Network Analysis
IP Address | Status | Action |
---|---|---|
121.254.136.27 | Active | Moloch |
142.250.204.110 | Active | Moloch |
142.250.204.129 | Active | Moloch |
142.250.204.35 | Active | Moloch |
142.250.204.46 | Active | Moloch |
142.250.204.74 | Active | Moloch |
142.250.207.99 | Active | Moloch |
142.250.66.132 | Active | Moloch |
142.250.66.77 | Active | Moloch |
146.75.50.191 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.217.24.99 | Active | Moloch |
216.58.200.227 | Active | Moloch |
34.104.35.123 | Active | Moloch |
45.83.122.52 | Active | Moloch |
52.6.155.20 | Active | Moloch |
66.220.9.58 | Active | Moloch |
67.199.248.10 | Active | Moloch |
- TCP Requests
-
-
175.208.134.153:59274 192.168.56.102:5911
-
192.168.56.102:49189 121.254.136.27:80apps.identrust.com
-
192.168.56.102:49200 142.250.204.110:443
-
192.168.56.102:49195 142.250.204.129:443clients2.googleusercontent.com
-
192.168.56.102:49178 142.250.204.35:443www.gstatic.com
-
192.168.56.102:49179 142.250.204.35:443www.gstatic.com
-
192.168.56.102:49180 142.250.204.35:443www.gstatic.com
-
192.168.56.102:49190 142.250.204.35:80www.gstatic.com
-
192.168.56.102:49222 142.250.204.35:443www.gstatic.com
-
192.168.56.102:49183 142.250.204.46:443apis.google.com
-
192.168.56.102:49181 142.250.204.74:443fonts.googleapis.com
-
192.168.56.102:49192 142.250.207.99:443
-
192.168.56.102:49221 142.250.207.99:443
-
192.168.56.102:49173 142.250.66.132:443www.google.com
-
192.168.56.102:49174 142.250.66.132:443www.google.com
-
192.168.56.102:49175 142.250.66.132:443www.google.com
-
192.168.56.102:49176 142.250.66.77:443accounts.google.com
-
192.168.56.102:49237 146.75.50.191:443www.smartsheet.com
-
192.168.56.102:49238 146.75.50.191:443www.smartsheet.com
-
192.168.56.102:49239 146.75.50.191:443www.smartsheet.com
-
192.168.56.102:49240 146.75.50.191:443www.smartsheet.com
-
192.168.56.102:49241 146.75.50.191:443www.smartsheet.com
-
192.168.56.102:49243 146.75.50.191:443www.smartsheet.com
-
192.168.56.102:49182 172.217.24.99:443fonts.gstatic.com
-
192.168.56.102:49177 216.58.200.227:443clientservices.googleapis.com
-
192.168.56.102:49229 23.45.56.171:443
-
192.168.56.102:49230 23.45.56.171:443
-
192.168.56.102:49223 34.104.35.123:80edgedl.me.gvt1.com
-
192.168.56.102:49186 45.83.122.52:443pdf-readonline.website
-
192.168.56.102:49187 45.83.122.52:443pdf-readonline.website
-
192.168.56.102:49194 45.83.122.52:443pdf-readonline.website
-
192.168.56.102:49196 45.83.122.52:443pdf-readonline.website
-
192.168.56.102:49198 45.83.122.52:443pdf-readonline.website
-
192.168.56.102:49199 45.83.122.52:443pdf-readonline.website
-
192.168.56.102:49225 52.6.155.20:443p13n.adobe.io
-
192.168.56.102:49226 52.6.155.20:443p13n.adobe.io
-
192.168.56.102:49203 66.220.9.58:443dhqid45r064utd5gygt2jy6.webdav.drivehq.com
-
192.168.56.102:49205 66.220.9.58:443dhqid45r064utd5gygt2jy6.webdav.drivehq.com
-
192.168.56.102:49207 66.220.9.58:443dhqid45r064utd5gygt2jy6.webdav.drivehq.com
-
192.168.56.102:49208 66.220.9.58:443dhqid45r064utd5gygt2jy6.webdav.drivehq.com
-
192.168.56.102:49212 66.220.9.58:443dhqid45r064utd5gygt2jy6.webdav.drivehq.com
-
192.168.56.102:49216 66.220.9.58:443dhqid45r064utd5gygt2jy6.webdav.drivehq.com
-
192.168.56.102:49235 67.199.248.10:80bit.ly
-
- UDP Requests
-
-
192.168.56.102:50014 164.124.101.2:53
-
192.168.56.102:50447 164.124.101.2:53
-
192.168.56.102:51405 164.124.101.2:53
-
192.168.56.102:51598 164.124.101.2:53
-
192.168.56.102:51903 164.124.101.2:53
-
192.168.56.102:52840 164.124.101.2:53
-
192.168.56.102:53778 164.124.101.2:53
-
192.168.56.102:53991 164.124.101.2:53
-
192.168.56.102:55774 164.124.101.2:53
-
192.168.56.102:56630 164.124.101.2:53
-
192.168.56.102:57203 164.124.101.2:53
-
192.168.56.102:57988 164.124.101.2:53
-
192.168.56.102:58521 164.124.101.2:53
-
192.168.56.102:59651 164.124.101.2:53
-
192.168.56.102:60523 164.124.101.2:53
-
192.168.56.102:62846 164.124.101.2:53
-
192.168.56.102:63709 164.124.101.2:53
-
192.168.56.102:64317 164.124.101.2:53
-
192.168.56.102:64513 164.124.101.2:53
-
192.168.56.102:65168 164.124.101.2:53
-
192.168.56.102:65226 164.124.101.2:53
-
192.168.56.102:65368 164.124.101.2:53
-
192.168.56.102:65488 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:5353 224.0.0.251:5353
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:57989 239.255.255.250:3702
-
192.168.56.102:58524 239.255.255.250:1900
-
192.168.56.102:63710 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
8.8.8.8:53 192.168.56.102:58521
-
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Wed, 08 Feb 2023 16:52:56 GMT
ETag: "37d-5f433188daa00"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Fri, 07 Jul 2023 02:07:34 GMT
Date: Fri, 07 Jul 2023 01:07:34 GMT
Connection: keep-alive
GET
204
http://www.gstatic.com/generate_204
REQUEST
RESPONSE
BODY
GET /generate_204 HTTP/1.1
Host: www.gstatic.com
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9,ko;q=0.8
HTTP/1.1 204 No Content
Content-Length: 0
Cross-Origin-Resource-Policy: cross-origin
Date: Fri, 07 Jul 2023 01:07:34 GMT
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Wed, 08 Feb 2023 16:52:56 GMT
ETag: "37d-5f433188daa00"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Fri, 07 Jul 2023 02:07:38 GMT
Date: Fri, 07 Jul 2023 01:07:38 GMT
Connection: keep-alive
HEAD
200
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
HEAD /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 200 OK
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: e3e55d58-f131-47d4-8640-8dc849f5be54
content-length: 36373
date: Thu, 06 Jul 2023 11:47:57 GMT
age: 48027
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=0-6159
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: 73071802-d6ad-4047-a7ac-0958b9655da9
content-length: 6160
date: Thu, 06 Jul 2023 11:47:57 GMT
age: 48041
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 0-6159/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
GET
301
http://bit.ly/2TwPVOe
REQUEST
RESPONSE
BODY
GET /2TwPVOe HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: bit.ly
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Fri, 07 Jul 2023 01:08:45 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 351
Cache-Control: private, max-age=90
Content-Security-Policy: referrer always;
Location: https://www.smartsheet.com/try-it?trp=10768&utm_source=integrated+content&utm_campaign=/content/free-pdf-invoice-templates&utm_medium=auto+repair+invoice+pdf+10768&lpa=auto+repair+invoice+pdf+10768&lx=2sgpTbF12suoPxu20v5CoABAgeTPLDIL8TQRu558b7w
Referrer-Policy: unsafe-url
Set-Cookie: _bit=n6718J-3e766ea34535b7a39b-00F; Domain=bit.ly; Expires=Wed, 03 Jan 2024 01:08:45 GMT
Via: 1.1 google
GET
206
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3
REQUEST
RESPONSE
BODY
GET /edgedl/release2/chrome_component/n3xmszuzmcp4pxq3qhmant63nm_9.45.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.45.0_all_ecp3yewcq3fuvht5wyi7t7s37y.crx3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Mon, 17 Apr 2023 17:29:06 GMT
Range: bytes=6160-14601
User-Agent: Microsoft BITS/7.5
Host: edgedl.me.gvt1.com
HTTP/1.1 206 Partial Content
accept-ranges: bytes
content-disposition: attachment
content-security-policy: default-src 'none'
server: Google-Edge-Cache
x-content-type-options: nosniff
x-frame-options: SAMEORIGIN
x-xss-protection: 0
x-request-id: 66d46726-69d3-4a2f-a3fe-fc359277d3cf
content-length: 8442
date: Thu, 06 Jul 2023 11:47:57 GMT
age: 48050
last-modified: Mon, 17 Apr 2023 17:29:06 GMT
etag: "1534ef2"
content-type: application/octet-stream
content-range: bytes 6160-14601/36373
alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000
cache-control: public,max-age=86400
coprocessor-response: download-server
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 146.75.50.191:443 -> 192.168.56.102:49241 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.102:49243 -> 146.75.50.191:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49237 -> 146.75.50.191:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49238 -> 146.75.50.191:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49240 -> 146.75.50.191:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49239 -> 146.75.50.191:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.102:49173 142.250.66.132:443 |
None | None | None |
TLS 1.3 192.168.56.102:49174 142.250.66.132:443 |
None | None | None |
TLS 1.3 192.168.56.102:49175 142.250.66.132:443 |
None | None | None |
TLS 1.3 192.168.56.102:49178 142.250.204.35:443 |
None | None | None |
TLS 1.3 192.168.56.102:49179 142.250.204.35:443 |
None | None | None |
TLS 1.3 192.168.56.102:49177 216.58.200.227:443 |
None | None | None |
TLS 1.3 192.168.56.102:49181 142.250.204.74:443 |
None | None | None |
TLS 1.3 192.168.56.102:49180 142.250.204.35:443 |
None | None | None |
TLS 1.3 192.168.56.102:49182 172.217.24.99:443 |
None | None | None |
TLS 1.3 192.168.56.102:49183 142.250.204.46:443 |
None | None | None |
TLS 1.3 192.168.56.102:49176 142.250.66.77:443 |
None | None | None |
TLS 1.3 192.168.56.102:49195 142.250.204.129:443 |
None | None | None |
TLS 1.2 192.168.56.102:49187 45.83.122.52:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pdf-readonline.website | 19:86:91:ef:29:9d:9a:a1:83:ca:a4:b0:32:65:04:3d:46:87:28:1d |
TLS 1.2 192.168.56.102:49186 45.83.122.52:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pdf-readonline.website | 19:86:91:ef:29:9d:9a:a1:83:ca:a4:b0:32:65:04:3d:46:87:28:1d |
TLS 1.2 192.168.56.102:49198 45.83.122.52:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pdf-readonline.website | 19:86:91:ef:29:9d:9a:a1:83:ca:a4:b0:32:65:04:3d:46:87:28:1d |
TLS 1.2 192.168.56.102:49194 45.83.122.52:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pdf-readonline.website | 19:86:91:ef:29:9d:9a:a1:83:ca:a4:b0:32:65:04:3d:46:87:28:1d |
TLS 1.2 192.168.56.102:49196 45.83.122.52:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pdf-readonline.website | 19:86:91:ef:29:9d:9a:a1:83:ca:a4:b0:32:65:04:3d:46:87:28:1d |
TLSv1 192.168.56.102:49207 66.220.9.58:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.webdav.drivehq.com | a6:bb:84:e8:8d:62:93:e2:b5:60:36:d3:c4:9b:9e:6b:00:7a:a5:82 |
TLSv1 192.168.56.102:49208 66.220.9.58:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.webdav.drivehq.com | a6:bb:84:e8:8d:62:93:e2:b5:60:36:d3:c4:9b:9e:6b:00:7a:a5:82 |
TLS 1.2 192.168.56.102:49199 45.83.122.52:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=pdf-readonline.website | 19:86:91:ef:29:9d:9a:a1:83:ca:a4:b0:32:65:04:3d:46:87:28:1d |
TLS 1.3 192.168.56.102:49200 142.250.204.110:443 |
None | None | None |
TLSv1 192.168.56.102:49203 66.220.9.58:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.webdav.drivehq.com | a6:bb:84:e8:8d:62:93:e2:b5:60:36:d3:c4:9b:9e:6b:00:7a:a5:82 |
TLSv1 192.168.56.102:49205 66.220.9.58:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.webdav.drivehq.com | a6:bb:84:e8:8d:62:93:e2:b5:60:36:d3:c4:9b:9e:6b:00:7a:a5:82 |
TLSv1 192.168.56.102:49216 66.220.9.58:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.webdav.drivehq.com | a6:bb:84:e8:8d:62:93:e2:b5:60:36:d3:c4:9b:9e:6b:00:7a:a5:82 |
TLSv1 192.168.56.102:49212 66.220.9.58:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.webdav.drivehq.com | a6:bb:84:e8:8d:62:93:e2:b5:60:36:d3:c4:9b:9e:6b:00:7a:a5:82 |
TLS 1.3 192.168.56.102:49221 142.250.207.99:443 |
None | None | None |
TLS 1.3 192.168.56.102:49222 142.250.204.35:443 |
None | None | None |
TLS 1.3 192.168.56.102:49225 52.6.155.20:443 |
None | None | None |
TLS 1.3 192.168.56.102:49226 52.6.155.20:443 |
None | None | None |
TLS 1.2 192.168.56.102:49229 23.45.56.171:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 | C=US, ST=California, L=San Jose, O=Adobe Inc, CN=*.adobe.com | b5:2f:f2:ba:e6:6a:d7:82:1c:df:03:c5:51:6c:84:5f:9e:70:0d:71 |
TLS 1.3 192.168.56.102:49192 142.250.207.99:443 |
None | None | None |
TLS 1.2 192.168.56.102:49230 23.45.56.171:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 | C=US, ST=California, L=San Jose, O=Adobe Inc, CN=*.adobe.com | b5:2f:f2:ba:e6:6a:d7:82:1c:df:03:c5:51:6c:84:5f:9e:70:0d:71 |
Snort Alerts
No Snort Alerts