分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
URL | win7-sp1-x64-hpdapp01-1 | 2020-02-18 06:02:46 | 2020-02-18 06:05:02 | 136 秒 |
URL |
---|
URL专业沙箱检测 -> http://www.kmplayer.com/ |
无主机纪录.
Name: None Country: None State: None City: None ZIP Code: None Address: None Orginization: None Domain Name(s): KMPLAYER.COM Creation Date: 2003-08-28 00:28:43 Updated Date: 2019-06-11 10:55:12 Expiration Date: 2020-08-28 00:28:43 Email(s): abuse@yesnic.com Registrar(s): Whois Corp. Name Server(s): N1.KMPMEDIA.NET N2.KMPMEDIA.NET N5.PANDORA.TV N6.PANDORA.TV N7.PANDORA.TV Referral URL(s): None
无主机纪录.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49167 | 104.17.64.4 cdnjs.cloudflare.com | 80 |
192.168.122.201 | 49160 | 110.45.195.236 www.kmplayer.com | 80 |
192.168.122.201 | 49174 | 114.31.33.45 vplayer.dawin.tv | 80 |
192.168.122.201 | 49175 | 14.0.44.208 wing.kmplayer.com | 80 |
192.168.122.201 | 49176 | 14.128.1.165 cdn.kmplayer.com | 80 |
192.168.122.201 | 49177 | 14.128.1.165 cdn.kmplayer.com | 80 |
192.168.122.201 | 49171 | 203.208.39.227 imasdk.googleapis.com | 80 |
192.168.122.201 | 49169 | 203.208.43.109 pagead2.googlesyndication.com | 80 |
192.168.122.201 | 49170 | 203.208.43.109 pagead2.googlesyndication.com | 443 |
192.168.122.201 | 49173 | 203.208.50.190 www.googletagmanager.com | 443 |
192.168.122.201 | 49168 | 203.208.50.77 securepubads.g.doubleclick.net | 443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49310 | 192.168.122.1 | 53 |
192.168.122.201 | 49608 | 192.168.122.1 | 53 |
192.168.122.201 | 49749 | 192.168.122.1 | 53 |
192.168.122.201 | 51856 | 192.168.122.1 | 53 |
192.168.122.201 | 58897 | 192.168.122.1 | 53 |
192.168.122.201 | 60905 | 192.168.122.1 | 53 |
192.168.122.201 | 62594 | 192.168.122.1 | 53 |
192.168.122.201 | 63681 | 192.168.122.1 | 53 |
192.168.122.201 | 64155 | 192.168.122.1 | 53 |
192.168.122.201 | 64725 | 192.168.122.1 | 53 |
192.168.122.201 | 64912 | 192.168.122.1 | 53 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49167 | 104.17.64.4 cdnjs.cloudflare.com | 80 |
192.168.122.201 | 49160 | 110.45.195.236 www.kmplayer.com | 80 |
192.168.122.201 | 49174 | 114.31.33.45 vplayer.dawin.tv | 80 |
192.168.122.201 | 49175 | 14.0.44.208 wing.kmplayer.com | 80 |
192.168.122.201 | 49176 | 14.128.1.165 cdn.kmplayer.com | 80 |
192.168.122.201 | 49177 | 14.128.1.165 cdn.kmplayer.com | 80 |
192.168.122.201 | 49171 | 203.208.39.227 imasdk.googleapis.com | 80 |
192.168.122.201 | 49169 | 203.208.43.109 pagead2.googlesyndication.com | 80 |
192.168.122.201 | 49170 | 203.208.43.109 pagead2.googlesyndication.com | 443 |
192.168.122.201 | 49173 | 203.208.50.190 www.googletagmanager.com | 443 |
192.168.122.201 | 49168 | 203.208.50.77 securepubads.g.doubleclick.net | 443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49310 | 192.168.122.1 | 53 |
192.168.122.201 | 49608 | 192.168.122.1 | 53 |
192.168.122.201 | 49749 | 192.168.122.1 | 53 |
192.168.122.201 | 51856 | 192.168.122.1 | 53 |
192.168.122.201 | 58897 | 192.168.122.1 | 53 |
192.168.122.201 | 60905 | 192.168.122.1 | 53 |
192.168.122.201 | 62594 | 192.168.122.1 | 53 |
192.168.122.201 | 63681 | 192.168.122.1 | 53 |
192.168.122.201 | 64155 | 192.168.122.1 | 53 |
192.168.122.201 | 64725 | 192.168.122.1 | 53 |
192.168.122.201 | 64912 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://www.kmplayer.com/ | GET / HTTP/1.1 Accept: */* Accept-Language: zh-cn User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: www.kmplayer.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js | GET /pagead/js/adsbygoogle.js HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: pagead2.googlesyndication.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://imasdk.googleapis.com/js/sdkloader/ima3.js | GET /js/sdkloader/ima3.js HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: imasdk.googleapis.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://cdnjs.cloudflare.com/ajax/libs/mobile-detect/1.3.1/mobile-detect.min.js | GET /ajax/libs/mobile-detect/1.3.1/mobile-detect.min.js HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: cdnjs.cloudflare.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://vplayer.dawin.tv/js/kmp/dawinapi.js | GET /js/kmp/dawinapi.js HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: vplayer.dawin.tv Connection: Keep-Alive |
URL专业沙箱检测 -> http://wing.kmplayer.com/static/js/mezzo/ad_movie_script_kmplayer.js | GET /static/js/mezzo/ad_movie_script_kmplayer.js HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: wing.kmplayer.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://cdn.kmplayer.com/KMP/static/js/global/player/kmp-videoSet.min.js?v=0.023 | GET /KMP/static/js/global/player/kmp-videoSet.min.js?v=0.023 HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: cdn.kmplayer.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://cdn.kmplayer.com/KMP/static/js/global/player/kmp-ptvAdPlayer.min.js?v=0.023 | GET /KMP/static/js/global/player/kmp-ptvAdPlayer.min.js?v=0.023 HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: cdn.kmplayer.com Connection: Keep-Alive |
URL专业沙箱检测 -> http://cdn.kmplayer.com/KMP/static/js/global/player/kmp-ptvPlayer.min.js?v=0.023 | GET /KMP/static/js/global/player/kmp-ptvPlayer.min.js?v=0.023 HTTP/1.1 Accept: */* Referer: http://www.kmplayer.com/ Accept-Language: zh-CN User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Accept-Encoding: gzip, deflate Host: cdn.kmplayer.com Connection: Keep-Alive |
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Version | Issuer | Subject | Fingerprint |
---|---|---|---|---|---|---|---|---|
2020-02-18 06:03:17.737487+0800 | 192.168.122.201 | 49173 | 203.208.50.190 | 443 | TLS 1.2 | C=US, O=Google Trust Services, CN=GTS CA 1O1 | C=US, ST=California, L=Mountain View, O=Google LLC, CN=*.google-analytics.com | 39:1d:ad:44:1c:36:67:ba:75:49:38:a0:61:01:66:c6:c6:17:6f:60 |
2020-02-18 06:03:17.692070+0800 | 192.168.122.201 | 49168 | 203.208.50.77 | 443 | TLS 1.2 | C=US, O=Google Trust Services, CN=GTS CA 1O1 | C=US, ST=California, L=Mountain View, O=Google LLC, CN=*.g.doubleclick.net | 30:d1:1e:75:f6:bc:a3:40:4a:8d:3e:46:c8:b8:ac:5b:a3:50:16:aa |
2020-02-18 06:03:17.689597+0800 | 192.168.122.201 | 49170 | 203.208.43.109 | 443 | TLS 1.2 | C=US, O=Google Trust Services, CN=GTS CA 1O1 | C=US, ST=California, L=Mountain View, O=Google LLC, CN=*.g.doubleclick.net | 30:d1:1e:75:f6:bc:a3:40:4a:8d:3e:46:c8:b8:ac:5b:a3:50:16:aa |
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 512434 |
---|---|
Mongo ID | 5e4b0e332f8f2e0dfb6c6da7 |
Cuckoo release | 1.4-Maldun |