Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
iplogger.com | 148.251.234.93 | |
dzen.ru | 62.217.160.2 | |
tokoi45.beget.tech | 5.101.152.100 | |
yandex.ru | 77.88.55.60 | |
sso.passport.yandex.ru |
CNAME
passport.yandex.ru
|
213.180.204.24 |
allansworthng.com | 108.178.17.142 |
- TCP Requests
-
-
192.168.56.103:49169 108.178.17.142:80allansworthng.com
-
192.168.56.103:49170 108.178.17.142:80allansworthng.com
-
192.168.56.103:49171 108.178.17.142:80allansworthng.com
-
192.168.56.103:49173 108.178.17.142:80allansworthng.com
-
192.168.56.103:49175 108.178.17.142:80allansworthng.com
-
192.168.56.103:49176 108.178.17.142:80allansworthng.com
-
192.168.56.103:49177 108.178.17.142:80allansworthng.com
-
192.168.56.103:49185 148.251.234.93:443iplogger.com
-
192.168.56.103:49186 148.251.234.93:443iplogger.com
-
192.168.56.103:49187 148.251.234.93:443iplogger.com
-
192.168.56.103:49183 168.119.239.218:36938
-
192.168.56.103:49184 213.180.204.24:443sso.passport.yandex.ru
-
192.168.56.103:49166 5.101.152.100:80tokoi45.beget.tech
-
192.168.56.103:49167 5.101.152.100:80tokoi45.beget.tech
-
192.168.56.103:49168 5.101.152.100:80tokoi45.beget.tech
-
192.168.56.103:49178 5.255.255.77:443yandex.ru
-
192.168.56.103:49180 62.217.160.2:443dzen.ru
-
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49154 239.255.255.250:1900
-
GET
302
https://yandex.ru/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
Host: yandex.ru
Connection: Keep-Alive
HTTP/1.1 302 Moved temporarily
Accept-CH: Sec-CH-UA-Platform-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA, Sec-CH-UA-Full-Version-List, Sec-CH-UA-WoW64, Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Platform, Sec-CH-UA-Full-Version, Viewport-Width, DPR, Device-Memory, RTT, Downlink, ECT
Cache-Control: max-age=1209600,private
Date: Wed, 28 Jun 2023 07:36:25 GMT
Location: https://dzen.ru/?yredirect=true
NEL: {"report_to": "network-errors", "max_age": 100, "success_fraction": 0.001, "failure_fraction": 0.1}
P3P: policyref="/w3c/p3p.xml", CP="NON DSP ADM DEV PSD IVDo OUR IND STP PHY PRE NAV UNI"
Portal: Home
Report-To: { "group": "network-errors", "max_age": 100, "endpoints": [{"url": "https://dr.yandex.net/nel", "priority": 1}, {"url": "https://dr2.yandex.net/nel", "priority": 2}]}
Transfer-Encoding: chunked
X-Content-Type-Options: nosniff
X-Robots-Tag: unavailable_after: 12 Sep 2022 00:00:00 PST
X-Yandex-Req-Id: 1687937785532286-1752845257647414032-balancer-l7leveler-kubr-yp-vla-47-BAL-7345
set-cookie: is_gdpr=0; Path=/; Domain=.yandex.ru; Expires=Fri, 27 Jun 2025 07:36:25 GMT
set-cookie: is_gdpr_b=CPzMERDavwEoAg==; Path=/; Domain=.yandex.ru; Expires=Fri, 27 Jun 2025 07:36:25 GMT
set-cookie: _yasc=XYKH1xSPlkiadZQ9d+4S5ebiq9Eqr+Uy+5Zsa0Z30yZoz6nwg1K/0Kj3FwFATIk=; domain=.yandex.ru; path=/; expires=Sat, 25 Jun 2033 07:36:25 GMT; secure
set-cookie: i=3cdL19/mGvq4bjII4wecjPnPgRWFNKMpLVHi0/hWpcJb8jn12QfTunCD057TKmmf0Ms6VBX5C1diQXoelgmK7esnrdg=; Expires=Fri, 27-Jun-2025 07:36:25 GMT; Domain=.yandex.ru; Path=/; Secure; HttpOnly
set-cookie: yandexuid=8474140321687937785; Expires=Fri, 27-Jun-2025 07:36:25 GMT; Domain=.yandex.ru; Path=/; Secure
GET
0
https://dzen.ru/?yredirect=true
REQUEST
RESPONSE
BODY
GET /?yredirect=true HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
Host: dzen.ru
Connection: Keep-Alive
GET
200
https://sso.passport.yandex.ru/push?uuid=8d007376-d291-49ab-b013-d8dcbfea0326&retpath=https%3A%2F%2Fdzen.ru%2F%3Fyredirect%3Dtrue
REQUEST
RESPONSE
BODY
GET /push?uuid=8d007376-d291-49ab-b013-d8dcbfea0326&retpath=https%3A%2F%2Fdzen.ru%2F%3Fyredirect%3Dtrue HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0
Host: sso.passport.yandex.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 28 Jun 2023 07:36:35 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 1958
Connection: close
Vary: Accept-Encoding
X-Download-Options: noopen
X-Content-Type-Options: nosniff
Surrogate-Control: no-store
Cache-Control: no-store, no-cache, must-revalidate, proxy-revalidate
Pragma: no-cache
Expires: 0
X-DNS-Prefetch-Control: off
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'none'; frame-ancestors https://*.dzen.ru https://dzen.ru; connect-src 'self'; script-src 'nonce-119a2d18216882e4767582820df11e73' 'self'; img-src 'self'
Set-Cookie: mda2_beacon=1687937795563; Domain=.passport.yandex.ru; Expires=Tue, 19 Jan 2038 03:14:07 GMT; Secure; Path=/
Set-Cookie: ys=c_chck.3159486963; Domain=.yandex.ru; Secure; Path=/
Set-Cookie: i=CLz/DSuhSANcK2S0heA8pc6qcMw+cJW33q9CCEqt4eKk4lZbUVnOEAYBchZYBCOyayB5svnq5I7i6zjio8WAYbhvXUk=; Domain=.yandex.ru; Expires=Sat, 25 Jun 2033 07:36:35 GMT; Secure; HttpOnly; Path=/
Set-Cookie: yandexuid=9010523461687937795; Domain=.yandex.ru; Expires=Sat, 25 Jun 2033 07:36:35 GMT; Secure; Path=/
Set-Cookie: mda2_domains=dzen.ru; Domain=.passport.yandex.ru; Expires=Tue, 19 Jan 2038 03:14:07 GMT; Secure; Path=/
Referrer-Policy: origin
ETag: W/"7a6-pDoapE2bz6CV4qA9+bM1DextIU0"
Strict-Transport-Security: max-age=315360000; includeSubDomains
GET
200
http://tokoi45.beget.tech/server.txt
REQUEST
RESPONSE
BODY
GET /server.txt HTTP/1.0
Host: tokoi45.beget.tech
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Server: nginx-reuseport/1.21.1
Date: Wed, 28 Jun 2023 07:36:15 GMT
Content-Type: text/plain
Content-Length: 17
Last-Modified: Mon, 26 Jun 2023 19:53:13 GMT
Connection: close
ETag: "6499eca9-11"
Expires: Wed, 05 Jul 2023 07:36:15 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes
GET
200
http://tokoi45.beget.tech/server1.txt
REQUEST
RESPONSE
BODY
GET /server1.txt HTTP/1.0
Host: tokoi45.beget.tech
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Server: nginx-reuseport/1.21.1
Date: Wed, 28 Jun 2023 07:36:16 GMT
Content-Type: text/plain
Content-Length: 0
Last-Modified: Mon, 12 Jun 2023 05:54:23 GMT
Connection: close
ETag: "6486b30f-0"
Expires: Wed, 05 Jul 2023 07:36:16 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes
GET
200
http://tokoi45.beget.tech/server2.txt
REQUEST
RESPONSE
BODY
GET /server2.txt HTTP/1.0
Host: tokoi45.beget.tech
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.1 200 OK
Server: nginx-reuseport/1.21.1
Date: Wed, 28 Jun 2023 07:36:17 GMT
Content-Type: text/plain
Content-Length: 0
Last-Modified: Mon, 29 May 2023 17:28:07 GMT
Connection: close
ETag: "6474e0a7-0"
Expires: Wed, 05 Jul 2023 07:36:17 GMT
Cache-Control: max-age=604800
Accept-Ranges: bytes
GET
404
http://allansworthng.com/1/data64_1.exe
REQUEST
RESPONSE
BODY
GET /1/data64_1.exe HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 404 Not Found
Connection: close
cache-control: private, no-cache, no-store, must-revalidate, max-age=0
pragma: no-cache
content-type: text/html
content-length: 708
date: Wed, 28 Jun 2023 07:36:17 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
GET
200
http://allansworthng.com/1/data64_2.exe
REQUEST
RESPONSE
BODY
GET /1/data64_2.exe HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 200 OK
Connection: close
content-type: application/x-msdownload
last-modified: Tue, 27 Jun 2023 17:50:23 GMT
etag: "0649b215f-0;;;"
accept-ranges: bytes
content-length: 838304
date: Wed, 28 Jun 2023 07:36:18 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
GET
200
http://allansworthng.com/1/data64_3.exe
REQUEST
RESPONSE
BODY
GET /1/data64_3.exe HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 200 OK
Connection: close
content-type: application/x-msdownload
last-modified: Tue, 27 Jun 2023 17:50:45 GMT
etag: "0649b2175-0;;;"
accept-ranges: bytes
content-length: 2856448
date: Wed, 28 Jun 2023 07:36:20 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
GET
404
http://allansworthng.com/1/data64_4.exe
REQUEST
RESPONSE
BODY
GET /1/data64_4.exe HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 404 Not Found
Connection: close
cache-control: private, no-cache, no-store, must-revalidate, max-age=0
pragma: no-cache
content-type: text/html
content-length: 708
date: Wed, 28 Jun 2023 07:36:22 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
GET
404
http://allansworthng.com/1/data64_5.exe
REQUEST
RESPONSE
BODY
GET /1/data64_5.exe HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 404 Not Found
Connection: close
cache-control: private, no-cache, no-store, must-revalidate, max-age=0
pragma: no-cache
content-type: text/html
content-length: 708
date: Wed, 28 Jun 2023 07:36:22 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
GET
404
http://allansworthng.com/1/data64_6.exe
REQUEST
RESPONSE
BODY
GET /1/data64_6.exe HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 404 Not Found
Connection: close
cache-control: private, no-cache, no-store, must-revalidate, max-age=0
pragma: no-cache
content-type: text/html
content-length: 708
date: Wed, 28 Jun 2023 07:36:23 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
GET
200
http://allansworthng.com/webArg1.txt
REQUEST
RESPONSE
BODY
GET /webArg1.txt HTTP/1.0
Host: allansworthng.com
*Accept: */*
*Connection: close
User-Agent: Firefox-6.0
HTTP/1.0 200 OK
Connection: close
content-type: text/plain
last-modified: Wed, 21 Jun 2023 00:25:56 GMT
etag: "064924394-0;;;"
accept-ranges: bytes
content-length: 27
date: Wed, 28 Jun 2023 07:36:24 GMT
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
cache-control: max-age=1333600, public, must-revalidate
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49178 5.255.255.77:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign ECC OV SSL CA 2018 | C=RU, ST=Moscow, L=Moscow, O=Yandex LLC, CN=*.xn--d1acpjx3f.xn--p1ai | 7a:e6:ff:bb:19:79:e4:52:b5:47:97:69:f8:78:1c:38:bd:e6:2f:c2 |
TLSv1 192.168.56.103:49180 62.217.160.2:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 | C=RU, ST=Moscow, L=Moscow, O=VK LLC, CN=*.dzen.ru | 6a:31:14:29:60:07:c9:c6:17:7b:d1:27:ad:53:57:ec:d8:c1:d8:d2 |
TLSv1 192.168.56.103:49184 213.180.204.24:443 |
C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 | C=RU, ST=Moscow, L=Moscow, O=Yandex LLC, CN=sso.passport.yandex.ru | f0:52:26:54:41:65:2b:6a:37:7b:c1:5b:de:9c:e9:d4:41:c6:81:2d |
Snort Alerts
No Snort Alerts