Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
piret-wismann.com | 162.33.179.65 | |
www.ssl.com | 54.236.82.84 |
- TCP Requests
-
-
192.168.56.101:49166 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49170 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49171 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49173 162.33.179.65:8080piret-wismann.com
-
192.168.56.101:49174 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49175 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49176 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49177 162.33.179.65:8080piret-wismann.com
-
192.168.56.101:49178 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49179 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49180 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49181 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49182 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49183 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49184 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49185 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49186 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49187 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49188 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49189 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49190 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49191 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49192 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49193 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49194 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49195 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49196 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49197 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49198 162.33.179.65:2351piret-wismann.com
-
192.168.56.101:49161 54.236.82.84:80www.ssl.com
-
- UDP Requests
-
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:55149 239.255.255.250:1900
-
GET
200
http://www.ssl.com/repository/SSLcom-RootCA-EV-RSA-4096-R2.crt
REQUEST
RESPONSE
BODY
GET /repository/SSLcom-RootCA-EV-RSA-4096-R2.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.ssl.com
HTTP/1.1 200 OK
Date: Tue, 10 Oct 2023 01:07:08 GMT
Content-Type: application/pkix-cert
Content-Length: 1519
Connection: keep-alive
Server: nginx
x-amz-id-2: YdwpBrPQv/3s/2FtiQNaf4+6I0mpHsFwqmBf+Yde6VseOkMNIz1xRX6e/BtDKHZRH3XyMgCRA5g=
x-amz-request-id: 22FGTBXZD78Y5KSB
Cache-Control: max-age=31556952, public
Last-Modified: Mon, 12 Jun 2023 19:56:14 GMT
ETag: "e11e31581aae545302f6176a117b4d95"
X-Proxy-Cache: HIT
GET
200
http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt
REQUEST
RESPONSE
BODY
GET /repository/SSLcomRootCertificationAuthorityRSA.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.ssl.com
HTTP/1.1 200 OK
Date: Tue, 10 Oct 2023 01:07:08 GMT
Content-Type: application/pkix-cert
Content-Length: 1505
Connection: keep-alive
Server: nginx
x-amz-id-2: MHbg0BMacRPffM3y10CLyRFivWOxd9ugH0zcgRpbwpP9+QaMhRVT9htBKISVpFQkgG173sTb0t4=
x-amz-request-id: XKJMNDF2555YN6SJ
Cache-Control: max-age=31556952, public
Last-Modified: Mon, 12 Jun 2023 19:57:31 GMT
ETag: "866912c070f1ecacacc2d5bca55ba129"
X-Proxy-Cache: HIT
POST
200
http://piret-wismann.com:8080/
REQUEST
RESPONSE
BODY
POST / HTTP/1.0
Host: piret-wismann.com:8080
Keep-Alive: 300
Connection: keep-alive
User-Agent: Mozilla/4.0 (compatible; Synapse)
Content-Type: Application/octet-stream
Content-Length: 140
HTTP/1.1 200 OK
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 4
Date: Tue, 10 Oct 2023 01:07:23 GMT
POST
200
http://piret-wismann.com:8080/
REQUEST
RESPONSE
BODY
POST / HTTP/1.0
Host: piret-wismann.com:8080
Keep-Alive: 300
Connection: keep-alive
User-Agent: Mozilla/4.0 (compatible; Synapse)
Content-Type: Application/octet-stream
Content-Length: 456
HTTP/1.1 200 OK
Connection: close
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 2
Date: Tue, 10 Oct 2023 01:07:23 GMT
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49166 -> 162.33.179.65:2351 | 2013028 | ET POLICY curl User-Agent Outbound | Attempted Information Leak |
TCP 192.168.56.101:49170 -> 162.33.179.65:2351 | 2013028 | ET POLICY curl User-Agent Outbound | Attempted Information Leak |
TCP 162.33.179.65:2351 -> 192.168.56.101:49166 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 162.33.179.65:2351 -> 192.168.56.101:49166 | 2014520 | ET INFO EXE - Served Attached HTTP | Misc activity |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts