Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
orpod.ru | 195.128.123.215 | |
www.google.com | 172.217.25.100 |
- UDP Requests
-
-
192.168.56.102:50839 164.124.101.2:53
-
192.168.56.102:57660 164.124.101.2:53
-
192.168.56.102:61459 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:56752 239.255.255.250:1900
-
192.168.56.102:56754 239.255.255.250:3702
-
192.168.56.102:56756 239.255.255.250:3702
-
192.168.56.102:61460 239.255.255.250:3702
-
GET
200
https://www.google.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Host: www.google.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 28 Mar 2021 03:23:58 GMT
Expires: -1
Cache-Control: private, max-age=0
Content-Type: text/html; charset=ISO-8859-1
P3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."
Server: gws
X-XSS-Protection: 0
X-Frame-Options: SAMEORIGIN
Set-Cookie: 1P_JAR=2021-03-28-03; expires=Tue, 27-Apr-2021 03:23:58 GMT; path=/; domain=.google.com; Secure
Set-Cookie: NID=212=aCE7fC2hp5KuWAkO4IJwj8t21OY3C3zEKLiUAdxnTkYc01cNdFEqgwDXSo-LEtu-KKjgHdslI4_u3kwQ5RvMjG1DPeazb3rzIvFsiXiIOruMJw99M8IZIvaoQ0gTuni4AwP6jzbVXR3rNw691jNUeddhHmMF7-OYSiKJQ3Ufic4; expires=Mon, 27-Sep-2021 03:23:58 GMT; path=/; domain=.google.com; HttpOnly
Alt-Svc: h3-29=":443"; ma=2592000,h3-T051=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
Accept-Ranges: none
Vary: Accept-Encoding
Transfer-Encoding: chunked
GET
200
https://www.bing.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Host: www.bing.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: private
Transfer-Encoding: chunked
Content-Type: text/html; charset=utf-8
P3P: CP="NON UNI COM NAV STA LOC CURa DEVa PSAa PSDa OUR IND"
Set-Cookie: MUID=2ACF9F746BE4687A0C508F7C6A4669C4; domain=.bing.com; expires=Fri, 22-Apr-2022 03:23:58 GMT; path=/; secure; SameSite=None
Set-Cookie: MUIDB=2ACF9F746BE4687A0C508F7C6A4669C4; expires=Fri, 22-Apr-2022 03:23:58 GMT; path=/
Set-Cookie: _EDGE_S=F=1&SID=14A2F3BA00C362922DD1E3B201616310; domain=.bing.com; path=/
Set-Cookie: _EDGE_V=1; domain=.bing.com; expires=Fri, 22-Apr-2022 03:23:58 GMT; path=/
Set-Cookie: SRCHD=AF=NOFORM; domain=.bing.com; expires=Tue, 28-Mar-2023 03:23:58 GMT; path=/
Set-Cookie: SRCHUID=V=2&GUID=303970FC2D984FD18A9D967130A8E73D&dmnchg=1; domain=.bing.com; expires=Tue, 28-Mar-2023 03:23:58 GMT; path=/
Set-Cookie: SRCHUSR=DOB=20210328; domain=.bing.com; expires=Tue, 28-Mar-2023 03:23:58 GMT; path=/
Set-Cookie: SRCHHPGUSR=SRCHLANGV2=ko; domain=.bing.com; expires=Tue, 28-Mar-2023 03:23:58 GMT; path=/
Set-Cookie: _SS=SID=14A2F3BA00C362922DD1E3B201616310; domain=.bing.com; path=/
Set-Cookie: ULC=; domain=.bing.com; expires=Sat, 27-Mar-2021 03:23:58 GMT; path=/
Set-Cookie: _HPVN=CS=eyJQbiI6eyJDbiI6MSwiU3QiOjAsIlFzIjowLCJQcm9kIjoiUCJ9LCJTYyI6eyJDbiI6MSwiU3QiOjAsIlFzIjowLCJQcm9kIjoiSCJ9LCJReiI6eyJDbiI6MSwiU3QiOjAsIlFzIjowLCJQcm9kIjoiVCJ9LCJBcCI6dHJ1ZSwiTXV0ZSI6dHJ1ZSwiTGFkIjoiMjAyMS0wMy0yOFQwMDowMDowMFoiLCJJb3RkIjowLCJEZnQiOm51bGwsIk12cyI6MCwiRmx0IjowLCJJbXAiOjF9; domain=.bing.com; expires=Tue, 28-Mar-2023 03:23:58 GMT; path=/
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-MSEdge-Ref: Ref A: B3ADB77A4EC54544AC1A85F1D3FB9680 Ref B: SLAEDGE0706 Ref C: 2021-03-28T03:23:58Z
Date: Sun, 28 Mar 2021 03:23:57 GMT
GET
200
http://orpod.ru/def.exe
REQUEST
RESPONSE
BODY
GET /def.exe HTTP/1.1
Host: orpod.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.16.1
Date: Sun, 28 Mar 2021 03:24:21 GMT
Content-Type: application/octet-stream
Content-Length: 121700
Connection: keep-alive
Last-Modified: Tue, 23 Mar 2021 07:23:12 GMT
ETag: "1db64-5be2f0e160261"
Accept-Ranges: bytes
GET
200
http://orpod.ru/putty.exe
REQUEST
RESPONSE
BODY
GET /putty.exe HTTP/1.1
Host: orpod.ru
HTTP/1.1 200 OK
Server: nginx/1.16.1
Date: Sun, 28 Mar 2021 03:24:22 GMT
Content-Type: application/octet-stream
Content-Length: 156160
Connection: keep-alive
Last-Modified: Tue, 23 Mar 2021 22:59:01 GMT
ETag: "26200-5be3c20cc22f0"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49805 216.58.221.228:443 |
C=US, O=Google Trust Services, CN=GTS CA 1O1 | C=US, ST=California, L=Mountain View, O=Google LLC, CN=www.google.com | 06:cb:c1:ed:3f:d8:18:b6:14:ee:10:02:2a:d8:2b:f3:bf:63:0f:20 |
TLSv1 192.168.56.102:49807 13.107.21.200:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | CN=www.bing.com | dc:c1:ac:40:22:1b:57:e3:9b:c9:2e:d2:eb:9b:a4:53:07:7f:62:f4 |
Snort Alerts
No Snort Alerts