分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
URL | win7-sp1-x64-shaapp03-1 | 2021-04-16 20:49:11 | 2021-04-16 20:51:15 | 124 秒 |
URL |
---|
URL专业沙箱检测 -> https://www.lanzous.com/b015a47le |
无主机纪录.
域名 | 安全评级 | 响应 |
---|---|---|
www.lanzous.com |
A 124.225.134.229 A 124.225.134.224 A 124.225.134.225 CNAME all.lanzous.com.w.kunluncan.com A 124.225.134.227 A 124.225.134.226 A 124.225.134.231 A 124.225.134.228 A 124.225.134.230 |
|
s4.cnzz.com |
A 58.215.157.250 CNAME all.cnzz.com.danuoyi.tbcache.com CNAME c.cnzz.com |
|
s95.cnzz.com | ||
z11.cnzz.com |
CNAME z.cnzz.com A 203.119.213.181 CNAME z.gds.cnzz.com |
|
c.cnzz.com | ||
cnzz.mmstat.com |
A 106.11.251.76 CNAME gm.gds.mmstat.com CNAME gm.mmstat.com |
|
z4.cnzz.com | ||
acroipm.adobe.com |
CNAME a1983.dscd.akamai.net CNAME acroipm.adobe.com.edgesuite.net A 23.220.167.49 A 23.220.167.35 |
Name: None Country: CN State: Shan Dong City: None ZIP Code: None Address: None Orginization: None Domain Name(s): LANZOUS.COM lanzous.com Creation Date: 2018-02-25 02:24:45 Updated Date: 2021-02-26 04:26:05 Expiration Date: 2022-02-25 02:24:45 Email(s): DomainAbuse@service.aliyun.com Registrar(s): Alibaba Cloud Computing (Beijing) Co., Ltd. Name Server(s): F1G1NS1.DNSPOD.NET F1G1NS2.DNSPOD.NET Referral URL(s): None
无主机纪录.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49164 | 106.11.251.76 cnzz.mmstat.com | 443 |
192.168.122.201 | 49165 | 106.11.251.76 cnzz.mmstat.com | 443 |
192.168.122.201 | 49159 | 124.225.134.224 www.lanzous.com | 443 |
192.168.122.201 | 49163 | 203.119.213.181 z11.cnzz.com | 443 |
192.168.122.201 | 49166 | 203.119.213.181 z11.cnzz.com | 443 |
192.168.122.201 | 49167 | 23.220.167.35 acroipm.adobe.com | 80 |
192.168.122.201 | 49160 | 58.215.157.250 s4.cnzz.com | 443 |
192.168.122.201 | 49161 | 58.215.157.250 s4.cnzz.com | 443 |
192.168.122.201 | 49162 | 58.215.157.250 s4.cnzz.com | 443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 52179 | 192.168.122.1 | 53 |
192.168.122.201 | 52207 | 192.168.122.1 | 53 |
192.168.122.201 | 53125 | 192.168.122.1 | 53 |
192.168.122.201 | 56270 | 192.168.122.1 | 53 |
192.168.122.201 | 59401 | 192.168.122.1 | 53 |
192.168.122.201 | 59906 | 192.168.122.1 | 53 |
192.168.122.201 | 65178 | 192.168.122.1 | 53 |
192.168.122.201 | 65179 | 192.168.122.1 | 53 |
域名 | 安全评级 | 响应 |
---|---|---|
www.lanzous.com |
A 124.225.134.229 A 124.225.134.224 A 124.225.134.225 CNAME all.lanzous.com.w.kunluncan.com A 124.225.134.227 A 124.225.134.226 A 124.225.134.231 A 124.225.134.228 A 124.225.134.230 |
|
s4.cnzz.com |
A 58.215.157.250 CNAME all.cnzz.com.danuoyi.tbcache.com CNAME c.cnzz.com |
|
s95.cnzz.com | ||
z11.cnzz.com |
CNAME z.cnzz.com A 203.119.213.181 CNAME z.gds.cnzz.com |
|
c.cnzz.com | ||
cnzz.mmstat.com |
A 106.11.251.76 CNAME gm.gds.mmstat.com CNAME gm.mmstat.com |
|
z4.cnzz.com | ||
acroipm.adobe.com |
