Network Analysis
IP Address | Status | Action |
---|---|---|
162.159.135.233 | Active | Moloch |
104.20.67.143 | Active | Moloch |
104.21.32.208 | Active | Moloch |
107.167.110.216 | Active | Moloch |
131.153.76.130 | Active | Moloch |
148.251.234.93 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.180.173 | Active | Moloch |
172.67.197.174 | Active | Moloch |
172.67.216.81 | Active | Moloch |
172.67.217.52 | Active | Moloch |
194.169.175.127 | Active | Moloch |
23.67.53.27 | Active | Moloch |
45.130.41.101 | Active | Moloch |
65.109.26.240 | Active | Moloch |
85.143.220.63 | Active | Moloch |
85.217.144.143 | Active | Moloch |
- TCP Requests
-
-
162.159.135.233:443 192.168.56.101:49166
-
192.168.56.101:49164 104.20.67.143:443pastebin.com
-
192.168.56.101:49168 104.21.32.208:443lycheepanel.info
-
192.168.56.101:49174 107.167.110.216:80net.geo.opera.com
-
192.168.56.101:49177 107.167.110.216:443net.geo.opera.com
-
192.168.56.101:49192 131.153.76.130:80pool.hashvault.pro
-
192.168.56.101:49178 148.251.234.93:443yip.su
-
192.168.56.101:49176 172.67.180.173:443potatogoose.com
-
192.168.56.101:49167 172.67.197.174:443grabyourpizza.com
-
192.168.56.101:49166 172.67.216.81:443flyawayaero.net
-
192.168.56.101:49175 172.67.217.52:443diplodoka.net
-
192.168.56.101:49169 194.169.175.127:80galandskiyher5.com
-
192.168.56.101:49171 23.67.53.27:80apps.identrust.com
-
192.168.56.101:49173 45.130.41.101:443laubenstein.space
-
192.168.56.101:49172 65.109.26.240:443darianentertainment.com
-
192.168.56.101:49170 85.143.220.63:80gobo02fc.top
-
192.168.56.101:49165 85.217.144.143:80
-
- UDP Requests
-
-
192.168.56.101:51901 164.124.101.2:53
-
192.168.56.101:52753 164.124.101.2:53
-
192.168.56.101:52797 164.124.101.2:53
-
192.168.56.101:52815 164.124.101.2:53
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:54883 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:57986 164.124.101.2:53
-
192.168.56.101:58120 164.124.101.2:53
-
192.168.56.101:58297 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:61950 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
8.8.8.8:53 192.168.56.101:52815
-
192.168.56.103:137 192.168.56.101:137
-
GET
200
https://pastebin.com/raw/xYhKBupz
REQUEST
RESPONSE
BODY
GET /raw/xYhKBupz HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:56:11 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: HIT
Age: 915
Last-Modified: Wed, 18 Oct 2023 22:40:56 GMT
Server: cloudflare
CF-RAY: 81845f86f88e3149-LAX
GET
307
https://grabyourpizza.com/7a54bdb20779c4359694feaa1398dd25.exe
REQUEST
RESPONSE
BODY
GET /7a54bdb20779c4359694feaa1398dd25.exe HTTP/1.1
Host: grabyourpizza.com
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
Date: Wed, 18 Oct 2023 22:56:12 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://diplodoka.net/4d1aaeb879448e5236e36d2209b40d34/7a54bdb20779c4359694feaa1398dd25.exe
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=6yKdK1ZVIBSyP5RYwsgp%2BNdINrkQ5KJknag8L0CIPuFwBWrn3jLi3hYJvbGPz1%2B7skcbJLqLrAj1Ie%2FZ%2BCXvKXcvgg3PvGEY7m3pLyQ8spztF1Tts2r67h2xBe82UfV%2FmhNNvA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845f88b889830e-KIX
alt-svc: h3=":443"; ma=86400
GET
307
https://flyawayaero.net/baf14778c246e15550645e30ba78ce1c.exe
REQUEST
RESPONSE
BODY
GET /baf14778c246e15550645e30ba78ce1c.exe HTTP/1.1
Host: flyawayaero.net
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
Date: Wed, 18 Oct 2023 22:56:12 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://potatogoose.com/4d1aaeb879448e5236e36d2209b40d34/baf14778c246e15550645e30ba78ce1c.exe
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=T8CVobC3QAZKdMz1bAF7Gme7gFVEV6TiarKxz1TE6SwMgT1m4bfcE51L%2BObAfTLvNiO%2BNb1cGKLcyw8phPMexcUSrf5pEA%2BbSF0BstI0uG2iHscBLQUeQQhI2QPqQ33Z3o4%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845f88e85a2047-NRT
alt-svc: h3=":443"; ma=86400
GET
200
https://diplodoka.net/4d1aaeb879448e5236e36d2209b40d34/7a54bdb20779c4359694feaa1398dd25.exe
REQUEST
RESPONSE
BODY
GET /4d1aaeb879448e5236e36d2209b40d34/7a54bdb20779c4359694feaa1398dd25.exe HTTP/1.1
Host: diplodoka.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:56:13 GMT
Content-Type: application/x-ms-dos-executable
Content-Length: 4369296
Connection: keep-alive
Last-Modified: Wed, 18 Oct 2023 20:34:10 GMT
Cache-Control: max-age=14400
CF-Cache-Status: MISS
Accept-Ranges: bytes
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=grktyvpVLdWUhqKH%2BjW8tmIuy4mpPlynkCKl9qsuiFTIhCQBSI3LXTINAcvn6BcyEcs44Xkefwcd3V0UoKYenqEaTIf%2FRO22cbXKwwXyd%2BJsU8G6q8K3MCaCzh8ninQR"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845f8d08edaf36-NRT
alt-svc: h3=":443"; ma=86400
GET
200
https://potatogoose.com/4d1aaeb879448e5236e36d2209b40d34/baf14778c246e15550645e30ba78ce1c.exe
REQUEST
RESPONSE
BODY
GET /4d1aaeb879448e5236e36d2209b40d34/baf14778c246e15550645e30ba78ce1c.exe HTTP/1.1
Host: potatogoose.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:56:13 GMT
Content-Type: application/x-ms-dos-executable
Content-Length: 4369264
Connection: keep-alive
Last-Modified: Wed, 18 Oct 2023 20:34:08 GMT
Cache-Control: max-age=14400
CF-Cache-Status: MISS
Accept-Ranges: bytes
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=0RbDAHMv6SVtDtmQiT%2BemD3kGG7V%2FCAX5w8pb1bOYjYjmmZIKJXGQLUA99wme0NflRXnYojQyha6hBS%2FTvegF%2FGCMdUevsYpHTURRUxyhOAuXdaRFyZqeT4zGPgGUxfY%2FPg%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81845f8d094d8d10-KIX
alt-svc: h3=":443"; ma=86400
GET
200
https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 18 Oct 2023 22:56:13 GMT
Content-Type: application/octet-stream
Transfer-Encoding: chunked
Connection: keep-alive
Content-Disposition: attachment; filename=OperaSetup.exe
ETag: "5c59df5bc464917b8c2335d1c280edf6"
Strict-Transport-Security: max-age=31536000; includeSubDomains
GET
200
http://85.217.144.143/files/My2.exe
REQUEST
RESPONSE
BODY
GET /files/My2.exe HTTP/1.1
Host: 85.217.144.143
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 22:56:12 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Thu, 12 Oct 2023 02:11:41 GMT
ETag: "53d718-6077b75f2e86b"
Accept-Ranges: bytes
Content-Length: 5494552
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://galandskiyher5.com/downloads/toolspub1.exe
REQUEST
RESPONSE
BODY
GET /downloads/toolspub1.exe HTTP/1.1
Host: galandskiyher5.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.20.2
Date: Wed, 18 Oct 2023 22:56:12 GMT
Content-Type: application/x-msdos-program
Content-Length: 268800
Connection: close
Last-Modified: Wed, 18 Oct 2023 22:56:01 GMT
ETag: "41a00-608058b16709c"
Accept-Ranges: bytes
GET
200
http://gobo02fc.top/build.exe
REQUEST
RESPONSE
BODY
GET /build.exe HTTP/1.1
Host: gobo02fc.top
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 18 Oct 2023 22:56:12 GMT
Content-Type: application/octet-stream
Content-Length: 381440
Connection: keep-alive
Last-Modified: Wed, 18 Oct 2023 20:04:33 GMT
ETag: "5d200-6080325dc6030"
Accept-Ranges: bytes
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 18 Oct 2023 23:56:11 GMT
Date: Wed, 18 Oct 2023 22:56:11 GMT
Connection: keep-alive
GET
301
http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Wed, 18 Oct 2023 22:56:12 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Location: https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Wed, 18 Oct 2023 23:56:12 GMT
Date: Wed, 18 Oct 2023 22:56:12 GMT
Connection: keep-alive
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.101 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49164 104.20.67.143:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 55:c8:82:61:30:05:42:80:db:47:5e:d0:66:b5:df:ac:14:5b:19:6f |
TLS 1.2 192.168.56.101:49167 172.67.197.174:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.grabyourpizza.com | 19:34:3f:f1:b2:75:20:7f:8a:58:d1:fd:26:b2:74:e2:ea:f8:76:e6 |
TLS 1.2 192.168.56.101:49166 172.67.216.81:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=flyawayaero.net | 34:8b:a3:9d:94:c4:8d:02:5c:e1:f1:43:da:57:49:64:a9:1c:b6:fe |
TLS 1.2 192.168.56.101:49173 45.130.41.101:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=laubenstein.space | d4:04:82:56:eb:8d:bb:fd:72:7a:36:fd:90:c1:07:aa:45:ac:92:27 |
TLS 1.2 192.168.56.101:49175 172.67.217.52:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=diplodoka.net | 08:f2:0c:9e:cc:84:cd:91:24:54:d5:fe:5e:3f:a9:46:68:a2:58:33 |
TLS 1.2 192.168.56.101:49176 172.67.180.173:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=potatogoose.com | 0f:a9:ea:9d:3e:af:d2:24:68:a0:8f:b7:58:00:c9:0b:f0:7f:31:37 |
TLS 1.2 192.168.56.101:49168 104.21.32.208:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=lycheepanel.info | 9f:29:fd:d3:0f:46:b4:fc:1f:d0:06:c7:4e:4d:21:d0:21:08:ea:43 |
TLS 1.2 192.168.56.101:49177 107.167.110.216:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 | C=NO, ST=Oslo, L=Oslo, O=Opera Norway AS, CN=net.geo.opera.com | 8b:1e:84:38:9c:97:8c:be:f7:e1:0e:28:14:15:bb:08:cc:fb:ad:af |
TLS 1.3 192.168.56.101:49192 131.153.76.130:80 |
None | None | None |
Snort Alerts
No Snort Alerts