Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
ftp.pfsbankgroup.com | 185.239.243.112 | |
whatsmyipaddress.biz | 111.90.156.84 | |
ifconfig.me | 34.117.59.81 | |
ip-api.com | 208.95.112.1 |
- TCP Requests
-
-
192.168.56.102:49169 111.90.156.84:443whatsmyipaddress.biz
-
192.168.56.102:49171 111.90.156.84:443whatsmyipaddress.biz
-
192.168.56.102:49176 111.90.156.84:443whatsmyipaddress.biz
-
185.239.243.112:21 192.168.56.102:49183
-
192.168.56.102:49184 185.239.243.112:35424ftp.pfsbankgroup.com
-
192.168.56.102:49175 208.95.112.1:80ip-api.com
-
192.168.56.102:49181 34.117.59.81:80ifconfig.me
-
- UDP Requests
-
-
192.168.56.102:52062 164.124.101.2:53
-
192.168.56.102:52336 164.124.101.2:53
-
192.168.56.102:64034 164.124.101.2:53
-
192.168.56.102:64995 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:49164 239.255.255.250:1900
-
GET
200
https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sb=1
REQUEST
RESPONSE
BODY
GET /?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sb=1 HTTP/1.1
User-Agent: agent2
Host: whatsmyipaddress.biz
Connection: Keep-Alive
HTTP/1.1 200 OK
Connection: Keep-Alive
X-Powered-By: PHP/7.4.22
Set-Cookie: PHPSESSID=efc344f2d6859695aa07d3940d8097bd; path=/; secure
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Date: Fri, 27 Aug 2021 06:45:54 GMT
Server: LiteSpeed
Alt-Svc: quic=":443"; ma=2592000; v="43,46", h3-Q043=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-25=":443"; ma=2592000, h3-27=":443"; ma=2592000
GET
200
https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sb=1
REQUEST
RESPONSE
BODY
GET /?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sb=1 HTTP/1.1
User-Agent: agent2
Host: whatsmyipaddress.biz
HTTP/1.1 200 OK
Connection: Keep-Alive
X-Powered-By: PHP/7.4.22
Set-Cookie: PHPSESSID=ee5db8d78f29a5986fcb8e67cfa4aee2; path=/; secure
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Date: Fri, 27 Aug 2021 06:45:56 GMT
Server: LiteSpeed
Alt-Svc: quic=":443"; ma=2592000; v="43,46", h3-Q043=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-25=":443"; ma=2592000, h3-27=":443"; ma=2592000
GET
200
https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sd=1
REQUEST
RESPONSE
BODY
GET /?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sd=1 HTTP/1.1
User-Agent: agent2
Host: whatsmyipaddress.biz
HTTP/1.1 200 OK
Connection: Keep-Alive
X-Powered-By: PHP/7.4.22
Set-Cookie: PHPSESSID=f93f4e830291fcf4f0a51dd91b139420; path=/; secure
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 9
Date: Fri, 27 Aug 2021 06:45:57 GMT
Server: LiteSpeed
GET
200
https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm
REQUEST
RESPONSE
BODY
GET /?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm HTTP/1.1
Host: whatsmyipaddress.biz
HTTP/1.1 200 OK
Connection: Keep-Alive
X-Powered-By: PHP/7.4.22
Set-Cookie: PHPSESSID=4068b828392514ff6da4f2b6240c004c; path=/; secure
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=UTF-8
Content-Length: 2
Date: Fri, 27 Aug 2021 06:46:15 GMT
Server: LiteSpeed
GET
200
http://ip-api.com/line/?fields=hosting
REQUEST
RESPONSE
BODY
GET /line/?fields=hosting HTTP/1.1
Host: ip-api.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 27 Aug 2021 06:46:14 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 6
Access-Control-Allow-Origin: *
X-Ttl: 60
X-Rl: 44
GET
200
http://ifconfig.me/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Host: ifconfig.me
Connection: Keep-Alive
HTTP/1.1 200 OK
access-control-allow-origin: *
content-type: text/plain; charset=utf-8
content-length: 15
date: Fri, 27 Aug 2021 06:46:18 GMT
x-envoy-upstream-service-time: 1
Via: 1.1 google
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49175 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
UDP 192.168.56.102:52336 -> 164.124.101.2:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD | Potentially Bad Traffic |
TCP 192.168.56.102:49171 -> 111.90.156.84:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 185.239.243.112:21 -> 192.168.56.102:49183 | 2260002 | SURICATA Applayer Detect protocol only one direction | Generic Protocol Command Decode |
TCP 192.168.56.102:49169 -> 111.90.156.84:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49176 -> 111.90.156.84:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49181 -> 34.117.59.81:80 | 2026718 | ET POLICY External IP Lookup Domain (ifconfig .me) | Device Retrieving External IP Address Detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.102:49171 111.90.156.84:443 |
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority | CN=whatsmyipaddress.biz | dd:ea:81:1d:37:20:c7:42:33:a9:63:10:94:3c:5f:4f:bd:6e:5c:c3 |
TLS 1.2 192.168.56.102:49169 111.90.156.84:443 |
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority | CN=whatsmyipaddress.biz | dd:ea:81:1d:37:20:c7:42:33:a9:63:10:94:3c:5f:4f:bd:6e:5c:c3 |
TLS 1.2 192.168.56.102:49176 111.90.156.84:443 |
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority | CN=whatsmyipaddress.biz | dd:ea:81:1d:37:20:c7:42:33:a9:63:10:94:3c:5f:4f:bd:6e:5c:c3 |
Snort Alerts
No Snort Alerts