Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
rl.ammyy.com | 188.42.129.148 | |
www.ammyy.com | 136.243.18.118 | |
x1.i.lencr.org | 104.109.240.205 |
POST
200
http://rl.ammyy.com/
REQUEST
RESPONSE
BODY
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: rl.ammyy.com
Content-Length: 275
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Thu, 17 Oct 2024 01:38:50 GMT
Server: Apache
X-Powered-By: PHP/5.4.16
Content-Length: 250
Content-Type: text/html
GET
301
http://www.ammyy.com/files/v8/aans64y2.gz
REQUEST
RESPONSE
BODY
GET /files/v8/aans64y2.gz HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Range: bytes=0-
Accept-Encoding: gzip, deflate
Host: www.ammyy.com
Cache-Control: no-cache
HTTP/1.1 301 Moved Permanently
Date: Thu, 17 Oct 2024 01:38:53 GMT
Server: Apache/2.4.6 (CentOS)
Location: https://www.ammyy.com/files/v8/aans64y2.gz
Content-Length: 328
Connection: close
Content-Type: text/html; charset=iso-8859-1
GET
200
http://x1.i.lencr.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: x1.i.lencr.org
HTTP/1.1 200 OK
Server: nginx
Content-Type: application/pkix-cert
Last-Modified: Fri, 04 Aug 2023 20:57:56 GMT
ETag: "64cd6654-56f"
Content-Disposition: attachment; filename="ISRG Root X1.der"
Cache-Control: max-age=42861
Expires: Thu, 17 Oct 2024 13:33:20 GMT
Date: Thu, 17 Oct 2024 01:38:59 GMT
Content-Length: 1391
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49163 -> 188.42.129.148:80 | 2025149 | ET POLICY IP Check (rl. ammyy. com) | Potential Corporate Privacy Violation |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49168 136.243.18.118:443 |
C=US, O=Let's Encrypt, CN=R11 | CN=ammyy.com | d8:77:cf:85:fd:30:35:98:82:2f:43:3d:b0:d5:a1:57:3b:30:5e:04 |
Snort Alerts
No Snort Alerts