Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
lan.persianremote.world | 195.85.201.36 | |
api.myip.com | 172.67.75.163 |
GET
200
http://api.myip.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Host: api.myip.com
Accept: text/html, image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Accept-Encoding: utf8, identity
User-Agent: Mozilla/4.0
HTTP/1.1 200 OK
Date: Sat, 07 Oct 2023 07:16:46 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=2whqdgragl1xnxfhhq%2F9NTKz66NbUkywPiI50QeopsXraOA%2BGG%2BRxenviPl2g%2FkCuyQSy4OCi4NfTaVij6eGR4AamghRAXjIK5%2BHFpciCLSIXs3pRNL7JPICavlsRQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81245c4e1ee117c0-KIX
GET
200
http://api.myip.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Host: api.myip.com
Accept: text/html, image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Accept-Encoding: utf8, identity
User-Agent: 'Mozilla/4.0
HTTP/1.1 200 OK
Date: Sat, 07 Oct 2023 07:16:47 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=LNSx4A21vCSwKbVIK1Ss3jEMRxUz6W4LZomxNTffxOa1fBIKUZLGamf6YICPrPtEw08X9plGbrfJYWSaJ7cauk90NbBiBHciDjBqw5MAHIV3wmZuofLn3Gwm6mzj9Q%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81245c50dbf68d01-KIX
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49161 -> 104.26.8.59:80 | 2031188 | ET POLICY IP Check (myip .com) | Potential Corporate Privacy Violation |
TCP 192.168.56.103:49161 -> 104.26.8.59:80 | 2003492 | ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) | Potentially Bad Traffic |
TCP 192.168.56.103:49166 -> 104.26.8.59:80 | 2031188 | ET POLICY IP Check (myip .com) | Potential Corporate Privacy Violation |
UDP 192.168.56.103:50800 -> 164.124.101.2:53 | 2027870 | ET INFO Observed DNS Query to .world TLD | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts