Network Analysis
IP Address | Status | Action |
---|---|---|
104.194.128.170 | Active | Moloch |
104.20.67.143 | Active | Moloch |
104.21.32.208 | Active | Moloch |
104.21.35.235 | Active | Moloch |
104.21.78.56 | Active | Moloch |
107.167.110.211 | Active | Moloch |
117.18.232.200 | Active | Moloch |
121.254.136.9 | Active | Moloch |
131.153.76.130 | Active | Moloch |
148.251.234.93 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.197.174 | Active | Moloch |
172.67.216.81 | Active | Moloch |
172.86.97.117 | Active | Moloch |
193.42.32.29 | Active | Moloch |
194.169.175.127 | Active | Moloch |
45.130.41.101 | Active | Moloch |
69.48.143.183 | Active | Moloch |
85.143.220.63 | Active | Moloch |
85.217.144.143 | Active | Moloch |
- TCP Requests
-
-
192.168.56.103:49231 104.194.128.170:80
-
192.168.56.103:49164 104.20.67.143:443pastebin.com
-
192.168.56.103:49170 104.21.32.208:443lycheepanel.info
-
192.168.56.103:49178 104.21.35.235:443potatogoose.com
-
192.168.56.103:49179 104.21.78.56:443diplodoka.net
-
192.168.56.103:49177 107.167.110.211:80net.geo.opera.com
-
192.168.56.103:49180 107.167.110.211:443net.geo.opera.com
-
192.168.56.103:49237 117.18.232.200:80
-
192.168.56.103:49175 121.254.136.9:80apps.identrust.com
-
192.168.56.103:49232 131.153.76.130:80pool.hashvault.pro
-
192.168.56.103:49165 148.251.234.93:443iplogger.com
-
192.168.56.103:49212 148.251.234.93:443iplogger.com
-
192.168.56.103:49213 148.251.234.93:443iplogger.com
-
192.168.56.103:49215 148.251.234.93:443iplogger.com
-
192.168.56.103:49216 148.251.234.93:443iplogger.com
-
192.168.56.103:49217 148.251.234.93:443iplogger.com
-
192.168.56.103:49171 172.67.197.174:443grabyourpizza.com
-
192.168.56.103:49167 172.67.216.81:443flyawayaero.net
-
192.168.56.103:49166 172.86.97.117:80
-
192.168.56.103:49172 194.169.175.127:80galandskiyher5.com
-
192.168.56.103:49176 45.130.41.101:443laubenstein.space
-
192.168.56.103:49174 69.48.143.183:443martvl.com
-
192.168.56.103:49173 85.143.220.63:80gons01b.top
-
192.168.56.103:49168 85.217.144.143:80
-
192.168.56.103:49169 85.217.144.143:80
-
- UDP Requests
-
-
192.168.56.103:50674 164.124.101.2:53
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52175 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53658 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:57986 164.124.101.2:53
-
192.168.56.103:60141 164.124.101.2:53
-
192.168.56.103:60225 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64178 164.124.101.2:53
-
192.168.56.103:64530 164.124.101.2:53
-
192.168.56.103:64631 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:65119 164.124.101.2:53
-
192.168.56.103:137 192.168.56.101:137
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:60144 239.255.255.250:1900
-
GET
200
https://pastebin.com/raw/HPj0MzD6
REQUEST
RESPONSE
BODY
GET /raw/HPj0MzD6 HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:53:55 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: HIT
Age: 505
Last-Modified: Wed, 18 Oct 2023 22:45:30 GMT
Server: cloudflare
CF-RAY: 81845c358b6bdbcc-LAX
GET
307
https://flyawayaero.net/baf14778c246e15550645e30ba78ce1c.exe
REQUEST
RESPONSE
BODY
GET /baf14778c246e15550645e30ba78ce1c.exe HTTP/1.1
Host: flyawayaero.net
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
Date: Wed, 18 Oct 2023 22:53:56 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://potatogoose.com/4d1aaeb879448e5236e36d2209b40d34/baf14778c246e15550645e30ba78ce1c.exe
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=KeIywejmw%2BloRUjr%2BevwkpIsBfaYlBKrVoHnX7rz%2BeWu5g28rwgKLjXb5jxy8TFSQKuq2LXMAk85%2B%2BDE%2FDrZWHW78TWdRSpnP4MnCh7cVNz3hPwSpzVOl9jhi2DC5olleWo%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845c374f01e086-NRT
alt-svc: h3=":443"; ma=86400
GET
307
https://grabyourpizza.com/7a54bdb20779c4359694feaa1398dd25.exe
REQUEST
RESPONSE
BODY
GET /7a54bdb20779c4359694feaa1398dd25.exe HTTP/1.1
Host: grabyourpizza.com
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
Date: Wed, 18 Oct 2023 22:53:56 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://diplodoka.net/4d1aaeb879448e5236e36d2209b40d34/7a54bdb20779c4359694feaa1398dd25.exe
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=HAYkgFaqV5eXiYGFVFnBUtgUuL8pFgdkaJEkahU52ln16uinVAGVRpOHJlCqD0hNK%2BaQF59CBZ3t0xjClJoXmwxQCn0xUcbup4rIw4JqfmsPOTkJfxMYIhbrJhgVJQtaoXMegQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845c378c4c8322-KIX
alt-svc: h3=":443"; ma=86400
GET
200
https://potatogoose.com/4d1aaeb879448e5236e36d2209b40d34/baf14778c246e15550645e30ba78ce1c.exe
REQUEST
RESPONSE
BODY
GET /4d1aaeb879448e5236e36d2209b40d34/baf14778c246e15550645e30ba78ce1c.exe HTTP/1.1
Host: potatogoose.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:53:57 GMT
Content-Type: application/x-ms-dos-executable
Content-Length: 4369264
Connection: keep-alive
Last-Modified: Wed, 18 Oct 2023 20:34:08 GMT
Cache-Control: max-age=14400
CF-Cache-Status: MISS
Accept-Ranges: bytes
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=jID2hNuxEDf75NAViXx90lelaowwJp4p17eatx8Vr3EH5REuh97UauYzGZhMKocFH5V4LktXMOq4MVzTgBbGZyBIiZcAQnwTz4qyvyAKimXfNqr3LMyv3zwfUUKYT%2Bd5XbY%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845c3b8c09e0b0-NRT
alt-svc: h3=":443"; ma=86400
GET
200
https://diplodoka.net/4d1aaeb879448e5236e36d2209b40d34/7a54bdb20779c4359694feaa1398dd25.exe
REQUEST
RESPONSE
BODY
GET /4d1aaeb879448e5236e36d2209b40d34/7a54bdb20779c4359694feaa1398dd25.exe HTTP/1.1
Host: diplodoka.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:53:57 GMT
Content-Type: application/x-ms-dos-executable
Content-Length: 4369296
Connection: keep-alive
Last-Modified: Wed, 18 Oct 2023 20:34:10 GMT
Cache-Control: max-age=14400
CF-Cache-Status: MISS
Accept-Ranges: bytes
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=%2BWYBTWJvSkncQnSAOVUQOyDk%2BPIMldQMtj2DQmmsW49v4%2BzXwY4Cd0UqV%2BKpKrj54I%2BDx%2Fb2Ee1w3LAyRg4fdSBafkkIRLnzfzsOy5CRpS2UI8MEDQ1omhGykCzdiNsM"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845c3bbaad19ec-KIX
alt-svc: h3=":443"; ma=86400
GET
200
http://172.86.97.117/himeffectivelyproress.exe
REQUEST
RESPONSE
BODY
GET /himeffectivelyproress.exe HTTP/1.1
Host: 172.86.97.117
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:53:55 GMT
Server: Apache/2.4.52 (Ubuntu)
Last-Modified: Wed, 18 Oct 2023 11:43:05 GMT
ETag: "5e000-607fc247c97bc"
Accept-Ranges: bytes
Content-Length: 385024
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdos-program
GET
200
http://85.217.144.143/files/Amadey.exe
REQUEST
RESPONSE
BODY
GET /files/Amadey.exe HTTP/1.1
Host: 85.217.144.143
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:53:56 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Sun, 01 Oct 2023 10:41:57 GMT
ETag: "38800-606a54e8fc226"
Accept-Ranges: bytes
Content-Length: 231424
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://85.217.144.143/files/My2.exe
REQUEST
RESPONSE
BODY
GET /files/My2.exe HTTP/1.1
Host: 85.217.144.143
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:53:56 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Thu, 12 Oct 2023 02:11:41 GMT
ETag: "53d718-6077b75f2e86b"
Accept-Ranges: bytes
Content-Length: 5494552
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://galandskiyher5.com/downloads/toolspub1.exe
REQUEST
RESPONSE
