pdb_path | C:\Source\solid\patcher\source\release\host.pdb |
suspicious_features | POST method with no referer header | suspicious_request | POST http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/ApplicationStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/DownloadStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 |
request | GET http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
request | GET http://geoip.snxd.com/geoip/json/ |
request | GET http://metadata.cdn.snxd.com/E_3532718B0BEE499AF229A18978F0CD6948575A24 |
request | POST http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/ApplicationStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 |
request | POST http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/DownloadStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 |
request | GET http://ironcad.trackers.snxd.com/?info_hash=52q%8B%0B%EEI%9A%F2%29%A1%89x%F0%CDiHWZ%24&peer_id=-SD3671-%00%EB5%E0%27%F6%B0b%C0%C1%07%A2&key=BFCDB8C3ED1CE83337841A1E730-31656139-1620990458&ip=192.168.56.101&port=0&compact=1&event=started&event_id=1&left=1462468616&downloaded=0&uploaded=0&sid=1&sflags=2&slocation=77CB964C&stfstart=126&stnow=2&ststart=0&stcheck=2&stdownload=2&t=1621022860&s=a123f4059a2b069 |
request | GET http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe |
request | POST http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/ApplicationStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 |
request | POST http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/DownloadStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\analytics-3.6.5.0-keen[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\enterprise-3.6.7.1.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\jquery.flot.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQSDCVAE\json2.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6ZOR341Z\jquery-ui-1.10.3.custom.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\jquery.zrssfeed[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\excanvas.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\downloader-3.6.7.1.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQSDCVAE\jquery.xml2json[1].js |
file | C:\ProgramData\Solid State Networks\Host.dd124e6e73f223197fd62f9075e86bca3da4ec80\downloader.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\mainwindow[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X6VHVO8H\jquery-1.8.0.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JSSP0KXB\host-3.6.7.1.min[1].js |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DQSDCVAE\custom[1].js |
host | 172.217.24.14 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
dead_host | 216.58.200.46:443 |
No hosts contacted.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49177 | 124.225.105.97 www.download.windowsupdate.com | 80 |
192.168.56.101 | 49232 | 184.28.98.100 ironcad.cdns3.snxd.com | 80 |
192.168.56.101 | 49234 | 184.28.98.100 ironcad.cdns3.snxd.com | 80 |
192.168.56.101 | 49229 | 184.28.98.70 ironcad.cdns3.snxd.com | 80 |
192.168.56.101 | 49230 | 184.28.98.70 ironcad.cdns3.snxd.com | 80 |
192.168.56.101 | 49231 | 184.28.98.70 ironcad.cdns3.snxd.com | 80 |
192.168.56.101 | 49233 | 184.28.98.70 ironcad.cdns3.snxd.com | 80 |
192.168.56.101 | 49224 | 4.27.28.126 metadata.cdn.snxd.com | 80 |
192.168.56.101 | 49225 | 52.25.18.145 5833691d7e58ca69092b1b55.ironcad.keen.snxd.com | 80 |
192.168.56.101 | 49223 | 54.225.35.173 ironcad.trackers.snxd.com | 80 |
192.168.56.101 | 49228 | 54.225.35.173 ironcad.trackers.snxd.com | 80 |
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 50534 | 114.114.114.114 | 53 |
192.168.56.101 | 50568 | 114.114.114.114 | 53 |
192.168.56.101 | 56539 | 114.114.114.114 | 53 |
192.168.56.101 | 57874 | 114.114.114.114 | 53 |
192.168.56.101 | 60123 | 114.114.114.114 | 53 |
192.168.56.101 | 61680 | 114.114.114.114 | 53 |
192.168.56.101 | 65004 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 49235 | 224.0.0.252 | 5355 |
192.168.56.101 | 50002 | 224.0.0.252 | 5355 |
192.168.56.101 | 51378 | 224.0.0.252 | 5355 |
192.168.56.101 | 51808 | 224.0.0.252 | 5355 |
192.168.56.101 | 54260 | 224.0.0.252 | 5355 |
192.168.56.101 | 55368 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 57756 | 224.0.0.252 | 5355 |
192.168.56.101 | 60384 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
URI | Data |
---|---|
http://5833691d7e58ca69092b1b55.ironcad.keen.snxd.com/3.0/projects/566758413bc6965ee6b1edfa/events/DownloadStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 | POST /3.0/projects/566758413bc6965ee6b1edfa/events/DownloadStart?api_key=d52b73202a8b40c676279f0fd4181cad8a2f620bf07f4f7bad0e3ac28ad49c015569cfe269013bb3613da3ed55786ebf4b4d1d4848ba33747f1d761081028f86c5ad794b3ef618fd3e9a8c2e7ab94f517e43abe05b52ad11d04ac4ec5233976d40e2e311c9edacdb02fb345635f9a056 HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Content-Type: application/json Accept: application/json User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) X-Requested-With: XMLHttpRequest Content-Length: 412 Host: 5833691d7e58ca69092b1b55.ironcad.keen.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Referer: http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe Range: bytes=17825792-18874367 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Referer: http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe Range: bytes=13631488-14680063 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Referer: http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe Range: bytes=15728640-16777215 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Range: bytes=2097152-3145727 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Range: bytes=1048576-2097151 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://geoip.snxd.com/geoip/json/ | GET /geoip/json/ HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: application/json, text/javascript, */*; q=0.01 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) X-Requested-With: XMLHttpRequest Host: geoip.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Referer: http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe Range: bytes=16777216-17825791 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Range: bytes=5242880-6291455 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe | GET /IronCAD2017PU1SP1_x86.exe HTTP/1.1 Cache-Control: no-cache Connection: Keep-Alive Pragma: no-cache Accept: */* Referer: http://ironcad.cdns3.snxd.com/IronCAD2017PU1SP1_x86.exe Range: bytes=8388608-9437183 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1.7601.65536; zh-CN) Host: ironcad.cdns3.snxd.com |
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts