Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
yigeyo.xyz | 185.117.88.231 |
- TCP Requests
GET
200
http://yigeyo.xyz/21_2/huge.dat
REQUEST
RESPONSE
BODY
GET /21_2/huge.dat HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: yigeyo.xyz
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.14.0
Date: Wed, 27 Mar 2024 22:46:58 GMT
Content-Type: application/octet-stream
Content-Length: 99200683
Last-Modified: Wed, 27 Mar 2024 15:06:07 GMT
Connection: keep-alive
ETag: "660435df-5e9aeab"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49163 -> 185.117.88.231:80 | 2011227 | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) | Potentially Bad Traffic |
TCP 185.117.88.231:80 -> 192.168.56.103:49163 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts