Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
d-wave.duckdns.org | 156.96.119.123 | |
dyn-bin.duckdns.org | 23.146.242.85 |
GET
200
http://dyn-bin.duckdns.org/remcos_d_fIqfwC80.bin
REQUEST
RESPONSE
BODY
GET /remcos_d_fIqfwC80.bin HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Host: dyn-bin.duckdns.org
Cache-Control: no-cache
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Sun, 22 Aug 2021 22:52:27 GMT
Accept-Ranges: bytes
ETag: "c4744661a897d71:0"
Server: Microsoft-IIS/8.5
Date: Mon, 06 Sep 2021 23:28:28 GMT
Content-Length: 469056
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.102:52336 -> 164.124.101.2:53 | 2022918 | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain | Misc activity |
UDP 192.168.56.102:64995 -> 164.124.101.2:53 | 2022918 | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain | Misc activity |
TCP 156.96.119.123:1144 -> 192.168.56.102:49171 | 2400015 | ET DROP Spamhaus DROP Listed Traffic Inbound group 16 | Misc Attack |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts