Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
gulf.moneroocean.stream |
CNAME
monerooceans.stream
|
54.250.156.221 |
conn.gta5cheatcode.world | 194.180.48.231 | |
pastebin.com | 172.67.34.170 | |
ppanel.freaktorrentz.xyz | 188.165.24.131 |
POST
200
http://ppanel.freaktorrentz.xyz/x/y/z/WebPanel/api/endpoint.php
REQUEST
RESPONSE
BODY
POST /x/y/z/WebPanel/api/endpoint.php HTTP/1.1
Accept: */*
Connection: close
Content-Length: 539
Content-Type: application/json
Host: ppanel.freaktorrentz.xyz
User-Agent: cpp-httplib/0.9
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 09 Jun 2023 01:02:30 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
X-Powered-By: PHP/7.4.33
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
X-Server-Powered-By: Engintron
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49164 -> 104.20.67.143:443 | 906200068 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (CoinMiner) | undefined |
TCP 192.168.56.103:49165 -> 188.165.24.131:80 | 2011341 | ET HUNTING Suspicious POST With Reference to WINDOWS Folder Possible Malware Infection | A Network Trojan was detected |
TCP 192.168.56.103:49165 -> 188.165.24.131:80 | 2035420 | ET MALWARE Win32/Pripyat Activity (POST) | A Network Trojan was detected |
TCP 192.168.56.103:49165 -> 188.165.24.131:80 | 2031189 | ET HUNTING HTTP POST to XYZ TLD Containing Pass - Possible Phishing | Misc activity |
TCP 192.168.56.103:49166 -> 194.180.48.231:3333 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
UDP 192.168.56.103:53673 -> 164.124.101.2:53 | 2027870 | ET INFO Observed DNS Query to .world TLD | Potentially Bad Traffic |
TCP 192.168.56.103:49166 -> 194.180.48.231:3333 | 2024792 | ET POLICY Cryptocurrency Miner Checkin | Potential Corporate Privacy Violation |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.103:49164 104.20.67.143:443 |
None | None | None |
TLS 1.3 192.168.56.103:49163 54.250.156.221:20128 |
None | None | None |
Snort Alerts
No Snort Alerts