Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
armmf.adobe.com | 23.212.12.57 |
HEAD
200
https://armmf.adobe.com/arm-manifests/win/ReaderDCManifest3.msi
REQUEST
RESPONSE
BODY
HEAD /arm-manifests/win/ReaderDCManifest3.msi HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: armmf.adobe.com
HTTP/1.1 200 OK
Server: Apache
Last-Modified: Wed, 28 Jul 2021 12:36:47 GMT
ETag: "4e00-5c82e3d685477"
Accept-Ranges: bytes
Content-Length: 19968
Content-Type: application/x-msi
Date: Mon, 09 Aug 2021 13:00:31 GMT
Connection: keep-alive
GET
206
https://armmf.adobe.com/arm-manifests/win/ReaderDCManifest3.msi
REQUEST
RESPONSE
BODY
GET /arm-manifests/win/ReaderDCManifest3.msi HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 28 Jul 2021 12:36:47 GMT
Range: bytes=0-4493
User-Agent: Microsoft BITS/7.5
Host: armmf.adobe.com
HTTP/1.1 206 Partial Content
Server: Apache
Last-Modified: Wed, 28 Jul 2021 12:36:47 GMT
ETag: "4e00-5c82e3d685477"
Accept-Ranges: bytes
Content-Type: application/x-msi
Date: Mon, 09 Aug 2021 13:00:58 GMT
Content-Range: bytes 0-4493/19968
Content-Length: 4494
Connection: keep-alive
GET
206
https://armmf.adobe.com/arm-manifests/win/ReaderDCManifest3.msi
REQUEST
RESPONSE
BODY
GET /arm-manifests/win/ReaderDCManifest3.msi HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 28 Jul 2021 12:36:47 GMT
Range: bytes=4494-10555
User-Agent: Microsoft BITS/7.5
Host: armmf.adobe.com
HTTP/1.1 206 Partial Content
Server: Apache
Last-Modified: Wed, 28 Jul 2021 12:36:47 GMT
ETag: "4e00-5c82e3d685477"
Accept-Ranges: bytes
Content-Type: application/x-msi
Date: Mon, 09 Aug 2021 13:01:02 GMT
Content-Range: bytes 4494-10555/19968
Content-Length: 6062
Connection: keep-alive
GET
206
https://armmf.adobe.com/arm-manifests/win/ReaderDCManifest3.msi
REQUEST
RESPONSE
BODY
GET /arm-manifests/win/ReaderDCManifest3.msi HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 28 Jul 2021 12:36:47 GMT
Range: bytes=10556-19242
User-Agent: Microsoft BITS/7.5
Host: armmf.adobe.com
HTTP/1.1 206 Partial Content
Server: Apache
Last-Modified: Wed, 28 Jul 2021 12:36:47 GMT
ETag: "4e00-5c82e3d685477"
Accept-Ranges: bytes
Content-Type: application/x-msi
Date: Mon, 09 Aug 2021 13:01:04 GMT
Content-Range: bytes 10556-19242/19968
Content-Length: 8687
Connection: keep-alive
GET
206
https://armmf.adobe.com/arm-manifests/win/ReaderDCManifest3.msi
REQUEST
RESPONSE
BODY
GET /arm-manifests/win/ReaderDCManifest3.msi HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 28 Jul 2021 12:36:47 GMT
Range: bytes=19243-19967
User-Agent: Microsoft BITS/7.5
Host: armmf.adobe.com
HTTP/1.1 206 Partial Content
Server: Apache
Last-Modified: Wed, 28 Jul 2021 12:36:47 GMT
ETag: "4e00-5c82e3d685477"
Accept-Ranges: bytes
Content-Type: application/x-msi
Date: Mon, 09 Aug 2021 13:01:06 GMT
Content-Range: bytes 19243-19967/19968
Content-Length: 725
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49165 -> 23.212.12.57:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49165 23.212.12.57:443 |
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA | C=US, ST=California, L=San Jose, O=Adobe Inc, CN=*.adobe.com | 34:65:16:66:1c:13:4a:0f:09:e2:e7:a8:54:c8:fc:ad:48:e8:ce:89 |
Snort Alerts
No Snort Alerts