Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
api.onedrive.com |
CNAME
common-afdrk.fe.1drv.com
CNAME
l-0003.l-msedge.net
|
13.107.42.12 |
GET
404
https://api.onedrive.com/v1.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL3UvcyFBalVyZDlodU1wUWNjTGt4bXhBV0pjQU1ja2M_ZT1mUnc4VHg/root/content
REQUEST
RESPONSE
BODY
GET /v1.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL3UvcyFBalVyZDlodU1wUWNjTGt4bXhBV0pjQU1ja2M_ZT1mUnc4VHg/root/content HTTP/1.1
User-Agent: MyAgent
Host: api.onedrive.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Cache-Control: no-store
Via: 1.1 SN3PPF9E3B07541 (wls-colorado)
Content-Length: 65
Content-Type: application/json
Vary: Accept,Accept-Language,Authorization,Prefer
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
X-WLSPROXY: SN3PPF9E3B07541
MS-CV: 0ZPVi+lo+Uu1c52CKR7yJA.0
X-MSNSERVER: BY3PPF8F9ADF332
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-VroomVersion: v1.0
X-QosStats: {"ApiId":0,"ResultType":2,"SourcePropertyId":0,"TargetPropertyId":42}
X-ThrowSite: 5433.1999
X-AsmVersion: UNKNOWN; 19.749.824.2003
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: E5C37004EFF441F099EF98ECF6017618 Ref B: SLAEDGE1118 Ref C: 2021-09-08T00:09:57Z
Date: Wed, 08 Sep 2021 00:09:57 GMT
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49166 -> 13.107.42.12:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49166 13.107.42.12:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=storage.live.com | ec:e5:02:98:e6:c9:9a:12:fc:c0:4d:19:cd:2b:0c:ae:d0:c0:37:8e |
Snort Alerts
No Snort Alerts