Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
business.instagram.com | 157.240.11.52 |
- UDP Requests
-
-
192.168.56.102:56630 164.124.101.2:53
-
192.168.56.102:62846 164.124.101.2:53
-
192.168.56.102:63709 164.124.101.2:53
-
192.168.56.102:64513 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:63713 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
GET
404
https://business.instagram.com/micro_site/url/?event_type=click
REQUEST
RESPONSE
BODY
GET /micro_site/url/?event_type=click HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: business.instagram.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
reporting-endpoints: coop_report="https://www.facebook.com/browser_reporting/coop/?minimize=0", coep_report="https://www.facebook.com/browser_reporting/coep/?minimize=0"
report-to: {"max_age":2592000,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coop\/?minimize=0"}],"group":"coop_report","include_subdomains":true}, {"max_age":86400,"endpoints":[{"url":"https:\/\/www.facebook.com\/browser_reporting\/coep\/?minimize=0"}],"group":"coep_report"}
cross-origin-embedder-policy-report-only: require-corp;report-to="coep_report"
cross-origin-opener-policy: same-origin-allow-popups;report-to="coop_report"
origin-agent-cluster: ?1
Strict-Transport-Security: max-age=31536000; preload; includeSubDomains
x-stack: www
Content-Type: text/html; charset="utf-8"
X-FB-Debug: 9QU7BSDbN2fJKDI8tmG8Zi7c2PsDuuXEO/UcJP+x61pvcKqPVqShc/E4CZHL0o60Hrc8mqbU0XhvNL1s/NJRrg==
Date: Mon, 24 Jun 2024 20:26:15 GMT
Proxy-Status: http_request_error; e_fb_configversion="AcJVtjaJOMbwQC_XAE-FGkCoyvjKRusQvZWDOnvXgPEcjNKkItM8kdgaUR-tEA"; e_fb_vipport="AcLlnPAdbh0aG1CIjspmUZAUgP3AilO8zxkj-23ya4iWziqXjI4pVD2BUiZE"; e_upip="AcLgSLGu3gOMGUGSm_sZ1Nr-FY9RyGCivXi63_SrY60WqOxAJoYlAGTg6NHalVXB2QY15Rbt9AYnFl2G1H69hg4aA4gPTla7zPs"; e_fb_requestsequencenumber="AcKUlZay1mI8MPb-SkuYKW2ZpZ8BDM7HvB-FCAR9TOOjsCAOhx5B3rBj1p9i"; e_fb_responsebytes="AcKAr_N2ZbNvEv3gJBK0M-qSk45_ZZplOu__-_YfYiomWRv3bigz_jdBdg"; e_fb_hostheader="AcIaIZGDmAZpw4PzMFr4YxznlSyx2G9me7DZjhUOtmGhwkJBV5htwu1QTuoOSRzVwN71_3_mP42eiOnWzJL95g"; e_fb_vipaddr="AcIAYPYK3Y6eRHOhcZUc4HzgyniWOp-u4qw8siu2ryRNsCWSdidQhajKe6wDJEEACDQSWu-hkWt7KjhUt1n-XgyMMTsb17gYCw"; e_fb_requesthandler="AcJlMOCldQEr5_b9EM1brjwsCZDbSUFdNyQWE22oD4xPUmHjAqpfT0zzpWLscPzTY3HcOi_Rmmg"; e_fb_requesttime="AcKkfUEja24Mpx3R3BzZ1qscS8ZlGjA2cyB9haBL92aWi7lq6FgOoa0IRfaABwg8NkHeiiOSmQ"; e_fb_builduser="AcJyqtWt4CaoJFU7RVoeoX9_7RmJrdP41CHa3EGtCH6aB_T7lcs_meKR2-_bdDDRupk"; e_fb_httpversion="AcL_S2W3zhefHUGk24uB1gVPFH4uViml9q9SNPGUCiyKe1rsiG796dD3vc8q"; e_fb_binaryversion="AcLv_eoBEJlCf4-B0jxYn4pb8OeCc6ubiECglSM2jEctNj7ZYRyoag2IRzbz1d6hB-rDx_U2IkMMTLZKl8cx1zN3sj0z3ahOBLA"; e_proxy="AcKHBlaIQ-z6yj1OFNfgZ69nyPHKOq_ay0ZZDHALkQiIV0255qK-8ctfGJl1en3yjmFhLoq1bUX7cU43Awk", http_request_error; e_fb_configversion="AcJ5y2pwfmFOy0YpPsDbzYYI8W-ZWTkEeeylka8jGqB01hf29zlW2SG5P5YGPA"; e_fb_vipport="AcJj8sKZBNr4Og2QItolPj92hsSwEFcLmVCbrhR_dZHI7Q2Fldf-sxCSdvi5"; e_upip="AcIZiykSjT1_Nb9Jifh9W4l28nxxPt9bTPfMT8w5gLR2ZXuOl9HMJtcc0-ZGNPI7sl1DLfe4OP4MgFMgjac_0JC6upqSyPApTQ"; e_fb_requestsequencenumber="AcL5M4CFlF1dzMAFzLhhMevG73fwD3tNgg3Ypx0nTmwzOYuz59YYqSyVBA"; e_fb_responsebytes="AcKfDgDzcs6-Faeeoimu_QUbSoPB59rNsAIUKLSjkkhwUsWmuzn3kpH2gw"; e_fb_hostheader="AcINYUUd6Lns2wrqCtmhE0JvNDqC96uvYx8dJnjARys8pr0kmHv1RXHuRLQas3DqVJPyvyTyJniqXUIIxlW6Hg"; e_fb_vipaddr="AcLlF8Rp9AxKCVwpvQ5FxvjOYEhJJpXkd4ubCENFET4-euVoVcJ7IsDdqQLtm7DqLNZxNjagLjg"; e_fb_requesthandler="AcIj2-3tJLg_Lcpi7d3Xm4cczUBJia2wt-FLMLWpENbQxWPhH6P1YFIXwKXDIpiovLhQTGDR42rh4IhlzqI"; e_fb_requesttime="AcInvEKJaGJH6RLj7bSADEJ7hf6Y77fW-eFP0BhKTvY-ngLBJkT1TdJQZyc3XuiCF8aJwLJd2A"; e_fb_builduser="AcJ9U3qjaTBsX3xQhW2gd8Xs7f_2LQC5l-qv_GYHmHwvYXlRwPgiHpGVWOamui9GFrU"; e_fb_httpversion="AcJD9c2pfs5SWCb3nQFf7v2aGZpwfNc0j7QyQpWvZ7oby6wZFttlvmpy_sXI"; e_fb_binaryversion="AcJ1TEckAjSKtaAZx8F-XdxTN4ANtoYS0Yfk5gn7V9Ji32oCaS28ltefZZphTr984-vHdj7BHE3QZCRkz_sQHS2Gj-Q4CWIZt_U"; e_proxy="AcLTz_gRg462M8VPPE3AO4TWu7fdAIKaInZVpVY2kCgHafM0GwmdBCWkK6JoB7dMeHYwZ8KWMq4zIu0"
Connection: keep-alive
Content-Length: 0
GET
304
http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE
BODY
GET /IE9CompatViewList.xml HTTP/1.1
Accept: */*
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Host: ie9cvlist.ie.microsoft.com
If-Modified-Since: Wed, 28 Jul 2021 23:12:31 GMT
If-None-Match: 0x8D9521D2D2DF1EC
Connection: Keep-Alive
HTTP/1.1 304 Not Modified
Age: 10866
Cache-Control: max-age=21600
Date: Mon, 24 Jun 2024 20:27:13 GMT
Etag: 0x8D9521D2D2DF1EC
Last-Modified: Wed, 28 Jul 2021 23:12:31 GMT
Server: ECAcc (tka/897A)
Vary: Accept-Encoding
X-Cache: HIT
x-ms-blob-type: BlockBlob
x-ms-lease-status: unlocked
x-ms-request-id: ccea4b82-801e-004a-605b-c6cb8f000000
x-ms-version: 2009-09-19
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49164 -> 157.240.215.63:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49165 -> 157.240.215.63:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 117.18.232.200:443 -> 192.168.56.102:49173 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.102:49172 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49171 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49164 157.240.215.63:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA | C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.instagram.com | ba:b0:f5:12:1a:8e:c7:3b:fb:dc:b7:53:e3:ae:a6:18:52:a1:c7:9d |
TLSv1 192.168.56.102:49165 157.240.215.63:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA | C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.instagram.com | ba:b0:f5:12:1a:8e:c7:3b:fb:dc:b7:53:e3:ae:a6:18:52:a1:c7:9d |
Snort Alerts
No Snort Alerts