Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
duckyu.biz | 178.208.83.29 | |
freegeoip.app | 104.21.19.200 | |
api.my-ip.io | 157.245.5.40 |
- UDP Requests
-
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62325 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
https://freegeoip.app/xml/
REQUEST
RESPONSE
BODY
GET /xml/ HTTP/1.1
Host: freegeoip.app
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 30 Jul 2021 01:39:55 GMT
Content-Type: application/xml
Content-Length: 356
Connection: keep-alive
Vary: Origin
X-Database-Date: Thu, 16 Jul 2020 08:44:46 GMT
X-Ratelimit-Limit: 15000
X-Ratelimit-Remaining: 14999
X-Ratelimit-Reset: 3600
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=FPOeqVyHXN4KmUtEUn68KZv0lwHpvYjK%2BrWDbup1sqttjKbtUb2Vu8T20509vgwvQhEsbXwF3m27KYmEM8lwL7beQbUxT6E%2F3%2BnksMTkmB1V7nxnlJPrvAF9VfbP9QAG"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 676ae03e4c1242a4-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
https://api.my-ip.io/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Host: api.my-ip.io
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 30 Jul 2021 01:39:57 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 15
Connection: keep-alive
Cache-Control: no-store,no-cache
Pragma: no-cache
X-IP-Type: IPv4
GET
200
https://freegeoip.app/xml/
REQUEST
RESPONSE
BODY
GET /xml/ HTTP/1.1
Host: freegeoip.app
HTTP/1.1 200 OK
Date: Fri, 30 Jul 2021 01:40:44 GMT
Content-Type: application/xml
Content-Length: 356
Connection: keep-alive
Vary: Origin
X-Database-Date: Thu, 16 Jul 2020 08:44:46 GMT
X-Ratelimit-Limit: 15000
X-Ratelimit-Remaining: 14998
X-Ratelimit-Reset: 3551
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=XPdYIqgL%2BQ6WLulYHASyL4M9xgzglnNN0c8J%2FJv7tu3tAfbbL7hCYL57KfAvwwW5LES%2BeF9RhiMZSiTxT4yOX6ou5so38DcjpcQNKHnd43Yk8h%2Bm6zPY6VBd2jmba1w6"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 676ae1724ff142a4-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
https://api.my-ip.io/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Host: api.my-ip.io
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 30 Jul 2021 01:40:45 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 15
Connection: keep-alive
Cache-Control: no-store,no-cache
Pragma: no-cache
X-IP-Type: IPv4
GET
301
http://freegeoip.app/xml/
REQUEST
RESPONSE
BODY
GET /xml/ HTTP/1.1
Host: freegeoip.app
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Date: Fri, 30 Jul 2021 01:39:45 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: max-age=3600
Expires: Fri, 30 Jul 2021 02:39:45 GMT
Location: https://freegeoip.app/xml/
cf-request-id: 0b96aa53d50000323a7f948000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=YyOYlQthGOMRBk2jTMbUa6zQWGlZVtkmaHT2AW5XJUxjzT%2BNNZurJKZqu90lzqHfB45vrAO7%2Bf1x1KhVDeIlD1KGULmfpr594C3RSPwvDiHOJcyxejwHhHt3NQhaZyw3"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 676adfffb8a6323a-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
301
http://api.my-ip.io/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Host: api.my-ip.io
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Fri, 30 Jul 2021 01:39:55 GMT
Content-Type: text/html
Content-Length: 178
Connection: keep-alive
Location: https://api.my-ip.io/ip
GET
301
http://freegeoip.app/xml/
REQUEST
RESPONSE
BODY
GET /xml/ HTTP/1.1
Host: freegeoip.app
HTTP/1.1 301 Moved Permanently
Date: Fri, 30 Jul 2021 01:40:44 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: max-age=3600
Expires: Fri, 30 Jul 2021 02:40:44 GMT
Location: https://freegeoip.app/xml/
cf-request-id: 0b96ab3ab20000323a3b1ea000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=qhWmVQdmwoQASidtKdkGRmRe2d2xBJ8XckFlqipwfEg3o2XtiaBalXEYioZ1tJK73UsbgTGYnWNdxf7TQfe6%2Beep4zOhvqblg9Po3YIBqog7s2rIr2f5QBM%2B3XnQzLM8"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 676ae1711b62323a-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
301
http://api.my-ip.io/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Host: api.my-ip.io
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Fri, 30 Jul 2021 01:40:44 GMT
Content-Type: text/html
Content-Length: 178
Connection: keep-alive
Location: https://api.my-ip.io/ip
GET
200
http://duckyu.biz/corona//image.png
REQUEST
RESPONSE
BODY
GET /corona//image.png HTTP/1.1
Host: duckyu.biz
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 30 Jul 2021 01:40:53 GMT
Content-Type: image/png
Content-Length: 22380
Last-Modified: Tue, 06 Jul 2021 18:44:54 GMT
Connection: keep-alive
Keep-Alive: timeout=5
ETag: "60e4a4a6-576c"
Expires: Thu, 31 Dec 2037 23:55:55 GMT
Cache-Control: max-age=315360000
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:54056 -> 164.124.101.2:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD | Potentially Bad Traffic |
TCP 192.168.56.101:49208 -> 178.208.83.29:80 | 2029754 | ET HUNTING Suspicious GET Request with Possible COVID-19 URI M2 | Potentially Bad Traffic |
TCP 192.168.56.101:49201 -> 172.67.188.154:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49203 -> 157.245.5.40:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49201 172.67.188.154:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | b4:1d:91:d8:54:ad:34:b6:35:88:c9:90:a4:e5:95:8d:b0:d1:ec:05 |
TLSv1 192.168.56.101:49203 157.245.5.40:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=my-ip.io | b3:dc:f4:67:05:b9:90:dd:97:12:85:19:f9:4e:a1:95:0b:15:ee:08 |
Snort Alerts
No Snort Alerts