Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
xmr.2miners.com | 162.19.139.184 |
POST
200
http://45.142.182.146/dashboard/para/un/api/endpoint.php
REQUEST
RESPONSE
BODY
POST /dashboard/para/un/api/endpoint.php HTTP/1.1
Accept: */*
Connection: close
Content-Length: 472
Content-Type: application/json
Host: 45.142.182.146
User-Agent: cpp-httplib/0.9
HTTP/1.1 200 OK
Date: Fri, 07 Jul 2023 09:06:03 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.2.4
X-Powered-By: PHP/8.2.4
Content-Length: 482
Connection: close
Content-Type: text/html; charset=UTF-8
POST
200
http://45.142.182.146/dashboard/para/un/api/endpoint.php
REQUEST
RESPONSE
BODY
POST /dashboard/para/un/api/endpoint.php HTTP/1.1
Accept: */*
Connection: close
Content-Length: 477
Content-Type: application/json
Host: 45.142.182.146
User-Agent: cpp-httplib/0.9
HTTP/1.1 200 OK
Date: Fri, 07 Jul 2023 09:07:01 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.2.4
X-Powered-By: PHP/8.2.4
Content-Length: 482
Connection: close
Content-Type: text/html; charset=UTF-8
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49165 -> 162.19.139.184:2222 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
TCP 192.168.56.101:49163 -> 162.19.139.184:2222 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
TCP 192.168.56.101:49163 -> 162.19.139.184:2222 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2040353 | ET COINMINER Observed DNS Query to Cryptocurrency Mining Pool Domain (xmr .2miners .com) | Crypto Currency Mining Activity Detected |
TCP 192.168.56.101:49164 -> 45.142.182.146:80 | 2035420 | ET MALWARE Win32/Pripyat Activity (POST) | A Network Trojan was detected |
TCP 192.168.56.101:49166 -> 45.142.182.146:80 | 2035420 | ET MALWARE Win32/Pripyat Activity (POST) | A Network Trojan was detected |
TCP 192.168.56.101:49165 -> 162.19.139.184:2222 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts