Network Analysis
IP Address | Status | Action |
---|---|---|
103.8.26.102 | Active | Moloch |
103.8.26.103 | Active | Moloch |
104.168.155.129 | Active | Moloch |
112.196.72.188 | Active | Moloch |
117.18.232.200 | Active | Moloch |
121.254.136.27 | Active | Moloch |
131.100.24.231 | Active | Moloch |
146.164.84.216 | Active | Moloch |
148.66.159.242 | Active | Moloch |
150.95.8.112 | Active | Moloch |
164.124.101.2 | Active | Moloch |
178.63.25.185 | Active | Moloch |
178.79.147.66 | Active | Moloch |
185.7.214.7 | Active | Moloch |
192.254.71.210 | Active | Moloch |
203.114.109.124 | Active | Moloch |
207.38.84.195 | Active | Moloch |
209.59.138.75 | Active | Moloch |
210.3.48.214 | Active | Moloch |
212.237.17.99 | Active | Moloch |
217.182.143.207 | Active | Moloch |
45.118.115.99 | Active | Moloch |
45.142.114.231 | Active | Moloch |
45.176.232.124 | Active | Moloch |
46.55.222.11 | Active | Moloch |
51.38.71.0 | Active | Moloch |
51.68.175.8 | Active | Moloch |
54.254.177.153 | Active | Moloch |
58.227.42.236 | Active | Moloch |
79.172.212.216 | Active | Moloch |
95.111.224.35 | Active | Moloch |
- TCP Requests
-
-
192.168.56.103:49222 103.8.26.102:8080
-
192.168.56.103:49223 103.8.26.102:8080
-
192.168.56.103:49224 103.8.26.102:8080
-
192.168.56.103:49202 103.8.26.103:8080
-
192.168.56.103:49203 103.8.26.103:8080
-
192.168.56.103:49204 103.8.26.103:8080
-
192.168.56.103:49213 104.168.155.129:8080
-
192.168.56.103:49214 104.168.155.129:8080
-
192.168.56.103:49215 104.168.155.129:8080
-
192.168.56.103:49170 112.196.72.188:443soomaal.softuvo.xyz
-
192.168.56.103:49183 117.18.232.200:80
-
192.168.56.103:49171 121.254.136.27:80apps.identrust.com
-
192.168.56.103:49192 131.100.24.231:80
-
192.168.56.103:49193 131.100.24.231:80
-
192.168.56.103:49194 131.100.24.231:80
-
192.168.56.103:49172 146.164.84.216:80ippur.ufrj.br
-
192.168.56.103:49173 146.164.84.216:443ippur.ufrj.br
-
192.168.56.103:49174 146.164.84.216:443ippur.ufrj.br
-
192.168.56.103:49178 148.66.159.242:80atplengineering.com
-
192.168.56.103:49179 150.95.8.112:80www2.s12.xrea.com
-
192.168.56.103:49169 185.7.214.7:80
-
192.168.56.103:49196 209.59.138.75:7080
-
192.168.56.103:49198 209.59.138.75:7080
-
192.168.56.103:49199 209.59.138.75:7080
-
192.168.56.103:49176 210.3.48.214:443wordpress.pixeleyenow.com
-
192.168.56.103:49218 46.55.222.11:443
-
192.168.56.103:49219 46.55.222.11:443
-
192.168.56.103:49220 46.55.222.11:443
-
192.168.56.103:49206 51.38.71.0:443
-
192.168.56.103:49207 51.38.71.0:443
-
192.168.56.103:49208 51.38.71.0:443
-
192.168.56.103:49229 51.68.175.8:8080
-
192.168.56.103:49230 51.68.175.8:8080
-
192.168.56.103:49231 51.68.175.8:8080
-
192.168.56.103:49175 54.254.177.153:443scoute.ai
-
192.168.56.103:49177 95.111.224.35:80sarvaero.com
-
- UDP Requests
-
-
192.168.56.103:51935 164.124.101.2:53
-
192.168.56.103:60117 164.124.101.2:53
-
192.168.56.103:60880 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:49350 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:49347
-
8.8.8.8:53 192.168.56.103:51958
-
8.8.8.8:53 192.168.56.103:53064
-
8.8.8.8:53 192.168.56.103:57573
-
8.8.8.8:53 192.168.56.103:60693
-
8.8.8.8:53 192.168.56.103:60880
-
8.8.8.8:53 192.168.56.103:61603
-
8.8.8.8:53 192.168.56.103:63183
-
8.8.8.8:53 192.168.56.103:63462
-
GET
200
http://185.7.214.7/ve/ve.png
REQUEST
RESPONSE
BODY
GET /ve/ve.png HTTP/1.1
Host: 185.7.214.7
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.20.1
Date: Wed, 19 Jan 2022 02:33:32 GMT
Content-Type: image/png
Content-Length: 972
