Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
aa.imgjeoogbb.com | 154.221.26.108 | |
us.imgjeoigaa.com | 103.100.211.218 |
GET
200
http://us.imgjeoigaa.com/sts/imagc.jpg
REQUEST
RESPONSE
BODY
GET /sts/imagc.jpg HTTP/1.1
User-Agent: HTTPREAD
Host: us.imgjeoigaa.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 07 Aug 2023 00:32:16 GMT
Content-Type: image/jpeg
Content-Length: 1506508
Last-Modified: Wed, 28 Jun 2023 02:36:24 GMT
Connection: keep-alive
ETag: "649b9ca8-16fccc"
Accept-Ranges: bytes
GET
200
http://aa.imgjeoogbb.com/check/safe
REQUEST
RESPONSE
BODY
GET /check/safe HTTP/1.1
Connection: Keep-Alive
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.43
Host: aa.imgjeoogbb.com
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Aug 2023 00:32:21 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/7.4.30
POST
200
http://aa.imgjeoogbb.com/check/?sid=144266&key=9905c940269e74e12bc7b18ce6ca2d14
REQUEST
RESPONSE
BODY
POST /check/?sid=144266&key=9905c940269e74e12bc7b18ce6ca2d14 HTTP/1.1
Connection: Keep-Alive
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.43
Content-Length: 160
Host: aa.imgjeoogbb.com
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 07 Aug 2023 00:32:21 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
X-Powered-By: PHP/7.4.30
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49165 -> 154.221.26.108:80 | 2045057 | ET MALWARE Win32/Fabookie.ek CnC Request M4 (GET) | A Network Trojan was detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts