Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
api.ipify.org | 172.67.74.152 |
- TCP Requests
GET
200
https://api.ipify.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0
Host: api.ipify.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 01 May 2024 22:25:29 GMT
Content-Type: text/plain
Content-Length: 15
Connection: keep-alive
Vary: Origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 87d3300fec7b721d-FUK
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.103:52760 -> 164.124.101.2:53 | 2047702 | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup | Misc activity |
UDP 192.168.56.103:52760 -> 8.8.8.8:53 | 2047702 | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup | Misc activity |
TCP 192.168.56.103:49166 -> 104.26.12.205:443 | 2047703 | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI | Misc activity |
TCP 192.168.56.103:49166 -> 104.26.12.205:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49166 104.26.12.205:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=ipify.org | c8:1a:05:47:c5:73:c6:ce:df:1d:a6:de:00:11:a9:9a:8c:db:ef:a7 |
Snort Alerts
No Snort Alerts