Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | March 16, 2023, 1:16 p.m. | March 16, 2023, 1:19 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
ipinfo.io | 34.117.59.81 | |
api.db-ip.com | 104.26.4.15 | |
www.maxmind.com | 104.17.215.67 | |
db-ip.com | 172.67.75.166 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49182 172.67.75.166:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 8d:c8:6e:29:ea:e9:15:f8:85:80:ae:fd:51:f0:44:ca:8c:7d:0c:dc |
TLSv1 192.168.56.102:49183 104.26.5.15:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 8d:c8:6e:29:ea:e9:15:f8:85:80:ae:fd:51:f0:44:ca:8c:7d:0c:dc |
suspicious_features | Connection to IP address | suspicious_request | GET http://149.154.158.34/api/tracemap.php |
request | GET http://149.154.158.34/api/tracemap.php |
request | GET http://www.maxmind.com/geoip/v2.1/city/me |
request | GET https://db-ip.com/ |
request | POST https://api.db-ip.com/v2/p31e4d59ee6ad1a0b5cc80695a873e43a8fbca06/self |
request | POST https://api.db-ip.com/v2/p31e4d59ee6ad1a0b5cc80695a873e43a8fbca06/self |
domain | ipinfo.io |
host | 149.154.158.34 |