Network Analysis
IP Address | Status | Action |
---|---|---|
131.188.40.189 | Active | Moloch |
141.255.162.34 | Active | Moloch |
149.56.45.200 | Active | Moloch |
164.124.101.2 | Active | Moloch |
185.215.113.93 | Active | Moloch |
212.83.168.196 | Active | Moloch |
45.66.156.176 | Active | Moloch |
5.196.71.24 | Active | Moloch |
51.195.253.209 | Active | Moloch |
83.212.103.129 | Active | Moloch |
86.59.21.38 | Active | Moloch |
95.217.42.50 | Active | Moloch |
Name | Response | Post-Analysis Lookup |
---|---|---|
api.wipmania.com | 212.83.168.196 |
- TCP Requests
-
-
192.168.56.101:49215 131.188.40.189:443
-
192.168.56.101:49216 149.56.45.200:9030
-
192.168.56.101:49200 185.215.113.93:80
-
192.168.56.101:49211 185.215.113.93:80
-
192.168.56.101:49204 212.83.168.196:80api.wipmania.com
-
192.168.56.101:49207 212.83.168.196:80api.wipmania.com
-
192.168.56.101:49217 5.196.71.24:9001
-
192.168.56.101:49218 51.195.253.209:9001
-
192.168.56.101:49219 83.212.103.129:44933
-
192.168.56.101:49212 86.59.21.38:80
-
- UDP Requests
-
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
192.168.56.101:62331 239.255.255.250:3702
-
192.168.56.101:62333 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
http://185.215.113.93/pepwn.exe
REQUEST
RESPONSE
BODY
GET /pepwn.exe HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
Host: 185.215.113.93
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 04 May 2021 04:46:58 GMT
Content-Type: application/octet-stream
Content-Length: 102912
Last-Modified: Sun, 02 May 2021 20:35:10 GMT
Connection: keep-alive
ETag: "608f0cfe-19200"
Accept-Ranges: bytes
GET
200
http://api.wipmania.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
Host: api.wipmania.com
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 04 May 2021 04:47:05 GMT
Content-Type: text/html
Content-Length: 21
Connection: keep-alive
Keep-Alive: timeout=20
GET
200
http://api.wipmania.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
Host: api.wipmania.com
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 04 May 2021 04:47:19 GMT
Content-Type: text/html
Content-Length: 21
Connection: keep-alive
Keep-Alive: timeout=20
GET
200
http://185.215.113.93/cc11
REQUEST
RESPONSE
BODY
GET /cc11 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36
Host: 185.215.113.93
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 04 May 2021 04:47:29 GMT
Content-Type: application/octet-stream
Content-Length: 103432
Last-Modified: Sun, 02 May 2021 18:15:21 GMT
Connection: keep-alive
ETag: "608eec39-19408"
Accept-Ranges: bytes
GET
200
http://86.59.21.38/tor/status-vote/current/consensus.z
REQUEST
RESPONSE
BODY
GET /tor/status-vote/current/consensus.z HTTP/1.1
Cache-Control: no-cache
Accept-Encoding: gzip
Host: 86.59.21.38
Connection: Close
HTTP/1.0 200 OK
Date: Tue, 04 May 2021 04:47:48 GMT
Content-Type: text/plain
X-Your-Address-Is: 175.208.134.150
Content-Encoding: deflate
Expires: Tue, 04 May 2021 05:00:00 GMT
Vary: X-Or-Diff-From-Consensus
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
95.217.42.50 | 192.168.56.101 | 3 | |
95.217.42.50 | 192.168.56.101 | 3 | |
95.217.42.50 | 192.168.56.101 | 3 |
IRC traffic
Command | Params | Type |
---|---|---|
CONNECT | %s:%s HTTP/1.0 | client |
CONNECT | %s:%s HTTP/1.1 | client |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49219 83.212.103.129:44933 |
CN=www.ftov32jlnn.com | CN=www.4yohmszal2vz7bh.net | 49:b6:3f:00:11:f7:04:03:0c:a2:73:1e:c6:30:cd:24:66:bc:62:8e |
Snort Alerts
No Snort Alerts