Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
c.pki.goog |
CNAME
pki-goog.l.google.com
|
142.250.76.131 |
ip-api.com | 208.95.112.1 | |
api.ipify.org | 104.26.13.205 |
GET
200
https://api.ipify.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Host: api.ipify.org
User-Agent: curl/8.11.0-DEV
Accept: */*
Accept-Encoding: deflate, gzip
HTTP/1.1 200 OK
Date: Sun, 13 Apr 2025 06:30:29 GMT
Content-Type: text/plain
Content-Length: 13
Connection: keep-alive
Vary: Origin
cf-cache-status: DYNAMIC
Server: cloudflare
CF-RAY: 92f8ea420ea029e0-FUK
server-timing: cfL4;desc="?proto=TCP&rtt=76821&min_rtt=67608&rtt_var=34613&sent=6&recv=6&lost=0&retrans=0&sent_bytes=3123&recv_bytes=432&delivery_rate=64785&cwnd=253&unsent_bytes=0&cid=61bb217a0ff1d7f1&ts=644&x=0"
GET
200
http://c.pki.goog/r/gsr1.crl
REQUEST
RESPONSE
BODY
GET /r/gsr1.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: c.pki.goog
HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
Cross-Origin-Resource-Policy: cross-origin
Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
Content-Length: 1739
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 0
Date: Sun, 13 Apr 2025 05:41:06 GMT
Expires: Sun, 13 Apr 2025 06:31:06 GMT
Cache-Control: public, max-age=3000
Age: 2963
Last-Modified: Mon, 07 Apr 2025 13:58:00 GMT
Content-Type: application/pkix-crl
Vary: Accept-Encoding
GET
200
http://c.pki.goog/r/r4.crl
REQUEST
RESPONSE
BODY
GET /r/r4.crl HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: c.pki.goog
HTTP/1.1 200 OK
Accept-Ranges: bytes
Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
Cross-Origin-Resource-Policy: cross-origin
Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
Content-Length: 530
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 0
Date: Sun, 13 Apr 2025 06:08:04 GMT
Expires: Sun, 13 Apr 2025 06:58:04 GMT
Cache-Control: public, max-age=3000
Age: 1345
Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
Content-Type: application/pkix-crl
Vary: Accept-Encoding
GET
200
http://ip-api.com/json/121.133.128.1
REQUEST
RESPONSE
BODY
GET /json/121.133.128.1 HTTP/1.1
Host: ip-api.com
User-Agent: curl/8.11.0-DEV
Accept: */*
Accept-Encoding: deflate, gzip
HTTP/1.1 200 OK
Date: Sun, 13 Apr 2025 06:30:29 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 267
Access-Control-Allow-Origin: *
X-Ttl: 60
X-Rl: 44
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2047702 | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup | Misc activity |
TCP 192.168.56.101:49165 -> 172.67.74.152:443 | 2047703 | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI | Misc activity |
TCP 192.168.56.101:49161 -> 45.227.252.199:7712 | 2061200 | ET MALWARE Aurotun Stealer CnC Checkin | A Network Trojan was detected |
UDP 192.168.56.101:53004 -> 164.124.101.2:53 | 2054141 | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) | Device Retrieving External IP Address Detected |
TCP 192.168.56.101:49169 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49165 172.67.74.152:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=ipify.org | bd:fd:0e:47:c4:8e:87:56:19:5e:86:99:5b:45:32:c3:13:aa:aa:f3 |
Snort Alerts
No Snort Alerts