Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
geo.netsupportsoftware.com | 62.172.138.67 | |
kororo.com | 188.127.225.231 |
GET
200
http://geo.netsupportsoftware.com/location/loca.asp
REQUEST
RESPONSE
BODY
GET /location/loca.asp HTTP/1.1
Host: geo.netsupportsoftware.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/10.0
Access-Control-Allow-Origin: *
Set-Cookie: ASPSESSIONIDCQDRSATD=BGNEOKMCKBMCAKJNICNFBLAE; path=/
X-Content-Type-Options: nosniff
Referrer-Policy: strict-origin-when-cross-origin
strict-transport-security: max-age=31536000; includeSubDomains
X-Frame-Options: SAMEORIGIN
Date: Fri, 30 Jun 2023 04:30:32 GMT
Content-Length: 15
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49210 -> 62.172.138.67:80 | 2034559 | ET POLICY NetSupport GeoLocation Lookup Request | Potential Corporate Privacy Violation |
TCP 192.168.56.101:49209 -> 94.158.244.118:1203 | 2035892 | ET INFO NetSupport Remote Admin Checkin | Misc activity |
TCP 94.158.244.118:1203 -> 192.168.56.101:49209 | 2035895 | ET INFO NetSupport Remote Admin Response | Misc activity |
TCP 192.168.56.101:49209 -> 94.158.244.118:1203 | 2035892 | ET INFO NetSupport Remote Admin Checkin | Misc activity |
TCP 94.158.244.118:1203 -> 192.168.56.101:49209 | 2035895 | ET INFO NetSupport Remote Admin Response | Misc activity |
TCP 192.168.56.101:49209 -> 94.158.244.118:1203 | 2035892 | ET INFO NetSupport Remote Admin Checkin | Misc activity |
TCP 192.168.56.101:49209 -> 94.158.244.118:1203 | 2035892 | ET INFO NetSupport Remote Admin Checkin | Misc activity |
TCP 192.168.56.101:49209 -> 94.158.244.118:1203 | 2035892 | ET INFO NetSupport Remote Admin Checkin | Misc activity |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49168 188.127.225.231:443 |
None | None | None |
TLS 1.3 192.168.56.101:49177 188.127.225.231:443 |
None | None | None |
TLS 1.3 192.168.56.101:49184 188.127.225.231:443 |
None | None | None |
Snort Alerts
No Snort Alerts