Network Analysis
IP Address | Status | Action |
---|---|---|
121.254.136.27 | Active | Moloch |
142.250.204.142 | Active | Moloch |
142.250.204.36 | Active | Moloch |
142.251.220.67 | Active | Moloch |
142.251.222.195 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.25.10 | Active | Moloch |
216.58.200.237 | Active | Moloch |
34.104.35.123 | Active | Moloch |
34.120.48.173 | Active | Moloch |
- TCP Requests
-
-
192.168.56.103:49168 121.254.136.27:80apps.identrust.com
-
192.168.56.103:49176 142.250.204.142:443apis.google.com
-
192.168.56.103:49165 142.250.204.36:443www.google.com
-
192.168.56.103:49166 142.250.204.36:443www.google.com
-
192.168.56.103:49167 142.250.204.36:443www.google.com
-
192.168.56.103:49170 142.251.220.67:443www.gstatic.com
-
192.168.56.103:49172 142.251.220.67:443www.gstatic.com
-
192.168.56.103:49173 142.251.220.67:443www.gstatic.com
-
192.168.56.103:49174 142.251.220.67:80www.gstatic.com
-
192.168.56.103:49175 142.251.222.195:443fonts.gstatic.com
-
192.168.56.103:49169 172.217.24.110:80
-
192.168.56.103:49178 172.217.24.227:443
-
192.168.56.103:49171 172.217.25.10:443fonts.googleapis.com
-
192.168.56.103:49162 216.58.200.237:443accounts.google.com
-
192.168.56.103:49163 216.58.200.237:443accounts.google.com
-
192.168.56.103:49179 34.104.35.123:80edgedl.me.gvt1.com
-
192.168.56.103:49164 34.120.48.173:443cdn.stubdownloader.services.mozilla.com
-
- UDP Requests
-
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.103:50674 164.124.101.2:53
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53658 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:57986 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64178 164.124.101.2:53
-
192.168.56.103:64530 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:5353 224.0.0.251:5353
-
192.168.56.103:49153 239.255.255.250:1900
-
192.168.56.103:53661 239.255.255.250:1900
-
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Wed, 08 Feb 2023 16:52:56 GMT
ETag: "37d-5f433188daa00"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Tue, 06 Jun 2023 23:37:24 GMT
Date: Tue, 06 Jun 2023 22:37:24 GMT
Connection: keep-alive
GET
200
http://clients2.google.com/time/1/current?cup2key=4:3591542034&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
REQUEST
RESPONSE
BODY
GET /time/1/current?cup2key=4:3591542034&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 HTTP/1.1
Host: clients2.google.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
Accept-Encoding: gzip, deflate
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
X-Content-Type-Options: nosniff
x-cup-server-proof: 3045022100c48c055c0e598dbb9be77236df648b95fb3ac3b1e21e549005f25697bb6c6661022051d1aaccc77e6622a72b211366d611145f332990f9a585bae21ad9347560afb3:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
ETag: W/"3045022100c48c055c0e598dbb9be77236df648b95fb3ac3b1e21e549005f25697bb6c6661022051d1aaccc77e6622a72b211366d611145f332990f9a585bae21ad9347560afb3:e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Date: Tue, 06 Jun 2023 22:37:24 GMT
Content-Disposition: attachment; filename="json.txt"; filename*=UTF-8''json.txt
Cross-Origin-Opener-Policy: same-origin
Content-Encoding: gzip
Transfer-Encoding: chunked
Server: ESF
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
GET
204
http://www.gstatic.com/generate_204
REQUEST
RESPONSE
BODY
GET /generate_204 HTTP/1.1
Host: www.gstatic.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,ko;q=0.8
HTTP/1.1 204 No Content
Content-Length: 0
Cross-Origin-Resource-Policy: cross-origin
Date: Tue, 06 Jun 2023 22:37:24 GMT
HEAD
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
HEAD /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-length: 36373
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: feff028d-c491-4bc6-a3e4-e53a88a10f3a
date: Tue, 06 Jun 2023 11:24:26 GMT
age: 40437
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=0-5533
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-length: 5534
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: b9efe666-5963-4e60-a0f5-338353e29b1b
date: Tue, 06 Jun 2023 11:24:26 GMT
age: 40460
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 0-5533/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=5534-13442
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-length: 7909
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: c0edab37-ceae-46eb-9533-845a7bc56c0e
date: Tue, 06 Jun 2023 11:24:26 GMT
age: 40465
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 5534-13442/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=13443-22669
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-length: 9227
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: dbf5be5d-0d17-4941-89f4-c15ff71733da
date: Tue, 06 Jun 2023 11:24:26 GMT
age: 40469
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 13443-22669/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=22670-31903
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-length: 9234
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: 9253e936-ce77-46b9-9861-d8ef4e77c117
date: Tue, 06 Jun 2023 11:24:26 GMT
age: 40470
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 22670-31903/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=31904-36372
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-length: 4469
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: 9984d38c-7789-47de-9706-88e964e2ed2b
date: Tue, 06 Jun 2023 11:24:26 GMT
age: 40471
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 31904-36372/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.103:49162 216.58.200.237:443 |
None | None | None |
TLS 1.3 192.168.56.103:49164 34.120.48.173:443 |
None | None | None |
TLS 1.3 192.168.56.103:49163 216.58.200.237:443 |
None | None | None |
TLS 1.3 192.168.56.103:49175 142.251.222.195:443 |
None | None | None |
TLS 1.3 192.168.56.103:49173 142.251.220.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49166 142.250.204.36:443 |
None | None | None |
TLS 1.3 192.168.56.103:49165 142.250.204.36:443 |
None | None | None |
TLS 1.3 192.168.56.103:49167 142.250.204.36:443 |
None | None | None |
TLS 1.3 192.168.56.103:49178 172.217.24.227:443 |
None | None | None |
TLS 1.3 192.168.56.103:49171 172.217.25.10:443 |
None | None | None |
TLS 1.3 192.168.56.103:49170 142.251.220.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49172 142.251.220.67:443 |
None | None | None |
TLS 1.3 192.168.56.103:49176 142.250.204.142:443 |
None | None | None |
Snort Alerts
No Snort Alerts