分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
URL | win7-sp1-x64-shaapp03-2 | 2021-04-20 15:40:18 | 2021-04-20 15:42:22 | 124 秒 |
无主机纪录.
Name: None Country: None State: None City: None ZIP Code: None Address: None Orginization: None Domain Name(s): MSAUTH.NET Creation Date: 2018-10-25 18:11:25 Updated Date: 2020-09-23 09:29:07 Expiration Date: 2021-10-25 18:11:25 Email(s): abusecomplaints@markmonitor.com Registrar(s): MarkMonitor Inc. Name Server(s): A1-115.AKAM.NET A28-64.AKAM.NET A5-65.AKAM.NET A9-66.AKAM.NET NS1-05.AZURE-DNS.COM NS2-05.AZURE-DNS.NET NS3-05.AZURE-DNS.ORG NS4-05.AZURE-DNS.INFO Referral URL(s): None
无主机纪录.
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 49159 | 152.199.40.6 logincdn.msauth.net | 443 |
192.168.122.202 | 49160 | 23.203.63.170 acroipm.adobe.com | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 50785 | 192.168.122.1 | 53 |
192.168.122.202 | 61239 | 192.168.122.1 | 53 |
192.168.122.202 | 62960 | 192.168.122.1 | 53 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 49159 | 152.199.40.6 logincdn.msauth.net | 443 |
192.168.122.202 | 49160 | 23.203.63.170 acroipm.adobe.com | 80 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 50785 | 192.168.122.1 | 53 |
192.168.122.202 | 61239 | 192.168.122.1 | 53 |
192.168.122.202 | 62960 | 192.168.122.1 | 53 |
URI | HTTP数据 |
---|---|
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip | GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1 Accept: */* If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT User-Agent: IPM Host: acroipm.adobe.com Connection: Keep-Alive Cache-Control: no-cache |
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Version | Issuer | Subject | Fingerprint |
---|---|---|---|---|---|---|---|---|
2021-04-20 15:40:36.500775+0800 | 192.168.122.202 | 49159 | 152.199.40.6 | 443 | TLS 1.2 | C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA | C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=identitycdn.msauth.net | 9d:e3:cc:fb:3f:16:5c:57:72:b6:61:50:3d:8d:ab:1a:23:36:2a:62 |
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 631526 |
---|---|
Mongo ID | 607e86077e769a0f6f493c63 |
Cuckoo release | 1.4-Maldun |