Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.into-org.com | 213.186.33.5 | |
www.mtauratarnt.com | 104.21.69.174 |
GET
200
http://www.mtauratarnt.com/rs10/?C0D=pPtLjK+gsCF+gBeBSkx+WEjNRlgjs/QTeyOfbuiR2sOl/G3k+8MocAF2pTNT/vXnM1YvSeQw&QZ3=ehux_vXh401Xart
REQUEST
RESPONSE
BODY
GET /rs10/?C0D=pPtLjK+gsCF+gBeBSkx+WEjNRlgjs/QTeyOfbuiR2sOl/G3k+8MocAF2pTNT/vXnM1YvSeQw&QZ3=ehux_vXh401Xart HTTP/1.1
Host: www.mtauratarnt.com
Connection: close
HTTP/1.1 200 OK
Date: Wed, 18 Oct 2023 23:04:02 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: close
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate
Pragma: no-cache
Set-Cookie: PHPSESSID=6bbm01i6c04novfkr21msu31fg; path=/
Set-Cookie: CART_SESSION_ID=3995c532972a3bad6bf48537a0b0bb7c; expires=Fri, 17-Nov-2023 23:04:01 GMT; Max-Age=2592000; path=/
Set-Cookie: print_val=USD; expires=Fri, 17-Nov-2023 23:04:01 GMT; Max-Age=2592000; path=/
Vary: Accept-Encoding
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=LKa%2Bihlsajq%2BZ0w5z%2BzflMevcwFx1tsdzVwJtBmaU64A%2FC4HqwUu9I7g33mW7%2F%2BBBIH6qgqrnvYG64q19eKBiqTURUKhYQt3zq6qJTzOlN%2FulLf6%2BaCLmOzUgAeVY2CcK6q4QD0r"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81846b009d8a8379-KIX
alt-svc: h3=":443"; ma=86400
GET
302
http://www.into-org.com/rs10/?C0D=+njUxLNT9hCOVJ3Lnug2QEI/7WyUV+ofb+5xay11NC0a753xJF4LqnCsTY0IVEvVOlnNjj+S&QZ3=ehux_vXh401Xart
REQUEST
RESPONSE
BODY
GET /rs10/?C0D=+njUxLNT9hCOVJ3Lnug2QEI/7WyUV+ofb+5xay11NC0a753xJF4LqnCsTY0IVEvVOlnNjj+S&QZ3=ehux_vXh401Xart HTTP/1.1
Host: www.into-org.com
Connection: close
HTTP/1.1 302 Moved Temporarily
server: nginx
date: Wed, 18 Oct 2023 23:04:23 GMT
content-type: text/html
content-length: 138
location: http://www.into-org.com
x-iplb-request-id: AFD08698:C00E_D5BA2105:0050_65306477_ED42A93:D352
x-iplb-instance: 16982
set-cookie: SERVERID77446=2001710|ZTBke|ZTBke; path=/; HttpOnly
connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49166 -> 213.186.33.5:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49165 -> 104.21.69.174:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts