Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
varied-flux-emails-grounds.trycloudflare.com | 104.16.231.132 |
- TCP Requests
-
-
192.168.56.101:49169 104.16.231.132:443varied-flux-emails-grounds.trycloudflare.com
-
192.168.56.101:49170 104.16.231.132:443varied-flux-emails-grounds.trycloudflare.com
-
192.168.56.101:49182 104.16.231.132:443varied-flux-emails-grounds.trycloudflare.com
-
192.168.56.101:49183 104.16.231.132:443varied-flux-emails-grounds.trycloudflare.com
-
192.168.56.101:49187 117.18.232.200:80
-
GET
200
https://varied-flux-emails-grounds.trycloudflare.com/a.pdf
REQUEST
RESPONSE
BODY
GET /a.pdf HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: varied-flux-emails-grounds.trycloudflare.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 01 Dec 2024 03:44:08 GMT
Content-Type: application/pdf
Content-Length: 2791500
Connection: keep-alive
CF-Ray: 8eb013ac48fdeaa7-ICN
CF-Cache-Status: DYNAMIC
Accept-Ranges: bytes
ETag: "07739021da5afe9f39cd220ae4c2ad2e-1717763048-2791500"
Last-Modified: Fri, 07 Jun 2024 12:24:08 GMT
Vary: Accept-Encoding
Server: cloudflare
GET
200
https://varied-flux-emails-grounds.trycloudflare.com/b.pdf
REQUEST
RESPONSE
BODY
GET /b.pdf HTTP/1.1
Accept: text/html, application/xhtml+xml, */*
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Accept-Encoding: gzip, deflate
Host: varied-flux-emails-grounds.trycloudflare.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 01 Dec 2024 03:44:13 GMT
Content-Type: application/pdf
Content-Length: 2791500
Connection: keep-alive
CF-Ray: 8eb013cb6f44aa78-ICN
CF-Cache-Status: DYNAMIC
Accept-Ranges: bytes
ETag: "1784005772054bb50cdd8b177efd1551-1717763048-2791500"
Last-Modified: Fri, 07 Jun 2024 12:24:08 GMT
Vary: Accept-Encoding
Server: cloudflare
GET
200
http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE
BODY
GET /IE9CompatViewList.xml HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: ie9cvlist.ie.microsoft.com
If-Modified-Since: Thu, 21 Nov 2019 19:37:08 GMT
If-None-Match: 0x8D76EBA32AF0BC3
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Encoding: gzip
Age: 7946
Cache-Control: max-age=21600
Content-MD5: p9g4jsuZO6TaLMVAI9ujVg==
Content-Type: text/xml
Date: Sun, 01 Dec 2024 03:45:06 GMT
Etag: 0x8D9521D2D2DF1EC
Last-Modified: Wed, 28 Jul 2021 23:12:31 GMT
Server: ECAcc (tka/897A)
Vary: Accept-Encoding
X-Cache: HIT
x-ms-blob-type: BlockBlob
x-ms-lease-status: unlocked
x-ms-request-id: 72fdfb41-501e-003b-4990-432da4000000
x-ms-version: 2009-09-19
Content-Length: 13702
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2034552 | ET POLICY Observed DNS Query to Commonly Abused Cloudflare Domain (trycloudflare .com) | Potentially Bad Traffic |
TCP 192.168.56.101:49170 -> 104.16.231.132:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49169 -> 104.16.231.132:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49182 -> 104.16.231.132:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49183 -> 104.16.231.132:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49170 104.16.231.132:443 |
C=US, O=Google Trust Services, CN=WR1 | CN=trycloudflare.com | 14:e5:5a:7a:3b:34:3a:c0:b2:af:48:86:76:27:89:d3:a5:3a:95:65 |
TLSv1 192.168.56.101:49169 104.16.231.132:443 |
C=US, O=Google Trust Services, CN=WR1 | CN=trycloudflare.com | 14:e5:5a:7a:3b:34:3a:c0:b2:af:48:86:76:27:89:d3:a5:3a:95:65 |
TLSv1 192.168.56.101:49183 104.16.231.132:443 |
C=US, O=Google Trust Services, CN=WR1 | CN=trycloudflare.com | 14:e5:5a:7a:3b:34:3a:c0:b2:af:48:86:76:27:89:d3:a5:3a:95:65 |
TLSv1 192.168.56.101:49182 104.16.231.132:443 |
C=US, O=Google Trust Services, CN=WR1 | CN=trycloudflare.com | 14:e5:5a:7a:3b:34:3a:c0:b2:af:48:86:76:27:89:d3:a5:3a:95:65 |
Snort Alerts
No Snort Alerts