Last-Modified: Tue, 18 Jan 2022 14:05:40 GMT
Connection: keep-alive
ETag: "61e6c934-3cc"
Accept-Ranges: bytes
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Fri, 29 Oct 2021 21:49:30 GMT
ETag: "37d-5cf84cd446e80"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 19 Jan 2022 03:33:42 GMT
Date: Wed, 19 Jan 2022 02:33:42 GMT
Connection: keep-alive
GET
302
http://ippur.ufrj.br/assets/W8jp7/
REQUEST
RESPONSE
BODY
GET /assets/W8jp7/ HTTP/1.1
Host: ippur.ufrj.br
Connection: Keep-Alive
HTTP/1.1 302 Moved Temporarily
Server: nginx
Date: Wed, 19 Jan 2022 02:33:44 GMT
Content-Type: text/html
Content-Length: 138
Connection: keep-alive
Location: https://ippur.ufrj.br/assets/W8jp7/
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Fri, 29 Oct 2021 21:49:30 GMT
ETag: "37d-5cf84cd446e80"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 19 Jan 2022 03:33:47 GMT
Date: Wed, 19 Jan 2022 02:33:47 GMT
Connection: keep-alive
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=15768000
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Content-Security-Policy: default-src 'self' *.identrust.com
Last-Modified: Fri, 29 Oct 2021 21:49:30 GMT
ETag: "37d-5cf84cd446e80"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 19 Jan 2022 03:33:48 GMT
Date: Wed, 19 Jan 2022 02:33:48 GMT
Connection: keep-alive
GET
404
http://sarvaero.com/assets/BRrGH0HSkc/
REQUEST
RESPONSE
BODY
GET /assets/BRrGH0HSkc/ HTTP/1.1
Host: sarvaero.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Wed, 19 Jan 2022 02:33:49 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <http://sarvaero.com/wp-json/>; rel="https://api.w.org/"
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://atplengineering.com/wp-admin/mDk/
REQUEST
RESPONSE
BODY
GET /wp-admin/mDk/ HTTP/1.1
Host: atplengineering.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Wed, 19 Jan 2022 02:33:50 GMT
Server: Apache
X-Powered-By: PHP/7.4.26
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <http://atplengineering.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, Keep-Alive
Keep-Alive: timeout=5
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
200
http://www2.s12.xrea.com/-/gkUMZLMfkddmFdMlJ/
REQUEST
RESPONSE
BODY
GET /-/gkUMZLMfkddmFdMlJ/ HTTP/1.1
Host: www2.s12.xrea.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 19 Jan 2022 02:33:52 GMT
Server: Apache
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Expires: Wed, 19 Jan 2022 02:33:52 GMT
Content-Disposition: attachment; filename="OjpasYr2.dll"
Content-Transfer-Encoding: binary
Set-Cookie: 61e778906cc32=1642559632; expires=Wed, 19-Jan-2022 02:34:52 GMT; Max-Age=60; path=/
Last-Modified: Wed, 19 Jan 2022 02:33:52 GMT
Content-Length: 407552
Vary: User-Agent
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE
BODY
GET /IE9CompatViewList.xml HTTP/1.1
Accept: */*
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Host: ie9cvlist.ie.microsoft.com
If-Modified-Since: Fri, 16 Oct 2020 17:54:09 GMT
If-None-Match: 0x8D871FC7BDF491D
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Encoding: gzip
Age: 9719
Cache-Control: max-age=21600
Content-MD5: p9g4jsuZO6TaLMVAI9ujVg==
Content-Type: text/xml
Date: Wed, 19 Jan 2022 02:34:00 GMT
Etag: 0x8D9521D2D2DF1EC
Last-Modified: Wed, 28 Jul 2021 23:12:31 GMT
Server: ECAcc (tka/897A)
Vary: Accept-Encoding
X-Cache: HIT
x-ms-blob-type: BlockBlob
x-ms-lease-status: unlocked
x-ms-request-id: 7ddfe4cc-c01e-00b4-06c6-0ce100000000
x-ms-version: 2009-09-19
Content-Length: 13702
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts