Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
geoplugin.net | 178.237.33.50 | |
xxggqg.bn.files.1drv.com |
CNAME
bn-files.fe.1drv.com
CNAME
l-0003.l-msedge.net
|
13.107.42.12 |
blackwealth001.duckdns.org | ||
onedrive.live.com |
CNAME
l-0004.l-msedge.net
|
13.107.42.13 |
- TCP Requests
-
-
192.168.56.103:49163 13.107.42.12:443xxggqg.bn.files.1drv.com
-
192.168.56.103:49164 13.107.42.12:443xxggqg.bn.files.1drv.com
-
192.168.56.103:49162 13.107.42.13:443onedrive.live.com
-
192.168.56.103:49178 178.237.33.50:80geoplugin.net
-
192.168.56.103:49177 185.157.162.137:59085blackwealth001.duckdns.org
-
- UDP Requests
-
-
192.168.56.103:49347 164.124.101.2:53
-
192.168.56.103:51084 164.124.101.2:53
-
192.168.56.103:51935 164.124.101.2:53
-
192.168.56.103:51958 164.124.101.2:53
-
192.168.56.103:53064 164.124.101.2:53
-
192.168.56.103:57573 164.124.101.2:53
-
192.168.56.103:60117 164.124.101.2:53
-
192.168.56.103:60556 164.124.101.2:53
-
192.168.56.103:60693 164.124.101.2:53
-
192.168.56.103:60880 164.124.101.2:53
-
192.168.56.103:61603 164.124.101.2:53
-
192.168.56.103:63183 164.124.101.2:53
-
192.168.56.103:63462 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:51087 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.103:123
-
8.8.8.8:53 192.168.56.103:49347
-
8.8.8.8:53 192.168.56.103:51958
-
8.8.8.8:53 192.168.56.103:57573
-
8.8.8.8:53 192.168.56.103:60556
-
8.8.8.8:53 192.168.56.103:60693
-
8.8.8.8:53 192.168.56.103:63462
-
GET
302
https://onedrive.live.com/download?cid=F547EE3E8FFF6BF5&resid=F547EE3E8FFF6BF5%21453&authkey=AOijTcPaFAa_sFY
REQUEST
RESPONSE
BODY
GET /download?cid=F547EE3E8FFF6BF5&resid=F547EE3E8FFF6BF5%21453&authkey=AOijTcPaFAa_sFY HTTP/1.1
User-Agent: lVali
Host: onedrive.live.com
HTTP/1.1 302 Found
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: -1
Location: https://xxggqg.bn.files.1drv.com/y4mo-OJo9wpmax2OvB29vRxbCR_XHI1S9TO9DxkvzSDmOtvVCfdjFA5iJe_tsCB5hke4QTjJLqf2DXsOokiGFDWYTUPxE1cccg9s5CHpH4mgpeJk7DEz2hTWHtbtslcxa5Szl4466KRJBjr-OM68hUz0Mri9n2FXq4bERFOmqvGuyLFMUhC1mk5TTcJ_Nro0Wjpsy2YHstADf0g6Zn42Lxg-w/Oywnaspxncyxayhkogvpxcsolzrnnly?download&psid=1
Set-Cookie: E=P:+QVfOWg92og=:lr0wgxLX6GyyFuFb/g7l69tEgbEu4lV9RozcEeyu9Hc=:F; domain=.live.com; path=/
Set-Cookie: xid=bec88a2c-90bc-4230-8904-ac6ae3d577d4&&RDE42AAC93EF52&184; domain=.live.com; path=/
Set-Cookie: xidseq=1; domain=.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Tue, 24-May-2022 07:51:47 GMT; path=/
Set-Cookie: wla42=; domain=live.com; expires=Tue, 31-May-2022 09:31:47 GMT; path=/
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000
X-MSNServer: RDE42AAC93EF52
X-ODWebServer: centralus0-odwebpl
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: 33F34AF2E5AE4A1EB7F8D9D5EBBE4E03 Ref B: SLAEDGE1212 Ref C: 2022-05-24T09:31:47Z
Date: Tue, 24 May 2022 09:31:47 GMT
Content-Length: 0
GET
200
https://xxggqg.bn.files.1drv.com/y4mo-OJo9wpmax2OvB29vRxbCR_XHI1S9TO9DxkvzSDmOtvVCfdjFA5iJe_tsCB5hke4QTjJLqf2DXsOokiGFDWYTUPxE1cccg9s5CHpH4mgpeJk7DEz2hTWHtbtslcxa5Szl4466KRJBjr-OM68hUz0Mri9n2FXq4bERFOmqvGuyLFMUhC1mk5TTcJ_Nro0Wjpsy2YHstADf0g6Zn42Lxg-w/Oywnaspxncyxayhkogvpxcsolzrnnly?download&psid=1
REQUEST
RESPONSE
BODY
GET /y4mo-OJo9wpmax2OvB29vRxbCR_XHI1S9TO9DxkvzSDmOtvVCfdjFA5iJe_tsCB5hke4QTjJLqf2DXsOokiGFDWYTUPxE1cccg9s5CHpH4mgpeJk7DEz2hTWHtbtslcxa5Szl4466KRJBjr-OM68hUz0Mri9n2FXq4bERFOmqvGuyLFMUhC1mk5TTcJ_Nro0Wjpsy2YHstADf0g6Zn42Lxg-w/Oywnaspxncyxayhkogvpxcsolzrnnly?download&psid=1 HTTP/1.1
User-Agent: lVali
Host: xxggqg.bn.files.1drv.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 651264
Content-Type: application/octet-stream
Content-Location: https://xxggqg.bn.files.1drv.com/y4m1Kqnuy1NjgJoLABFlG6EKscDB0xTAC0u3iRR0B9OoS9GvxB2nj1663nLn4rV8qwwx0hyA8gwufYDMgUMwShRQIh3pxATGHL8AD5EEUipp6LmAiV2z8NVAgfrk0m_add9D78udvQc4kCpJoQkbG1Ih2UHlq420T38hU6P8RlOafOJmjZMmqIdhyBQfyLWGl1j
Expires: Mon, 22 Aug 2022 09:31:48 GMT
Last-Modified: Tue, 24 May 2022 05:51:01 GMT
Accept-Ranges: bytes
ETag: F547EE3E8FFF6BF5!453.2
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
X-MSNSERVER: BN5PPF467DA0FC0
Strict-Transport-Security: max-age=31536000; includeSubDomains
MS-CV: yc+Zezv9Y0u9Bv/tOOShHg.0
X-SqlDataOrigin: S
CTag: aYzpGNTQ3RUUzRThGRkY2QkY1ITQ1My4yNTc
X-PreAuthInfo: rv;poba;
Content-Disposition: attachment; filename="Oywnaspxncyxayhkogvpxcsolzrnnly"
X-Content-Type-Options: nosniff
X-StreamOrigin: X
X-AsmVersion: UNKNOWN; 19.914.505.2010
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: BBAF632ADB6B4193B805DAB53200B663 Ref B: SLAEDGE1118 Ref C: 2022-05-24T09:31:47Z
Date: Tue, 24 May 2022 09:31:47 GMT
GET
302
https://onedrive.live.com/download?cid=F547EE3E8FFF6BF5&resid=F547EE3E8FFF6BF5%21453&authkey=AOijTcPaFAa_sFY
REQUEST
RESPONSE
BODY
GET /download?cid=F547EE3E8FFF6BF5&resid=F547EE3E8FFF6BF5%21453&authkey=AOijTcPaFAa_sFY HTTP/1.1
User-Agent: 82
Host: onedrive.live.com
Cache-Control: no-cache
Cookie: E=P:+QVfOWg92og=:lr0wgxLX6GyyFuFb/g7l69tEgbEu4lV9RozcEeyu9Hc=:F; xid=bec88a2c-90bc-4230-8904-ac6ae3d577d4&&RDE42AAC93EF52&184; xidseq=1; wla42=
HTTP/1.1 302 Found
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: -1
Location: https://xxggqg.bn.files.1drv.com/y4mZ04JFnfIkWTrcbGjKJqnT1_whH5a4gewQUd9rU-zn-XASy9kj8861d5lBJpZeiYItjRRzNnljnkwb-cBR7SG3qIXnbzoRculh-hJehFsDMopV_mS3cHJ15pKloJfM014cqwcYcymtXfE3IbN-GlX5I6C_DkCFpK_5vHbP03E9NaOhkc8UXhmv9g4lALU24-ASME_KLf4QhHXs5iYy9VoUg/Oywnaspxncyxayhkogvpxcsolzrnnly?download&psid=1
Set-Cookie: E=P:HdjZOWg92og=:wmT37XRYgHSYCp4/K20PKQyVUonIvOtj5wVcEg1e/WM=:F; domain=.live.com; path=/
Set-Cookie: xidseq=2; domain=.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Tue, 24-May-2022 07:51:48 GMT; path=/
Set-Cookie: wla42=; domain=live.com; expires=Tue, 31-May-2022 09:31:48 GMT; path=/
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000
X-MSNServer: RDE42AAC93DDA5
X-ODWebServer: centralus0-odwebpl
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: 727BCC3FAED349178064DC674D8D0719 Ref B: SLAEDGE1212 Ref C: 2022-05-24T09:31:48Z
Date: Tue, 24 May 2022 09:31:48 GMT
Content-Length: 0
GET
200
https://xxggqg.bn.files.1drv.com/y4mZ04JFnfIkWTrcbGjKJqnT1_whH5a4gewQUd9rU-zn-XASy9kj8861d5lBJpZeiYItjRRzNnljnkwb-cBR7SG3qIXnbzoRculh-hJehFsDMopV_mS3cHJ15pKloJfM014cqwcYcymtXfE3IbN-GlX5I6C_DkCFpK_5vHbP03E9NaOhkc8UXhmv9g4lALU24-ASME_KLf4QhHXs5iYy9VoUg/Oywnaspxncyxayhkogvpxcsolzrnnly?download&psid=1
REQUEST
RESPONSE
BODY
GET /y4mZ04JFnfIkWTrcbGjKJqnT1_whH5a4gewQUd9rU-zn-XASy9kj8861d5lBJpZeiYItjRRzNnljnkwb-cBR7SG3qIXnbzoRculh-hJehFsDMopV_mS3cHJ15pKloJfM014cqwcYcymtXfE3IbN-GlX5I6C_DkCFpK_5vHbP03E9NaOhkc8UXhmv9g4lALU24-ASME_KLf4QhHXs5iYy9VoUg/Oywnaspxncyxayhkogvpxcsolzrnnly?download&psid=1 HTTP/1.1
User-Agent: 82
Host: xxggqg.bn.files.1drv.com
Cache-Control: no-cache
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 651264
Content-Type: application/octet-stream
Content-Location: https://xxggqg.bn.files.1drv.com/y4m1Kqnuy1NjgJoLABFlG6EKscDB0xTAC0u3iRR0B9OoS9GvxB2nj1663nLn4rV8qwwx0hyA8gwufYDMgUMwShRQIh3pxATGHL8AD5EEUipp6LmAiV2z8NVAgfrk0m_add9D78udvQc4kCpJoQkbG1Ih2UHlq420T38hU6P8RlOafOJmjZMmqIdhyBQfyLWGl1j
Expires: Mon, 22 Aug 2022 09:31:48 GMT
Last-Modified: Tue, 24 May 2022 05:51:01 GMT
Accept-Ranges: bytes
ETag: F547EE3E8FFF6BF5!453.2
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
X-MSNSERVER: BN4SCH102400206
Strict-Transport-Security: max-age=31536000; includeSubDomains
MS-CV: WEZBrytYPUi15Zg+CnVfsg.0
X-SqlDataOrigin: S
CTag: aYzpGNTQ3RUUzRThGRkY2QkY1ITQ1My4yNTc
X-PreAuthInfo: rv;poba;
Content-Disposition: attachment; filename="Oywnaspxncyxayhkogvpxcsolzrnnly"
X-Content-Type-Options: nosniff
X-StreamOrigin: X
X-AsmVersion: UNKNOWN; 19.914.505.2010
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: 2CC721F116424350B5901B12CCD00EB6 Ref B: SLAEDGE1418 Ref C: 2022-05-24T09:31:48Z
Date: Tue, 24 May 2022 09:31:48 GMT
GET
200
http://geoplugin.net/json.gp
REQUEST
RESPONSE
BODY
GET /json.gp HTTP/1.1
Host: geoplugin.net
Cache-Control: no-cache
HTTP/1.1 200 OK
date: Tue, 24 May 2022 09:33:02 GMT
server: Apache
expires: Tue, 24 May 2022 09:33:02 GMT
content-length: 948
content-type: application/json; charset=utf-8
cache-control: public, max-age=300
access-control-allow-origin: *
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49162 13.107.42.13:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | CN=onedrive.com | 77:7f:f2:95:29:a7:e3:cc:0f:bf:2f:ba:2e:6f:2a:38:62:8b:48:4d |
TLSv1 192.168.56.103:49163 13.107.42.12:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=storage.live.com | c2:e0:68:f2:b8:12:58:f2:43:68:ba:74:5a:78:76:f9:19:2d:a1:60 |
TLS 1.3 192.168.56.103:49177 185.157.162.137:59085 |
None | None | None |
TLSv1 192.168.56.103:49164 13.107.42.12:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=storage.live.com | c2:e0:68:f2:b8:12:58:f2:43:68:ba:74:5a:78:76:f9:19:2d:a1:60 |
Snort Alerts
No Snort Alerts