Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
firebasestorage.googleapis.com | 142.250.76.138 |
GET
200
https://firebasestorage.googleapis.com/v0/b/droid-21a46.appspot.com/o/43444VBS%20NO%20STARTUP.vbs?alt=media&token=90e47504-2ac3-4d85-afe1-40f9e0a0ca50
REQUEST
RESPONSE
BODY
GET /v0/b/droid-21a46.appspot.com/o/43444VBS%20NO%20STARTUP.vbs?alt=media&token=90e47504-2ac3-4d85-afe1-40f9e0a0ca50 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Host: firebasestorage.googleapis.com
Connection: Keep-Alive
HTTP/1.1 200 OK
X-GUploader-UploadID: ADPycdsuuR_kuHUkYXnpoEPjKKG8v2jjVFeXWFRlE_vi8iU7E2MzdWd3TXkD3JDxAqWdob41hv5Ft0aaCTx3MRKEUsL6XuLbfWHU
Expires: Mon, 20 Mar 2023 02:19:39 GMT
Date: Mon, 20 Mar 2023 02:19:39 GMT
Cache-Control: private, max-age=0
Last-Modified: Fri, 17 Mar 2023 20:25:10 GMT
ETag: "7b470a829fac968e56744f805ab85efc"
x-goog-generation: 1679084710623652
x-goog-metageneration: 1
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 1042886
x-goog-meta-firebaseStorageDownloadTokens: 90e47504-2ac3-4d85-afe1-40f9e0a0ca50
Content-Type: application/octet-stream
Content-Disposition: inline; filename*=utf-8''43444VBS%20NO%20STARTUP.vbs
x-goog-hash: crc32c=JLNJYw==
x-goog-hash: md5=e0cKgp+slo5WdE+AWrhe/A==
x-goog-storage-class: STANDARD
Accept-Ranges: bytes
Content-Length: 1042886
Server: UploadServer
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49162 -> 142.250.66.74:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49162 142.250.66.74:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=upload.video.google.com | 22:ad:71:ad:a1:33:7e:c2:2b:d0:a9:14:30:db:5c:e4:e7:01:5d:15 |
Snort Alerts
No Snort Alerts