Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
GET
302
https://138.34.28.219/rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
HTTP/1.1 302 Found
Set-Cookie: AIROS_F492BFD61C49=206be78585aa5afd12526b4712060e1f; Path=/; Version=1
Location: /cookiechecker?uri=/rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/
Content-Length: 0
Date: Sun, 01 Aug 2021 00:28:10 GMT
Server: lighttpd/1.4.39
GET
302
https://138.34.28.219/cookiechecker?uri=/rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/
REQUEST
RESPONSE
BODY
GET /cookiechecker?uri=/rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=206be78585aa5afd12526b4712060e1f
HTTP/1.1 302 Found
Location: /index.html
Content-Length: 0
Date: Sun, 01 Aug 2021 00:28:10 GMT
Server: lighttpd/1.4.39
GET
302
https://138.34.28.219/index.html
REQUEST
RESPONSE
BODY
GET /index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=206be78585aa5afd12526b4712060e1f
HTTP/1.1 302 Found
Location: /login.cgi?uri=/index.html
Content-Length: 0
Date: Sun, 01 Aug 2021 00:28:10 GMT
Server: lighttpd/1.4.39
GET
200
https://138.34.28.219/login.cgi?uri=/index.html
REQUEST
RESPONSE
BODY
GET /login.cgi?uri=/index.html HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 138.34.28.219
Cookie: AIROS_F492BFD61C49=206be78585aa5afd12526b4712060e1f
HTTP/1.1 200 OK
Set-Cookie: ui_language=en_US; Path=/; Expires=Tuesday, 1-Jan-38 00:00:00 GMT; HttpOnly
Content-Type: text/html
Transfer-Encoding: chunked
Date: Sun, 01 Aug 2021 00:28:11 GMT
Server: lighttpd/1.4.39
GET
404
https://38.110.103.113/rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/
REQUEST
RESPONSE
BODY
GET /rob116/TEST22-PC_W617601.E07BB07373A3BB3F491F304B3B719B93/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.74.0
Host: 38.110.103.113
HTTP/1.1 404 Not Found
Content-Type: text/html
Content-Length: 341
Date: Fri, 23 Jul 2021 06:53:13 GMT
Server: lighttpd/1.4.54
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 80.15.2.105:443 -> 192.168.56.102:49166 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.102:49166 -> 80.15.2.105:443 | 2028401 | ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex | Unknown Traffic |
TCP 192.168.56.102:49165 -> 38.110.103.113:443 | 2028401 | ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex | Unknown Traffic |
TCP 192.168.56.102:49164 -> 138.34.28.219:443 | 2028401 | ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex | Unknown Traffic |
TCP 80.15.2.105:443 -> 192.168.56.102:49167 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 80.15.2.105:443 -> 192.168.56.102:49168 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 80.15.2.105:443 -> 192.168.56.102:49169 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.102:49169 -> 80.15.2.105:443 | 2028401 | ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex | Unknown Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49165 38.110.103.113:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:10:C4:5A/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-78:8A:20:10:C4:5A/emailAddress=support@ubnt.com | f8:a6:1d:83:c7:74:cb:aa:74:13:1b:31:74:93:a5:b4:a4:1b:bd:c5 |
TLSv1 192.168.56.102:49164 138.34.28.219:443 |
C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | C=US, ST=CA, L=San Jose, O=Ubiquiti Networks Inc., OU=Technical Support, CN=UBNT-F4:92:BF:D6:1C:49/emailAddress=support@ubnt.com | 0f:6c:9c:c8:a9:10:1e:c8:98:3f:01:df:32:ad:f1:7f:5d:d0:4c:54 |
Snort Alerts
No Snort Alerts