Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
navercorp.ru | 46.254.21.69 |
- TCP Requests
GET
200
http://navercorp.ru/dashboard/image/202302/4.html
REQUEST
RESPONSE
BODY
GET /dashboard/image/202302/4.html HTTP/1.1
Accept: */*
Accept-Language: ko-KR
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/5.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Host: navercorp.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
content-type: text/html
last-modified: Tue, 22 Aug 2023 06:50:41 GMT
etag: "498e-64e45ac1-3f04d7001d30bea0;gz"
accept-ranges: bytes
content-encoding: gzip
vary: Accept-Encoding
content-length: 4754
date: Mon, 04 Sep 2023 01:28:14 GMT
server: LiteSpeed
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 46.254.21.69:80 -> 192.168.56.101:49172 | 2026989 | ET HUNTING PowerShell Hidden Window Command Common In Powershell Stagers M1 | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts