Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
prodownload.live | 74.208.236.24 |
- TCP Requests
-
-
192.168.56.101:49197 74.208.236.24:80prodownload.live
-
192.168.56.101:49199 74.208.236.24:80prodownload.live
-
192.168.56.101:49201 74.208.236.24:80prodownload.live
-
192.168.56.101:49202 74.208.236.24:80prodownload.live
-
192.168.56.101:49203 74.208.236.24:80prodownload.live
-
192.168.56.101:49204 74.208.236.24:80prodownload.live
-
- UDP Requests
-
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:59370 239.255.255.250:3702
-
192.168.56.101:61480 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
http://prodownload.live/iam//index.php
REQUEST
RESPONSE
BODY
GET /iam//index.php HTTP/1.1
Host: prodownload.live
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=15
Date: Wed, 27 Oct 2021 00:24:23 GMT
Server: Apache
GET
200
http://prodownload.live/ixset.php?ip=175.208.134.150&mcid=1
REQUEST
RESPONSE
BODY
GET /ixset.php?ip=175.208.134.150&mcid=1 HTTP/1.1
Host: prodownload.live
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=15
Date: Wed, 27 Oct 2021 00:24:24 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: PHPSESSID=8ad95d0aaaa96bb1183c9d6454939e71; path=/
GET
200
http://prodownload.live/ixpkey.php
REQUEST
RESPONSE
BODY
GET /ixpkey.php HTTP/1.1
Host: prodownload.live
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=15
Date: Wed, 27 Oct 2021 00:24:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: PHPSESSID=8c79d7d5cc08ba0c82328d7ca4bad3c0; path=/
GET
200
http://prodownload.live/ixptexts.php
REQUEST
RESPONSE
BODY
GET /ixptexts.php HTTP/1.1
Host: prodownload.live
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=15
Date: Wed, 27 Oct 2021 00:24:25 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: PHPSESSID=4613a0a0341d787fb273518386b6c07b; path=/
GET
200
http://prodownload.live/setad.php
REQUEST
RESPONSE
BODY
GET /setad.php HTTP/1.1
Host: prodownload.live
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=15
Date: Wed, 27 Oct 2021 00:24:26 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: PHPSESSID=56c826c1ddaf27aa5ae79339cc5e45bf; path=/
GET
200
http://prodownload.live/ixlive.php?uid=1
REQUEST
RESPONSE
BODY
GET /ixlive.php?uid=1 HTTP/1.1
Host: prodownload.live
Accept: */*
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Keep-Alive: timeout=15
Date: Wed, 27 Oct 2021 00:24:27 GMT
Server: Apache
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: PHPSESSID=b2c9e13fed2a02056a5e648e8fb3195c; path=/
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49202 -> 74.208.236.24:80 | 2029286 | ET MALWARE CrownAdPro CnC Activity M3 | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49203 -> 74.208.236.24:80 | 2029287 | ET MALWARE CrownAdPro CnC Activity M4 | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49199 -> 74.208.236.24:80 | 2029143 | ET MALWARE CrownAdPro CnC Activity M1 | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49201 -> 74.208.236.24:80 | 2029285 | ET MALWARE CrownAdPro CnC Activity M2 | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49204 -> 74.208.236.24:80 | 2029288 | ET MALWARE CrownAdPro CnC Activity M5 | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts