Network Analysis
- TCP Requests
-
-
192.168.56.101:49180 162.241.217.45:80www.glenwoodstudiocrafts.com
-
192.168.56.101:49181 162.241.217.45:80www.glenwoodstudiocrafts.com
-
192.168.56.101:49174 172.67.174.131:80www.aviator238.cyou
-
192.168.56.101:49175 172.67.174.131:80www.aviator238.cyou
-
192.168.56.101:49176 195.24.68.5:80www.tiflovector.ru
-
192.168.56.101:49177 195.24.68.5:80www.tiflovector.ru
-
192.168.56.101:49172 3.14.161.55:80www.tonica.life
-
192.168.56.101:49173 3.14.161.55:80www.tonica.life
-
192.168.56.101:49170 34.117.168.233:80www.elaynegullis.com
-
192.168.56.101:49178 43.250.124.88:80www.ghyvmze5s.com
-
192.168.56.101:49179 43.250.124.88:80www.ghyvmze5s.com
-
192.168.56.101:49171 45.33.6.223:80www.sqlite.org
-
- UDP Requests
-
-
192.168.56.101:52815 164.124.101.2:53
-
192.168.56.101:53004 164.124.101.2:53
-
192.168.56.101:53850 164.124.101.2:53
-
192.168.56.101:54148 164.124.101.2:53
-
192.168.56.101:54883 164.124.101.2:53
-
192.168.56.101:55146 164.124.101.2:53
-
192.168.56.101:59002 164.124.101.2:53
-
192.168.56.101:61950 164.124.101.2:53
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.101:137 192.168.56.255:137
-
192.168.56.101:138 192.168.56.255:138
-
192.168.56.101:54151 239.255.255.250:1900
-
GET
301
http://www.elaynegullis.com/pz6u/?gfuoJ=RLN7TRGvjwHq7PUV878gaeLXTOoLSh2gVAY4HztmGBYlfrA0o1jLcKhByS7l3UvVa8DWXe8maGDlvA7o1isB3qskVRFdaINY+8OOoek=&Ib=JpVVn8kuJmjvnz
REQUEST
RESPONSE
BODY
GET /pz6u/?gfuoJ=RLN7TRGvjwHq7PUV878gaeLXTOoLSh2gVAY4HztmGBYlfrA0o1jLcKhByS7l3UvVa8DWXe8maGDlvA7o1isB3qskVRFdaINY+8OOoek=&Ib=JpVVn8kuJmjvnz HTTP/1.1
Host: www.elaynegullis.com
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Thu, 16 Mar 2023 00:31:56 GMT
Content-Length: 0
location: https://www.elaynegullis.com/pz6u?gfuoJ=RLN7TRGvjwHq7PUV878gaeLXTOoLSh2gVAY4HztmGBYlfrA0o1jLcKhByS7l3UvVa8DWXe8maGDlvA7o1isB3qskVRFdaINY+8OOoek%3D&Ib=JpVVn8kuJmjvnz
strict-transport-security: max-age=3600
x-wix-request-id: 1678926716.27811915017316634
Age: 0
X-Seen-By: GXNXSWFXisshliUcwO20NXdyD4zpCpFzpCPkLds0yMeO9mNG6rJTIRHoFrDCDqzQ,qquldgcFrj2n046g4RNSVIAgcgCEfo+CxkPwqc2yH31YgeUJqUXtid+86vZww+nL,2d58ifebGbosy5xc+FRalt7A3rlFE2EIGlaub7rFpYpNDVGiMFtticG36PhXDRNTVMWfjHc5QJEcCJ27E94ikxyU9vksvQRQsfKuIZE4K04=,2UNV7KOq4oGjA5+PKsX47Nz8mhJI5Apbbptt0fKts0Wa46R9xNIlpQ4eUPYpBuqs,R8nVwPJv9QJL1m78OROO+KfF+qk2SB2u2E/Bl3ouc68=,g1tEHL6KXqacD6ojcO5kMhuQXydWLarWk4+Fctse44E=,mNYkRqsux5VmQ8IQhEXF2j/+/IcOe9bpddJL8eP/xMcSO5XmrrCSQNDehIjmfew3WpG9Lf3E1zSTqRbAOfH1AA==
Cache-Control: no-cache
server-timing: cache;desc=miss, varnish;desc=miss, dc;desc=ane1_g
X-Content-Type-Options: nosniff
Server: Pepyaka/1.19.10
Via: 1.1 google
Connection: close
GET
200
http://www.sqlite.org/2016/sqlite-dll-win32-x86-3100000.zip
REQUEST
RESPONSE
BODY
GET /2016/sqlite-dll-win32-x86-3100000.zip HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: www.sqlite.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Connection: keep-alive
Date: Thu, 16 Mar 2023 00:32:01 GMT
Last-Modified: Sat, 30 Jul 2016 15:11:53 GMT
Cache-Control: max-age=120
ETag: "m579cc3b9s642da"
Content-type: application/zip; charset=utf-8
Content-length: 410330
POST
404
http://www.tonica.life/pz6u/
REQUEST
RESPONSE
BODY
POST /pz6u/ HTTP/1.1
Host: www.tonica.life
Connection: close
Content-Length: 187
Cache-Control: no-cache
Origin: http://www.tonica.life
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.tonica.life/pz6u/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 404 Not Found
Date: Thu, 16 Mar 2023 00:32:11 GMT
Content-Type: text/html
Content-Length: 555
Connection: close
Server: nginx/1.20.1
GET
404
http://www.tonica.life/pz6u/?gfuoJ=H3cqQrnleOtYl7hnGPubiIS0labqzqigzX8IXx/talSmztzMUlwIfpk89Fh5WaVP3Lmv67mvQzkZfbTpOci4WeTcTAhchhNQbkNGdls=&Ib=JpVVn8kuJmjvnz
REQUEST
RESPONSE
BODY
GET /pz6u/?gfuoJ=H3cqQrnleOtYl7hnGPubiIS0labqzqigzX8IXx/talSmztzMUlwIfpk89Fh5WaVP3Lmv67mvQzkZfbTpOci4WeTcTAhchhNQbkNGdls=&Ib=JpVVn8kuJmjvnz HTTP/1.1
Host: www.tonica.life
Connection: close
HTTP/1.1 404 Not Found
Date: Thu, 16 Mar 2023 00:32:14 GMT
Content-Type: text/html
Content-Length: 153
Connection: close
Server: nginx/1.20.1
POST
404
http://www.aviator238.cyou/pz6u/
REQUEST
RESPONSE
BODY
POST /pz6u/ HTTP/1.1
Host: www.aviator238.cyou
Connection: close
Content-Length: 187
Cache-Control: no-cache
Origin: http://www.aviator238.cyou
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.aviator238.cyou/pz6u/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 404 Not Found
Date: Thu, 16 Mar 2023 00:32:20 GMT
Content-Type: text/html; charset=iso-8859-1
Transfer-Encoding: chunked
Connection: close
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=8IGut5LWn2tjNmgxa5okLB2GRcwyvgLxijQt4xwPBmSaG9maXnA4ty%2FnN6At9855u55kQr99VYGAaEut8UBjXyAVS93cNdamONMkxMR6xdsmL1Y7xLnTuGJMViuGTsfbd2fws3Uf"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a88e5fc0a7e0aca-KIX
Content-Encoding: gzip
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
404
http://www.aviator238.cyou/pz6u/?gfuoJ=UyrgSxFtu3lXz+BcpDcql/UhilAww6e/QPXCtiRRfbVUoJ6/YhP9B1EmFWXTHuUT6TvndHSDvnTdkZIXPbpDZFJbIQW9nmMntHv5nFk=&Ib=JpVVn8kuJmjvnz
REQUEST
RESPONSE
BODY
GET /pz6u/?gfuoJ=UyrgSxFtu3lXz+BcpDcql/UhilAww6e/QPXCtiRRfbVUoJ6/YhP9B1EmFWXTHuUT6TvndHSDvnTdkZIXPbpDZFJbIQW9nmMntHv5nFk=&Ib=JpVVn8kuJmjvnz HTTP/1.1
Host: www.aviator238.cyou
Connection: close
HTTP/1.1 404 Not Found
Date: Thu, 16 Mar 2023 00:32:22 GMT
Content-Type: text/html; charset=iso-8859-1
Transfer-Encoding: chunked
Connection: close
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=BWQ2dAG61titu4NcJwbil9hlqJPUKxUpF83pFg3jiep3m9f3RloN41Y5a0WVG%2FkKc2xNMmlM5%2BeNkuPCXb0YT4eBinokI1pw1d%2BswGQPQD8WN8%2ByAaZa06I8Q1sta8wAtwg6TNt6"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7a88e60bfaa4835a-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
POST
404
http://www.tiflovector.ru/pz6u/
REQUEST
RESPONSE
BODY
POST /pz6u/ HTTP/1.1
Host: www.tiflovector.ru
Connection: close
Content-Length: 187
Cache-Control: no-cache
Origin: http://www.tiflovector.ru
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.tiflovector.ru/pz6u/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 404 Not Found
Server: openresty
Date: Thu, 16 Mar 2023 00:32:28 GMT
Content-Type: text/html
Content-Length: 555
Connection: close
GET
404
http://www.tiflovector.ru/pz6u/?gfuoJ=0G6+4PQ3ff1VVX3bDlZY7prfmcsmSisC64ofEkjldKjfJt8rvq/jB6ECdFdI4gZQYQqDLzr6mpjEiqs3GX+9BiMAwHwt4KekEuDtmGU=&Ib=JpVVn8kuJmjvnz
REQUEST
RESPONSE
BODY
GET /pz6u/?gfuoJ=0G6+4PQ3ff1VVX3bDlZY7prfmcsmSisC64ofEkjldKjfJt8rvq/jB6ECdFdI4gZQYQqDLzr6mpjEiqs3GX+9BiMAwHwt4KekEuDtmGU=&Ib=JpVVn8kuJmjvnz HTTP/1.1
Host: www.tiflovector.ru
Connection: close
HTTP/1.1 404 Not Found
Server: openresty
Date: Thu, 16 Mar 2023 00:32:30 GMT
Content-Type: text/html
Content-Length: 153
Connection: close
POST
200
http://www.ghyvmze5s.com/pz6u/
REQUEST
RESPONSE
BODY
POST /pz6u/ HTTP/1.1
Host: www.ghyvmze5s.com
Connection: close
Content-Length: 187
Cache-Control: no-cache
Origin: http://www.ghyvmze5s.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.ghyvmze5s.com/pz6u/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 200 OK
Date: Thu, 16 Mar 2023 00:32:35 GMT
Server: Apache/2.4.35 (FreeBSD) PHP/5.6.38
X-Powered-By: PHP/5.6.38
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
GET
200
http://www.ghyvmze5s.com/pz6u/?gfuoJ=uytR2Tiz1twpM2dhblQC1B7BthyLXXG5FY7Kn1WRtAiI0duJ2fbunveoTy7fDIn07wry7tOJS3Y6hqcaHiueaqrp/c4n5kqaEVxvo8M=&Ib=JpVVn8kuJmjvnz
REQUEST
RESPONSE
BODY
GET /pz6u/?gfuoJ=uytR2Tiz1twpM2dhblQC1B7BthyLXXG5FY7Kn1WRtAiI0duJ2fbunveoTy7fDIn07wry7tOJS3Y6hqcaHiueaqrp/c4n5kqaEVxvo8M=&Ib=JpVVn8kuJmjvnz HTTP/1.1
Host: www.ghyvmze5s.com
Connection: close
HTTP/1.1 200 OK
Date: Thu, 16 Mar 2023 00:32:38 GMT
Server: Apache/2.4.35 (FreeBSD) PHP/5.6.38
X-Powered-By: PHP/5.6.38
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
POST
404
http://www.glenwoodstudiocrafts.com/pz6u/
REQUEST
RESPONSE
BODY
POST /pz6u/ HTTP/1.1
Host: www.glenwoodstudiocrafts.com
Connection: close
Content-Length: 187
Cache-Control: no-cache
Origin: http://www.glenwoodstudiocrafts.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.glenwoodstudiocrafts.com/pz6u/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 404 Not Found
Date: Thu, 16 Mar 2023 00:32:50 GMT
Server: Apache
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
Link: <https://glenwoodstudiocrafts.com/wp-json/>; rel="https://api.w.org/"
Upgrade: h2,h2c
Connection: Upgrade
Vary: Accept-Encoding
Content-Encoding: gzip
host-header: c2hhcmVkLmJsdWVob3N0LmNvbQ==
X-Endurance-Cache-Level: 2
X-nginx-cache: WordPress
Content-Length: 11848
Content-Type: text/html; charset=UTF-8
GET
301
http://www.glenwoodstudiocrafts.com/pz6u/?gfuoJ=AdMEqTYsvTG/AjKkKRLLui12hmt7noCWJPmXTDPlMsv+HXciE9QtIkdJXTqGLnrKTXLO19vQM3NQPwEWsx9FOo1L3PbWSzYh6xsrb6I=&Ib=JpVVn8kuJmjvnz
REQUEST
RESPONSE
BODY
GET /pz6u/?gfuoJ=AdMEqTYsvTG/AjKkKRLLui12hmt7noCWJPmXTDPlMsv+HXciE9QtIkdJXTqGLnrKTXLO19vQM3NQPwEWsx9FOo1L3PbWSzYh6xsrb6I=&Ib=JpVVn8kuJmjvnz HTTP/1.1
Host: www.glenwoodstudiocrafts.com
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Thu, 16 Mar 2023 00:32:52 GMT
Server: nginx/1.21.6
Content-Type: text/html; charset=UTF-8
Content-Length: 0
Expires: Wed, 11 Jan 1984 05:00:00 GMT
Cache-Control: no-cache, must-revalidate, max-age=0
X-Redirect-By: WordPress
Location: http://glenwoodstudiocrafts.com/pz6u/?gfuoJ=AdMEqTYsvTG/AjKkKRLLui12hmt7noCWJPmXTDPlMsv+HXciE9QtIkdJXTqGLnrKTXLO19vQM3NQPwEWsx9FOo1L3PbWSzYh6xsrb6I=&Ib=JpVVn8kuJmjvnz
host-header: c2hhcmVkLmJsdWVob3N0LmNvbQ==
X-Endurance-Cache-Level: 2
X-nginx-cache: WordPress
X-Server-Cache: true
X-Proxy-Cache: MISS
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts