Network Analysis
IP Address | Status | Action |
---|---|---|
138.34.28.219 | Active | Moloch |
185.56.76.108 | Active | Moloch |
185.56.76.28 | Active | Moloch |
185.56.76.72 | Active | Moloch |
185.56.76.94 | Active | Moloch |
204.138.26.60 | Active | Moloch |
24.162.214.166 | Active | Moloch |
38.110.100.104 | Active | Moloch |
38.110.103.124 | Active | Moloch |
38.110.103.136 | Active | Moloch |
60.51.47.65 | Active | Moloch |
74.85.157.139 | Active | Moloch |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
- TCP Requests
-
-
192.168.56.103:49171 138.34.28.219:443
-
192.168.56.103:49167 24.162.214.166:443
-
192.168.56.103:49173 38.110.100.104:443
-
192.168.56.103:49169 38.110.103.124:443
-
192.168.56.103:49177 38.110.103.124:443
-
192.168.56.103:49172 38.110.103.136:443
-
192.168.56.103:49176 38.110.103.136:443
-
192.168.56.103:49170 60.51.47.65:443
-
GET
200
https://24.162.214.166/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 24.162.214.166
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Wed, 28 Jul 2021 00:43:16 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
404
https://38.110.103.124/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.103.124
HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Mon, 06 Jul 2020 17:03:26 GMT
Server: lighttpd/1.4.39
GET
200
https://60.51.47.65/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 60.51.47.65
HTTP/1.1 200 OK
Server: nginx/1.14.0 (Ubuntu)
Date: Wed, 28 Jul 2021 00:43:27 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
302
https://138.34.28.219/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
HTTP/1.1 302 Found
Set-Cookie: AIROS_F492BFD61C49=4c1c07145635d61350e385b742d07ba7; Path=/; Version=1
Location: /cookiechecker?uri=/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
Content-Length: 0
Date: Wed, 28 Jul 2021 00:43:29 GMT
Server: lighttpd/1.4.39
GET
302
https://138.34.28.219/cookiechecker?uri=/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /cookiechecker?uri=/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=4c1c07145635d61350e385b742d07ba7
HTTP/1.1 302 Found
Location: /index.html
Content-Length: 0
Date: Wed, 28 Jul 2021 00:43:29 GMT
Server: lighttpd/1.4.39
GET
302
https://138.34.28.219/index.html
REQUEST
RESPONSE
BODY
GET /index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=4c1c07145635d61350e385b742d07ba7
HTTP/1.1 302 Found
Location: /login.cgi?uri=/index.html
Content-Length: 0
Date: Wed, 28 Jul 2021 00:43:29 GMT
Server: lighttpd/1.4.39
GET
200
https://138.34.28.219/login.cgi?uri=/index.html
REQUEST
RESPONSE
BODY
GET /login.cgi?uri=/index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=4c1c07145635d61350e385b742d07ba7
HTTP/1.1 200 OK
Set-Cookie: ui_language=en_US; Path=/; Expires=Tuesday, 1-Jan-38 00:00:00 GMT; HttpOnly
Content-Type: text/html
Transfer-Encoding: chunked
Date: Wed, 28 Jul 2021 00:43:30 GMT
Server: lighttpd/1.4.39
GET
404
https://38.110.103.136/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.103.136
HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Tue, 07 Jul 2020 05:21:43 GMT
Server: lighttpd/1.4.39
GET
200
https://38.110.100.104/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.100.104
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Wed, 28 Jul 2021 00:43:35 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
404
https://38.110.103.136/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.103.136
HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Tue, 07 Jul 2020 05:22:16 GMT
Server: lighttpd/1.4.39
GET
404
https://38.110.103.124/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.103.124
HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 345
Date: Mon, 06 Jul 2020 17:04:08 GMT
Server: lighttpd/1.4.39
GET
200
https://38.110.100.104/rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/
REQUEST
RESPONSE
BODY
GET /rob112/TEST22-PC_W617601.FFDA4B5123BB5AAFD6D6B3F691D7C683/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.100.104
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Wed, 28 Jul 2021 00:44:14 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49172 38.110.103.136:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:6C:22:98/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:6C:22:98/emailAddress=support@ubnt.com | ba:d7:95:38:aa:e6:8c:48:3e:83:06:69:20:ec:3a:a2:9c:0c:61:47 |
TLSv1 192.168.56.103:49169 38.110.103.124:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:EC:48:A1/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:EC:48:A1/emailAddress=support@ubnt.com | e6:60:4a:40:4a:b9:63:85:da:e8:fc:ec:75:e2:1a:7e:85:1f:49:1e |
TLSv1 192.168.56.103:49173 38.110.100.104:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.103:49167 24.162.214.166:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.103:49170 60.51.47.65:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | 50:fd:fd:4e:2c:57:ea:f7:c9:cd:3f:61:4a:a2:40:01:1b:b8:df:02 |
TLSv1 192.168.56.103:49176 38.110.103.136:443 |
None | None | None |
TLSv1 192.168.56.103:49171 138.34.28.219:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | 0f:6c:9c:c8:a9:10:1e:c8:98:3f:01:df:32:ad:f1:7f:5d:d0:4c:54 |
TLSv1 192.168.56.103:49177 38.110.103.124:443 |
None | None | None |
Snort Alerts
No Snort Alerts