Network Analysis
IP Address | Status | Action |
---|---|---|
138.34.28.219 | Active | Moloch |
154.58.23.192 | Active | Moloch |
164.124.101.2 | Active | Moloch |
185.56.76.108 | Active | Moloch |
185.56.76.28 | Active | Moloch |
185.56.76.94 | Active | Moloch |
217.115.240.248 | Active | Moloch |
24.162.214.166 | Active | Moloch |
38.110.100.142 | Active | Moloch |
38.110.103.18 | Active | Moloch |
45.36.99.184 | Active | Moloch |
60.51.47.65 | Active | Moloch |
68.69.26.182 | Active | Moloch |
97.83.40.67 | Active | Moloch |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
- TCP Requests
-
-
192.168.56.102:49177 138.34.28.219:443
-
192.168.56.102:49174 217.115.240.248:443
-
192.168.56.102:49172 24.162.214.166:443
-
192.168.56.102:49168 38.110.100.142:443
-
192.168.56.102:49169 38.110.103.18:443
-
192.168.56.102:49175 45.36.99.184:443
-
192.168.56.102:49164 60.51.47.65:443
-
192.168.56.102:49166 97.83.40.67:443
-
GET
200
https://60.51.47.65/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 60.51.47.65
HTTP/1.1 200 OK
Server: nginx/1.14.0 (Ubuntu)
Date: Fri, 30 Jul 2021 01:43:59 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
200
https://97.83.40.67/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 97.83.40.67
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 30 Jul 2021 01:44:08 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
302
https://38.110.100.142/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.100.142
HTTP/1.1 302 Found
Set-Cookie: AIROS_BB5A8520CDA9=fc42e9568879bd848a322279cb0c2e5e; Path=/; Version=1
Location: /cookiechecker?uri=/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
Content-Length: 0
Date: Fri, 30 Jul 2021 01:44:17 GMT
Server: lighttpd/1.4.39
GET
302
https://38.110.100.142/cookiechecker?uri=/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /cookiechecker?uri=/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.100.142
Cookie: AIROS_BB5A8520CDA9=fc42e9568879bd848a322279cb0c2e5e
HTTP/1.1 302 Found
Location: /index.html
Content-Length: 0
Date: Fri, 30 Jul 2021 01:44:17 GMT
Server: lighttpd/1.4.39
GET
200
https://38.110.100.142/index.html
REQUEST
RESPONSE
BODY
GET /index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.100.142
Cookie: AIROS_BB5A8520CDA9=fc42e9568879bd848a322279cb0c2e5e
HTTP/1.1 200 OK
Content-Type: text/html
Accept-Ranges: bytes
ETag: "659265186"
Last-Modified: Tue, 28 Jul 2020 11:14:16 GMT
Content-Length: 2549
Date: Fri, 30 Jul 2021 01:44:17 GMT
Server: lighttpd/1.4.39
GET
404
https://38.110.103.18/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.103.18
HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 341
Date: Fri, 30 Jul 2021 01:44:19 GMT
Server: lighttpd/1.4.54
GET
200
https://24.162.214.166/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 24.162.214.166
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 30 Jul 2021 01:44:51 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
404
https://217.115.240.248/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 217.115.240.248
HTTP/1.1 404 Not Found
Date: Thu, 23 Nov 2017 10:50:48 GMT
Content-Length: 284
Connection: Keep-Alive
Server: Xavante 2.2.0 embeded
Content-Type: text/html
GET
200
https://45.36.99.184/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 45.36.99.184
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 30 Jul 2021 01:45:18 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
302
https://138.34.28.219/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
HTTP/1.1 302 Found
Set-Cookie: AIROS_F492BFD61C49=fd7db335221f3bb288e84f662692cb45; Path=/; Version=1
Location: /cookiechecker?uri=/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
Content-Length: 0
Date: Fri, 30 Jul 2021 01:45:26 GMT
Server: lighttpd/1.4.39
GET
302
https://138.34.28.219/cookiechecker?uri=/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/
REQUEST
RESPONSE
BODY
GET /cookiechecker?uri=/rob116/TEST22-PC_W617601.8B538ABB9337784DFF0195FB9533B201/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=fd7db335221f3bb288e84f662692cb45
HTTP/1.1 302 Found
Location: /index.html
Content-Length: 0
Date: Fri, 30 Jul 2021 01:45:27 GMT
Server: lighttpd/1.4.39
GET
302
https://138.34.28.219/index.html
REQUEST
RESPONSE
BODY
GET /index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=fd7db335221f3bb288e84f662692cb45
HTTP/1.1 302 Found
Location: /login.cgi?uri=/index.html
Content-Length: 0
Date: Fri, 30 Jul 2021 01:45:27 GMT
Server: lighttpd/1.4.39
GET
200
https://138.34.28.219/login.cgi?uri=/index.html
REQUEST
RESPONSE
BODY
GET /login.cgi?uri=/index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=fd7db335221f3bb288e84f662692cb45
HTTP/1.1 200 OK
Set-Cookie: ui_language=en_US; Path=/; Expires=Tuesday, 1-Jan-38 00:00:00 GMT; HttpOnly
Content-Type: text/html
Transfer-Encoding: chunked
Date: Fri, 30 Jul 2021 01:45:27 GMT
Server: lighttpd/1.4.39
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49164 60.51.47.65:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | 50:fd:fd:4e:2c:57:ea:f7:c9:cd:3f:61:4a:a2:40:01:1b:b8:df:02 |
TLSv1 192.168.56.102:49169 38.110.103.18:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-B4:FB:E4:B8:30:7E/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-B4:FB:E4:B8:30:7E/emailAddress=support@ubnt.com | 2e:0f:ca:9b:3e:95:2e:8f:f6:42:a6:1e:7a:21:66:83:0d:31:cb:c1 |
TLSv1 192.168.56.102:49168 38.110.100.142:443 |
C=US, ST=NY, L=New York, O=Ubiquiti Inc., OU=Technical Support, CN=UBNT-18:E8:29:1F:F2:01/emailAddress=support@ui.com | C=US, ST=NY, L=New York, O=Ubiquiti Inc., OU=Technical Support, CN=UBNT-18:E8:29:1F:F2:01/emailAddress=support@ui.com | f1:bf:98:64:45:62:e6:de:5f:a4:b5:d9:2a:11:e4:6f:21:99:7b:61 |
TLSv1 192.168.56.102:49166 97.83.40.67:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.102:49175 45.36.99.184:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.102:49172 24.162.214.166:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.102:49174 217.115.240.248:443 |
C=US, ST=GA, L=Canton, O=LigoWave LLC, OU=R&D, CN=LigoWave SSL CA | C=US, ST=GA, L=Canton, O=LigoWave LLC, OU=R&D, CN=LigoWave SSL CA | d3:39:ab:71:76:bb:9c:d2:1c:3e:b1:17:92:c7:3f:25:1f:25:f8:88 |
TLSv1 192.168.56.102:49177 138.34.28.219:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | 0f:6c:9c:c8:a9:10:1e:c8:98:3f:01:df:32:ad:f1:7f:5d:d0:4c:54 |
Snort Alerts
No Snort Alerts