Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
gwenetha.info | 172.67.131.232 | |
pastebin.com | 104.23.98.190 | |
cdn.discordapp.com | 162.159.133.233 | |
iplogger.org | 88.99.66.31 | |
whatitis.website |
- TCP Requests
-
-
192.168.56.101:49206 104.21.12.27:443gwenetha.info
-
192.168.56.101:49201 104.23.98.190:443pastebin.com
-
192.168.56.101:49204 162.159.130.233:443cdn.discordapp.com
-
192.168.56.101:49205 162.159.130.233:443cdn.discordapp.com
-
192.168.56.101:49208 162.159.130.233:443cdn.discordapp.com
-
192.168.56.101:49209 162.159.130.233:443cdn.discordapp.com
-
192.168.56.101:49210 162.159.130.233:443cdn.discordapp.com
-
192.168.56.101:49207 88.99.66.31:443iplogger.org
-
- UDP Requests
-
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:55450 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:65329 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
192.168.56.101:62331 239.255.255.250:3702
-
192.168.56.101:62333 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
8.8.8.8:53 192.168.56.101:55450
-
GET
200
https://pastebin.com/raw/gCyjHCCH
REQUEST
RESPONSE
BODY
GET /raw/gCyjHCCH HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 07 Apr 2021 03:32:55 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=df08a34bf4fa03301935a05f91a6548d31617766375; expires=Fri, 07-May-21 03:32:55 GMT; path=/; domain=.pastebin.com; HttpOnly; SameSite=Lax; Secure
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: HIT
Age: 455
cf-request-id: 094bfcf70d0000e9c85e050000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Server: cloudflare
CF-RAY: 63c03104eb16e9c8-ICN
GET
403
https://cdn.discordapp.com/attachments/826198252025675816/826538114838298715/install_setupVPSfree.exe
REQUEST
RESPONSE
BODY
GET /attachments/826198252025675816/826538114838298715/install_setupVPSfree.exe HTTP/1.1
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 403 Forbidden
Date: Wed, 07 Apr 2021 03:33:02 GMT
Content-Type: application/xml; charset=UTF-8
Content-Length: 223
Connection: keep-alive
Set-Cookie: __cfduid=ddadf93a81631d3a013447c3b6abf483b1617766381; expires=Fri, 07-May-21 03:33:01 GMT; path=/; domain=.discordapp.com; HttpOnly; SameSite=Lax
CF-Ray: 63c0312eafc5015c-ICN
Cache-Control: private, max-age=0
Expires: Wed, 07 Apr 2021 03:33:02 GMT
Vary: Accept-Encoding
CF-Cache-Status: EXPIRED
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
cf-request-id: 094bfd112c0000015ca2281000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-GUploader-UploadID: ABg5-Uz9Q1cpcTjqjNPPMNjh3BAlMrzbTKOUcz0t2G_ViulbXJH7Hr0KvSrbLlCRrdasFzqp6-_VGslG7OlybLN-5gz4ndgO5w
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report?s=TCsO0jfq%2BpXhVaCScNrcXk0wSvRbxUTWgEvSS5Na6dQJCLe27WpM8jq96ZEwMoPBcI2fMTJOlVJfN7X9mP8xmmFeh30oGxo61HZteQSsY%2Fo6AZg%3D"}]}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
403
https://cdn.discordapp.com/attachments/826416818390040589/826855866228670474/7525b875715555.exe
REQUEST
RESPONSE
BODY
GET /attachments/826416818390040589/826855866228670474/7525b875715555.exe HTTP/1.1
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 403 Forbidden
Date: Wed, 07 Apr 2021 03:33:02 GMT
Content-Type: application/xml; charset=UTF-8
Content-Length: 223
Connection: keep-alive
Set-Cookie: __cfduid=d66b3fc857cb0b20d4e43cd9aeb1405f71617766382; expires=Fri, 07-May-21 03:33:02 GMT; path=/; domain=.discordapp.com; HttpOnly; SameSite=Lax
CF-Ray: 63c0312fcc4a3525-ICN
Cache-Control: private, max-age=0
Expires: Wed, 07 Apr 2021 03:33:02 GMT
Vary: Accept-Encoding
CF-Cache-Status: EXPIRED
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
cf-request-id: 094bfd11de000035251aad1000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-GUploader-UploadID: ABg5-Uw_9ReKX1n7XDsdWEL0QSy0P0trrNtbnY2ScgOa-hX5am8uKPknDTeHy1Kn4DcZFROQYsZLOWW50-GvfODf15c
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report?s=B41ntDAH7N9%2FLVx%2FJ9pBL139X5B0gpLiZ6%2FlnxmaNRPw%2FXxZRuJ4YEYjvGcHvscqATKLBPZjLXWO1quKfZ7qTR1ElX6HLyUVzGIfcvgJV8PRMGg%3D"}],"max_age":604800,"group":"cf-nel"}
NEL: {"max_age":604800,"report_to":"cf-nel"}
Server: cloudflare
GET
404
https://gwenetha.info/setup-KGQJ-1.exe
REQUEST
RESPONSE
BODY
GET /setup-KGQJ-1.exe HTTP/1.1
Host: gwenetha.info
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Wed, 07 Apr 2021 03:33:02 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 19
Connection: keep-alive
Set-Cookie: __cfduid=d21ef7e627398daae36610d85e632dd611617766382; expires=Fri, 07-May-21 03:33:02 GMT; path=/; domain=.gwenetha.info; HttpOnly; SameSite=Lax
X-Content-Type-Options: nosniff
CF-Cache-Status: DYNAMIC
cf-request-id: 094bfd12bf0000365572b17000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"max_age":604800,"group":"cf-nel","endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report?s=iTSCffIXTbpbLuJMW1QZtTijUHX%2FSI3x8yXUBBOIjCUHlp5DmKk%2FUop%2FSq0LwvbCipEa8suMbdMAt0D5IhvtNWbOevVEhhD84FXlCx76"}]}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 63c031313cdb3655-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
GET
301
https://iplogger.org/2LehR6.exe
REQUEST
RESPONSE
BODY
GET /2LehR6.exe HTTP/1.1
Host: iplogger.org
Connection: Keep-Alive
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Wed, 07 Apr 2021 03:33:08 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: PHPSESSID=o1c5urr6unco68fet23474kn23; path=/; HttpOnly
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
Set-Cookie: clhf03028ja=175.208.134.150; expires=Wed, 18-Jul-2029 05:49:51 GMT; Max-Age=261281803; path=/
Set-Cookie: timezone=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Set-Cookie: timezone=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Location: https://cdn.discordapp.com/attachments/826416818390040589/826531006563352596/Bussed_2021-03-30_21-01.exe
Strict-Transport-Security: max-age=31536000; preload
X-Frame-Options: DENY
GET
403
https://cdn.discordapp.com/attachments/826416818390040589/826469949593485312/file.exe
REQUEST
RESPONSE
BODY
GET /attachments/826416818390040589/826469949593485312/file.exe HTTP/1.1
Host: cdn.discordapp.com
HTTP/1.1 403 Forbidden
Date: Wed, 07 Apr 2021 03:33:15 GMT
Content-Type: application/xml; charset=UTF-8
Content-Length: 223
Connection: keep-alive
Set-Cookie: __cfduid=dbb0f362b5ece289e9132f6ac2968be861617766394; expires=Fri, 07-May-21 03:33:14 GMT; path=/; domain=.discordapp.com; HttpOnly; SameSite=Lax
CF-Ray: 63c0317ff9833532-ICN
Cache-Control: private, max-age=0
Expires: Wed, 07 Apr 2021 03:33:15 GMT
Vary: Accept-Encoding
CF-Cache-Status: EXPIRED
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
cf-request-id: 094bfd43f900003532e43b7000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-GUploader-UploadID: ABg5-UwQZXnZEOlnTG3RSr4E1O2jKuna2jpdjpODg4YFgsW1SHFnrVzKKJrHMwEdq_YKLuLWaAuGiYgf-hbJw5GpBOmPd6AVzA
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report?s=0wCd6javsw1iGMP1rK%2BOtWdoNQVoXbzhsXv97pjyO3Up5FUF%2BgTIQnYEgJ2CQ0fcYxT8h%2BIYjZQl2gUPFG6HPkTrkF11lDuaNjHyrxa62Ve51Xs%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"max_age":604800,"report_to":"cf-nel"}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/826416818390040589/826531006563352596/Bussed_2021-03-30_21-01.exe
REQUEST
RESPONSE
BODY
GET /attachments/826416818390040589/826531006563352596/Bussed_2021-03-30_21-01.exe HTTP/1.1
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Wed, 07 Apr 2021 03:33:17 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=d79d3aac25392ca914c536e371891caaf1617766397; expires=Fri, 07-May-21 03:33:17 GMT; path=/; domain=.discordapp.com; HttpOnly; SameSite=Lax
X-Frame-Options: SAMEORIGIN
cf-request-id: 094bfd4cee0000a225acbf6000000001
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"group":"cf-nel","endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report?s=YeC%2FvyHGkDUb2pbDa4QEwSUkOGyyMWy%2FMxfkr6uofCV5f%2BiI%2BBYuprqR4L1pEUqfsTTM7fBo2eOcdhFcmDHlp6KpKlcYAH%2FzSS2OGFUh1qwPb9s%3D"}],"max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 63c0318e4e94a225-ICN
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
GET
0
https://cdn.discordapp.com/attachments/826416818390040589/826531006563352596/Bussed_2021-03-30_21-01.exe
REQUEST
RESPONSE
BODY
GET /attachments/826416818390040589/826531006563352596/Bussed_2021-03-30_21-01.exe HTTP/1.1
Host: cdn.discordapp.com
GET
0
https://cdn.discordapp.com/attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe
REQUEST
RESPONSE
GET /attachments/826416818390040589/826540039764705360/7525b875713675d4ff0018cf084f493a4e4977de_2021-03-30_22-25.exe HTTP/1.1
Host: cdn.discordapp.com
xwK¢«sÐYC©UY©XSÚ;3Ev(RMªb`(¢åÓÕ
EÉ¥/²e½#²¥ÉÁÿÙo¯á4i5ë ¯H§PÔ¬é^pÙ<7c»Õ':ô|Ú'íÇz?õ\û¯ô¯kQñ<¾¼}û]¹=Ú¥ÆØ
Ó8¢4¬E°P©ÝÃ/(Q!pÙáÖ÷Ú·M-ñ#Vêø"
Þ[¾Zp«Ð}ÜZ]»qíTÚ<}1Órú=ÄLÖå©«ÒÖÿíÆézðGøé^èSTVoXA
VÎÀbÏå¯/±]}'t©`Q0»×ûÌ`o;N/b@^ÚVhé«ÂF¤Ðzè7,
¯Îä4ûF³7¥ºgýv<ì!/|mF'7_·ùRçåm
9:Ê AëVR%^ë;4#ÏOs<|J#`2µOÂݲ>hÉÖ;&Dp)ÞÁù%Òí®U²ÎÎwO-¨¦+»¸V²]\ì¼õð ÃÍàÕúÜßü?óµ~[,,é´ÑL%ׯ¯Û~ûQ.ÖÒ«ÖÄèSy÷~ç%ôr{,×xS¤ñÜGTGy#ûG{L"1ÿÅø4OS÷àó*?TÓSDLú,ú_xaç¤3V=)¤qñöD½iÒ|éÖ!l7«¤ô^îç+$ªá>µ¶Dïuü21õð¤ Ü.f#ܶ|Rh öejMÑâë
ÖäjE½eÊ©ì¥vÏÕ½gÌÄI ´vÎ C ¼âæHãÅ°ÁöO¤À¦oJ eºÞGF@[â}Aˤò#Q¡æ¿æw³>6((B{ö;BgT /NüÃë&$li°ÍàPvÓ̬,³
<¡þÒ(²BrXâ8¡-
ëÀ}ÃY
´âmùÉ
â¥ÌܶÿIâ·áß&Cv1®W¯;®Meýìð×~oÏ
;{¬èc¯.]PqäÔ´ÝbÍ<47ÚfûGUÿÔò'