Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
music-sec.xyz | 172.67.190.140 | |
iplogger.org | 88.99.66.31 |
- UDP Requests
-
-
192.168.56.101:59369 164.124.101.2:53
-
192.168.56.101:61479 164.124.101.2:53
-
192.168.56.101:62324 164.124.101.2:53
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:49152 239.255.255.250:3702
-
192.168.56.101:62327 239.255.255.250:1900
-
192.168.56.101:62329 239.255.255.250:3702
-
192.168.56.101:62331 239.255.255.250:3702
-
192.168.56.101:62333 239.255.255.250:3702
-
52.231.114.183:123 192.168.56.101:123
-
GET
200
https://iplogger.org/1WQBy7
REQUEST
RESPONSE
BODY
GET /1WQBy7 HTTP/1.1
User-Agent: th812
Host: iplogger.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 14 Aug 2021 00:39:35 GMT
Content-Type: image/png
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: PHPSESSID=5urdbfj4mh3qb8vk2lo1dtklc4; path=/; HttpOnly
Pragma: no-cache
Set-Cookie: clhf03028ja=175.208.134.150; expires=Wed, 18-Jul-2029 05:49:51 GMT; Max-Age=250146616; path=/
Set-Cookie: timezone=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Set-Cookie: timezone=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Answers:
whoami: 7b841a07867dc6a4f26547772f4de98ad622f278d45640c0e564ff699edfb59d
Strict-Transport-Security: max-age=31536000; preload
X-Frame-Options: DENY
GET
200
https://iplogger.org/1WEBy7
REQUEST
RESPONSE
BODY
GET /1WEBy7 HTTP/1.1
Host: iplogger.org
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 14 Aug 2021 00:39:37 GMT
Content-Type: image/png
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: PHPSESSID=etso0v31n6gpeiat80u06u8933; path=/; HttpOnly
Pragma: no-cache
Set-Cookie: clhf03028ja=175.208.134.150; expires=Wed, 18-Jul-2029 05:49:51 GMT; Max-Age=250146614; path=/
Set-Cookie: timezone=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Set-Cookie: timezone=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; Max-Age=0; path=/
Cache-Control: no-cache
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Answers:
whoami: 2d939b5aee78649ba5dcf483ea0aaa5e19e86948b4778e339f04998c89927566
Strict-Transport-Security: max-age=31536000; preload
X-Frame-Options: DENY
GET
200
http://music-sec.xyz/?k=v2&user=p2_1
REQUEST
RESPONSE
BODY
GET /?k=v2&user=p2_1 HTTP/1.1
Host: music-sec.xyz
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 14 Aug 2021 00:39:06 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
vary: Accept-Encoding
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Bq1uVbscmcaDb7fDhBJu0Yph%2F%2FcLasady9aB6df8vtRumlssPyFJ8c3QfwxpHuPrri%2BJF%2F7rtysix5PG6Kq8X8cxcQ%2B2WlAToliCBDuUS7omeGEnhkB%2BhGOm39rYIbEW"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67e61fc5cd06523f-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
http://music-sec.xyz/?k=v2&user=p2_2
REQUEST
RESPONSE
BODY
GET /?k=v2&user=p2_2 HTTP/1.1
Host: music-sec.xyz
HTTP/1.1 200 OK
Date: Sat, 14 Aug 2021 00:39:21 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
vary: Accept-Encoding
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=f7jbch9dPZoU9EmhrdcX9bLi3OW4cpfPuzcklTdqj%2BU46zFH9e31Duxq8xV0%2Bmt3Jn1%2BFmZi8GtcEQCJjbEPxgzmJ0%2Flj8Tx%2FezyZk1wgRsdiHXW6HiS%2BCEuXj%2B8nu8L"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67e62023e933523f-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
http://music-sec.xyz/?k=v2&user=p2_3
REQUEST
RESPONSE
BODY
GET /?k=v2&user=p2_3 HTTP/1.1
Host: music-sec.xyz
HTTP/1.1 200 OK
Date: Sat, 14 Aug 2021 00:39:23 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=enUnDdEjNyaJjtsMbqQmI0H46Stlo8eZyftFo4RdrqRO6NG8a7WuRUCKskBMDvJyus9ccUbSLdN0RV3edS2rW7F58ep71SOjISJHpZiks59EyLowtS%2B5E%2BPaQY9xhJRP"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67e62031aa02523f-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
http://music-sec.xyz/?k=v2&user=p2_4
REQUEST
RESPONSE
BODY
GET /?k=v2&user=p2_4 HTTP/1.1
Host: music-sec.xyz
HTTP/1.1 200 OK
Date: Sat, 14 Aug 2021 00:39:24 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=OIQbgnuh1yhCKq%2FMm4ileHt%2FRPdWPZIFCjVfubv9EbFiRAKIv56EgHjpnUspApkx0EOc2iBzjksyQ6IqPs7jwImr2mifyg%2BdwGMlEIFEsX6myJ3ms9tln%2BkVv95QLPor"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67e620350b64523f-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
http://music-sec.xyz/?k=v2&user=p2_5
REQUEST
RESPONSE
BODY
GET /?k=v2&user=p2_5 HTTP/1.1
Host: music-sec.xyz
HTTP/1.1 200 OK
Date: Sat, 14 Aug 2021 00:39:24 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=IIX9V7dftMNGoTCjeMs3aa%2FjzQKqj9eehLfQj05V9voeWJ7r3QEXjlIi9EfDhSi4fFYD9%2FvuJr5gSApMETW51Wv7OK%2F%2FHx%2BVTfGNUv7UkqyWOPsvfS7UEm6umHHH5kYA"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67e620386d3b523f-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
GET
200
http://music-sec.xyz/?k=v2&user=p2_6
REQUEST
RESPONSE
BODY
GET /?k=v2&user=p2_6 HTTP/1.1
Host: music-sec.xyz
HTTP/1.1 200 OK
Date: Sat, 14 Aug 2021 00:39:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=NGMXGHVvbAl2jVWf1qFV3xvfHvHA40ANMe97rHYB%2Fn%2BmsIggZgDwSWI1rpvKaz2XporSjG01bSbTXKYQm%2BKX0hRqTNZoN9TE%2BQm5YWLh31lBSkpKj4J5q97DBIs0CYQb"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 67e6203c2952523f-LAX
alt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49208 -> 88.99.66.31:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49206 -> 88.99.66.31:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49201 -> 104.21.92.87:80 | 2031088 | ET HUNTING Request to .XYZ Domain with Minimal Headers | Potentially Bad Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49208 88.99.66.31:443 |
None | None | None |
TLSv1 192.168.56.101:49206 88.99.66.31:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA | CN=*.iplogger.org | 55:1e:13:99:46:1c:67:40:a3:48:7f:38:0d:16:e7:51:f4:c4:43:cb |
Snort Alerts
No Snort Alerts