Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
server.toeicswt.co.kr | 210.116.108.238 |
- TCP Requests
-
-
192.168.56.101:49164 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49166 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49171 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49174 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49175 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49176 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49178 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49179 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49181 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49183 210.116.108.238:443server.toeicswt.co.kr
-
192.168.56.101:49186 210.116.108.238:443server.toeicswt.co.kr
-
POST
200
https://server.toeicswt.co.kr/update/update_global.asp
REQUEST
RESPONSE
BODY
POST /update/update_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 162
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html
Server: Microsoft-IIS/10.0
Set-Cookie: ASPSESSIONIDSABRQCRD=POALIJIDFLAONHCMFMJGLOPH; path=/
Date: Mon, 08 Nov 2021 04:11:08 GMT
Connection: close
Content-Length: 1894
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 148
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 5210624
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\SJPTManager.exe
Set-Cookie: ASPSESSIONIDSABRQCRD=BPALIJIDGMDFGJLIIEKPNNNO; path=/
Date: Mon, 08 Nov 2021 04:11:08 GMT
Connection: close
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 148
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 4206703
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\sample\S999.zds
Set-Cookie: ASPSESSIONIDSABRQCRD=EPALIJIDDKBCAIAKPENAOEOP; path=/
Date: Mon, 08 Nov 2021 04:11:14 GMT
Connection: close
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 150
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\sample\survey.zds
Set-Cookie: ASPSESSIONIDSABRQCRD=FPALIJIDMLNINHMHCMENBAGK; path=/
Date: Mon, 08 Nov 2021 04:11:16 GMT
Connection: close
Content-Length: 744
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 159
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\setup\sjpt\client\clst.zds
Set-Cookie: ASPSESSIONIDSABRQCRD=GPALIJIDAGDMOCGLIMGFMHAD; path=/
Date: Mon, 08 Nov 2021 04:11:16 GMT
Connection: close
Content-Length: 200
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 160
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\setup\sjpt\client\page.html
Set-Cookie: ASPSESSIONIDSABRQCRD=HPALIJIDBNKCBIOMIFLPDDHN; path=/
Date: Mon, 08 Nov 2021 04:11:16 GMT
Connection: close
Content-Length: 33005
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 159
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\setup\sjpt\client\rlst.zds
Set-Cookie: ASPSESSIONIDSABRQCRD=KPALIJIDOGLEFLFBENCEJJHG; path=/
Date: Mon, 08 Nov 2021 04:11:19 GMT
Connection: close
Content-Length: 112
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 163
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 8298496
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\setup\sjpt\client\sjpt_cbt.exe
Set-Cookie: ASPSESSIONIDSABRQCRD=LPALIJIDGJDHMIOLNFDKEHFB; path=/
Date: Mon, 08 Nov 2021 04:11:19 GMT
Connection: close
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 152
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\setup\yspt\YSPT.exe
Set-Cookie: ASPSESSIONIDSABRQCRD=MPALIJIDNMMCGELKECPLCLDK; path=/
Date: Mon, 08 Nov 2021 04:11:21 GMT
Connection: close
Content-Length: 3638272
POST
200
https://server.toeicswt.co.kr/update/download_file_global.asp
REQUEST
RESPONSE
BODY
POST /update/download_file_global.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset=euc-kr
Host: server.toeicswt.co.kr
Content-Length: 160
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: application/octet-stream; Charset=UTF-8
Server: Microsoft-IIS/10.0
content-disposition: attachment; sFileName=D:\yts_setup\SJPTMANAGER\setup\yspt\YSPTLauncher.exe
Set-Cookie: ASPSESSIONIDSABRQCRD=PPALIJIDKDPJFHLBNECJDNND; path=/
Date: Mon, 08 Nov 2021 04:11:22 GMT
Connection: close
Content-Length: 651264
POST
200
https://server.toeicswt.co.kr/svr_sjpt/server.asp
REQUEST
RESPONSE
BODY
POST /svr_sjpt/server.asp HTTP/1.1
Content-Type: application/x-www-form-urlencoded; charset='utf-8'
Host: server.toeicswt.co.kr
Content-Length: 292
Connection: Close
HTTP/1.1 200 OK
Cache-Control: private
Content-Type: text/html; Charset=utf-8
Server: Microsoft-IIS/10.0
Set-Cookie: ASPSESSIONIDSABRQCRD=BABLIJIDOCBODJIFPIMBNMNO; path=/
Date: Mon, 08 Nov 2021 04:11:25 GMT
Connection: close
Content-Length: 149
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49166 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49164 210.116.108.238:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 | C=KR, ST=Gyeonggi-do, L=Seongnam-si, O=YBM NET, Inc., CN=*.ybmnet.co.kr | 37:1d:7f:0b:90:fc:61:e4:4b:1d:c5:14:a0:48:2e:8d:cb:04:8f:51 |
TLSv1 192.168.56.101:49174 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49178 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49175 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49179 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49176 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49171 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49181 210.116.108.238:443 |
None | None | None |
TLSv1 192.168.56.101:49186 210.116.108.238:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 | C=KR, ST=Gyeonggi-do, L=Seongnam-si, O=YBM NET, Inc., CN=*.ybmnet.co.kr | 37:1d:7f:0b:90:fc:61:e4:4b:1d:c5:14:a0:48:2e:8d:cb:04:8f:51 |
TLSv1 192.168.56.101:49183 210.116.108.238:443 |
None | None | None |
Snort Alerts
No Snort Alerts