Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
leaseagent.xyz | 104.21.42.182 |
GET
200
http://leaseagent.xyz/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
User-Agent: TeslaBrowser/5.5
Host: leaseagent.xyz
HTTP/1.1 200 OK
Date: Mon, 18 Sep 2023 00:46:14 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Fri, 15 Sep 2023 04:50:13 GMT
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=BiAWnDuxOeKdeuKHBnZGJ2%2BoyAp1DLhYynxQpIM72NV1XnIAtnMxekYonRAXcaweXvxkS0c6Np93kPiTOkoD60bSPqPo78Ln4MjJULcqXNp%2FV03GLtteD42carhGKdnpgQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 80859219b859af64-NRT
POST
404
http://leaseagent.xyz/c2conf
REQUEST
RESPONSE
BODY
POST /c2conf HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: leaseagent.xyz
Content-Length: 28
Cache-Control: no-cache
HTTP/1.1 404 Not Found
Date: Mon, 18 Sep 2023 00:46:15 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=aj1Ks7jik%2BqqOOKZusJ%2BVTjj3Gn1WR2RYlJYmmoAncn0bj6qDwGrrhpVljIlO2IhQaeigZFrIof2YVsfhWVjQhX7xKwMoy%2BEQNjN2q%2Fj4YgAki5DZz66AcRQPmAzVXd%2FCA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 8085921ddb54e04f-NRT
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49166 -> 104.21.42.182:80 | 2046637 | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Configuration Request Attempt | Malware Command and Control Activity Detected |
TCP 104.21.42.182:80 -> 192.168.56.103:49165 | 2023668 | ET INFO Unconfigured nginx Access | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts