Network Analysis
IP Address | Status | Action |
---|---|---|
121.254.136.27 | Active | Moloch |
142.250.199.78 | Active | Moloch |
142.250.204.67 | Active | Moloch |
142.250.207.67 | Active | Moloch |
142.250.207.78 | Active | Moloch |
142.250.66.36 | Active | Moloch |
142.250.66.67 | Active | Moloch |
142.251.220.1 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.24.227 | Active | Moloch |
172.217.24.74 | Active | Moloch |
172.217.31.13 | Active | Moloch |
34.120.48.173 | Active | Moloch |
- TCP Requests
-
-
192.168.56.103:49169 121.254.136.27:80apps.identrust.com
-
192.168.56.103:49177 142.250.199.78:443apis.google.com
-
192.168.56.103:49179 142.250.204.67:443
-
192.168.56.103:49172 142.250.207.67:443www.gstatic.com
-
192.168.56.103:49173 142.250.207.67:443www.gstatic.com
-
192.168.56.103:49174 142.250.207.67:443www.gstatic.com
-
192.168.56.103:49175 142.250.207.67:80www.gstatic.com
-
192.168.56.103:49170 142.250.207.78:80
-
192.168.56.103:49162 142.250.66.36:443www.google.com
-
192.168.56.103:49163 142.250.66.36:443www.google.com
-
192.168.56.103:49176 142.250.66.67:443fonts.gstatic.com
-
192.168.56.103:49180 142.251.220.1:443clients2.googleusercontent.com
-
192.168.56.103:49164 172.217.24.227:443clientservices.googleapis.com
-
192.168.56.103:49166 172.217.24.227:443clientservices.googleapis.com
-
192.168.56.103:49171 172.217.24.74:443fonts.googleapis.com
-
192.168.56.103:49165 172.217.31.13:443accounts.google.com
-
192.168.56.103:49181 172.217.31.14:443
-
192.168.56.103:49167 34.120.48.173:443cdn.stubdownloader.services.mozilla.com
-
- UDP Requests
-
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.103:50674 164.124.101.2:53
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53658 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:57986 164.124.101.2:53
-
192.168.56.103:60225 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64178 164.124.101.2:53
-
192.168.56.103:64530 164.124.101.2:53
-
192.168.56.103:64631 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:5353 224.0.0.251:5353
-
192.168.56.103:49153 239.255.255.250:1900
-
192.168.56.103:50678 239.255.255.250:1900
-
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Wed, 08 Feb 2023 16:52:56 GMT
ETag: "37d-5f433188daa00"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Mon, 27 Mar 2023 02:46:40 GMT
Date: Mon, 27 Mar 2023 01:46:40 GMT
Connection: keep-alive
GET
200
http://clients2.google.com/time/1/current?cup2key=4:3305170296&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
REQUEST
RESPONSE
BODY
GET /time/1/current?cup2key=4:3305170296&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 HTTP/1.1
Host: clients2.google.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
Accept-Encoding: gzip, deflate
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
x-cup-server-proof: 3045022100b4a46e56a60331563c59132f9765bda5899688adeda5ad61682bf7f3471f59d0022019124b6a3144eb29e5cfa2e4d8006a6ea1c9d438cdf172ef8f0ebced83fe9f56:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
ETag: W/"3045022100b4a46e56a60331563c59132f9765bda5899688adeda5ad61682bf7f3471f59d0022019124b6a3144eb29e5cfa2e4d8006a6ea1c9d438cdf172ef8f0ebced83fe9f56:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Date: Mon, 27 Mar 2023 01:46:40 GMT
Content-Disposition: attachment; filename="json.txt"; filename*=UTF-8''json.txt
Cross-Origin-Opener-Policy: same-origin
Content-Encoding: gzip
Transfer-Encoding: chunked
Server: ESF
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
GET
204
http://www.gstatic.com/generate_204
REQUEST
RESPONSE
BODY
GET /generate_204 HTTP/1.1
Host: www.gstatic.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,ko;q=0.8
HTTP/1.1 204 No Content
Content-Length: 0
Cross-Origin-Resource-Policy: cross-origin
Date: Mon, 27 Mar 2023 01:46:40 GMT
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.103:49171 172.217.24.74:443 |
None | None | None |
TLS 1.3 192.168.56.103:49165 172.217.31.13:443 |
None | None | None |
TLS 1.3 192.168.56.103:49164 172.217.24.227:443 |
None | None | None |
TLS 1.3 192.168.56.103:49162 142.250.66.36:443 |
None | None | None |
TLS 1.3 192.168.56.103:49167 34.120.48.173:443 |
None | None | None |
TLS 1.3 192.168.56.103:49166 172.217.24.227:443 |
None | None | None |
TLS 1.3 192.168.56.103:49177 142.250.199.78:443 |
None | None | None |
TLS 1.3 192.168.56.103:49172 142.250.207.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49176 142.250.66.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49179 142.250.204.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49180 142.251.220.1:443 |
None | None | None |
TLS 1.3 192.168.56.103:49163 142.250.66.36:443 |
None | None | None |
TLS 1.3 192.168.56.103:49173 142.250.207.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49181 172.217.31.14:443 |
None | None | None |
UNDETERMINED 192.168.56.103:49174 142.250.207.67:443 |
None | None | None |
Snort Alerts
No Snort Alerts