Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
skanfordiporka.com | 68.183.10.71 |
GET
403
http://skanfordiporka.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
Cookie: __gads=3531431994:1:71:149; _gat=6.1.7601.64; _ga=1.591594.2020557398.110; _u=5445535432322D5043:746573743232:39433841463346364531304630393141; __io=21_3832866432_4053218753_3017428901; _gid=A4FE497CB1CB
Host: skanfordiporka.com
HTTP/1.1 403 Forbidden
Server: nginx
Date: Wed, 15 Mar 2023 00:01:57 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
GET
403
http://skanfordiporka.com/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
Cookie: __gads=3531431994:1:71:149; _gat=6.1.7601.64; _ga=1.591594.2020557398.110; _u=5445535432322D5043:746573743232:39433841463346364531304630393141; __io=21_3832866432_4053218753_3017428901; _gid=A4FE497CB1CB
Host: skanfordiporka.com
HTTP/1.1 403 Forbidden
Server: nginx
Date: Wed, 15 Mar 2023 00:02:58 GMT
Content-Type: text/html
Content-Length: 162
Connection: keep-alive
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49290 -> 68.183.10.71:80 | 2032086 | ET MALWARE Win32/IcedID Request Cookie | A Network Trojan was detected |
TCP 192.168.56.101:49283 -> 68.183.10.71:80 | 2032086 | ET MALWARE Win32/IcedID Request Cookie | A Network Trojan was detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts