Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
iplogger.com | 148.251.234.93 | |
mynsd2u.com | 103.8.25.128 | |
tokoi45.beget.tech | 5.101.152.100 |
- TCP Requests
-
-
192.168.56.103:49169 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49170 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49171 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49172 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49173 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49174 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49175 103.8.25.128:80mynsd2u.com
-
192.168.56.103:49177 148.251.234.93:443iplogger.com
-
192.168.56.103:49178 148.251.234.93:443iplogger.com
-
192.168.56.103:49179 148.251.234.93:443iplogger.com
-
192.168.56.103:49165 5.101.152.100:80tokoi45.beget.tech
-
192.168.56.103:49166 5.101.152.100:80tokoi45.beget.tech
-
192.168.56.103:49167 5.101.152.100:80tokoi45.beget.tech
-
GET
200
http://tokoi45.beget.tech/server.txt
REQUEST
RESPONSE
BODY
GET /server.txt HTTP/1.0
Host: tokoi45.beget.tech
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Server: nginx-reuseport/1.21.1
Date: Wed, 21 Jun 2023 07:04:28 GMT
Content-Type: text/plain
Content-Length: 11
Last-Modified: Tue, 20 Jun 2023 16:38:58 GMT
Connection: close
ETag: "6491d622-b"
Expires: Wed, 28 Jun 2023 07:04:28 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes
GET
200
http://tokoi45.beget.tech/server1.txt
REQUEST
RESPONSE
BODY
GET /server1.txt HTTP/1.0
Host: tokoi45.beget.tech
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Server: nginx-reuseport/1.21.1
Date: Wed, 21 Jun 2023 07:04:29 GMT
Content-Type: text/plain
Content-Length: 0
Last-Modified: Mon, 12 Jun 2023 05:54:23 GMT
Connection: close
ETag: "6486b30f-0"
Expires: Wed, 28 Jun 2023 07:04:29 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes
GET
200
http://tokoi45.beget.tech/server2.txt
REQUEST
RESPONSE
BODY
GET /server2.txt HTTP/1.0
Host: tokoi45.beget.tech
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Server: nginx-reuseport/1.21.1
Date: Wed, 21 Jun 2023 07:04:29 GMT
Content-Type: text/plain
Content-Length: 0
Last-Modified: Mon, 29 May 2023 17:28:07 GMT
Connection: close
ETag: "6474e0a7-0"
Expires: Wed, 28 Jun 2023 07:04:29 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes
GET
404
http://mynsd2u.com/1/data64_1.exe
REQUEST
RESPONSE
BODY
GET /1/data64_1.exe HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 404 Not Found
Date: Wed, 21 Jun 2023 07:04:30 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://mynsd2u.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, close
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
GET
404
http://mynsd2u.com/1/data64_2.exe
REQUEST
RESPONSE
BODY
GET /1/data64_2.exe HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 404 Not Found
Date: Wed, 21 Jun 2023 07:04:32 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://mynsd2u.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, close
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
GET
404
http://mynsd2u.com/1/data64_3.exe
REQUEST
RESPONSE
BODY
GET /1/data64_3.exe HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 404 Not Found
Date: Wed, 21 Jun 2023 07:04:33 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://mynsd2u.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, close
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
GET
404
http://mynsd2u.com/1/data64_4.exe
REQUEST
RESPONSE
BODY
GET /1/data64_4.exe HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 404 Not Found
Date: Wed, 21 Jun 2023 07:04:34 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://mynsd2u.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, close
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
GET
404
http://mynsd2u.com/1/data64_5.exe
REQUEST
RESPONSE
BODY
GET /1/data64_5.exe HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 404 Not Found
Date: Wed, 21 Jun 2023 07:04:35 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://mynsd2u.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, close
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
GET
404
http://mynsd2u.com/1/data64_6.exe
REQUEST
RESPONSE
BODY
GET /1/data64_6.exe HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 404 Not Found
Date: Wed, 21 Jun 2023 07:04:36 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://mynsd2u.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade, close
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
GET
200
http://mynsd2u.com/webArg1.txt
REQUEST
RESPONSE
BODY
GET /webArg1.txt HTTP/1.0
Host: mynsd2u.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Date: Wed, 21 Jun 2023 07:04:38 GMT
Server: Apache
Upgrade: h2,h2c
Connection: Upgrade, close
Last-Modified: Tue, 20 Jun 2023 11:25:56 GMT
Accept-Ranges: bytes
Content-Length: 27
Vary: Accept-Encoding
Content-Type: text/plain
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49177 -> 148.251.234.93:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49178 -> 148.251.234.93:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 148.251.234.93:443 -> 192.168.56.103:49179 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts