Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
download.visualstudio.microsoft.com |
CNAME
cs10.wpc.v0cdn.net
CNAME
4316b.wpc.azureedge.net
|
192.229.232.200 |
GET
200
http://download.visualstudio.microsoft.com/download/pr/d6835aa3-6ec4-47ec-a5a5-9052ed310e4f/c1171996e95717bf532475f4546e479c/windowsdesktop-runtime-6.0.26-win-x86.exe
REQUEST
RESPONSE
BODY
GET /download/pr/d6835aa3-6ec4-47ec-a5a5-9052ed310e4f/c1171996e95717bf532475f4546e479c/windowsdesktop-runtime-6.0.26-win-x86.exe HTTP/1.1
Accept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1
Accept-Language: ru-RU,ru;q=0.9,en;q=0.8
Accept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1
Accept-Encoding: deflate, gzip, x-gzip, identity, *;q=0
Host: download.visualstudio.microsoft.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Accept-Ranges: bytes
Age: 126278
Cache-Control: public, max-age=259200
Content-Disposition: attachment; filename=windowsdesktop-runtime-6.0.26-win-x86.exe; filename*=UTF-8''windowsdesktop-runtime-6.0.26-win-x86.exe
Content-Type: application/octet-stream
Date: Sun, 04 Feb 2024 08:00:31 GMT
Etag: "0x122298F96B3589159538F50848F8ABF82DCC29C67249E90319653646E890B16D"
Last-Modified: Fri, 15 Dec 2023 20:38:25 GMT
Server: ECAcc (tkb/73BB)
X-Cache: HIT
X-Ms-ApiVersion: Distribute 1.2
X-Ms-Region: prod-neu-z1
Content-Length: 52244696
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.229.232.200:80 -> 192.168.56.103:49161 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 192.229.232.200:80 -> 192.168.56.103:49161 | 2014520 | ET INFO EXE - Served Attached HTTP | Misc activity |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts