Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
repo1.maven.org | 199.232.196.209 | |
50kteam.dynamic-dns.net | 185.222.58.83 | |
github.com | 20.200.245.247 | |
objects.githubusercontent.com | 185.199.109.133 | |
wshsoft.company | 185.232.14.169 |
- UDP Requests
-
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:61950 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:55149 239.255.255.250:1900
-
GET
200
http://wshsoft.company/jv/jrex.zip
REQUEST
RESPONSE
BODY
GET /jv/jrex.zip HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Language: ko
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: wshsoft.company
HTTP/1.1 200 OK
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
content-type: application/zip
last-modified: Mon, 31 May 2021 19:27:32 GMT
etag: "44468c2-60b538a4-eb442fd524df8c21;;;"
accept-ranges: bytes
content-length: 71592130
date: Tue, 31 Oct 2023 00:14:11 GMT
server: LiteSpeed
platform: hostinger
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49171 185.199.110.133:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS RSA SHA256 2020 CA1 | C=US, ST=California, L=San Francisco, O=GitHub, Inc., CN=*.github.io | a1:46:14:c7:2a:1d:52:79:f6:aa:2b:b2:c5:0a:3b:d3:f5:02:06:75 |
TLS 1.2 192.168.56.101:49170 151.101.40.209:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1 | CN=repo1.maven.org | 94:bc:2a:d0:1a:cf:41:94:d4:9a:de:44:ab:b4:42:39:8a:f6:bf:f3 |
TLS 1.2 192.168.56.101:49169 151.101.40.209:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1 | CN=repo1.maven.org | 94:bc:2a:d0:1a:cf:41:94:d4:9a:de:44:ab:b4:42:39:8a:f6:bf:f3 |
TLS 1.2 192.168.56.101:49167 20.200.245.247:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 | C=US, ST=California, L=San Francisco, O=GitHub, Inc., CN=github.com | a3:b5:9e:5f:e8:84:ee:1f:34:d9:8e:ef:85:8e:3f:b6:62:ac:10:4a |
TLS 1.2 192.168.56.101:49168 151.101.40.209:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 DV TLS CA 2023 Q1 | CN=repo1.maven.org | 94:bc:2a:d0:1a:cf:41:94:d4:9a:de:44:ab:b4:42:39:8a:f6:bf:f3 |
Snort Alerts
No Snort Alerts