分析类型 | 虚拟机标签 | 开始时间 | 结束时间 | 持续时间 |
---|---|---|---|---|
URL | win7-sp1-x64-hpdapp01-2 | 2018-11-17 10:07:57 | 2018-11-17 10:10:22 | 145 秒 |
URL |
---|
URL专业沙箱检测 -> https://www.lanzous.com/i2e5q8f |
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
否 | 106.11.250.81 | 中国 | |
否 | 117.91.192.216 | 中国 | |
否 | 203.119.206.95 | 中国 | |
否 | 58.218.215.120 | 中国 | |
否 | 58.218.215.188 | 中国 |
域名 | 安全评级 | 响应 |
---|---|---|
www.lanzous.com |
A 117.91.192.216 CNAME www.lanzous.com.scdno5zl.com |
|
s95.cnzz.com |
A 58.218.215.120 A 58.218.215.188 CNAME all.cnzz.com.danuoyi.tbcache.com CNAME c.cnzz.com |
|
z4.cnzz.com |
CNAME z.cnzz.com CNAME z.gds.cnzz.com A 203.119.206.95 |
|
c.cnzz.com | ||
cnzz.mmstat.com |
A 106.11.250.81 CNAME gm.gds.mmstat.com CNAME gm.mmstat.com |
Name: None Country: None State: Shan Dong City: None ZIP Code: None Address: None Orginization: None Domain Name(s): LANZOUS.COM lanzous.com Creation Date: 2018-02-25 02:24:45 Updated Date: 2018-05-17 03:36:56 Expiration Date: 2019-02-25 02:24:45 Email(s): DomainAbuse@service.aliyun.com Registrar(s): Alibaba Cloud Computing (Beijing) Co., Ltd. Name Server(s): F1G1NS1.DNSPOD.NET F1G1NS2.DNSPOD.NET Referral URL(s): None
直接 | IP | 安全评级 | 地理位置 |
---|---|---|---|
否 | 106.11.250.81 | 中国 | |
否 | 117.91.192.216 | 中国 | |
否 | 203.119.206.95 | 中国 | |
否 | 58.218.215.120 | 中国 | |
否 | 58.218.215.188 | 中国 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 49165 | 106.11.250.81 cnzz.mmstat.com | 443 |
192.168.122.202 | 49159 | 117.91.192.216 www.lanzous.com | 443 |
192.168.122.202 | 49160 | 117.91.192.216 www.lanzous.com | 443 |
192.168.122.202 | 49164 | 117.91.192.216 www.lanzous.com | 443 |
192.168.122.202 | 49162 | 203.119.206.95 z4.cnzz.com | 443 |
192.168.122.202 | 49163 | 58.218.215.120 s95.cnzz.com | 443 |
192.168.122.202 | 49161 | 58.218.215.188 s95.cnzz.com | 443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 51869 | 192.168.122.1 | 53 |
192.168.122.202 | 58377 | 192.168.122.1 | 53 |
192.168.122.202 | 61145 | 192.168.122.1 | 53 |
192.168.122.202 | 63417 | 192.168.122.1 | 53 |
192.168.122.202 | 65070 | 192.168.122.1 | 53 |
域名 | 安全评级 | 响应 |
---|---|---|
www.lanzous.com |
A 117.91.192.216 CNAME www.lanzous.com.scdno5zl.com |
|
s95.cnzz.com |
A 58.218.215.120 A 58.218.215.188 CNAME all.cnzz.com.danuoyi.tbcache.com CNAME c.cnzz.com |
|
z4.cnzz.com |
CNAME z.cnzz.com CNAME z.gds.cnzz.com A 203.119.206.95 |
|
c.cnzz.com | ||
cnzz.mmstat.com |
A 106.11.250.81 CNAME gm.gds.mmstat.com CNAME gm.mmstat.com |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 49165 | 106.11.250.81 cnzz.mmstat.com | 443 |
192.168.122.202 | 49159 | 117.91.192.216 www.lanzous.com | 443 |
192.168.122.202 | 49160 | 117.91.192.216 www.lanzous.com | 443 |
192.168.122.202 | 49164 | 117.91.192.216 www.lanzous.com | 443 |
192.168.122.202 | 49162 | 203.119.206.95 z4.cnzz.com | 443 |
192.168.122.202 | 49163 | 58.218.215.120 s95.cnzz.com | 443 |
192.168.122.202 | 49161 | 58.218.215.188 s95.cnzz.com | 443 |
源地址 | 源端口 | 目标地址 | 目标端口 |
---|---|---|---|
192.168.122.202 | 51869 | 192.168.122.1 | 53 |
192.168.122.202 | 58377 | 192.168.122.1 | 53 |
192.168.122.202 | 61145 | 192.168.122.1 | 53 |
192.168.122.202 | 63417 | 192.168.122.1 | 53 |
192.168.122.202 | 65070 | 192.168.122.1 | 53 |
未发现HTTP请求.
无SMTP流量.
无IRC请求.
无ICMP流量.
无 CIF 结果
无警报
Timestamp | Source IP | Source Port | Destination IP | Destination Port | Version | Issuer | Subject | Fingerprint |
---|---|---|---|---|---|---|---|---|
2018-11-17 10:08:28.470769+0800 | 192.168.122.202 | 49161 | 58.218.215.188 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 66:4d:a5:95:02:54:b9:fe:f9:7c:1e:ed:cb:24:ad:d8:5b:8a:06:42 |
2018-11-17 10:08:30.474742+0800 | 192.168.122.202 | 49162 | 203.119.206.95 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 66:4d:a5:95:02:54:b9:fe:f9:7c:1e:ed:cb:24:ad:d8:5b:8a:06:42 |
2018-11-17 10:08:30.469566+0800 | 192.168.122.202 | 49163 | 58.218.215.120 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.cnzz.com | 66:4d:a5:95:02:54:b9:fe:f9:7c:1e:ed:cb:24:ad:d8:5b:8a:06:42 |
2018-11-17 10:08:26.323841+0800 | 192.168.122.202 | 49159 | 117.91.192.216 | 443 | TLS 1.2 | C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Domain Validation Secure Server CA | OU=Domain Control Validated, OU=PositiveSSL Wildcard, CN=*.lanzous.com | 85:61:5c:04:6a:ed:81:fd:12:a0:17:e8:ee:d0:38:65:1d:5f:58:54 |
2018-11-17 10:08:33.933090+0800 | 192.168.122.202 | 49165 | 106.11.250.81 | 443 | TLS 1.2 | C=BE, O=GlobalSign nv-sa, CN=GlobalSign Organization Validation CA - SHA256 - G2 | C=CN, ST=ZheJiang, L=HangZhou, O=Alibaba (China) Technology Co., Ltd., CN=*.mmstat.com | 0f:95:1d:03:5e:e7:ba:8e:ff:76:f9:b4:41:c1:1f:15:7d:67:24:7b |
No Suricata HTTP
HTML 总结报告 (需15-60分钟同步) |
下载 |
---|
Task ID | 214518 |
---|---|
Mongo ID | 5bef78b02e06331156ecd27b |
Cuckoo release | 1.4-Maldun |