Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
elturky.net | 68.178.227.97 |
GET
404
http://elturky.net/ERP/public/js/dd_64.exe
REQUEST
RESPONSE
BODY
GET /ERP/public/js/dd_64.exe HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:43 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Upgrade: h2,h2c
Connection: Upgrade
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc2.exe
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc2.exe HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:43 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc3.exe
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc3.exe HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:43 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc4.exe
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc4.exe HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:43 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc5.exe
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc5.exe HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:43 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc1.php
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc1.php HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:44 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc2.php
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc2.php HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:44 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
404
http://elturky.net/ERP/public/js/cc3.php
REQUEST
RESPONSE
BODY
GET /ERP/public/js/cc3.php HTTP/1.1
Host: elturky.net
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Fri, 28 Jul 2023 08:34:44 GMT
Server: Apache
X-Powered-By: PHP/7.4.33
Cache-Control: no-cache, private
Vary: Accept-Encoding
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
GET
200
http://elturky.net/ERP/public/js/debug2.ps1
REQUEST
RESPONSE
BODY
GET /ERP/public/js/debug2.ps1 HTTP/1.1
Host: elturky.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 28 Jul 2023 08:35:06 GMT
Server: Apache
Upgrade: h2,h2c
Connection: Upgrade, Keep-Alive
Last-Modified: Thu, 08 Jun 2023 21:01:45 GMT
ETag: "964cc5-4fdf6-5fda48f592040"
Accept-Ranges: bytes
Content-Length: 327158
Vary: Accept-Encoding
Keep-Alive: timeout=5
GET
200
http://38.180.1.27/index.php?id=017bd04f-b3bf-45b6-8167-9e8f41ff87bf&subid=HnTgSX1R
REQUEST
RESPONSE
BODY
GET /index.php?id=017bd04f-b3bf-45b6-8167-9e8f41ff87bf&subid=HnTgSX1R HTTP/1.1
Host: 38.180.1.27
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 28 Jul 2023 08:35:12 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49169 -> 68.178.227.97:80 | 2032162 | ET INFO PS1 Powershell File Request | Potentially Bad Traffic |
TCP 192.168.56.103:49162 -> 68.178.227.97:80 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | Potentially Bad Traffic |
TCP 192.168.56.103:49162 -> 68.178.227.97:80 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | Potentially Bad Traffic |
TCP 192.168.56.103:49162 -> 68.178.227.97:80 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | Potentially Bad Traffic |
TCP 192.168.56.103:49162 -> 68.178.227.97:80 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts