| request | GET http://ip.ws.126.net/ipquery |
| name | RT_VERSION | language | LANG_CHINESE | offset | 0x00007180 | filetype | MS Windows COFF PowerPC object file | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | size | 0x000001f0 | ||||||||||||||||||
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\myJSFrame[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\checklogin[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\public[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\Toolbar[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\lang[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\zDialog[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\index[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\main[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\ad_right[1].js |
| file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\ad_right1[1].js |
| host | 172.217.24.14 | |||
| dead_host | 172.217.24.14:443 |
| dead_host | 216.58.200.46:443 |
No hosts contacted.
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 49178 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49179 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49180 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49185 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49186 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49188 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49189 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49190 | 120.77.146.229 www.ysbaojia.com | 88 |
| 192.168.56.101 | 49197 | 203.208.41.66 update.googleapis.com | 443 |
| 192.168.56.101 | 49181 | 59.111.181.52 ip.ws.126.net | 80 |
| Source | Source Port | Destination | Destination Port |
|---|---|---|---|
| 192.168.56.101 | 50002 | 114.114.114.114 | 53 |
| 192.168.56.101 | 50568 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51808 | 114.114.114.114 | 53 |
| 192.168.56.101 | 51963 | 114.114.114.114 | 53 |
| 192.168.56.101 | 53380 | 114.114.114.114 | 53 |
| 192.168.56.101 | 54260 | 114.114.114.114 | 53 |
| 192.168.56.101 | 55368 | 114.114.114.114 | 53 |
| 192.168.56.101 | 60123 | 114.114.114.114 | 53 |
| 192.168.56.101 | 137 | 192.168.56.255 | 137 |
| 192.168.56.101 | 138 | 192.168.56.255 | 138 |
| 192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
| 192.168.56.101 | 51378 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 53237 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 54178 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 57236 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 58367 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 60088 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 60384 | 224.0.0.252 | 5355 |
| 192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
| URI | Data |
|---|---|
| http://www.ysbaojia.com:88/web/JavaScript/Toolbar.js | GET /web/JavaScript/Toolbar.js HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/web/css/chromestyle.css | GET /web/css/chromestyle.css HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/api/main.asp?pid=2049&Unid=0&comefrom=10&vvv=5.9&SysCode=Web | GET /api/main.asp?pid=2049&Unid=0&comefrom=10&vvv=5.9&SysCode=Web HTTP/1.1 Accept: */* Accept-Language: zh-cn Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/web/images/left_close.gif | GET /web/images/left_close.gif HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/web/css/help.css | GET /web/css/help.css HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/web/images/zDialog/dialog_cb.png | GET /web/images/zDialog/dialog_cb.png HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive Cookie: PVIBDQKTQYWBSNWOYWTD=LTPSKIXFVTVMFKCIEMNQEZWQJMFXZHMQWZDWPBOO |
| http://www.ysbaojia.com:88/web/images/zDialog/dialog_rt.png | GET /web/images/zDialog/dialog_rt.png HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive Cookie: PVIBDQKTQYWBSNWOYWTD=LTPSKIXFVTVMFKCIEMNQEZWQJMFXZHMQWZDWPBOO |
| http://www.ysbaojia.com:88/web/images/tabs-list.gif | GET /web/images/tabs-list.gif HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/web/images/handle.gif | GET /web/images/handle.gif HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive |
| http://www.ysbaojia.com:88/web/images/zDialog/dialog_lt.png | GET /web/images/zDialog/dialog_lt.png HTTP/1.1 Accept: */* Referer: http://www.ysbaojia.com:88/web/xiaomishu.html?pid=2049&unid=0 Accept-Language: zh-CN Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Host: www.ysbaojia.com:88 Connection: Keep-Alive Cookie: PVIBDQKTQYWBSNWOYWTD=LTPSKIXFVTVMFKCIEMNQEZWQJMFXZHMQWZDWPBOO |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts