Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
doc-0g-8k-docstext.googleusercontent.com | 216.58.197.193 | |
docs.google.com | 142.250.196.110 | |
ip-api.com | 208.95.112.1 |
- UDP Requests
-
-
192.168.56.103:51935 164.124.101.2:53
-
192.168.56.103:60117 164.124.101.2:53
-
192.168.56.103:60880 164.124.101.2:53
-
192.168.56.103:63183 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:63186 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.103:123
-
GET
307
https://docs.google.com/document/d/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ/export?format=txt
REQUEST
RESPONSE
BODY
GET /document/d/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ/export?format=txt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: docs.google.com
HTTP/1.1 307 Temporary Redirect
Content-Type: text/html; charset=UTF-8
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Date: Wed, 10 Nov 2021 00:44:41 GMT
Location: https://doc-0g-8k-docstext.googleusercontent.com/export/kr014gggnh0d9kvhc4c60ctnp0/qobs2n84j988rv25et34agsloo/1636505080000/109814536751784867157/*/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ?format=txt
P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Content-Security-Policy: frame-ancestors 'self'
X-XSS-Protection: 1; mode=block
Server: GSE
Set-Cookie: S=documents=JTgViapzHkb1s-dtPc601JWXe-ttlk3ZP0BKB23gOuY; Domain=.docs.google.com; Expires=Wed, 10-Nov-2021 01:44:41 GMT; Path=/document/d/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ; Secure; HttpOnly; SameSite=none
Set-Cookie: COMPASS=documents=CjIACWuJVxzBHtlcPnLuWRLr4Qo1b9sLM7W7Trs2p_Ukqhmj7GffAVMuuTXAuoim_Mi0GhCJyKyMBho0AAlriVdvI8b-Zp5AQJfjo0CumCF4cg-3_qmccBJP-G_x-WmE5-v3U7YaIEBAcUgdI8Ut_A==; Domain=.docs.google.com; Expires=Wed, 10-Nov-2021 01:44:41 GMT; Path=/document/d/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ; Secure; HttpOnly; SameSite=none
Set-Cookie: NID=511=pRGN8ZdumzeVzsyYFolmRK9beMZnFWn_kAlg4049RIyPSfhWYKrZzBCj_7L3ESJTBC4FP463UafGaMiyP3Fdb9wl7Y0wHcMJncV_B-VcaObdXCW-tp690Yl77aMv0rk_LxSXtsJDwR0AFxcjBrwGTO6GK3UwamERdJ-9Yk73W6Y; expires=Thu, 12-May-2022 00:44:41 GMT; path=/; domain=.google.com; HttpOnly
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
Accept-Ranges: none
Vary: Accept-Encoding
Transfer-Encoding: chunked
GET
200
https://doc-0g-8k-docstext.googleusercontent.com/export/kr014gggnh0d9kvhc4c60ctnp0/qobs2n84j988rv25et34agsloo/1636505080000/109814536751784867157/*/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ?format=txt
REQUEST
RESPONSE
BODY
GET /export/kr014gggnh0d9kvhc4c60ctnp0/qobs2n84j988rv25et34agsloo/1636505080000/109814536751784867157/*/10HvsTYa9mOZkmz5pyA-Za4wVTeJi4XzWOBmXG4x--SQ?format=txt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: doc-0g-8k-docstext.googleusercontent.com
HTTP/1.1 200 OK
Content-Type: text/plain; charset=utf-8
X-Robots-Tag: noindex, nofollow, nosnippet
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Date: Wed, 10 Nov 2021 00:44:42 GMT
Content-Disposition: attachment; filename="Documentosemttulo.txt"; filename*=UTF-8''Documento%20sem%20t%C3%ADtulo.txt
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: Cache-Control,Content-Disposition,Content-Encoding,Content-Length,Content-Type,Date,Expires,Pragma,Server,Transfer-Encoding,X-Google-GFE-Backend-Request-Cost
X-Frame-Options: ALLOW-FROM https://docs.google.com
Content-Security-Policy: frame-ancestors 'self' https://docs.google.com
Content-Security-Policy: base-uri 'self';object-src 'none';report-uri https://doc-0g-8k-docstext.googleusercontent.com/document/cspreport;script-src 'report-sample' 'nonce-lsR1+VlXHBLv7RP4cyqD4w' 'unsafe-inline' 'strict-dynamic' https: http: 'unsafe-eval';worker-src 'self' blob:
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Server: GSE
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
Accept-Ranges: none
Vary: Accept-Encoding
Transfer-Encoding: chunked
GET
200
http://ip-api.com/json/
REQUEST
RESPONSE
BODY
GET /json/ HTTP/1.1
Host: ip-api.com
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Date: Wed, 10 Nov 2021 00:44:42 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 276
Access-Control-Allow-Origin: *
X-Ttl: 16
X-Rl: 43
GET
200
http://ip-api.com/json/
REQUEST
RESPONSE
BODY
GET /json/ HTTP/1.1
Host: ip-api.com
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Date: Wed, 10 Nov 2021 00:44:42 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 276
Access-Control-Allow-Origin: *
X-Ttl: 16
X-Rl: 42
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49181 -> 142.250.66.78:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49182 -> 142.250.204.129:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49183 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
TCP 192.168.56.103:49183 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49181 142.250.66.78:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.google.com | 16:80:69:27:68:35:54:61:3c:a2:bd:00:dc:49:ed:bb:d7:df:ee:cf |
TLSv1 192.168.56.103:49182 142.250.204.129:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.googleusercontent.com | a3:0c:85:1d:48:7f:3c:72:8f:9a:23:c7:23:f8:e4:03:ae:d0:4d:dc |
Snort Alerts
No Snort Alerts