Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.getmavin.com |
CNAME
custom.convertri.com
|
35.185.181.239 |
www.project-global-corp.us |
GET
307
http://www.getmavin.com/ad6n/?p0G=OjJsxC4geh8I7FqpHa9UrgAH/E1KMhjJ+gcNVa/pzu129pZ482obDOVio5WqFRS9BSrfkXt2&DXEXx=X6jPuRePGH0PXF8P
REQUEST
RESPONSE
BODY
GET /ad6n/?p0G=OjJsxC4geh8I7FqpHa9UrgAH/E1KMhjJ+gcNVa/pzu129pZ482obDOVio5WqFRS9BSrfkXt2&DXEXx=X6jPuRePGH0PXF8P HTTP/1.1
Host: www.getmavin.com
Connection: close
HTTP/1.1 307 Temporary Redirect
Content-Type: text/html; charset=utf-8
Location: http://getmavin.com/ad6n?p0G=OjJsxC4geh8I7FqpHa9UrgAH/E1KMhjJ+gcNVa/pzu129pZ482obDOVio5WqFRS9BSrfkXt2&DXEXx=X6jPuRePGH0PXF8P
Vary: Accept-Encoding
Date: Tue, 16 Nov 2021 22:45:00 GMT
Content-Length: 164
Connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49170 -> 35.185.181.239:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49170 -> 35.185.181.239:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49170 -> 35.185.181.239:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts