Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
cdn.discordapp.com | 162.159.133.233 |
- UDP Requests
-
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:61480 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
https://cdn.discordapp.com/attachments/893177342426509335/899196909166686208/87858A4B.jpg
REQUEST
RESPONSE
BODY
GET /attachments/893177342426509335/899196909166686208/87858A4B.jpg HTTP/1.1
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 19 Oct 2021 00:29:54 GMT
Content-Type: image/jpeg
Content-Length: 1023400
Connection: keep-alive
CF-Ray: 6a05e50cbad76189-ICN
Accept-Ranges: bytes
Age: 145073
Cache-Control: public, max-age=31536000
ETag: "66ca8975f02076b86e12d75a4d0de41d"
Expires: Wed, 19 Oct 2022 00:29:54 GMT
Last-Modified: Sun, 17 Oct 2021 07:27:29 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Cf-Bgj: h2pri
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634455649476805
x-goog-hash: crc32c=5ieqvQ==
x-goog-hash: md5=ZsqJdfAgdrhuEtdaTQ3kHQ==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 1023400
X-GUploader-UploadID: ADPycdv9FaeZCVvNxJ0j9J9me9Pb21bY5FAzUm7lRQ2XEvJk8RBNWjiDd2ydLz6k5Dbqb7XHAdbF6YWU87s8h9PS9PFWQjdpPg
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=JlJhAwWI5JT8G7TrTfYGGYhGEzI2%2F0iSythBeWZQCAKJShnylQ8lG70DidwOCTMMiGwD%2BsB%2FVyo%2FNyQPzdVXdg%2BnO6bFmWzO%2F1HpvUNqLdjPiVVIqLLSV7aenxqeCi7J4N6Zcg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/893177342426509335/899196911062511676/938B601D.jpg
REQUEST
RESPONSE
BODY
GET /attachments/893177342426509335/899196911062511676/938B601D.jpg HTTP/1.1
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Tue, 19 Oct 2021 00:29:54 GMT
Content-Type: image/jpeg
Content-Length: 369626
Connection: keep-alive
CF-Ray: 6a05e50dabed6189-ICN
Accept-Ranges: bytes
Age: 145072
Cache-Control: public, max-age=31536000
ETag: "b6e552324005b602fc51371f4fe77ab4"
Expires: Wed, 19 Oct 2022 00:29:54 GMT
Last-Modified: Sun, 17 Oct 2021 07:27:29 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Cf-Bgj: h2pri
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634455649910438
x-goog-hash: crc32c=ZBSnlw==
x-goog-hash: md5=tuVSMkAFtgL8UTcfT+d6tA==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 369626
X-GUploader-UploadID: ADPycdsmOzZ3g4snr9M5BlMhLb0D_Ift-z8HZUNBOCaWds-afrNUxu9FjkZ7rwqCuZmG0NTl9owZLy8gmaa7HiBYzw2UnBz3ow
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=AuoKHVYhq%2FxS47Xkj4mLcsvpyhiqjhAgU1wADG5ozOxshJObk4iPk8oiNC4fJQx2mxoCkd9QTvscGBW1ruOvi%2FQF0hhrU14DbHYzPHh5qlBOJVVO3LPRb8GEpey0C9XjfYWomg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/893177342426509335/899196909166686208/87858A4B.jpg
REQUEST
RESPONSE
BODY
GET /attachments/893177342426509335/899196909166686208/87858A4B.jpg HTTP/1.1
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 19 Oct 2021 00:30:08 GMT
Content-Type: image/jpeg
Content-Length: 1023400
Connection: keep-alive
CF-Ray: 6a05e568b8570fb9-ICN
Accept-Ranges: bytes
Age: 145087
Cache-Control: public, max-age=31536000
ETag: "66ca8975f02076b86e12d75a4d0de41d"
Expires: Wed, 19 Oct 2022 00:30:08 GMT
Last-Modified: Sun, 17 Oct 2021 07:27:29 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Cf-Bgj: h2pri
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634455649476805
x-goog-hash: crc32c=5ieqvQ==
x-goog-hash: md5=ZsqJdfAgdrhuEtdaTQ3kHQ==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 1023400
X-GUploader-UploadID: ADPycdv9FaeZCVvNxJ0j9J9me9Pb21bY5FAzUm7lRQ2XEvJk8RBNWjiDd2ydLz6k5Dbqb7XHAdbF6YWU87s8h9PS9PFWQjdpPg
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=44KLDL0aBXyxF98%2BmgfCn8Y8cjxYnpEaQWNvdYKGuVM7juYCo0GGtL0jlXyq5kXYYXljYsPBc5zFBJ%2Fmr92o0Bfm4ixUhi%2FNtel8V%2BsUk3%2FxYrrWZgW4%2Bxoxud145WWgtFswew%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/893177342426509335/899196911062511676/938B601D.jpg
REQUEST
RESPONSE
BODY
GET /attachments/893177342426509335/899196911062511676/938B601D.jpg HTTP/1.1
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Tue, 19 Oct 2021 00:30:09 GMT
Content-Type: image/jpeg
Content-Length: 369626
Connection: keep-alive
CF-Ray: 6a05e56a8a740fb9-ICN
Accept-Ranges: bytes
Age: 145087
Cache-Control: public, max-age=31536000
ETag: "b6e552324005b602fc51371f4fe77ab4"
Expires: Wed, 19 Oct 2022 00:30:09 GMT
Last-Modified: Sun, 17 Oct 2021 07:27:29 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Cf-Bgj: h2pri
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634455649910438
x-goog-hash: crc32c=ZBSnlw==
x-goog-hash: md5=tuVSMkAFtgL8UTcfT+d6tA==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 369626
X-GUploader-UploadID: ADPycdsmOzZ3g4snr9M5BlMhLb0D_Ift-z8HZUNBOCaWds-afrNUxu9FjkZ7rwqCuZmG0NTl9owZLy8gmaa7HiBYzw2UnBz3ow
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Jb7mMQOwOgYUqr3EswqlwTo9xKVeDZZ9r0pDniGD4ZirLoUyow8zoJFTRh%2BALCt3JpqC028JqQHE9hg136Ptu2hQJPYubSeUTY1pdkR3Z5hPC3wuQjVNLd95vCdW8hBTD0ldOg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/893177342426509335/899196909166686208/87858A4B.jpg
REQUEST
RESPONSE
BODY
GET /attachments/893177342426509335/899196909166686208/87858A4B.jpg HTTP/1.1
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 19 Oct 2021 00:30:13 GMT
Content-Type: image/jpeg
Content-Length: 1023400
Connection: keep-alive
CF-Ray: 6a05e583dd9e61a0-ICN
Accept-Ranges: bytes
Age: 145092
Cache-Control: public, max-age=31536000
ETag: "66ca8975f02076b86e12d75a4d0de41d"
Expires: Wed, 19 Oct 2022 00:30:13 GMT
Last-Modified: Sun, 17 Oct 2021 07:27:29 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Cf-Bgj: h2pri
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634455649476805
x-goog-hash: crc32c=5ieqvQ==
x-goog-hash: md5=ZsqJdfAgdrhuEtdaTQ3kHQ==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 1023400
X-GUploader-UploadID: ADPycdv9FaeZCVvNxJ0j9J9me9Pb21bY5FAzUm7lRQ2XEvJk8RBNWjiDd2ydLz6k5Dbqb7XHAdbF6YWU87s8h9PS9PFWQjdpPg
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=xwfliNOGpFKHT1HSQAZKyaK8%2BJc0rlFfqLDfUOH6s9Phm96nmM5WbYJjlgxPnFF%2F2K9fEIYOlEu%2BPMqcFCIDtlEdDj0xAY9ePMYE85j%2BRyvVopceKhsfBq2OnHRfTo0cxfb2OA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/893177342426509335/899196911062511676/938B601D.jpg
REQUEST
RESPONSE
BODY
GET /attachments/893177342426509335/899196911062511676/938B601D.jpg HTTP/1.1
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Tue, 19 Oct 2021 00:30:13 GMT
Content-Type: image/jpeg
Content-Length: 369626
Connection: keep-alive
CF-Ray: 6a05e5847e4861a0-ICN
Accept-Ranges: bytes
Age: 145091
Cache-Control: public, max-age=31536000
ETag: "b6e552324005b602fc51371f4fe77ab4"
Expires: Wed, 19 Oct 2022 00:30:13 GMT
Last-Modified: Sun, 17 Oct 2021 07:27:29 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Cf-Bgj: h2pri
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634455649910438
x-goog-hash: crc32c=ZBSnlw==
x-goog-hash: md5=tuVSMkAFtgL8UTcfT+d6tA==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 369626
X-GUploader-UploadID: ADPycdsmOzZ3g4snr9M5BlMhLb0D_Ift-z8HZUNBOCaWds-afrNUxu9FjkZ7rwqCuZmG0NTl9owZLy8gmaa7HiBYzw2UnBz3ow
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=f0gf3TEBmF8m8YDy8QQjOjF%2FYCswfjPP0W9RjL%2BfymjO04Hk8ESJW46LTEidq9Zs3yT3LKCNYiLNuUY6jeS1mvZmpauFfaF4L2NcVk6pFSd%2FNHw5eJAldg8oxTb%2BBN1Hcbnt5w%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49197 -> 162.159.134.233:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49214 -> 162.159.130.233:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49215 -> 162.159.130.233:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49197 162.159.134.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.101:49214 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.101:49215 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
Snort Alerts
No Snort Alerts