Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
- TCP Requests
-
-
192.168.56.101:49174 137.226.34.45:9008
-
192.168.56.101:49178 137.226.34.45:9008
-
192.168.56.101:49182 137.226.34.45:9008
-
192.168.56.101:49171 145.239.136.129:8080
-
192.168.56.101:49175 178.33.36.64:8080
-
192.168.56.101:49177 178.33.36.64:8080
-
192.168.56.101:49180 178.33.36.64:8080
-
192.168.56.101:49170 199.195.253.180:9000
-
192.168.56.101:49172 84.240.60.234:9001
-
No traffic
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 199.195.253.180:9000 -> 192.168.56.101:49170 | 2520069 | ET TOR Known Tor Exit Node Traffic group 70 | Misc Attack |
TCP 199.195.253.180:9000 -> 192.168.56.101:49170 | 2522069 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 70 | Misc Attack |
TCP 178.33.36.64:8080 -> 192.168.56.101:49175 | 2522257 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 258 | Misc Attack |
TCP 145.239.136.129:8080 -> 192.168.56.101:49171 | 2522193 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 194 | Misc Attack |
TCP 84.240.60.234:9001 -> 192.168.56.101:49172 | 2522787 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 788 | Misc Attack |
TCP 137.226.34.45:9008 -> 192.168.56.101:49174 | 2522169 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 170 | Misc Attack |
TCP 137.226.34.45:9008 -> 192.168.56.101:49182 | 2522169 | ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 170 | Misc Attack |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49170 199.195.253.180:9000 |
None | None | None |
TLS 1.3 192.168.56.101:49175 178.33.36.64:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49171 145.239.136.129:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49172 84.240.60.234:9001 |
None | None | None |
TLS 1.3 192.168.56.101:49177 178.33.36.64:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49174 137.226.34.45:9008 |
None | None | None |
TLS 1.3 192.168.56.101:49180 178.33.36.64:8080 |
None | None | None |
TLS 1.3 192.168.56.101:49178 137.226.34.45:9008 |
None | None | None |
TLS 1.3 192.168.56.101:49182 137.226.34.45:9008 |
None | None | None |
Snort Alerts
No Snort Alerts