Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.ssl.com | 3.213.199.135 |
GET
200
http://www.ssl.com/repository/SSLcomRootCertificationAuthorityRSA.crt
REQUEST
RESPONSE
BODY
GET /repository/SSLcomRootCertificationAuthorityRSA.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.ssl.com
HTTP/1.1 200 OK
Date: Tue, 07 Nov 2023 00:43:45 GMT
Content-Type: application/pkix-cert
Content-Length: 1505
Connection: keep-alive
Server: nginx
x-amz-id-2: MHbg0BMacRPffM3y10CLyRFivWOxd9ugH0zcgRpbwpP9+QaMhRVT9htBKISVpFQkgG173sTb0t4=
x-amz-request-id: XKJMNDF2555YN6SJ
Cache-Control: max-age=31556952, public
Last-Modified: Mon, 12 Jun 2023 19:57:31 GMT
ETag: "866912c070f1ecacacc2d5bca55ba129"
X-Proxy-Cache: HIT
GET
200
http://167.235.241.120/jogX/Olluc
REQUEST
RESPONSE
BODY
GET /jogX/Olluc HTTP/1.1
Host: 167.235.241.120
User-Agent: curl/7.85.0
Accept: */*
HTTP/1.1 200 OK
Date: Tue, 07 Nov 2023 00:43:48 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
GET
200
http://167.235.241.120/jogX/Olluc
REQUEST
RESPONSE
BODY
GET /jogX/Olluc HTTP/1.1
Host: 167.235.241.120
User-Agent: curl/7.85.0
Accept: */*
HTTP/1.1 200 OK
Date: Tue, 07 Nov 2023 00:43:50 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49171 -> 167.235.241.120:80 | 2013028 | ET POLICY curl User-Agent Outbound | Attempted Information Leak |
TCP 192.168.56.102:49171 -> 167.235.241.120:80 | 2034567 | ET HUNTING curl User-Agent to Dotted Quad | Potentially Bad Traffic |
TCP 192.168.56.102:49170 -> 167.235.241.120:80 | 2013028 | ET POLICY curl User-Agent Outbound | Attempted Information Leak |
TCP 192.168.56.102:49170 -> 167.235.241.120:80 | 2034567 | ET HUNTING curl User-Agent to Dotted Quad | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts