Network Analysis
- TCP Requests
-
-
192.168.56.101:49184 104.21.64.12:443ip.cn
-
192.168.56.101:49167 119.176.27.237:8021yp37sq.sched.sma.tdnsv5.com
-
192.168.56.101:49170 119.176.27.237:8021yp37sq.sched.sma.tdnsv5.com
-
192.168.56.101:49173 119.176.27.237:8021yp37sq.sched.sma.tdnsv5.com
-
192.168.56.101:49176 119.176.27.237:8021yp37sq.sched.sma.tdnsv5.com
-
192.168.56.101:49179 119.176.27.237:8021yp37sq.sched.sma.tdnsv5.com
-
192.168.56.101:49164 119.63.197.139:443sp0.baidu.com
-
192.168.56.101:49183 124.156.105.121:443site.ip138.com
-
192.168.56.101:49161 198.54.117.242:80cdn.qqb3.com
-
192.168.56.101:49168 198.54.117.242:80cdn.qqb3.com
-
192.168.56.101:49171 198.54.117.242:80cdn.qqb3.com
-
192.168.56.101:49174 198.54.117.242:80cdn.qqb3.com
-
192.168.56.101:49177 198.54.117.242:80cdn.qqb3.com
-
192.168.56.101:49180 198.54.117.242:80cdn.qqb3.com
-
192.168.56.101:49165 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49169 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49172 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49175 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49178 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49181 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49182 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49185 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49186 23.225.34.75:80cdn.sackow.com
-
192.168.56.101:49163 43.129.138.220:80apps.game.qq.com
-
- UDP Requests
-
-
192.168.56.101:51901 164.124.101.2:53
-
192.168.56.101:52753 164.124.101.2:53
-
192.168.56.101:52797 164.124.101.2:53
-
192.168.56.101:52815 164.124.101.2:53
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:54883 164.124.101.2:53
-
192.168.56.101:54915 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:57081 164.124.101.2:53
-
192.168.56.101:57986 164.124.101.2:53
-
192.168.56.101:58120 164.124.101.2:53
-
192.168.56.101:58166 164.124.101.2:53
-
192.168.56.101:58297 164.124.101.2:53
-
192.168.56.101:58887 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:61950 164.124.101.2:53
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:55148 223.5.5.5:53
-
192.168.56.101:57085 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.101:53005
-
8.8.8.8:53 192.168.56.101:53006
-
8.8.8.8:53 192.168.56.101:53851
-
8.8.8.8:53 192.168.56.101:53852
-
8.8.8.8:53 192.168.56.101:55147
-
8.8.8.8:53 192.168.56.101:57082
-
8.8.8.8:53 192.168.56.101:58888
-
8.8.8.8:53 192.168.56.101:61951
-
8.8.8.8:53 192.168.56.101:61952
-
GET
200
https://site.ip138.com/domain/read.do?domain=cdn.cuilet.com&time=1724129865281
REQUEST
RESPONSE
BODY
GET /domain/read.do?domain=cdn.cuilet.com&time=1724129865281 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: site.ip138.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:54 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: nginx
Content-Encoding: gzip
GET
200
https://ip.cn/api/index?ip=cdn.cuilet.com&type=1
REQUEST
RESPONSE
BODY
GET /api/index?ip=cdn.cuilet.com&type=1 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: ip.cn
Cache-Control: no-cache
HTTP/1.1 200
Date: Tue, 20 Aug 2024 01:37:55 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: close
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=c4NHLyWOsXYB3JPZVeXKuzR6TEluHx7EEq3b1eLY3W2Ep7ruT6DRqtLxrWoGcyMCcknd97JIv1Fki03zrxPYcLkelryT0y4g7Ryzf8JjSSMsr41RIYBIyQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 8b5ea9306b7108e2-LAX
Content-Encoding: gzip
alt-svc: h3=":443"; ma=86400
GET
200
http://cdn.qqb3.com/API/General/client_log_user
REQUEST
RESPONSE
BODY
GET /API/General/client_log_user HTTP/1.1
Accept-Encoding: gzip
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:40 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: SessionId=c341bb8278d14506a5351b08558092ee; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5a00d71c1a614ba2adcc0319135a44d0; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://apps.game.qq.com/comm-htdocs/ip/get_ip.php
REQUEST
RESPONSE
BODY
GET /comm-htdocs/ip/get_ip.php HTTP/1.1
User-Agent: HttpSend
Host: apps.game.qq.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:42 GMT
Content-Type: text/html
Content-Length: 32
Connection: keep-alive
Server: swoole-http-server
GET
200
http://cdn.qqb3.com/API/General/lsrpu
REQUEST
RESPONSE
BODY
GET /API/General/lsrpu HTTP/1.1
Accept-Encoding: gzip
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:42 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Set-Cookie: SessionId=c341bb8278d14506a5351b08558092ee; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5a00d71c1a614ba2adcc0319135a44d0; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:44 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Content-Encoding: gzip
GET
404
http://cdn.sackow.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.sackow.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Length: 0
X-NWS-LOG-UUID: 10483553459321577799
Connection: close
Server: Lego Server
Date: Tue, 20 Aug 2024 01:37:46 GMT
X-Cache-Lookup: Return Directly
GET
200
http://cdn.qqb3.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:47 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Set-Cookie: SessionId=1ef426eb91b245e79217af6586d08db4; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5141d365279b4ca8a9661c442e20ae3f; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:48 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Content-Encoding: gzip
GET
404
http://cdn.sackow.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.sackow.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Length: 0
X-NWS-LOG-UUID: 1111396266135886045
Connection: close
Server: Lego Server
Date: Tue, 20 Aug 2024 01:37:48 GMT
X-Cache-Lookup: Return Directly
GET
200
http://cdn.qqb3.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:48 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Set-Cookie: SessionId=c341bb8278d14506a5351b08558092ee; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5a00d71c1a614ba2adcc0319135a44d0; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:49 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Content-Encoding: gzip
GET
404
http://cdn.sackow.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.sackow.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Length: 0
X-NWS-LOG-UUID: 11926913616054636834
Connection: close
Server: Lego Server
Date: Tue, 20 Aug 2024 01:37:49 GMT
X-Cache-Lookup: Return Directly
GET
200
http://cdn.qqb3.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:49 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Set-Cookie: SessionId=c341bb8278d14506a5351b08558092ee; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5a00d71c1a614ba2adcc0319135a44d0; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Content-Encoding: gzip
GET
404
http://cdn.sackow.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.sackow.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Length: 0
X-NWS-LOG-UUID: 619302993762388256
Connection: close
Server: Lego Server
Date: Tue, 20 Aug 2024 01:37:50 GMT
X-Cache-Lookup: Return Directly
GET
200
http://cdn.qqb3.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:50 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Set-Cookie: SessionId=c341bb8278d14506a5351b08558092ee; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5a00d71c1a614ba2adcc0319135a44d0; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:51 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Content-Encoding: gzip
GET
404
http://cdn.sackow.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.sackow.com
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Content-Length: 0
X-NWS-LOG-UUID: 9620701211685483857
Connection: close
Server: Lego Server
Date: Tue, 20 Aug 2024 01:37:51 GMT
X-Cache-Lookup: Return Directly
GET
200
http://cdn.qqb3.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET /api/filegoto1/d76b29f56b8bed99 HTTP/1.1
Accept-Encoding: gzip
Connection: Close
User-Agent: CHM_MSDN
Host: cdn.qqb3.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 20 Aug 2024 01:37:51 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Set-Cookie: SessionId=c341bb8278d14506a5351b08558092ee; domain=.www.namecheap.com; path=/; httponly
Set-Cookie: x-ncpl-csrf=5a00d71c1a614ba2adcc0319135a44d0; domain=.www.namecheap.com; path=/; secure; samesite=none
X-Proxy-Cache: HIT
Server: namecheap-nginx
Content-Encoding: gzip
GET
200
http://cdn.cuilet.comhttp://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99 HTTP/1.0
Accept-Encoding: gzip
Pragma: no-cache
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
GET
200
http://cdn.cuilet.comhttp://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99 HTTP/1.0
Accept-Encoding: gzip
Pragma: no-cache
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:52 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
GET
200
http://cdn.cuilet.comhttp://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99 HTTP/1.0
Accept-Encoding: gzip
Pragma: no-cache
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:55 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
GET
200
http://cdn.cuilet.comhttp://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99
REQUEST
RESPONSE
BODY
GET http://cdn.cuilet.com/api/filegoto1/d76b29f56b8bed99 HTTP/1.0
Accept-Encoding: gzip
Pragma: no-cache
User-Agent: CHM_MSDN
Host: cdn.cuilet.com
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 20 Aug 2024 01:37:56 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Vary: Accept-Encoding
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49183 124.156.105.121:443 |
C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G4 | CN=site.ip138.com | 1f:4a:7e:5a:dd:da:5b:38:e0:1d:40:26:d9:97:cc:dc:1c:db:bc:36 |
TLSv1 192.168.56.101:49184 104.21.64.12:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=ip.cn | 15:f7:45:c7:89:82:91:c9:28:a1:91:a4:e0:c9:e1:00:f1:64:f3:a1 |
TLSv1 192.168.56.101:49164 119.63.197.139:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 | C=CN, ST=beijing, L=beijing, O=Beijing Baidu Netcom Science Technology Co., Ltd, CN=baidu.com | ef:0f:be:13:02:e2:c4:d4:89:ba:8f:ba:88:ef:6f:95:dc:cf:7b:e0 |
Snort Alerts
No Snort Alerts