NetWork | ZeroBOX

Network Analysis

IP Address Status Action
106.15.139.117 Active Moloch
115.238.192.238 Active Moloch
115.238.192.244 Active Moloch
120.27.82.56 Active Moloch
122.225.67.193 Active Moloch
139.129.105.182 Active Moloch
164.124.101.2 Active Moloch
183.136.197.100 Active Moloch
47.117.76.201 Active Moloch
58.218.203.239 Active Moloch
GET 0 https://cdn-ssl-wan.ludashi.com/assets/superjs/pageMicro.js?v=20210527
REQUEST
RESPONSE
GET 0 https://cdn-ssl-wan.ludashi.com/assets/superjs/modules/commonTool.js?v=20210527
REQUEST
RESPONSE
GET 0 https://cdn-ssl-wan.ludashi.com/assets/superjs/modules/commonLoginApi.js?v=20200810
REQUEST
RESPONSE
GET 200 http://cdn-file-ssl-wan.ludashi.com/wan/wan/7z.dll
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=install&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=8ffeb14d433dcc0c2b98a3cf2716c5f4&from=taskpop_sdly&forcetick=2950015
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=7z_noexist&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=31673de8d494f02142e1edb517399942&from=taskpop_sdly&forcetick=2950062
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=7z_download_start&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=faf774bde5506632e0936450a2b05bac&from=taskpop_sdly&forcetick=2950062
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=7z_download_success&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=222806ca1968aee2104845ac0bb1e961&from=taskpop_sdly&forcetick=2950546
REQUEST
RESPONSE
GET 200 http://cdn-file-ssl-pc.ludashi.com/pc/cef/CefRes.dll?t=202106142055
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=res_down_success&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=c8bafc2df3f18850e666c570733e30ee&from=taskpop_sdly&forcetick=2964062
REQUEST
RESPONSE
GET 200 http://cdn-file-ssl-wan.ludashi.com/pc/game/flash/pepflashplayer.7z?t=202106142055
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=pepflash_down_success&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=1eb066f8aee684651bb6886e75ddddec&from=taskpop_sdly&forcetick=2966453
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=add_uninst_item&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=90fc48554d411fc4bdbd8c4cba5dcac7&from=taskpop_sdly&forcetick=2966703
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=add_desk_icon&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=29e0f6a694aea37940ed2c0d91f5f3c5&from=taskpop_sdly&forcetick=2966750
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=install_extra&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=bda3e2d3873bc6b8751a06ecfa64faa6&from=taskpop_sdly&forcetick=2971046
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=inst_open&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=76d90940607a4e1fc8c4e780c107c434&from=taskpop_sdly&forcetick=2971046
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=wd_install_success&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=9816a49d782b4cc6abf68cd3e4f25e57&from=taskpop_sdly&forcetick=2976109
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=inst_succ&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=9326e042414b37b0a465d68435568572&from=taskpop_sdly&forcetick=2976109
REQUEST
RESPONSE
GET 200 http://wan.ludashi.com/micro/sdly/index_lds.html?channel=taskpop&from=taskpop_wd_sdly
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=run&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=bb1adc4f55a84cf7c0830a76e4cfec69&from=taskpop_sdly&forcetick=2978593
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=wd_show_success&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=a77a4190d391498058b650400ce279b4&from=taskpop_sdly&forcetick=2979031
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=weiduan&action=main_show&channel=taskpop&mid=fa7bb520099706f4d9615c3663eacc55&mid2=c2a9b458c8eb84d52f3369329facb48b9ff9f7ac2b54&uid=d&appver=&modver=3.2.5.61&sign=5ecbfcbcece4eea0291ea4146880caf7&from=taskpop_sdly&forcetick=2979031
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/upload.jpg
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/main.css
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/assets/jquery/jquery183.js
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/assets/sea/sea.js
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/bg.jpg
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/nav.png
REQUEST
RESPONSE
GET 200 http://cdn-wan.ludashi.com/assets/superjs/config.js?v=20210527
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/news-bg.png
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/log_btn.png
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/reg.jpg?t=20200105
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/input_reg_act.png?t=20191021
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/input_reg_pwd.png?t=20191021
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/input_reg_code.png?t=20191021
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/checkbox.png
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/third_qq.png
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/third_weixin.png
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/login_tit.png
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/input_log_act.png?t=20191021
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/input_log_pwd.png?t=20191021
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/input_log_code.png?t=20191021
REQUEST
RESPONSE
POST 200 http://wan.ludashi.com/api/CheckGameStatus?callback=jQuery18308462895474002294_1623672818021
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=accurate&action=t0&channel=taskpop&from=taskpop_wd_sdly&mid=fa7bb520099706f4d9615c3663eacc55&appver=3.2.5.61&uid=0&game=sdly&timestamp=1623672819149&ex_ary[guid]=
REQUEST
RESPONSE
GET 200 http://wan.ludashi.com/announce/list?callback=jQuery18308462895474002294_1623672818022&type=2&gid=sdly&skip=0&num=5&_=1623672819146
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/cir.png
REQUEST
RESPONSE
GET 200 http://i.ludashi.com/ajax/gettoken?user_from=youxi&callback=jQuery18308462895474002294_1623672818022&_=1623672819545
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=accurate&action=t1&channel=taskpop&from=taskpop_wd_sdly&mid=fa7bb520099706f4d9615c3663eacc55&appver=3.2.5.61&uid=0&game=sdly&timestamp=1623672829177&ex_ary[guid]=
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=accurate&action=t2&channel=taskpop&from=taskpop_wd_sdly&mid=fa7bb520099706f4d9615c3663eacc55&appver=3.2.5.61&uid=0&game=sdly&timestamp=1623672849175&ex_ary[guid]=
REQUEST
RESPONSE
GET 200 http://cdn-file.ludashi.com/wan/micro/sdly/assets_lds/v1/log_btn_h.png
REQUEST
RESPONSE
GET 200 http://s.ludashi.com/wan?type=accurate&action=t3&channel=taskpop&from=taskpop_wd_sdly&mid=fa7bb520099706f4d9615c3663eacc55&appver=3.2.5.61&uid=0&game=sdly&timestamp=1623672879174&ex_ary[guid]=
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 115.238.192.244:80 -> 192.168.56.101:49199 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 183.136.197.100:80 -> 192.168.56.101:49206 2014819 ET INFO Packed Executable Download Misc activity
TCP 183.136.197.100:80 -> 192.168.56.101:49206 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 183.136.197.100:80 -> 192.168.56.101:49206 2015744 ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging) Misc activity
TCP 192.168.56.101:49225 -> 115.238.192.238:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49225
115.238.192.238:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL RSA CA 2018 CN=*.ludashi.com de:bb:03:64:46:22:7a:b6:88:99:ca:90:fc:d7:1b:f7:af:40:25:e3

Snort Alerts

No Snort Alerts