Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
rc30.tuktuk.ug | 85.209.3.9 |
GET
200
http://95.214.27.254/getfile/winlog.exe
REQUEST
RESPONSE
BODY
GET /getfile/winlog.exe HTTP/1.1
Host: 95.214.27.254
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.17.10 (Ubuntu)
Date: Thu, 31 Aug 2023 00:40:25 GMT
Content-Type: application/octet-stream
Content-Length: 13320192
Last-Modified: Wed, 30 Aug 2023 18:08:02 GMT
Connection: keep-alive
ETag: "64ef8582-cb4000"
Accept-Ranges: bytes
GET
200
http://95.214.27.254/getfile/msedge.exe
REQUEST
RESPONSE
BODY
GET /getfile/msedge.exe HTTP/1.1
Host: 95.214.27.254
HTTP/1.1 200 OK
Server: nginx/1.17.10 (Ubuntu)
Date: Thu, 31 Aug 2023 00:40:32 GMT
Content-Type: application/octet-stream
Content-Length: 21412864
Last-Modified: Wed, 30 Aug 2023 18:08:46 GMT
Connection: keep-alive
ETag: "64ef85ae-146bc00"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts