Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
7tgopa.am.files.1drv.com |
CNAME
am-files.fe.1drv.com
CNAME
l-0003.l-msedge.net
|
13.107.42.12 |
darkeye.hopto.org | 160.152.6.54 | |
onedrive.live.com |
CNAME
l-0004.l-msedge.net
|
13.107.42.13 |
- UDP Requests
-
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62325 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
192.168.56.101:62449 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
8.8.8.8:53 192.168.56.101:54056
-
8.8.8.8:53 192.168.56.101:55450
-
8.8.8.8:53 192.168.56.101:56977
-
8.8.8.8:53 192.168.56.101:65329
-
GET
302
https://onedrive.live.com/download?cid=6BC744122027ACE8&resid=6BC744122027ACE8%21137&authkey=AHDc8B9P60uuA9c
REQUEST
RESPONSE
BODY
GET /download?cid=6BC744122027ACE8&resid=6BC744122027ACE8%21137&authkey=AHDc8B9P60uuA9c HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Host: onedrive.live.com
Cache-Control: no-cache
HTTP/1.1 302 Found
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: -1
Location: https://7tgopa.am.files.1drv.com/y4mgxpWp6MuASym9689Gu9OG8JBEZdImPuWF8Jt3g9nSjLfECHCRL9ygUaWQdsoG1GX0-oc9EDP1KXA0U4UdMMnZ8kM8ogtP2jsnNr1wzR6tdejAJLZCL5AiCF5ZZL_P57JUsM_YPvJWRlHFbJb3lM5Ylmk9lcGLwSt3VvC6t138iQKIUjqgUVF1kjo191ujlXuc_A7R_tpWhoCYDTb1KQ5tw/LIGHT.bin?download&psid=1
Set-Cookie: E=P:+2bjISGD2Yg=:ljRa8ygiDvXhU5XB2p/9haTSPe06k5qyKAmyhKREosg=:F; domain=.live.com; path=/
Set-Cookie: xid=a1a9a9f9-a75d-40da-b5b8-89cc30d2a2db&&RD00155D99A691&317; domain=.live.com; path=/
Set-Cookie: xidseq=1; domain=.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Wed, 29-Sep-2021 06:34:17 GMT; path=/
Set-Cookie: wla42=; domain=live.com; expires=Wed, 06-Oct-2021 08:14:18 GMT; path=/
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000
X-MSNServer: RD00155D99A691
X-ODWebServer: eastus1-odwebpl
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: A6448C1171FE4EEA9E1B6784EE54B2FE Ref B: SLAEDGE1018 Ref C: 2021-09-29T08:14:17Z
Date: Wed, 29 Sep 2021 08:14:18 GMT
Content-Length: 0
GET
200
https://7tgopa.am.files.1drv.com/y4mgxpWp6MuASym9689Gu9OG8JBEZdImPuWF8Jt3g9nSjLfECHCRL9ygUaWQdsoG1GX0-oc9EDP1KXA0U4UdMMnZ8kM8ogtP2jsnNr1wzR6tdejAJLZCL5AiCF5ZZL_P57JUsM_YPvJWRlHFbJb3lM5Ylmk9lcGLwSt3VvC6t138iQKIUjqgUVF1kjo191ujlXuc_A7R_tpWhoCYDTb1KQ5tw/LIGHT.bin?download&psid=1
REQUEST
RESPONSE
BODY
GET /y4mgxpWp6MuASym9689Gu9OG8JBEZdImPuWF8Jt3g9nSjLfECHCRL9ygUaWQdsoG1GX0-oc9EDP1KXA0U4UdMMnZ8kM8ogtP2jsnNr1wzR6tdejAJLZCL5AiCF5ZZL_P57JUsM_YPvJWRlHFbJb3lM5Ylmk9lcGLwSt3VvC6t138iQKIUjqgUVF1kjo191ujlXuc_A7R_tpWhoCYDTb1KQ5tw/LIGHT.bin?download&psid=1 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Connection: Keep-Alive
Cache-Control: no-cache
Host: 7tgopa.am.files.1drv.com
HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 207936
Content-Type: application/octet-stream
Content-Location: https://7tgopa.am.files.1drv.com/y4mHBfW8fM_9H4qEduKvseyAfZzPvyZte9Fwt0RYD1FSw_NhIM61s4QqPc1NosO9TdPA1x70mX2Rnh4GE1iPjLu0mnFy-mOxky87vLxEM9i_BA8gNLFPNYHms_Zu1heHt2avQuzkGwAWH_n5VrRUwmEoS_pEwrMK916_EJkg9PmpIM2dPm8HjgyxGTZOlSgT3qM
Expires: Tue, 28 Dec 2021 08:14:19 GMT
Last-Modified: Fri, 27 Aug 2021 03:05:44 GMT
Accept-Ranges: bytes
ETag: 6BC744122027ACE8!137.2
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
X-MSNSERVER: AM3PPF1ED31D5A8
Strict-Transport-Security: max-age=31536000; includeSubDomains
MS-CV: PJpKhtCMtEquexNSMx+9tA.0
X-SqlDataOrigin: S
CTag: aYzo2QkM3NDQxMjIwMjdBQ0U4ITEzNy4yNTc
X-PreAuthInfo: rv;poba;
Content-Disposition: attachment; filename="LIGHT.bin"
X-Content-Type-Options: nosniff
X-StreamOrigin: X
X-AsmVersion: UNKNOWN; 19.766.916.2003
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: 5396D0932C3344D5A0C73314479CA45B Ref B: SLAEDGE1108 Ref C: 2021-09-29T08:14:18Z
Date: Wed, 29 Sep 2021 08:14:18 GMT
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:54056 -> 8.8.8.8:53 | 2028681 | ET POLICY DNS Query to DynDNS Domain *.hopto .org | Potentially Bad Traffic |
UDP 192.168.56.101:55450 -> 8.8.8.8:53 | 2028681 | ET POLICY DNS Query to DynDNS Domain *.hopto .org | Potentially Bad Traffic |
UDP 192.168.56.101:56977 -> 8.8.8.8:53 | 2028681 | ET POLICY DNS Query to DynDNS Domain *.hopto .org | Potentially Bad Traffic |
TCP 192.168.56.101:49204 -> 13.107.42.12:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49202 -> 13.107.42.13:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
UDP 192.168.56.101:65329 -> 8.8.8.8:53 | 2028681 | ET POLICY DNS Query to DynDNS Domain *.hopto .org | Potentially Bad Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49204 13.107.42.12:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=storage.live.com | ec:e5:02:98:e6:c9:9a:12:fc:c0:4d:19:cd:2b:0c:ae:d0:c0:37:8e |
TLSv1 192.168.56.101:49202 13.107.42.13:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 | CN=onedrive.com | 50:2f:33:10:92:ac:27:7b:17:be:82:68:3b:e2:29:ad:97:41:b7:bb |
Snort Alerts
No Snort Alerts