509658/Setup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Fri, 09 Apr 2021 19:06:10 GMT
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=1
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: flownetserv.com
HTTP/1.1 200 OK
Date: Thu, 24 Jun 2021 14:14:11 GMT
Content-Type: application/octet-stream
Content-Length: 62909168
Connection: keep-alive
Last-Modified: Fri, 09 Apr 2021 19:06:10 GMT
ETag: "6070a5a2-3bfeaf0"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
cf-request-id: 0adff8192c0000fbe0170bf000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=4w8kLjA2OQULzbual7q6br7gJXXOHQrJOvDET%2Bzp%2B6YjvWGLT7BNupeuIeJQ%2B1iot0DR5206z8YaSwlMM4%2FNUXobnl4R0GSUexTFBTEPTdsHK8f1xn4HwqoE4V19"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 66468fa1e88cfbe0-KIX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
HEAD
200
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFUTGhWQUViMUVlUQ/0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crx
REQUEST
RESPONSE
BODY
HEAD /edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFUTGhWQUViMUVlUQ/0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crx HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-length: 6760942
content-security-policy: default-src 'none'
content-type: application/x-chrome-extension
etag: "2e2fe7"
last-modified: Wed, 10 Oct 2018 17:49:21 GMT
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
date: Wed, 23 Jun 2021 20:00:20 GMT
age: 65720
alt-svc: h3=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
206
http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFUTGhWQUViMUVlUQ/0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crx
REQUEST
RESPONSE
BODY
GET /edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFUTGhWQUViMUVlUQ/0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crx HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 10 Oct 2018 17:49:21 GMT
Range: bytes=0-5481
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-length: 5482
content-security-policy: default-src 'none'
content-type: application/x-chrome-extension
etag: "2e2fe7"
last-modified: Wed, 10 Oct 2018 17:49:21 GMT
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
date: Wed, 23 Jun 2021 20:00:20 GMT
age: 65737
content-range: bytes 0-5481/6760942
alt-svc: h3=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 172.67.223.135:80 -> 192.168.56.101:49221 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 192.168.56.101:49216 -> 172.67.223.135:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49217 -> 172.67.223.135:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49305 -> 193.70.47.128:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49315 -> 172.67.223.135:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49216 172.67.223.135:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 58:02:7f:64:99:8c:33:d7:44:80:ce:b8:4a:40:da:1b:4a:2d:a5:52 |
TLS 1.2 192.168.56.101:49217 172.67.223.135:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 58:02:7f:64:99:8c:33:d7:44:80:ce:b8:4a:40:da:1b:4a:2d:a5:52 |
TLS 1.3 192.168.56.101:49300 142.250.199.77:443 |
None | None | None |
TLS 1.3 192.168.56.101:49301 216.58.200.78:443 |
None | None | None |
TLS 1.3 192.168.56.101:49304 59.18.44.80:443 |
None | None | None |
TLS 1.3 192.168.56.101:49306 59.18.30.144:443 |
None | None | None |
TLS 1.3 192.168.56.101:49307 142.250.207.78:443 |
None | None | None |
TLSv1 192.168.56.101:49305 193.70.47.128:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=soloyama.com | 2c:79:5b:29:8f:93:e2:61:60:7f:ba:5e:de:b3:cb:de:24:ef:0b:f2 |
TLS 1.3 192.168.56.101:49317 8.8.8.8:443 |
None | None | None |
TLS 1.3 192.168.56.101:49308 65.8.17.57:443 |
None | None | None |
TLS 1.3 192.168.56.101:49318 8.8.4.4:443 |
None | None | None |
TLS 1.3 192.168.56.101:49319 142.250.196.131:443 |
None | None | None |
TLS 1.3 192.168.56.101:49322 13.225.134.82:443 |
None | None | None |
TLS 1.3 192.168.56.101:49321 172.217.161.65:443 |
None | None | None |
TLS 1.3 192.168.56.101:49324 172.217.26.35:443 |
None | None | None |
TLS 1.2 192.168.56.101:49310 35.83.118.206:443 |
C=US, O=Amazon, OU=Server CA 1B, CN=Amazon | CN=mywot.com | ae:ee:12:ae:1a:81:d0:1b:e1:c1:0a:da:d9:0c:33:ce:20:b1:e9:50 |
TLS 1.2 192.168.56.101:49311 52.54.193.222:443 |
C=US, O=Amazon, OU=Server CA 1B, CN=Amazon | CN=mywot.com | 7b:68:a6:5e:ec:e3:81:e6:28:1c:8e:a7:a2:95:28:21:86:b1:ec:df |
TLS 1.2 192.168.56.101:49315 172.67.223.135:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 58:02:7f:64:99:8c:33:d7:44:80:ce:b8:4a:40:da:1b:4a:2d:a5:52 |
TLS 1.3 192.168.56.101:49323 13.225.134.82:443 |
None | None | None |
TLS 1.3 192.168.56.101:49302 216.58.200.78:443 |
None | None | None |
TLS 1.3 192.168.56.101:49320 172.217.26.35:443 |
None | None | None |
TLS 1.3 192.168.56.101:49325 172.217.31.131:443 |
None | None | None |
UNDETERMINED 192.168.56.101:49309 35.83.118.206:443 |
None | None | None |
Snort Alerts
No Snort Alerts