Hosts
No hosts contacted.
TCP
Source |
Source Port |
Destination |
Destination Port |
192.168.56.101 |
49182 |
118.112.225.35 www.download.windowsupdate.com |
80 |
192.168.56.101 |
49178 |
13.227.228.93 cdn.slimcleaner.com |
443 |
192.168.56.101 |
49185 |
13.227.228.93 cdn.slimcleaner.com |
443 |
192.168.56.101 |
49179 |
13.227.250.142 x.ss2.us |
80 |
192.168.56.101 |
49174 |
34.194.20.225 trk.slimwareutilities.com |
80 |
192.168.56.101 |
49176 |
52.207.195.86 trk.slimwareutilities.com |
80 |
192.168.56.101 |
49175 |
52.44.44.47 apps-api.slimwareutilities.com |
80 |
UDP
Source |
Source Port |
Destination |
Destination Port |
192.168.56.101 |
50534 |
114.114.114.114 |
53 |
192.168.56.101 |
50568 |
114.114.114.114 |
53 |
192.168.56.101 |
51378 |
114.114.114.114 |
53 |
192.168.56.101 |
53237 |
114.114.114.114 |
53 |
192.168.56.101 |
56539 |
114.114.114.114 |
53 |
192.168.56.101 |
57236 |
114.114.114.114 |
53 |
192.168.56.101 |
57756 |
114.114.114.114 |
53 |
192.168.56.101 |
57874 |
114.114.114.114 |
53 |
192.168.56.101 |
58367 |
114.114.114.114 |
53 |
192.168.56.101 |
63429 |
114.114.114.114 |
53 |
192.168.56.101 |
65004 |
114.114.114.114 |
53 |
192.168.56.101 |
137 |
192.168.56.255 |
137 |
192.168.56.101 |
138 |
192.168.56.255 |
138 |
192.168.56.101 |
123 |
20.189.79.72 time.windows.com |
123 |
192.168.56.101 |
49235 |
224.0.0.252 |
5355 |
192.168.56.101 |
50002 |
224.0.0.252 |
5355 |
192.168.56.101 |
51963 |
224.0.0.252 |
5355 |
192.168.56.101 |
53210 |
224.0.0.252 |
5355 |
192.168.56.101 |
53657 |
224.0.0.252 |
5355 |
192.168.56.101 |
54178 |
224.0.0.252 |
5355 |
HTTP & HTTPS Requests
URI |
Data |
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 3600
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Wed, 03 Mar 2021 06:32:16 GMT
If-None-Match: "0d8f4f3f6fd71:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com
|
http://x.ss2.us/x.cer |
GET /x.cer HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: x.ss2.us
|
http://apps-api.slimwareutilities.com/install/scp/6.1/x64/SlimCleanerPlus-setup.msi.bz2?machineId=E690B718-D217-49EF-893A-2E552F941D23 |
GET /install/scp/6.1/x64/SlimCleanerPlus-setup.msi.bz2?machineId=E690B718-D217-49EF-893A-2E552F941D23 HTTP/1.1
Connection: Keep-Alive
User-Agent: SlimCleaner Plus Installer/2.24.6.37 (os:windows; ver:6.1; arc:AMD64)
Host: apps-api.slimwareutilities.com
|
http://trk.slimwareutilities.com/ulc.php?ev=InstallerAccepted&upl=YTo5OntzOjk6InVsX3N0dWJpZCI7czozNjoiYjBkNTJkZmQtMmMwYS00NWRhLWFjNDYtOWQwYzRkNWJiNzc4IjtzOjEwOiJ1bF9jb2JyYW5kIjtzOjM6IlNXMSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMSI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMToiL2Rvd25sb2FkL3NsaW1jbGVhbmVyIjt9fXM6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjY6IjEyLjI0NiI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjA6IiI7czoxMDoicGxhdGZvcm1PUyI7czo3OiJXaW5kb3dzIjtzOjE3OiJwbGF0Zm9ybU9TVmVyc2lvbiI7czo0OiIxMC4wIjt9&machineId=E690B718-D217-49EF-893A-2E552F941D23&platformOS=Windows&platformOSVersion=6.1&installer=LI0&installerVersion=2.24.6.37&product=SW1 |
GET /ulc.php?ev=InstallerAccepted&upl=YTo5OntzOjk6InVsX3N0dWJpZCI7czozNjoiYjBkNTJkZmQtMmMwYS00NWRhLWFjNDYtOWQwYzRkNWJiNzc4IjtzOjEwOiJ1bF9jb2JyYW5kIjtzOjM6IlNXMSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMSI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMToiL2Rvd25sb2FkL3NsaW1jbGVhbmVyIjt9fXM6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjY6IjEyLjI0NiI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjA6IiI7czoxMDoicGxhdGZvcm1PUyI7czo3OiJXaW5kb3dzIjtzOjE3OiJwbGF0Zm9ybU9TVmVyc2lvbiI7czo0OiIxMC4wIjt9&machineId=E690B718-D217-49EF-893A-2E552F941D23&platformOS=Windows&platformOSVersion=6.1&installer=LI0&installerVersion=2.24.6.37&product=SW1 HTTP/1.1
Connection: Keep-Alive
User-Agent: SlimCleaner Plus Installer/2.24.6.37 (os:windows; ver:6.1; arc:AMD64)
Host: trk.slimwareutilities.com
|
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1
Cache-Control: max-age = 900
Connection: Keep-Alive
Accept: */*
If-Modified-Since: Mon, 19 Apr 2021 20:17:25 GMT
If-None-Match: "80f8835935d71:0"
User-Agent: Microsoft-CryptoAPI/6.1
Host: www.download.windowsupdate.com
|
http://apps-api.slimwareutilities.com/install/scp/6.1/x64/SlimCleanerPlus-setup.msi.bz2?machineId=E690B718-D217-49EF-893A-2E552F941D23 |
GET /install/scp/6.1/x64/SlimCleanerPlus-setup.msi.bz2?machineId=E690B718-D217-49EF-893A-2E552F941D23 HTTP/1.1
Connection: Keep-Alive
User-Agent: SlimCleaner Plus Installer/2.24.6.37 (os:windows; ver:6.1; arc:AMD64)
Host: apps-api.slimwareutilities.com
Cookie: AWSALBCORS=A5cFJv0BhVx+18evcHlwu2eegCZ2e7tdY0wiRYW5fUCs2mISIXhGPJBTC7fv5DF3gGbPF2swXENjtFmq121gh6/uwa9/dTW39MIxakvFoddbDxhL/yYwkDLu/3Qz; AWSALB=A5cFJv0BhVx+18evcHlwu2eegCZ2e7tdY0wiRYW5fUCs2mISIXhGPJBTC7fv5DF3gGbPF2swXENjtFmq121gh6/uwa9/dTW39MIxakvFoddbDxhL/yYwkDLu/3Qz
|
http://trk.slimwareutilities.com/ulc.php?ev=InstallerInvoked&upl=YTo5OntzOjk6InVsX3N0dWJpZCI7czozNjoiYjBkNTJkZmQtMmMwYS00NWRhLWFjNDYtOWQwYzRkNWJiNzc4IjtzOjEwOiJ1bF9jb2JyYW5kIjtzOjM6IlNXMSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMSI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMToiL2Rvd25sb2FkL3NsaW1jbGVhbmVyIjt9fXM6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjY6IjEyLjI0NiI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjA6IiI7czoxMDoicGxhdGZvcm1PUyI7czo3OiJXaW5kb3dzIjtzOjE3OiJwbGF0Zm9ybU9TVmVyc2lvbiI7czo0OiIxMC4wIjt9&machineId=E690B718-D217-49EF-893A-2E552F941D23&platformOS=Windows&platformOSVersion=6.1&installer=LI0&installerVersion=2.24.6.37&product=SW1&msBclVersion=4.0.0 |
GET /ulc.php?ev=InstallerInvoked&upl=YTo5OntzOjk6InVsX3N0dWJpZCI7czozNjoiYjBkNTJkZmQtMmMwYS00NWRhLWFjNDYtOWQwYzRkNWJiNzc4IjtzOjEwOiJ1bF9jb2JyYW5kIjtzOjM6IlNXMSI7czo3OiJwcm9kdWN0IjtzOjM6IlNXMSI7czoxMjoidXNlclNlZ21lbnRzIjtPOjg6InN0ZENsYXNzIjoxOntzOjQ6IlNpdGUiO086ODoic3RkQ2xhc3MiOjI6e3M6NjoiRG9tYWluIjtzOjEyOiJzbGltd2FyZS5jb20iO3M6NDoiUGFnZSI7czoyMToiL2Rvd25sb2FkL3NsaW1jbGVhbmVyIjt9fXM6MTE6ImJyb3dzZXJUeXBlIjtzOjQ6IkVkZ2UiO3M6MTQ6ImJyb3dzZXJWZXJzaW9uIjtzOjY6IjEyLjI0NiI7czoxNToiYnJvd3Nlckxhbmd1YWdlIjtzOjA6IiI7czoxMDoicGxhdGZvcm1PUyI7czo3OiJXaW5kb3dzIjtzOjE3OiJwbGF0Zm9ybU9TVmVyc2lvbiI7czo0OiIxMC4wIjt9&machineId=E690B718-D217-49EF-893A-2E552F941D23&platformOS=Windows&platformOSVersion=6.1&installer=LI0&installerVersion=2.24.6.37&product=SW1&msBclVersion=4.0.0 HTTP/1.1
Connection: Keep-Alive
User-Agent: SlimCleaner Plus Installer/2.24.6.37 (os:windows; ver:6.1; arc:AMD64)
Host: trk.slimwareutilities.com
|
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts