Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.autoe.live | ||
www.ted-clean.co.uk | 172.64.148.75 |
GET
301
http://www.ted-clean.co.uk/bk08/?Dxlpd=+vQ8uwPhIxMy1Xprj+0sjAwt1KdbtiR10qRZGHD0jKk8bidmNcZrdUvorywV4CWGqKiz+9gb&6l=lnPh
REQUEST
RESPONSE
BODY
GET /bk08/?Dxlpd=+vQ8uwPhIxMy1Xprj+0sjAwt1KdbtiR10qRZGHD0jKk8bidmNcZrdUvorywV4CWGqKiz+9gb&6l=lnPh HTTP/1.1
Host: www.ted-clean.co.uk
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Tue, 14 Mar 2023 08:49:14 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Tue, 14 Mar 2023 09:49:14 GMT
Location: https://www.ted-clean.co.uk/bk08/?Dxlpd=+vQ8uwPhIxMy1Xprj+0sjAwt1KdbtiR10qRZGHD0jKk8bidmNcZrdUvorywV4CWGqKiz+9gb&6l=lnPh
Set-Cookie: __cf_bm=OENWT.fnFllAVVxtKAQIDF0SU.PXmf1FiR1rYSFXQCQ-1678783754-0-AVD3d9F+7xW+OL19CAZg53P325A9suIkZtfMaQCBQCGwjDs6U0WoVOHpfjuNuZgOGuVeVSEOI5Z7Z9akdxu3yDE=; path=/; expires=Tue, 14-Mar-23 09:19:14 GMT; domain=.www.ted-clean.co.uk; HttpOnly
Server-Timing: cf-q-config;dur=6.9999950937927e-06
Server: cloudflare
CF-RAY: 7a7b4322ae33c116-ICN
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49168 -> 172.64.148.75:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49168 -> 172.64.148.75:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49168 -> 172.64.148.75:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts