Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
firebasestorage.googleapis.com | 172.217.25.170 |
- UDP Requests
-
-
192.168.56.102:62846 164.124.101.2:53
-
192.168.56.102:63709 164.124.101.2:53
-
192.168.56.102:64513 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:63712 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
GET
200
https://firebasestorage.googleapis.com/v0/b/fir-8c14f.appspot.com/o/jod.jpg?alt=media&token=3735f1cc-35d0-4cea-8a29-811cec71fe1b
REQUEST
RESPONSE
BODY
GET /v0/b/fir-8c14f.appspot.com/o/jod.jpg?alt=media&token=3735f1cc-35d0-4cea-8a29-811cec71fe1b HTTP/1.1
Host: firebasestorage.googleapis.com
Connection: Keep-Alive
HTTP/1.1 200 OK
X-GUploader-UploadID: ADPycdvnG2bO0N3Zirfv9EGYhpSsO0FDGBjU4xsnSKO5xPreMGS6seLQaMJpLhoGhmCrigVQkOVoHWy_FmQ87qBMt-RCxQ
Expires: Sun, 18 Jun 2023 03:13:59 GMT
Date: Sun, 18 Jun 2023 03:13:59 GMT
Cache-Control: private, max-age=0
Last-Modified: Fri, 16 Jun 2023 00:00:57 GMT
ETag: "c9da7cce58dd9eda2dd5720f6b702958"
x-goog-generation: 1686873657571698
x-goog-metageneration: 1
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 4217259
x-goog-meta-firebaseStorageDownloadTokens: 3735f1cc-35d0-4cea-8a29-811cec71fe1b
Content-Type: image/jpeg
Content-Disposition: inline; filename*=utf-8''jod.jpg
x-goog-hash: crc32c=Pr8B+w==
x-goog-hash: md5=ydp8zljdntot1XIPa3ApWA==
x-goog-storage-class: STANDARD
Accept-Ranges: bytes
Content-Length: 4217259
Server: UploadServer
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49165 -> 172.217.31.10:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49165 172.217.31.10:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=upload.video.google.com | a4:d0:2e:0c:fb:98:7c:38:24:ed:cc:2b:fe:74:aa:48:c4:9a:27:90 |
Snort Alerts
No Snort Alerts