Network Analysis
IP Address | Status | Action | VT | Location |
---|---|---|---|---|
No hosts contacted. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
No traffic
No traffic
No traffic
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.168.204:49224 104.20.6.133:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=t.ly | dc:4a:cc:06:7d:0d:e3:d7:1d:26:4f:60:1d:81:c9:05:99:68:ef:40 |
TLS 1.2 192.168.168.204:49223 104.20.6.133:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=t.ly | dc:4a:cc:06:7d:0d:e3:d7:1d:26:4f:60:1d:81:c9:05:99:68:ef:40 |
TLS 1.2 192.168.168.204:49234 104.21.80.1:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=buthoi.info | 35:0c:51:a0:02:c4:9c:7e:9a:08:53:01:3e:6d:af:ae:22:76:12:fa |
TLS 1.2 192.168.168.204:49233 104.21.80.1:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=buthoi.info | 35:0c:51:a0:02:c4:9c:7e:9a:08:53:01:3e:6d:af:ae:22:76:12:fa |
TLS 1.2 192.168.168.204:49236 172.67.141.239:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=vericaptcha-metahorizonau.org | b9:b3:fe:d9:da:b9:f2:a3:b5:8f:bb:52:d2:1e:7c:5c:59:39:6f:6b |
TLS 1.2 192.168.168.204:49235 172.67.141.239:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=vericaptcha-metahorizonau.org | b9:b3:fe:d9:da:b9:f2:a3:b5:8f:bb:52:d2:1e:7c:5c:59:39:6f:6b |
TLS 1.2 192.168.168.204:49239 216.58.209.170:443 |
C=US, O=Google Trust Services, CN=WR2 | CN=upload.video.google.com | 74:c1:9b:d3:5d:65:ce:2e:7c:cc:41:c0:7c:f9:2c:ab:41:a3:ec:aa |
TLS 1.2 192.168.168.204:49240 216.58.209.170:443 |
C=US, O=Google Trust Services, CN=WR2 | CN=upload.video.google.com | 74:c1:9b:d3:5d:65:ce:2e:7c:cc:41:c0:7c:f9:2c:ab:41:a3:ec:aa |
Snort Alerts
Flow | SID | Message |
---|---|---|
UDP 192.168.168.204:50760 -> 8.8.8.8:53 | 2040135 | ET INFO URL Shortening Service Domain in DNS Lookup (t .ly) |
TCP 192.168.168.204:49224 -> 104.20.6.133:443 | 2040136 | ET INFO Observed URL Shortening Service Domain (t .ly in TLS SNI) |
TCP 192.168.168.204:49223 -> 104.20.6.133:443 | 2040136 | ET INFO Observed URL Shortening Service Domain (t .ly in TLS SNI) |