Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
geoplugin.net | 178.237.33.50 | |
google.com | 172.217.161.78 | |
eter101.dvrlists.com | 79.134.225.82 |
GET
200
http://192.210.149.242/nokey.txt
REQUEST
RESPONSE
BODY
GET /nokey.txt HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: 192.210.149.242
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 20 May 2022 01:07:45 GMT
Server: Apache/2.4.51 (Win64) OpenSSL/1.1.1l PHP/8.0.12
Last-Modified: Wed, 18 May 2022 21:37:37 GMT
ETag: "12de-5df5010ea1f98"
Accept-Ranges: bytes
Content-Length: 4830
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain
GET
200
http://192.210.149.242/favicon.ico
REQUEST
RESPONSE
BODY
GET /favicon.ico HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: 192.210.149.242
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 20 May 2022 01:07:46 GMT
Server: Apache/2.4.51 (Win64) OpenSSL/1.1.1l PHP/8.0.12
Last-Modified: Thu, 16 Jul 2015 15:32:32 GMT
ETag: "78ae-51affc7a4c400"
Accept-Ranges: bytes
Content-Length: 30894
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: image/x-icon
GET
200
http://192.210.149.242/nokey.jpg
REQUEST
RESPONSE
BODY
GET /nokey.jpg HTTP/1.1
Host: 192.210.149.242
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 20 May 2022 01:07:48 GMT
Server: Apache/2.4.51 (Win64) OpenSSL/1.1.1l PHP/8.0.12
Last-Modified: Wed, 18 May 2022 21:37:18 GMT
ETag: "1f6488-5df500fcb4d14"
Accept-Ranges: bytes
Content-Length: 2057352
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: image/jpeg
GET
200
http://geoplugin.net/json.gp
REQUEST
RESPONSE
BODY
GET /json.gp HTTP/1.1
Host: geoplugin.net
Cache-Control: no-cache
HTTP/1.1 200 OK
date: Fri, 20 May 2022 02:21:56 GMT
server: Apache
content-length: 948
content-type: application/json; charset=utf-8
cache-control: public, max-age=300
access-control-allow-origin: *
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.101 | 142.251.42.142 | 8 | abcdefghijklmnopqrstuvwabcdefghi |
142.251.42.142 | 192.168.56.101 | 0 | abcdefghijklmnopqrstuvwabcdefghi |
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49173 79.134.225.82:2050 |
None | None | None |
Snort Alerts
No Snort Alerts