Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
mofa-gov-pk.dowmload.info | 213.183.55.169 | |
x1.i.lencr.org | 23.207.177.83 |
- TCP Requests
-
-
192.168.56.101:49163 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49165 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49167 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49169 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49170 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49171 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49172 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49173 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49174 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49175 213.183.55.169:443mofa-gov-pk.dowmload.info
-
192.168.56.101:49164 23.41.113.9:80x1.i.lencr.org
-
GET
200
http://x1.i.lencr.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: x1.i.lencr.org
HTTP/1.1 200 OK
Server: nginx
Content-Type: application/pkix-cert
Last-Modified: Fri, 04 Aug 2023 20:57:56 GMT
ETag: "64cd6654-56f"
Content-Disposition: attachment; filename="ISRG Root X1.der"
Cache-Control: max-age=29049
Expires: Thu, 08 Aug 2024 15:12:16 GMT
Date: Thu, 08 Aug 2024 07:08:07 GMT
Content-Length: 1391
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49172 213.183.55.169:443 |
C=US, O=Let's Encrypt, CN=R10 | CN=*.dowmload.info | 05:35:10:77:9e:f0:88:c6:11:08:90:96:77:42:1f:e3:52:23:4e:1b |
TLSv1 192.168.56.101:49175 213.183.55.169:443 |
None | None | None |
TLSv1 192.168.56.101:49171 213.183.55.169:443 |
C=US, O=Let's Encrypt, CN=R10 | CN=*.dowmload.info | 05:35:10:77:9e:f0:88:c6:11:08:90:96:77:42:1f:e3:52:23:4e:1b |
TLSv1 192.168.56.101:49165 213.183.55.169:443 |
C=US, O=Let's Encrypt, CN=R10 | CN=*.dowmload.info | 05:35:10:77:9e:f0:88:c6:11:08:90:96:77:42:1f:e3:52:23:4e:1b |
TLSv1 192.168.56.101:49163 213.183.55.169:443 |
C=US, O=Let's Encrypt, CN=R10 | CN=*.dowmload.info | 05:35:10:77:9e:f0:88:c6:11:08:90:96:77:42:1f:e3:52:23:4e:1b |
TLSv1 192.168.56.101:49169 213.183.55.169:443 |
None | None | None |
TLSv1 192.168.56.101:49170 213.183.55.169:443 |
None | None | None |
TLSv1 192.168.56.101:49167 213.183.55.169:443 |
C=US, O=Let's Encrypt, CN=R10 | CN=*.dowmload.info | 05:35:10:77:9e:f0:88:c6:11:08:90:96:77:42:1f:e3:52:23:4e:1b |
TLSv1 192.168.56.101:49173 213.183.55.169:443 |
None | None | None |
TLSv1 192.168.56.101:49174 213.183.55.169:443 |
None | None | None |
Snort Alerts
No Snort Alerts