Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
client-updates.lumu.io | 3.229.137.113 | |
lumu-updates.s3.amazonaws.com |
CNAME
s3-1-w.amazonaws.com
|
54.231.203.249 |
x1.i.lencr.org | 23.207.177.83 |
- TCP Requests
-
-
192.168.56.101:49176 23.41.113.9:80x1.i.lencr.org
-
192.168.56.101:49177 23.52.33.11:80x1.i.lencr.org
-
192.168.56.101:49173 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49175 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49178 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49179 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49188 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49189 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49191 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49192 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49195 3.229.137.113:80client-updates.lumu.io
-
192.168.56.101:49197 3.229.137.113:80client-updates.lumu.io
-
192.168.56.101:49213 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49214 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49215 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49216 3.229.137.113:443client-updates.lumu.io
-
192.168.56.101:49217 3.229.137.113:80client-updates.lumu.io
-
192.168.56.101:49200 54.231.194.33:443lumu-updates.s3.amazonaws.com
-
192.168.56.101:49202 54.231.194.33:443lumu-updates.s3.amazonaws.com
-
192.168.56.101:49205 54.231.194.33:443lumu-updates.s3.amazonaws.com
-
GET
200
https://lumu-updates.s3.amazonaws.com/build/Agent/win/2203318943744/desktop_single_agent-d47545d41d.exe
REQUEST
RESPONSE
BODY
GET /build/Agent/win/2203318943744/desktop_single_agent-d47545d41d.exe HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.107.1;winhttp
X-Old-UID: cnt=1
X-Last-HR: 0x80072f7d
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 2
Host: lumu-updates.s3.amazonaws.com
HTTP/1.1 200 OK
x-amz-id-2: LzhR6kSmDgVfX07sR7xss8U/bpIJwF7lIW+/ve7kHvQlCPCkgOXtFqJI6bmd5JGIbPhU1FltzC4=
x-amz-request-id: MVVWPHZJMM4DJHPP
Date: Fri, 23 Aug 2024 11:06:32 GMT
Last-Modified: Thu, 23 May 2024 15:18:10 GMT
ETag: "8438df02ba5aab4ae7998393611b7251"
x-amz-server-side-encryption: AES256
Accept-Ranges: bytes
Content-Type: application/x-msdownload
Server: AmazonS3
Content-Length: 2761096
GET
200
http://x1.i.lencr.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: x1.i.lencr.org
HTTP/1.1 200 OK
Server: nginx
Content-Type: application/pkix-cert
Last-Modified: Fri, 04 Aug 2023 20:57:56 GMT
ETag: "64cd6654-56f"
Content-Disposition: attachment; filename="ISRG Root X1.der"
Cache-Control: max-age=54444
Expires: Sat, 24 Aug 2024 02:13:33 GMT
Date: Fri, 23 Aug 2024 11:06:09 GMT
Content-Length: 1391
Connection: keep-alive
GET
200
http://x1.i.lencr.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: x1.i.lencr.org
HTTP/1.1 200 OK
Server: nginx
Content-Type: application/pkix-cert
Last-Modified: Fri, 04 Aug 2023 20:57:56 GMT
ETag: "64cd6654-56f"
Content-Disposition: attachment; filename="ISRG Root X1.der"
Cache-Control: max-age=54433
Expires: Sat, 24 Aug 2024 02:13:22 GMT
Date: Fri, 23 Aug 2024 11:06:09 GMT
Content-Length: 1391
Connection: keep-alive
POST
200
http://client-updates.lumu.io/service/update2
REQUEST
RESPONSE
BODY
POST /service/update2 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.107.1;winhttp
X-Old-UID: age=-1; cnt=1
X-Goog-Update-Updater: Omaha-1.3.107.1
X-Goog-Update-Interactivity: bg
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Content-Length: 742
Host: client-updates.lumu.io
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 23 Aug 2024 11:06:23 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 250
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
POST
200
http://client-updates.lumu.io/service/update2?cup2key=1:aiyktIlMWjC_YDIJkn6k3-6XqffwkP2DaBfamURTQIA&cup2hreq=a4125a8074c9af063159ba78027272f9671c42488dea9878a9c5f20b4b7c8dc7
REQUEST
RESPONSE
BODY
POST /service/update2?cup2key=1:aiyktIlMWjC_YDIJkn6k3-6XqffwkP2DaBfamURTQIA&cup2hreq=a4125a8074c9af063159ba78027272f9671c42488dea9878a9c5f20b4b7c8dc7 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.107.1;winhttp;cup-ecdsa
X-Old-UID: cnt=1
X-Goog-Update-AppId: {F29544FA-DF33-470F-90E9-B19EF24DF010}
X-Goog-Update-Updater: Omaha-1.3.107.1
X-Goog-Update-Interactivity: fg
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Content-Length: 690
Host: client-updates.lumu.io
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 23 Aug 2024 11:06:24 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 870
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
ETag: 30460221008ac756b8afdfff14b56b7d778fb1618a93006a0c55491699f0c45ea07f81bda70221009b9dd5e192a3454503f7e33b39457c76552426432bb300e7051985532fccf7b4:a4125a8074c9af063159ba78027272f9671c42488dea9878a9c5f20b4b7c8dc7
POST
200
http://client-updates.lumu.io/service/update2
REQUEST
RESPONSE
BODY
POST /service/update2 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Google Update/1.3.107.1;winhttp
X-Old-UID: cnt=1
X-Goog-Update-Updater: Omaha-1.3.107.1
X-Goog-Update-Interactivity: bg
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Content-Length: 1619
Host: client-updates.lumu.io
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 23 Aug 2024 11:07:00 GMT
Content-Type: text/xml; charset=utf-8
Content-Length: 400
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
Cross-Origin-Opener-Policy: same-origin
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49175 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49179 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49173 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49188 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49205 54.231.194.33:443 |
C=US, O=Amazon, CN=Amazon RSA 2048 M01 | CN=*.s3.amazonaws.com | 57:fe:c9:73:13:31:ca:2c:91:7f:05:c3:3b:16:ff:3f:1b:d8:7d:e2 |
TLS 1.2 192.168.56.101:49191 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49178 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49189 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49192 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49214 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49213 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49215 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
TLS 1.2 192.168.56.101:49216 3.229.137.113:443 |
C=US, O=Let's Encrypt, CN=E5 | CN=client-updates.lumu.io | ea:b7:e2:ce:8f:e9:1f:e8:31:28:68:38:19:6d:89:0f:7e:6b:be:8e |
Snort Alerts
No Snort Alerts