Network Analysis
IP Address | Status | Action | VT | Location |
---|---|---|---|---|
No hosts contacted. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
No traffic
No traffic
POST
100
http://wecan.hasthe.technology/upload
REQUEST
RESPONSE
BODY
POST /upload HTTP/1.1
Host: wecan.hasthe.technology
Accept: */*
Content-Length: 85477
Expect: 100-continue
Content-Type: multipart/form-data; boundary=------------------------5829c2d711b05cfc
HTTP/1.1 100 Continue
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.168.212:49231 -> 199.59.243.228:80 | 2839369 | ETPRO MALWARE Win32/Snojan Variant Uploading EXE | Malware Command and Control Activity Detected |
TCP 192.168.168.212:49231 -> 199.59.243.228:80 | 2016775 | ET INFO Generic HTTP EXE Upload Outbound | Misc activity |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts