Network Analysis
IP Address | Status | Action |
---|---|---|
104.20.68.143 | Active | Moloch |
104.21.22.166 | Active | Moloch |
104.21.6.189 | Active | Moloch |
107.167.110.211 | Active | Moloch |
121.254.136.9 | Active | Moloch |
131.153.76.130 | Active | Moloch |
148.251.234.93 | Active | Moloch |
164.124.101.2 | Active | Moloch |
171.22.28.204 | Active | Moloch |
172.67.169.89 | Active | Moloch |
172.67.187.122 | Active | Moloch |
37.139.129.88 | Active | Moloch |
69.90.162.0 | Active | Moloch |
74.119.239.234 | Active | Moloch |
85.217.144.143 | Active | Moloch |
95.214.26.28 | Active | Moloch |
- TCP Requests
-
-
192.168.56.103:49164 104.20.68.143:443pastebin.com
-
192.168.56.103:49166 104.21.22.166:443foryourbar.org
-
192.168.56.103:49168 104.21.6.189:80pic.himanfast.com
-
192.168.56.103:49176 107.167.110.211:80net.geo.opera.com
-
192.168.56.103:49178 107.167.110.211:443net.geo.opera.com
-
192.168.56.103:49177 121.254.136.9:80apps.identrust.com
-
192.168.56.103:49554 131.153.76.130:3333pool.hashvault.pro
-
192.168.56.103:49174 148.251.234.93:443iplogger.com
-
192.168.56.103:49173 171.22.28.204:443632432.space
-
192.168.56.103:49165 172.67.169.89:443yip.su
-
192.168.56.103:49170 172.67.187.122:443lycheepanel.info
-
192.168.56.103:49169 37.139.129.88:80dl2-broomcleaner.online
-
192.168.56.103:49172 69.90.162.0:443insuport.com
-
192.168.56.103:49167 85.217.144.143:80
-
192.168.56.103:49171 95.214.26.28:80galandskiyher5.com
-
- UDP Requests
-
-
192.168.56.103:50674 164.124.101.2:53
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53658 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:57986 164.124.101.2:53
-
192.168.56.103:60141 164.124.101.2:53
-
192.168.56.103:60225 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64178 164.124.101.2:53
-
192.168.56.103:64530 164.124.101.2:53
-
192.168.56.103:64631 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:65119 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:60144 239.255.255.250:1900
-
GET
200
https://yip.su/RNWPd.exe
REQUEST
RESPONSE
BODY
GET /RNWPd.exe HTTP/1.1
Host: yip.su
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 29 Oct 2023 22:42:58 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
expires: Sun, 29 Oct 2023 22:42:58 +0000
strict-transport-security: max-age=604800
strict-transport-security: max-age=31536000
content-security-policy: img-src https: data:; upgrade-insecure-requests
x-frame-options: SAMEORIGIN
Cache-Control: max-age=14400
CF-Cache-Status: EXPIRED
Last-Modified: Sun, 29 Oct 2023 19:45:17 GMT
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=uROhJ89IDIfHTD%2FHdP%2BIbWj1tjRSfC%2BB7J72kUNusQf0NlSjKJ78HP5pW7REBbBQIoVKCuXMIfxvMv0h%2FNG7QPfGjeAsfjGdky2O5P%2BxzhPGCuE9L5%2FzpdI%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81deef49286a14da-LAX
alt-svc: h3=":443"; ma=86400
GET
200
https://pastebin.com/raw/E0rY26ni
REQUEST
RESPONSE
BODY
GET /raw/E0rY26ni HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 29 Oct 2023 22:42:58 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: MISS
Last-Modified: Sun, 29 Oct 2023 22:42:58 GMT
Server: cloudflare
CF-RAY: 81deef492ecc527b-LAX
GET
200
https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 29 Oct 2023 22:43:00 GMT
Content-Type: application/octet-stream
Transfer-Encoding: chunked
Connection: keep-alive
Content-Disposition: attachment; filename=OperaSetup.exe
ETag: "4d68aad13445d83897422da70890be29"
Strict-Transport-Security: max-age=31536000; includeSubDomains
GET
200
http://85.217.144.143/files/My2.exe
REQUEST
RESPONSE
BODY
GET /files/My2.exe HTTP/1.1
Host: 85.217.144.143
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 29 Oct 2023 22:42:59 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.0.28
Last-Modified: Thu, 26 Oct 2023 19:21:10 GMT
ETag: "53d718-608a379705a2c"
Accept-Ranges: bytes
Content-Length: 5494552
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdownload
GET
200
http://pic.himanfast.com/order/tuc15.exe
REQUEST
RESPONSE
BODY
GET /order/tuc15.exe HTTP/1.1
Host: pic.himanfast.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 29 Oct 2023 22:42:59 GMT
Content-Type: application/octet-stream
Content-Length: 3002749
Connection: keep-alive
Content-Description: File Transfer
Content-Disposition: attachment; filename=tuc15.exe
Content-Transfer-Encoding: binary
Expires: 0
Cache-Control: max-age=120, must-revalidate
Pragma: public
CF-Cache-Status: EXPIRED
Last-Modified: Sun, 29 Oct 2023 18:55:31 GMT
Accept-Ranges: bytes
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Y4rn%2B%2BZO34LOvMSB4gS1IoH0DOTq0ojysMQqTD9OvNZ%2BTs6biyHmsrwlJ145ESDTx%2FLgyy%2F0c3e5sBjlMKQyNOjdspOaC3n9zsxM458mVpXkmM0v3zzceeysei3m42UdHX%2F%2BGA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81deef4f1c927d82-LAX
alt-svc: h3=":443"; ma=86400
GET
200
http://dl2-broomcleaner.online/InstallSetup6.exe
REQUEST
RESPONSE
BODY
GET /InstallSetup6.exe HTTP/1.1
Host: dl2-broomcleaner.online
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sun, 29 Oct 2023 22:42:59 GMT
Server: Apache/2.4.52 (Ubuntu)
Last-Modified: Sat, 28 Oct 2023 16:56:59 GMT
ETag: "28c50e-608c9b175ccc0"
Accept-Ranges: bytes
Content-Length: 2671886
Connection: close
Content-Type: application/x-msdos-program
GET
200
http://galandskiyher5.com/downloads/toolspub1.exe
REQUEST
RESPONSE
BODY
GET /downloads/toolspub1.exe HTTP/1.1
Host: galandskiyher5.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.20.2
Date: Sun, 29 Oct 2023 22:42:59 GMT
Content-Type: application/x-msdos-program
Content-Length: 266240
Connection: close
Last-Modified: Fri, 20 Oct 2023 18:45:01 GMT
ETag: "41000-6082a451f2224"
Accept-Ranges: bytes
GET
301
http://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
REQUEST
RESPONSE
BODY
GET /opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767 HTTP/1.1
Host: net.geo.opera.com
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Sun, 29 Oct 2023 22:42:59 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
Location: https://net.geo.opera.com/opera/stable/windows/?utm_medium=apb&utm_source=mkt&utm_campaign=767
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Sun, 29 Oct 2023 23:42:59 GMT
Date: Sun, 29 Oct 2023 22:42:59 GMT
Connection: keep-alive
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Sun, 29 Oct 2023 23:42:59 GMT
Date: Sun, 29 Oct 2023 22:42:59 GMT
Connection: keep-alive
GET
200
http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
BODY
GET /roots/dstrootcax3.p7c HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: apps.identrust.com
HTTP/1.1 200 OK
X-XSS-Protection: 1; mode=block
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
X-Robots-Tag: noindex
Referrer-Policy: same-origin
Last-Modified: Fri, 13 Oct 2023 16:28:31 GMT
ETag: "37d-6079b8c0929c0"
Accept-Ranges: bytes
Content-Length: 893
X-Content-Type-Options: nosniff
X-Frame-Options: sameorigin
Content-Type: application/pkcs7-mime
Cache-Control: max-age=3600
Expires: Sun, 29 Oct 2023 23:42:59 GMT
Date: Sun, 29 Oct 2023 22:42:59 GMT
Connection: keep-alive
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
162.144.240.175 | 192.168.56.103 | 3 | |
162.144.240.175 | 192.168.56.103 | 3 | |
162.144.240.175 | 192.168.56.103 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49165 172.67.169.89:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=yip.su | b6:2b:8b:a8:8c:60:65:fb:9d:d6:9b:25:cf:96:b2:78:7a:29:76:6b |
TLS 1.2 192.168.56.103:49164 104.20.68.143:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 55:c8:82:61:30:05:42:80:db:47:5e:d0:66:b5:df:ac:14:5b:19:6f |
TLS 1.2 192.168.56.103:49166 104.21.22.166:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=foryourbar.org | 2d:18:5b:82:ec:83:90:40:85:58:f0:6f:e9:b6:cd:1b:07:00:58:4a |
TLS 1.2 192.168.56.103:49170 172.67.187.122:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=lycheepanel.info | fa:2e:ff:d8:31:ff:34:7b:0d:ed:0c:88:91:99:bd:b3:72:10:92:93 |
TLS 1.2 192.168.56.103:49173 171.22.28.204:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=632432.space | 8b:28:80:18:1c:86:17:be:28:cd:58:ed:e2:b7:54:fd:15:f2:b5:16 |
TLS 1.2 192.168.56.103:49178 107.167.110.211:443 |
C=US, O=DigiCert Inc, CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1 | C=NO, ST=Oslo, L=Oslo, O=Opera Norway AS, CN=net.geo.opera.com | 8b:1e:84:38:9c:97:8c:be:f7:e1:0e:28:14:15:bb:08:cc:fb:ad:af |
TLS 1.3 192.168.56.103:49554 131.153.76.130:3333 |
None | None | None |
Snort Alerts
No Snort Alerts