CNAME a1983.dscd.akamai.net CNAME acroipm.adobe.com.edgesuite.net A 23.220.167.49 A 23.220.167.35 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 49164 | 106.11.251.76 cnzz.mmstat.com | 443 |
192.168.122.201 | 49165 | 106.11.251.76 cnzz.mmstat.com | 443 |
192.168.122.201 | 49159 | 124.225.134.224 www.lanzous.com | 443 |
192.168.122.201 | 49163 | 203.119.213.181 z11.cnzz.com | 443 |
192.168.122.201 | 49166 | 203.119.213.181 z11.cnzz.com | 443 |
192.168.122.201 | 49167 | 23.220.167.35 acroipm.adobe.com | 80 |
192.168.122.201 | 49160 | 58.215.157.250 s4.cnzz.com | 443 |
192.168.122.201 | 49161 | 58.215.157.250 s4.cnzz.com | 443 |
192.168.122.201 | 49162 | 58.215.157.250 s4.cnzz.com | 443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.201 | 52179 | 192.168.122.1 | 53 |
192.168.122.201 | 52207 | 192.168.122.1 | 53 |
192.168.122.201 | 53125 | 192.168.122.1 | 53 |
192.168.122.201 | 56270 | 192.168.122.1 | 53 |
192.168.122.201 | 59401 | 192.168.122.1 | 53 |
192.168.122.201 | 59906 | 192.168.122.1 | 53 |
192.168.122.201 | 65178 | 192.168.122.1 | 53 |
192.168.122.201 | 65179 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Version | Issuer | Subject | Fingerprint |
---|---|---|---|---|---|---|---|---|
2021-04-16 20:49:30.838849+0800 | 192.168.122.201 | 49160 | 58.215.157.250 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 79:58:35:0e:31:d2:98:03:51:0c:9b:c1:52:dc:09:26:c7:fd:40:0f |
2021-04-16 20:49:30.831595+0800 | 192.168.122.201 | 49161 | 58.215.157.250 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 79:58:35:0e:31:d2:98:03:51:0c:9b:c1:52:dc:09:26:c7:fd:40:0f |
2021-04-16 20:49:31.254169+0800 | 192.168.122.201 | 49166 | 203.119.213.181 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 79:58:35:0e:31:d2:98:03:51:0c:9b:c1:52:dc:09:26:c7:fd:40:0f |
2021-04-16 20:49:30.147366+0800 | 192.168.122.201 | 49159 | 124.225.134.224 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=AlphaSSL CA - SHA256 - G2 | CN=*.lanzous.com | 63:12:9d:5e:91:6e:b9:97:17:f2:23:b0:41:d0:b4:a2:f1:83:8a:4c |
2021-04-16 20:49:31.153290+0800 | 192.168.122.201 | 49165 | 106.11.251.76 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.mmstat.com | 1c:32:2c:16:1b:08:b7:c6:0a:0e:fd:4e:76:f6:1a:cf:d3:05:e6:d1 |
2021-04-16 20:49:31.060498+0800 | 192.168.122.201 | 49163 | 203.119.213.181 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 79:58:35:0e:31:d2:98:03:51:0c:9b:c1:52:dc:09:26:c7:fd:40:0f |
2021-04-16 20:49:31.014053+0800 | 192.168.122.201 | 49162 | 58.215.157.250 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 79:58:35:0e:31:d2:98:03:51:0c:9b:c1:52:dc:09:26:c7:fd:40:0f |
2021-04-16 20:49:31.117697+0800 | 192.168.122.201 | 49164 | 106.11.251.76 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.mmstat.com | 1c:32:2c:16:1b:08:b7:c6:0a:0e:fd:4e:76:f6:1a:cf:d3:05:e6:d1 |
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 630873 |
---|---|
Mongo ID | 6079885f7e769a5b9f0d6d85 |
Cuckoo release | 1.4-Maldun |