BODY
GET /downloads/toolspub1.exe HTTP/1.1
Host: galandskiyher5.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.20.2
Date: Wed, 18 Oct 2023 22:53:56 GMT
Content-Type: application/x-msdos-program
Content-Length: 268800
Connection: close
Last-Modified: Wed, 18 Oct 2023 22:53:02 GMT
ETag: "41a00-60805806252d5"
Accept-Ranges: bytes
GET
200
http://gons01b.top/build.exe
REQUEST
RESPONSE
BODY
GET /build.exe HTTP/1.1
Host: gons01b.top
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 18 Oct 2023 22:53:56 GMT
Content-Type: application/octet-stream
Content-Length: 381952
Connection: keep-alive
Last-Modified: Wed, 18 Oct 2023 15:56:07 GMT
ETag: "5d400-607ffad6b86c2"
Accept-Ranges: bytes
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 18 Oct 2023 23:53:55 GMT
Date: Wed, 18 Oct 2023 22:53:55 GMT
Connection: keep-alive
GET
301
http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Wed, 18 Oct 2023 22:53:56 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Location: https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 18 Oct 2023 23:53:56 GMT
Date: Wed, 18 Oct 2023 22:53:56 GMT
Connection: keep-alive
GET
0
http://104.194.128.170/svp/Ykwrxaauw.dat
REQUEST
RESPONSE
BODY
GET /svp/Ykwrxaauw.dat HTTP/1.1
Host: 104.194.128.170
Connection: Keep-Alive
GET
200
http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE
BODY
GET /IE9CompatViewList.xml HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
Host: ie9cvlist.ie.microsoft.com
If-Modified-Since: Fri, 16 Oct 2020 17:54:09 GMT
If-None-Match: 0x8D871FC7BDF491D
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Encoding: gzip
Age: 20736
Cache-Control: max-age=21600
Content-MD5: p9g4jsuZO6TaLMVAI9ujVg==
Content-Type: text/xml
Date: Wed, 18 Oct 2023 22:55:19 GMT
Etag: 0x8D9521D2D2DF1EC
Last-Modified: Wed, 28 Jul 2021 23:12:31 GMT
Server: ECAcc (tka/897A)
Vary: Accept-Encoding
X-Cache: HIT
x-ms-blob-type: BlockBlob
x-ms-lease-status: unlocked
x-ms-request-id: 788bd352-c01e-0078-4ae5-0185b5000000
x-ms-version: 2009-09-19
Content-Length: 13702
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49170 104.21.32.208:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=lycheepanel.info | 9f:29:fd:d3:0f:46:b4:fc:1f:d0:06:c7:4e:4d:21:d0:21:08:ea:43 |
TLS 1.2 192.168.56.103:49164 104.20.67.143:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 55:c8:82:61:30:05:42:80:db:47:5e:d0:66:b5:df:ac:14:5b:19:6f |
TLS 1.2 192.168.56.103:49167 172.67.216.81:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=flyawayaero.net | 34:8b:a3:9d:94:c4:8d:02:5c:e1:f1:43:da:57:49:64:a9:1c:b6:fe |
TLS 1.2 192.168.56.103:49171 172.67.197.174:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.grabyourpizza.com | 19:34:3f:f1:b2:75:20:7f:8a:58:d1:fd:26:b2:74:e2:ea:f8:76:e6 |
TLS 1.2 192.168.56.103:49179 104.21.78.56:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=diplodoka.net | 08:f2:0c:9e:cc:84:cd:91:24:54:d5:fe:5e:3f:a9:46:68:a2:58:33 |
TLS 1.2 192.168.56.103:49176 45.130.41.101:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=laubenstein.space | d4:04:82:56:eb:8d:bb:fd:72:7a:36:fd:90:c1:07:aa:45:ac:92:27 |
TLS 1.2 192.168.56.103:49178 104.21.35.235:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=potatogoose.com | 0f:a9:ea:9d:3e:af:d2:24:68:a0:8f:b7:58:00:c9:0b:f0:7f:31:37 |
TLS 1.2 192.168.56.103:49180 107.167.110.211:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 | C=NO, ST=Oslo, L=Oslo, O=Opera Norway AS, CN=net.geo.opera.com | 8b:1e:84:38:9c:97:8c:be:f7:e1:0e:28:14:15:bb:08:cc:fb:ad:af |
TLS 1.3 192.168.56.103:49232 131.153.76.130:80 |
None | None | None |
Snort Alerts
No Snort Alerts