Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
ia803402.us.archive.org | 207.241.232.192 |
GET
200
http://93.123.12.248/xampp/Adrp/flowersloverainingbeautifulday.gif
REQUEST
RESPONSE
BODY
GET /xampp/Adrp/flowersloverainingbeautifulday.gif HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: 93.123.12.248
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 27 Jun 2024 01:02:59 GMT
Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.1.25
Last-Modified: Wed, 26 Jun 2024 01:31:15 GMT
ETag: "da4-61bc0f869dbd7"
Accept-Ranges: bytes
Content-Length: 3492
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: image/gif
GET
200
http://66.70.160.254/Users_API/syscore/file_0tq1mssf.to2.txt
REQUEST
RESPONSE
BODY
GET /Users_API/syscore/file_0tq1mssf.to2.txt HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Language: ko
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: 66.70.160.254
HTTP/1.1 200 OK
Date: Thu, 27 Jun 2024 01:03:00 GMT
Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
Last-Modified: Wed, 26 Jun 2024 01:31:15 GMT
ETag: "573-61bc0f8684042"
Accept-Ranges: bytes
Content-Length: 1395
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/plain
GET
200
http://ia803402.us.archive.org/17/items/new_image_20240625_2128/new_image.jpg
REQUEST
RESPONSE
BODY
GET /17/items/new_image_20240625_2128/new_image.jpg HTTP/1.1
Host: ia803402.us.archive.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.25.1
Date: Thu, 27 Jun 2024 01:03:02 GMT
Content-Type: image/jpeg
Content-Length: 9377069
Last-Modified: Tue, 25 Jun 2024 21:29:30 GMT
Connection: keep-alive
ETag: "667b36ba-8f152d"
Strict-Transport-Security: max-age=15724800
Expires: Thu, 27 Jun 2024 07:03:02 GMT
Cache-Control: max-age=21600
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Accept-Encoding,Accept-Language,Authorization,Cache-Control,Content-Length,Content-Range,DNT,Pragma,Range,X-Requested-With
Access-Control-Allow-Credentials: true
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 66.70.160.254:80 -> 192.168.56.101:49164 | 2049038 | ET MALWARE Malicious Base64 Encoded Payload In Image | A Network Trojan was detected |
TCP 207.241.232.192:80 -> 192.168.56.101:49166 | 2047750 | ET MALWARE Base64 Encoded MZ In Image | A Network Trojan was detected |
TCP 66.70.160.254:80 -> 192.168.56.101:49164 | 2012325 | ET WEB_CLIENT Obfuscated Javascript // ptth | Potentially Bad Traffic |
TCP 207.241.232.192:80 -> 192.168.56.101:49166 | 2025011 | ET MALWARE Powershell commands sent B64 2 | A Network Trojan was detected |
TCP 207.241.232.192:80 -> 192.168.56.101:49166 | 2049038 | ET MALWARE Malicious Base64 Encoded Payload In Image | A Network Trojan was detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts