Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
bitbucket.org | 104.192.141.1 | |
twitter.com | 104.244.42.65 | |
mas.to | 88.99.75.82 | |
bbuseruploads.s3.amazonaws.com |
CNAME
s3-1-w.amazonaws.com
|
52.217.228.169 |
- UDP Requests
-
-
192.168.56.103:51935 164.124.101.2:53
-
192.168.56.103:60117 164.124.101.2:53
-
192.168.56.103:60880 164.124.101.2:53
-
192.168.56.103:63183 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:63186 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:63183
-
GET
302
https://bitbucket.org/setupfx1/software/downloads/Tango.bin
REQUEST
RESPONSE
BODY
GET /setupfx1/software/downloads/Tango.bin HTTP/1.1
Host: bitbucket.org
Connection: Keep-Alive
HTTP/1.1 302 Found
Content-Security-Policy-Report-Only: script-src 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' http: https: https://d301sr5gafysq2.cloudfront.net; style-src 'self' 'unsafe-inline' https://aui-cdn.atlassian.com https://d301sr5gafysq2.cloudfront.net; report-uri https://web-security-reports.services.atlassian.com/csp-report/bb-website; default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *; connect-src bitbucket.org *.bitbucket.org bb-inf.net *.bb-inf.net id.atlassian.com analytics.atlassian.com as.atlassian.com api-private.stg.atlassian.com api-private.atlassian.com cofs.staging.public.atl-paas.net cofs.prod.public.atl-paas.net intake.opbeat.com api.media.atlassian.com api.segment.io xid.statuspage.io xid.atlassian.com xid.sourcetreeapp.com bam.nr-data.net bam-cell.nr-data.net sentry.io bqlf8qjztdtr.statuspage.io https://d301sr5gafysq2.cloudfront.net; object-src about:; base-uri 'self'
Server: nginx
X-Usage-Quota-Remaining: 999082.861
Vary: Accept-Language, Origin
X-Usage-Request-Cost: 934.80
Cache-Control: no-cache, no-store, must-revalidate, max-age=0
Content-Type: text/html; charset=utf-8
X-B3-TraceId: 9d50c9c5ce657e45
X-Usage-Output-Ops: 0
X-Dc-Location: Micros
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Mon, 08 Nov 2021 09:17:16 GMT
X-Usage-User-Time: 0.023091
X-Usage-System-Time: 0.004953
Location: https://bbuseruploads.s3.amazonaws.com/dd8f3efb-aea4-4888-a2bc-db69074fc43e/downloads/f3cf9db5-402d-4ac0-81bf-ed03f37f3813/Tango.bin?Signature=saZRMEukgw4Kolbfgg8osLa73Hk%3D&Expires=1636364715&AWSAccessKeyId=AKIA6KOSE3BNJRRFUUX6&versionId=OQ.Ov51xs6RULvB9iL41ndXqzROZqFlU&response-content-disposition=attachment%3B%20filename%3D%22Tango.bin%22
X-Served-By: 5ed65cd739a3
Expires: Mon, 08 Nov 2021 09:17:16 GMT
Content-Language: en
X-View-Name: bitbucket.apps.downloads.views.download_file
X-Static-Version: 736e3ea92432
X-Render-Time: 0.059592962265
Connection: keep-alive
X-Usage-Input-Ops: 0
X-Request-Count: 2449
X-Frame-Options: SAMEORIGIN
X-Version: 736e3ea92432
X-Cache-Info: not cacheable; response specified "Cache-Control: no-cache"
Content-Length: 0
GET
200
https://bbuseruploads.s3.amazonaws.com/dd8f3efb-aea4-4888-a2bc-db69074fc43e/downloads/f3cf9db5-402d-4ac0-81bf-ed03f37f3813/Tango.bin?Signature=saZRMEukgw4Kolbfgg8osLa73Hk%3D&Expires=1636364715&AWSAccessKeyId=AKIA6KOSE3BNJRRFUUX6&versionId=OQ.Ov51xs6RULvB9iL41ndXqzROZqFlU&response-content-disposition=attachment%3B%20filename%3D%22Tango.bin%22
REQUEST
RESPONSE
BODY
GET /dd8f3efb-aea4-4888-a2bc-db69074fc43e/downloads/f3cf9db5-402d-4ac0-81bf-ed03f37f3813/Tango.bin?Signature=saZRMEukgw4Kolbfgg8osLa73Hk%3D&Expires=1636364715&AWSAccessKeyId=AKIA6KOSE3BNJRRFUUX6&versionId=OQ.Ov51xs6RULvB9iL41ndXqzROZqFlU&response-content-disposition=attachment%3B%20filename%3D%22Tango.bin%22 HTTP/1.1
Host: bbuseruploads.s3.amazonaws.com
Connection: Keep-Alive
HTTP/1.1 200 OK
x-amz-id-2: nTxMv70mx11ZreYxXGXXuXPN+PpUN+i/YuVboYQ4I0cd2/iFJg/P8AeZ29eeuxzPEmJsO4VzZV0=
x-amz-request-id: HRDW4JFXVKFEBER7
Date: Mon, 08 Nov 2021 09:17:18 GMT
Last-Modified: Sun, 07 Nov 2021 13:52:40 GMT
ETag: "2c4e01b61b79a94374dfb4c42756af4a"
x-amz-version-id: OQ.Ov51xs6RULvB9iL41ndXqzROZqFlU
Content-Disposition: attachment; filename="Tango.bin"
Accept-Ranges: bytes
Content-Type: application/octet-stream
Server: AmazonS3
Content-Length: 750592
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 104.244.42.1 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
104.244.42.1 | 192.168.56.103 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49178 -> 52.217.130.161:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49182 -> 88.99.75.82:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
UDP 192.168.56.103:63183 -> 8.8.8.8:53 | 2027757 | ET DNS Query for .to TLD | Potentially Bad Traffic |
TCP 192.168.56.103:49177 -> 104.192.141.1:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
UDP 192.168.56.103:63183 -> 164.124.101.2:53 | 2027757 | ET DNS Query for .to TLD | Potentially Bad Traffic |
TCP 192.168.56.103:49181 -> 88.99.75.82:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 88.99.75.82:443 -> 192.168.56.103:49183 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49178 52.217.130.161:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert Baltimore CA-2 G2 | C=US, ST=Washington, L=Seattle, O=Amazon.com, Inc., CN=*.s3.amazonaws.com | 90:e0:af:dc:fa:f7:0b:ac:50:bb:fa:43:e1:ec:e2:3d:ce:91:90:47 |
TLS 1.2 192.168.56.103:49177 104.192.141.1:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=Private Organization, unknown=US, unknown=Delaware, serialNumber=3928449, C=US, ST=California, L=San Francisco, O=Atlassian, Inc., OU=Bitbucket, CN=bitbucket.org | 4e:6a:4c:3b:82:15:ef:df:97:38:5e:50:ef:b9:86:42:84:3b:89:f0 |
Snort Alerts
No Snort Alerts