Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.datings69.com | 172.67.150.74 | |
www.kd-quilts.com | 199.115.116.43 |
GET
301
http://www.datings69.com/pr29/?v4=iWIxv15JsrJJkCjZ8Z2o3kuz+1NpAQWXASqKJKsuslEEMxeXMyCRxey2t2zedcxZSr3jS5XB&nt=V48HiDzp
REQUEST
RESPONSE
BODY
GET /pr29/?v4=iWIxv15JsrJJkCjZ8Z2o3kuz+1NpAQWXASqKJKsuslEEMxeXMyCRxey2t2zedcxZSr3jS5XB&nt=V48HiDzp HTTP/1.1
Host: www.datings69.com
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Mon, 22 May 2023 00:00:47 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 22 May 2023 01:00:47 GMT
Location: https://www.datings69.com/pr29/?v4=iWIxv15JsrJJkCjZ8Z2o3kuz+1NpAQWXASqKJKsuslEEMxeXMyCRxey2t2zedcxZSr3jS5XB&nt=V48HiDzp
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=wH7QwFRDRXDDnk3X3S5epJBBiEqI3gApC768uGCD6H6m7dSyplyjaaa5%2BDCqtr5NeBkHUjcgXWBMj9pWfC8gv0XNLcQ%2FYf%2BJofvyOidqYr0f4sdneIly3O7e8OczA%2F46CQNPvQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7cb0c7e6eb4619e8-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
GET
302
http://www.kd-quilts.com/pr29/?v4=wXyY+y/V+y1/AnxM16dRfRBuxbe/Yr8e2DlPMb8DPd7MrVB1Ku0tny0zWEj61KI8d3SuNV54&nt=V48HiDzp
REQUEST
RESPONSE
BODY
GET /pr29/?v4=wXyY+y/V+y1/AnxM16dRfRBuxbe/Yr8e2DlPMb8DPd7MrVB1Ku0tny0zWEj61KI8d3SuNV54&nt=V48HiDzp HTTP/1.1
Host: www.kd-quilts.com
Connection: close
HTTP/1.1 302 Found
date: Mon, 22 May 2023 00:01:10 GMT
server: Apache
set-cookie: __tad=1684713670.3025406; expires=Thu, 19-May-2033 00:01:10 GMT; Max-Age=315360000
location: http://ww38.kd-quilts.com/pr29/?v4=wXyY+y/V+y1/AnxM16dRfRBuxbe/Yr8e2DlPMb8DPd7MrVB1Ku0tny0zWEj61KI8d3SuNV54&nt=V48HiDzp
content-length: 0
content-type: text/html; charset=UTF-8
connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49165 -> 104.21.88.25:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49165 -> 104.21.88.25:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49165 -> 104.21.88.25:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 70.32.1.32:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 70.32.1.32:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 70.32.1.32:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts