Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.virustotal.com | 34.54.88.138 | |
fonts.gstatic.com | 172.217.25.163 | |
cacerts.digicert.com |
CNAME
crl.edge.digicert.com
CNAME
e3913.cd.akamaiedge.net
|
118.214.79.16 |
www.googletagmanager.com | 142.250.206.200 | |
fonts.googleapis.com | 172.217.161.234 |
- TCP Requests
-
-
192.168.56.103:49170 142.250.197.234:443fonts.googleapis.com
-
192.168.56.103:49171 142.250.197.234:443fonts.googleapis.com
-
192.168.56.103:49166 142.250.199.232:443www.googletagmanager.com
-
192.168.56.103:49167 142.250.199.232:443www.googletagmanager.com
-
192.168.56.103:49172 142.250.76.3:443fonts.gstatic.com
-
192.168.56.103:49173 142.250.76.3:443fonts.gstatic.com
-
192.168.56.103:49179 23.219.19.250:80cacerts.digicert.com
-
192.168.56.103:49168 34.54.88.138:443www.virustotal.com
-
192.168.56.103:49169 34.54.88.138:443www.virustotal.com
-
192.168.56.103:49178 52.239.160.33:443
-
192.168.56.103:49180 52.239.160.33:443
-
- UDP Requests
-
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.102:137 192.168.56.103:137
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64178 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:53676 239.255.255.250:1900
-
GET
200
https://www.virustotal.com/ui/users/Arkadij_0/avatar
REQUEST
RESPONSE
BODY
GET /ui/users/Arkadij_0/avatar HTTP/1.1
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: www.virustotal.com
Connection: Keep-Alive
HTTP/1.1 200 OK
content-type: image
set-cookie: VT_SESSION_ID=; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Max-Age=0; Path=/
set-cookie: VT_SESSION_HASH=; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Max-Age=0; Path=/
set-cookie: VT_AUGMENT=; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Max-Age=0; Path=/
set-cookie: VT_SESSION_ID=; Domain=virustotal.com; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Max-Age=0; Path=/
set-cookie: VT_SESSION_HASH=; Domain=virustotal.com; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Max-Age=0; Path=/
set-cookie: VT_AUGMENT=; Domain=virustotal.com; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Max-Age=0; Path=/
x-cloud-trace-context: ccfe0361fdda01e876b892eef152ecbd
date: Thu, 17 Apr 2025 20:10:16 GMT
server: Google Frontend
Content-Length: 16871
via: 1.1 google
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
GET
200
https://www.googletagmanager.com/gtm.js?id=GTM-KFBGZNL
REQUEST
RESPONSE
BODY
GET /gtm.js?id=GTM-KFBGZNL HTTP/1.1
Accept: application/javascript, */*;q=0.8
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: www.googletagmanager.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: application/javascript; charset=UTF-8
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Cache-Control
Content-Encoding: gzip
Vary: Accept-Encoding
Date: Thu, 17 Apr 2025 20:10:16 GMT
Expires: Thu, 17 Apr 2025 20:10:16 GMT
Cache-Control: private, max-age=900
Last-Modified: Thu, 17 Apr 2025 18:20:06 GMT
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cross-Origin-Resource-Policy: cross-origin
Content-Security-Policy-Report-Only: script-src 'none'; form-action 'none'; frame-src 'none'; report-uri https://csp.withgoogle.com/csp/scaffolding/ascgcycc:1297:0
Cross-Origin-Opener-Policy-Report-Only: same-origin; report-to=ascgcycc:1297:0
Report-To: {"group":"ascgcycc:1297:0","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/scaffolding/ascgcycc:1297:0"}],}
Server: Google Tag Manager
X-XSS-Protection: 0
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Transfer-Encoding: chunked
GET
200
https://fonts.googleapis.com/icon?family=Material+Icons
REQUEST
RESPONSE
BODY
GET /icon?family=Material+Icons HTTP/1.1
Accept: text/css
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: fonts.googleapis.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Expires: Thu, 17 Apr 2025 20:10:16 GMT
Date: Thu, 17 Apr 2025 20:10:16 GMT
Cache-Control: private, max-age=86400
Cross-Origin-Opener-Policy: same-origin-allow-popups
Cross-Origin-Resource-Policy: cross-origin
Content-Encoding: gzip
Server: ESF
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Transfer-Encoding: chunked
GET
200
https://fonts.googleapis.com/icon?family=Material+Icons
REQUEST
RESPONSE
BODY
GET /icon?family=Material+Icons HTTP/1.1
Accept: text/css
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: fonts.googleapis.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: text/css; charset=utf-8
Vary: Sec-Fetch-Dest, Sec-Fetch-Mode, Sec-Fetch-Site
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
Expires: Thu, 17 Apr 2025 20:10:17 GMT
Date: Thu, 17 Apr 2025 20:10:17 GMT
Cache-Control: private, max-age=86400
Cross-Origin-Opener-Policy: same-origin-allow-popups
Cross-Origin-Resource-Policy: cross-origin
Content-Encoding: gzip
Server: ESF
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Transfer-Encoding: chunked
GET
200
https://fonts.gstatic.com/s/materialicons/v143/flUhRq6tzZclQEJ-Vdg-IuiaDsNa.woff
REQUEST
RESPONSE
BODY
GET /s/materialicons/v143/flUhRq6tzZclQEJ-Vdg-IuiaDsNa.woff HTTP/1.1
Accept: */*
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Origin: file:
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
Host: fonts.gstatic.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/apps-themes
Cross-Origin-Resource-Policy: cross-origin
Cross-Origin-Opener-Policy: same-origin; report-to="apps-themes"
Report-To: {"group":"apps-themes","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/apps-themes"}]}
Timing-Allow-Origin: *
Content-Length: 164912
X-Content-Type-Options: nosniff
Server: sffe
X-XSS-Protection: 0
Date: Tue, 15 Apr 2025 13:13:20 GMT
Expires: Wed, 15 Apr 2026 13:13:20 GMT
Cache-Control: public, max-age=31536000
Age: 197818
Last-Modified: Wed, 08 Jan 2025 18:24:16 GMT
Content-Type: font/woff
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
GET
200
http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
REQUEST
RESPONSE
BODY
GET /DigiCertGlobalRootG2.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: cacerts.digicert.com
HTTP/1.1 200 OK
Last-Modified: Wed, 06 Dec 2017 21:41:43 GMT
ETag: "5a286417-392"
Content-Type: application/pkix-cert
Content-Length: 914
Accept-Ranges: bytes
Cache-Control: public, max-age=168385
Expires: Sat, 19 Apr 2025 18:58:07 GMT
Date: Thu, 17 Apr 2025 20:11:42 GMT
Connection: keep-alive
Server-Timing: cdn-cache; desc=HIT
Server-Timing: edge; dur=1
Akamai-GRN: 0.de3a6f3d.1744920702.7a78a7b7
Server-Timing: ak_p; desc="1744920702866_1030699742_2054727607_11_692_2_0_-";dur=1
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49167 142.250.199.232:443 |
C=US, O=Google Trust Services, CN=WE2 | CN=*.google-analytics.com | e4:97:12:2a:2b:30:84:66:33:9d:d6:09:14:d3:8f:ce:3e:20:73:24 |
TLSv1 192.168.56.103:49166 142.250.199.232:443 |
C=US, O=Google Trust Services, CN=WE2 | CN=*.google-analytics.com | e4:97:12:2a:2b:30:84:66:33:9d:d6:09:14:d3:8f:ce:3e:20:73:24 |
TLSv1 192.168.56.103:49168 34.54.88.138:443 |
C=US, O=Google Trust Services, CN=WR3 | CN=www.virustotal.com | a9:93:a3:e6:12:e2:0b:b1:6f:73:f6:8d:fd:d3:0f:1e:ae:d2:ed:8a |
TLSv1 192.168.56.103:49171 142.250.197.234:443 |
C=US, O=Google Trust Services, CN=WE2 | CN=upload.video.google.com | 7e:14:87:08:df:ba:04:65:17:ba:3b:4f:ba:ea:bc:8c:3f:0a:a4:00 |
TLSv1 192.168.56.103:49172 142.250.76.3:443 |
C=US, O=Google Trust Services, CN=WE2 | CN=*.gstatic.com | 62:27:9c:c9:95:ff:8f:83:34:d0:b1:42:cb:b7:63:c0:8e:6f:3e:f1 |
TLSv1 192.168.56.103:49169 34.54.88.138:443 |
C=US, O=Google Trust Services, CN=WR3 | CN=www.virustotal.com | a9:93:a3:e6:12:e2:0b:b1:6f:73:f6:8d:fd:d3:0f:1e:ae:d2:ed:8a |
TLSv1 192.168.56.103:49173 142.250.76.3:443 |
C=US, O=Google Trust Services, CN=WE2 | CN=*.gstatic.com | 62:27:9c:c9:95:ff:8f:83:34:d0:b1:42:cb:b7:63:c0:8e:6f:3e:f1 |
TLSv1 192.168.56.103:49178 52.239.160.33:443 |
C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 03 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=*.web.core.windows.net | 22:d9:a8:14:ff:86:7a:4b:f0:95:ea:b0:9f:c1:b5:62:6b:b0:62:a9 |
TLSv1 192.168.56.103:49170 142.250.197.234:443 |
C=US, O=Google Trust Services, CN=WE2 | CN=upload.video.google.com | 7e:14:87:08:df:ba:04:65:17:ba:3b:4f:ba:ea:bc:8c:3f:0a:a4:00 |
TLSv1 192.168.56.103:49180 52.239.160.33:443 |
C=US, O=Microsoft Corporation, CN=Microsoft Azure RSA TLS Issuing CA 03 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=*.web.core.windows.net | 22:d9:a8:14:ff:86:7a:4b:f0:95:ea:b0:9f:c1:b5:62:6b:b0:62:a9 |
Snort Alerts
No Snort Alerts