Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
nutsstats.com |
- TCP Requests
-
-
192.168.56.103:49182 108.62.12.61:80
-
192.168.56.103:49183 108.62.12.61:99
-
192.168.56.103:49184 108.62.12.61:99
-
192.168.56.103:49186 108.62.12.61:99
-
192.168.56.103:49189 108.62.12.61:99
-
192.168.56.103:49190 108.62.12.61:99
-
192.168.56.103:49191 108.62.12.61:99
-
192.168.56.103:49192 108.62.12.61:99
-
192.168.56.103:49193 108.62.12.61:99
-
192.168.56.103:49194 108.62.12.61:99
-
192.168.56.103:49195 108.62.12.61:99
-
192.168.56.103:49196 108.62.12.61:99
-
192.168.56.103:49197 108.62.12.61:99
-
192.168.56.103:49198 108.62.12.61:99
-
192.168.56.103:49199 108.62.12.61:99
-
192.168.56.103:49200 108.62.12.61:99
-
192.168.56.103:49201 108.62.12.61:99
-
192.168.56.103:49202 108.62.12.61:99
-
192.168.56.103:49203 108.62.12.61:99
-
192.168.56.103:49204 108.62.12.61:99
-
192.168.56.103:49205 108.62.12.61:99
-
192.168.56.103:49206 108.62.12.61:99
-
192.168.56.103:49207 108.62.12.61:99
-
192.168.56.103:49208 108.62.12.61:99
-
192.168.56.103:49209 108.62.12.61:99
-
192.168.56.103:49210 108.62.12.61:99
-
192.168.56.103:49211 108.62.12.61:99
-
192.168.56.103:49171 194.5.212.190:80
-
- UDP Requests
-
-
192.168.56.103:53893 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:49168 239.255.255.250:1900
-
192.168.56.103:49170 239.255.255.250:3702
-
192.168.56.103:49172 239.255.255.250:3702
-
192.168.56.103:49174 239.255.255.250:3702
-
GET
200
http://194.5.212.190/load/trendmicro2.dll
REQUEST
RESPONSE
BODY
GET /load/trendmicro2.dll HTTP/1.1
Host: 194.5.212.190
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 01 Nov 2021 02:10:55 GMT
Server: Apache/2.4.29 (Ubuntu)
Last-Modified: Thu, 21 Oct 2021 13:23:17 GMT
ETag: "125a00-5cedccc3822d3"
Accept-Ranges: bytes
Content-Length: 1202688
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdos-program
GET
200
http://108.62.12.61/home2
REQUEST
RESPONSE
BODY
GET /home2 HTTP/1.1
Host: 108.62.12.61
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 1 Nov 2021 02:10:59 GMT
Server: Apache
Content-Length: 199408
Keep-Alive: timeout=10, max=100
Connection: Keep-Alive
Content-Type: text/plain
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts