Network Analysis
- TCP Requests
-
-
192.168.56.101:49212 104.21.84.71:80www.gaigoilaocai.com
-
192.168.56.101:49213 104.21.84.71:80www.gaigoilaocai.com
-
192.168.56.101:49216 156.231.25.88:80www.cuadorcoast.com
-
192.168.56.101:49217 156.231.25.88:80www.cuadorcoast.com
-
192.168.56.101:49204 198.54.117.216:80www.frystmor.city
-
192.168.56.101:49205 198.54.117.216:80www.frystmor.city
-
192.168.56.101:49214 199.59.242.153:80www.pon.xyz
-
192.168.56.101:49215 199.59.242.153:80www.pon.xyz
-
192.168.56.101:49202 23.82.12.30:80www.thetravellingwitch.com
-
192.168.56.101:49203 23.82.12.30:80www.thetravellingwitch.com
-
192.168.56.101:49208 31.13.83.16:80www.333s998.com
-
192.168.56.101:49209 31.13.83.16:80www.333s998.com
-
192.168.56.101:49206 34.102.136.180:80www.hk6628.com
-
192.168.56.101:49207 34.102.136.180:80www.hk6628.com
-
192.168.56.101:49210 34.102.136.180:80www.hk6628.com
-
192.168.56.101:49211 34.102.136.180:80www.hk6628.com
-
- UDP Requests
-
-
192.168.56.101:54056 164.124.101.2:53
-
192.168.56.101:55450 164.124.101.2:53
-
192.168.56.101:56887 164.124.101.2:53
-
192.168.56.101:56977 164.124.101.2:53
-
192.168.56.101:57460 164.124.101.2:53
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:65329 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62325 239.255.255.250:3702
-
192.168.56.101:62445 239.255.255.250:1900
-
192.168.56.101:62447 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
8.8.8.8:53 192.168.56.101:57460
-
POST
0
http://www.thetravellingwitch.com/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.thetravellingwitch.com
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.thetravellingwitch.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.thetravellingwitch.com/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
GET
302
http://www.thetravellingwitch.com/wufn/?uZhPcRQ=SkZZDimVFNr5ByBNwXdupEC24fazy/RNnO17U5xCKPPDvCtbTF67loPH83UjHGCD+yr52EUp&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=SkZZDimVFNr5ByBNwXdupEC24fazy/RNnO17U5xCKPPDvCtbTF67loPH83UjHGCD+yr52EUp&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.thetravellingwitch.com
Connection: close
HTTP/1.1 302 Found
cache-control: max-age=0, private, must-revalidate
connection: close
content-length: 11
date: Fri, 06 Aug 2021 07:48:10 GMT
location: http://survey-smiles.com
server: nginx
set-cookie: sid=a5bb74b6-f68a-11eb-805f-57986510d53b; path=/; domain=.thetravellingwitch.com; expires=Wed, 24 Aug 2089 11:02:18 GMT; max-age=2147483647; HttpOnly
POST
405
http://www.frystmor.city/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.frystmor.city
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.frystmor.city
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.frystmor.city/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 405 Not Allowed
Date: Fri, 06 Aug 2021 07:48:21 GMT
Content-Type: text/html
Content-Length: 556
Connection: close
Server: namecheap-nginx
Allow: GET, HEAD
GET
0
http://www.frystmor.city/wufn/?uZhPcRQ=eWg3OYora75B6Z+tLCzm5f6Ri2Qy6T4wPAbOFkNyDPrqSJvJlKf467sJrNVRbgaUTepkudSS&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=eWg3OYora75B6Z+tLCzm5f6Ri2Qy6T4wPAbOFkNyDPrqSJvJlKf467sJrNVRbgaUTepkudSS&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.frystmor.city
Connection: close
POST
405
http://www.hk6628.com/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.hk6628.com
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.hk6628.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.hk6628.com/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 405 Not Allowed
Server: openresty
Date: Fri, 06 Aug 2021 07:48:27 GMT
Content-Type: text/html
Content-Length: 556
X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAJRmzcpTevQqkWn6dJuX/N/Hxl7YxbOwy8+73ijqYSQEN+WGxrruAKtZtliWC86+ewQ0msW1W8psOFL/b00zWqsCAwEAAQ_EZWQEG+DIfKTmYZVOhR26ndEFhtgAvs+2IuHnhXS3E+2FGhws0+mB4379EgTlXizh6rUcR+UAhK5UlHihUzo1w
Via: 1.1 google
Connection: close
GET
403
http://www.hk6628.com/wufn/?uZhPcRQ=Mbz3eb2htBuwJm9my9qYpH4UWvi7L1jn54VVewVZerqVccc7GhECZ0+c8NYoPjvN/okzts0t&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=Mbz3eb2htBuwJm9my9qYpH4UWvi7L1jn54VVewVZerqVccc7GhECZ0+c8NYoPjvN/okzts0t&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.hk6628.com
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Fri, 06 Aug 2021 07:48:27 GMT
Content-Type: text/html
Content-Length: 275
ETag: "61064ea1-113"
Via: 1.1 google
Connection: close
POST
400
http://www.333s998.com/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.333s998.com
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.333s998.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.333s998.com/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 400 Bad Request
Content-Type: text/plain
Server: proxygen-bolt
Date: Fri, 06 Aug 2021 07:48:32 GMT
Connection: close
Content-Length: 0
GET
400
http://www.333s998.com/wufn/?uZhPcRQ=VTesff5V8BaVQfct7ufB+ZGDNoZjfYL94mUu5cNf67hmTMf3dCw98cZx4Ykp6QvQWnzQdmMu&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=VTesff5V8BaVQfct7ufB+ZGDNoZjfYL94mUu5cNf67hmTMf3dCw98cZx4Ykp6QvQWnzQdmMu&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.333s998.com
Connection: close
HTTP/1.1 400 Bad Request
Content-Type: text/plain
Server: proxygen-bolt
Date: Fri, 06 Aug 2021 07:48:33 GMT
Connection: close
Content-Length: 0
POST
405
http://www.peak-valleyadvertising.com/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.peak-valleyadvertising.com
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.peak-valleyadvertising.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.peak-valleyadvertising.com/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 405 Not Allowed
Server: openresty
Date: Fri, 06 Aug 2021 07:48:38 GMT
Content-Type: text/html
Content-Length: 556
X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAJRmzcpTevQqkWn6dJuX/N/Hxl7YxbOwy8+73ijqYSQEN+WGxrruAKtZtliWC86+ewQ0msW1W8psOFL/b00zWqsCAwEAAQ_TkFKCtD+5EkCcujFtTy660WfZQtwnsENn1/PVqXxQym+j4t29wNUsTaIKAjnxMXPJRJe56uICn3rFlWVc8JGNw
Via: 1.1 google
Connection: close
GET
403
http://www.peak-valleyadvertising.com/wufn/?uZhPcRQ=FgzG7Qx2bDHQRqzBshosqp2KyuZ4BKgjCPQpIPsUZT2saqt6xf80CxpLR0Dj1LrdceOnKHHp&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=FgzG7Qx2bDHQRqzBshosqp2KyuZ4BKgjCPQpIPsUZT2saqt6xf80CxpLR0Dj1LrdceOnKHHp&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.peak-valleyadvertising.com
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Fri, 06 Aug 2021 07:48:38 GMT
Content-Type: text/html
Content-Length: 275
ETag: "610650f1-113"
Via: 1.1 google
Connection: close
POST
0
http://www.gaigoilaocai.com/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.gaigoilaocai.com
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.gaigoilaocai.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.gaigoilaocai.com/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
GET
301
http://www.gaigoilaocai.com/wufn/?uZhPcRQ=+cvcaH9t4IGOvfSH2s/pGQCzCoMlKLNX9S4pg+CdqO+ehvTRSw4m6C0WiIEOYf+cYXNRRXby&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=+cvcaH9t4IGOvfSH2s/pGQCzCoMlKLNX9S4pg+CdqO+ehvTRSw4m6C0WiIEOYf+cYXNRRXby&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.gaigoilaocai.com
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Fri, 06 Aug 2021 07:48:44 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Fri, 06 Aug 2021 08:48:44 GMT
Location: https://www.gaigoilaocai.com/wufn/?uZhPcRQ=+cvcaH9t4IGOvfSH2s/pGQCzCoMlKLNX9S4pg+CdqO+ehvTRSw4m6C0WiIEOYf+cYXNRRXby&U4kp=Ntx4ZRIXOr7dPRJ
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=2WVLHE0yBiAP2LJEZACrGRMTY1AiBeMLohzNWxqXVLz7%2F3IvLGyKoo%2FFqrzJdVGpyz7BYz5Qt01EEFYe6S7H0ypwot5e41jmMwRcQFn0uCY2z5Yfjo4x3%2F1lDz7Z6Br5JzekDvFtpw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67a6aa20eee742bd-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
POST
0
http://www.pon.xyz/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.pon.xyz
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.pon.xyz
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.pon.xyz/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
GET
200
http://www.pon.xyz/wufn/?uZhPcRQ=TjHmMFEWoC7f3AvZD4fy73K0u4EyZw5fKqkeqDjs9aj0G9oQA4BDCe56sbMIcecYmi82gg8d&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=TjHmMFEWoC7f3AvZD4fy73K0u4EyZw5fKqkeqDjs9aj0G9oQA4BDCe56sbMIcecYmi82gg8d&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.pon.xyz
Connection: close
HTTP/1.1 200 OK
Server: openresty
Date: Fri, 06 Aug 2021 07:48:51 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_XGbUU0Brpk6M6Ca5RHHEu4RGBUHxvNkA9BEzlfH6Awqf3/XD3zAoWTBOlswQiVl86Nbk+oGtppw0fV3t+CfsDA==
POST
0
http://www.cuadorcoast.com/wufn/
REQUEST
RESPONSE
BODY
POST /wufn/ HTTP/1.1
Host: www.cuadorcoast.com
Connection: close
Content-Length: 285
Cache-Control: no-cache
Origin: http://www.cuadorcoast.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.cuadorcoast.com/wufn/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
GET
0
http://www.cuadorcoast.com/wufn/?uZhPcRQ=kYzY+WOATOJvl0LGKoTI9L4ky9M8/RXPaPgWsg9EorAZ9N2DAW9xe5TyjlQCxAJLBvRqjfNR&U4kp=Ntx4ZRIXOr7dPRJ
REQUEST
RESPONSE
BODY
GET /wufn/?uZhPcRQ=kYzY+WOATOJvl0LGKoTI9L4ky9M8/RXPaPgWsg9EorAZ9N2DAW9xe5TyjlQCxAJLBvRqjfNR&U4kp=Ntx4ZRIXOr7dPRJ HTTP/1.1
Host: www.cuadorcoast.com
Connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts