Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
0.tcp.ngrok.io | 3.134.39.220 |
- TCP Requests
-
-
192.168.56.103:49162 139.144.16.247:80
-
192.168.56.103:49165 139.144.16.247:80
-
192.168.56.103:49167 139.144.16.247:80
-
192.168.56.103:49169 139.144.16.247:80
-
192.168.56.103:49173 139.144.16.247:80
-
192.168.56.103:49175 139.144.16.247:80
-
192.168.56.103:49177 139.144.16.247:80
-
192.168.56.103:49181 139.144.16.247:80
-
192.168.56.103:49183 139.144.16.247:80
-
192.168.56.103:49188 139.144.16.247:80
-
192.168.56.103:49190 139.144.16.247:80
-
192.168.56.103:49194 139.144.16.247:80
-
192.168.56.103:49196 139.144.16.247:80
-
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:05:58 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:03 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:09 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:16 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:20 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:24 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:30 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:36 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:41 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:45 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:48 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:06:55 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:02 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:04 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:07 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:13 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:19 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:24 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:29 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:36 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
GET
200
http://139.144.16.247/thisisahiddendirectory/Connection.php
REQUEST
RESPONSE
BODY
GET /thisisahiddendirectory/Connection.php HTTP/1.1
User-Agent: <1225567896233>
Host: 139.144.16.247
HTTP/1.1 200 OK
Date: Fri, 07 Apr 2023 00:07:40 GMT
Server: Apache/2.4.54 (Ubuntu)
Content-Length: 20
Content-Type: text/html; charset=UTF-8
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.103:50800 -> 164.124.101.2:53 | 2022642 | ET INFO DNS Query to a *.ngrok domain (ngrok.io) | Potential Corporate Privacy Violation |
UDP 192.168.56.103:52760 -> 164.124.101.2:53 | 2022642 | ET INFO DNS Query to a *.ngrok domain (ngrok.io) | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts