Network Analysis
IP Address | Status | Action |
---|---|---|
142.250.207.67 | Active | Moloch |
142.250.66.78 | Active | Moloch |
142.251.220.99 | Active | Moloch |
162.0.217.30 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.24.100 | Active | Moloch |
172.217.24.74 | Active | Moloch |
172.217.25.3 | Active | Moloch |
172.217.27.13 | Active | Moloch |
34.104.35.123 | Active | Moloch |
- TCP Requests
-
-
175.208.134.153:51076 192.168.56.102:5911
-
192.168.56.102:49200 142.250.207.67:443fonts.gstatic.com
-
192.168.56.102:49201 142.250.66.78:443apis.google.com
-
192.168.56.102:49191 142.251.220.99:443clientservices.googleapis.com
-
192.168.56.102:49214 142.251.220.99:443clientservices.googleapis.com
-
192.168.56.102:49166 162.0.217.30:443zacuta.com
-
192.168.56.102:49167 162.0.217.30:443zacuta.com
-
192.168.56.102:49169 162.0.217.30:443zacuta.com
-
192.168.56.102:49170 162.0.217.30:443zacuta.com
-
192.168.56.102:49171 162.0.217.30:443zacuta.com
-
192.168.56.102:49172 162.0.217.30:443zacuta.com
-
192.168.56.102:49173 162.0.217.30:443zacuta.com
-
192.168.56.102:49204 162.0.217.30:443zacuta.com
-
192.168.56.102:49205 162.0.217.30:443zacuta.com
-
192.168.56.102:49193 172.217.24.100:443www.google.com
-
192.168.56.102:49194 172.217.24.100:443www.google.com
-
192.168.56.102:49196 172.217.24.74:443fonts.googleapis.com
-
192.168.56.102:49197 172.217.25.3:443www.gstatic.com
-
192.168.56.102:49198 172.217.25.3:443www.gstatic.com
-
192.168.56.102:49199 172.217.25.3:443www.gstatic.com
-
192.168.56.102:49241 172.217.25.3:443www.gstatic.com
-
192.168.56.102:49192 172.217.27.13:443accounts.google.com
-
192.168.56.102:49242 216.58.203.67:443
-
192.168.56.102:49243 34.104.35.123:80edgedl.me.gvt1.com
-
- UDP Requests
-
-
192.168.56.102:50014 164.124.101.2:53
-
192.168.56.102:50447 164.124.101.2:53
-
192.168.56.102:51405 164.124.101.2:53
-
192.168.56.102:51598 164.124.101.2:53
-
192.168.56.102:51903 164.124.101.2:53
-
192.168.56.102:53778 164.124.101.2:53
-
192.168.56.102:56630 164.124.101.2:53
-
192.168.56.102:57988 164.124.101.2:53
-
192.168.56.102:58521 164.124.101.2:53
-
192.168.56.102:60523 164.124.101.2:53
-
192.168.56.102:62846 164.124.101.2:53
-
192.168.56.102:63709 164.124.101.2:53
-
192.168.56.102:64513 164.124.101.2:53
-
192.168.56.102:65226 164.124.101.2:53
-
192.168.56.102:65368 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:5353 224.0.0.251:5353
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:60528 239.255.255.250:1900
-
192.168.56.102:60530 239.255.255.250:3702
-
192.168.56.102:65227 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
HEAD
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
BODY
HEAD /edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 40980
x-request-id: cd3763d8-4645-44ce-a8e0-d45f51e9ea29
date: Mon, 10 Apr 2023 20:55:00 GMT
age: 35195
last-modified: Thu, 09 Mar 2023 23:09:56 GMT
etag: "13c2406"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Mar 2023 23:09:56 GMT
Range: bytes=0-6786
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 6787
x-request-id: a8be77f8-ab0d-4a6d-a571-8d14ba924474
date: Mon, 10 Apr 2023 20:55:00 GMT
age: 35208
last-modified: Thu, 09 Mar 2023 23:09:56 GMT
etag: "13c2406"
content-type: application/octet-stream
content-range: bytes 0-6786/40980
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Mar 2023 23:09:56 GMT
Range: bytes=6787-16934
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 10148
x-request-id: 0adeb379-78a8-47c1-abf8-2ddd19a0a32d
date: Mon, 10 Apr 2023 20:55:00 GMT
age: 35212
last-modified: Thu, 09 Mar 2023 23:09:56 GMT
etag: "13c2406"
content-type: application/octet-stream
content-range: bytes 6787-16934/40980
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Mar 2023 23:09:56 GMT
Range: bytes=16935-27092
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 10158
x-request-id: 08174b27-a163-4014-b807-cb0b8b08419f
date: Mon, 10 Apr 2023 20:55:00 GMT
age: 35214
last-modified: Thu, 09 Mar 2023 23:09:56 GMT
etag: "13c2406"
content-type: application/octet-stream
content-range: bytes 16935-27092/40980
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Mar 2023 23:09:56 GMT
Range: bytes=27093-37249
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 10157
x-request-id: dabce3e1-c314-4b2c-9782-196dfe3cd917
date: Mon, 10 Apr 2023 20:55:00 GMT
age: 35215
last-modified: Thu, 09 Mar 2023 23:09:56 GMT
etag: "13c2406"
content-type: application/octet-stream
content-range: bytes 27093-37249/40980
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Mar 2023 23:09:56 GMT
Range: bytes=37250-40979
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 3730
x-request-id: 964fa445-f755-4c0b-8efd-06e51c9e3100
date: Mon, 10 Apr 2023 20:55:00 GMT
age: 35216
last-modified: Thu, 09 Mar 2023 23:09:56 GMT
etag: "13c2406"
content-type: application/octet-stream
content-range: bytes 37250-40979/40980
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
HEAD
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/cxpsjblnoxgjoqggdsbvujtof4_58/khaoiebndkojlmppeemjhbpbandiljpe_58_win_advr4ucepztwtigvw3fduftsvbeq.crx3
REQUEST
RESPONSE
BODY
HEAD /edgedl/release2/chrome_component/cxpsjblnoxgjoqggdsbvujtof4_58/khaoiebndkojlmppeemjhbpbandiljpe_58_win_advr4ucepztwtigvw3fduftsvbeq.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 5586
x-request-id: bc5260ff-e1cf-41a8-8ed4-3d4b1780f16a
date: Tue, 11 Apr 2023 03:28:09 GMT
age: 11630
last-modified: Tue, 14 Feb 2023 03:17:24 GMT
etag: "1313dba"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/cxpsjblnoxgjoqggdsbvujtof4_58/khaoiebndkojlmppeemjhbpbandiljpe_58_win_advr4ucepztwtigvw3fduftsvbeq.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/cxpsjblnoxgjoqggdsbvujtof4_58/khaoiebndkojlmppeemjhbpbandiljpe_58_win_advr4ucepztwtigvw3fduftsvbeq.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Tue, 14 Feb 2023 03:17:24 GMT
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 5586
x-request-id: eb38bfc5-a910-4a21-8194-34424f30ba44
date: Tue, 11 Apr 2023 03:28:09 GMT
age: 11630
last-modified: Tue, 14 Feb 2023 03:17:24 GMT
etag: "1313dba"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
HEAD
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/g6v7tvx6ixuzstk5etcqebphhq_7954/hfnkpimlhhgieaddgfemjhofmfblmnib_7954_all_adj2i674lrtcwrqqfhv37vujcaya.crx3
REQUEST
RESPONSE
BODY
HEAD /edgedl/release2/chrome_component/g6v7tvx6ixuzstk5etcqebphhq_7954/hfnkpimlhhgieaddgfemjhofmfblmnib_7954_all_adj2i674lrtcwrqqfhv37vujcaya.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 25405
x-request-id: e3c8b4ab-ff6c-4b2d-87af-b6bdbe94ceba
date: Mon, 10 Apr 2023 20:32:40 GMT
age: 36568
last-modified: Wed, 05 Apr 2023 20:32:17 GMT
etag: "14c9697"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/g6v7tvx6ixuzstk5etcqebphhq_7954/hfnkpimlhhgieaddgfemjhofmfblmnib_7954_all_adj2i674lrtcwrqqfhv37vujcaya.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/g6v7tvx6ixuzstk5etcqebphhq_7954/hfnkpimlhhgieaddgfemjhofmfblmnib_7954_all_adj2i674lrtcwrqqfhv37vujcaya.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 05 Apr 2023 20:32:17 GMT
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
content-length: 25405
x-request-id: b8060cad-135c-418d-b0ff-257460ac8ea0
date: Mon, 10 Apr 2023 20:32:40 GMT
age: 36568
last-modified: Wed, 05 Apr 2023 20:32:17 GMT
etag: "14c9697"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49167 -> 162.0.217.30:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49171 -> 162.0.217.30:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49169 -> 162.0.217.30:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49170 -> 162.0.217.30:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 162.0.217.30:443 -> 192.168.56.102:49172 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.102:49173 -> 162.0.217.30:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49166 -> 162.0.217.30:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.102:49192 172.217.27.13:443 |
None | None | None |
TLS 1.3 192.168.56.102:49193 172.217.24.100:443 |
None | None | None |
TLS 1.3 192.168.56.102:49196 172.217.24.74:443 |
None | None | None |
TLS 1.3 192.168.56.102:49198 172.217.25.3:443 |
None | None | None |
TLS 1.3 192.168.56.102:49197 172.217.25.3:443 |
None | None | None |
TLS 1.3 192.168.56.102:49200 142.250.207.67:443 |
None | None | None |
TLS 1.3 192.168.56.102:49191 142.251.220.99:443 |
None | None | None |
TLS 1.3 192.168.56.102:49201 142.250.66.78:443 |
None | None | None |
TLS 1.3 192.168.56.102:49194 172.217.24.100:443 |
None | None | None |
TLS 1.3 192.168.56.102:49214 142.251.220.99:443 |
None | None | None |
TLS 1.3 192.168.56.102:49204 162.0.217.30:443 |
None | None | None |
TLS 1.3 192.168.56.102:49205 162.0.217.30:443 |
None | None | None |
TLS 1.3 192.168.56.102:49241 172.217.25.3:443 |
None | None | None |
TLS 1.3 192.168.56.102:49242 216.58.203.67:443 |
None | None | None |
UNDETERMINED 192.168.56.102:49199 172.217.25.3:443 |
None | None | None |
Snort Alerts
No Snort Alerts