Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
ip-api.com | 208.95.112.1 | |
api.ipify.org | 104.26.13.205 |
GET
200
https://api.ipify.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0
Host: api.ipify.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 20 Jul 2024 11:14:34 GMT
Content-Type: text/plain
Content-Length: 15
Connection: keep-alive
Vary: Origin
CF-Cache-Status: DYNAMIC
Server: cloudflare
CF-RAY: 8a6287441ed529e0-FUK
GET
200
http://ip-api.com/line/?fields=hosting
REQUEST
RESPONSE
BODY
GET /line/?fields=hosting HTTP/1.1
Host: ip-api.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 20 Jul 2024 11:14:34 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 6
Access-Control-Allow-Origin: *
X-Ttl: 60
X-Rl: 44
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2047702 | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup | Misc activity |
UDP 192.168.56.101:59002 -> 8.8.8.8:53 | 2047702 | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup | Misc activity |
UDP 192.168.56.101:54148 -> 8.8.8.8:53 | 2054141 | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) | Device Retrieving External IP Address Detected |
TCP 192.168.56.101:49165 -> 104.26.13.205:443 | 2047703 | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI | Misc activity |
TCP 192.168.56.101:49165 -> 104.26.13.205:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49166 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49165 104.26.13.205:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=ipify.org | 14:92:0d:1d:39:e0:d3:ad:dc:06:2e:2e:6b:21:c6:c0:ac:d6:a1:b6 |
Snort Alerts
No Snort Alerts