Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.fem-studio.com |
CNAME
fem-studio.com
|
192.0.78.211 |
www.abstractcertify.com | ||
www.lobby138.monster | 91.195.240.123 | |
www.ssongg13026.cfd | 101.32.68.183 | |
www.g7bety.com | 172.67.171.189 |
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49154 239.255.255.250:1900
-
GET
200
http://www.lobby138.monster/t6tg/?hB9=3b8u1mK8VHbHBfK/UsLoDkPDaVA31KqbuvBNGor4kXVmAL21gM7ZM3KDEr8Jm2Spn741Hpzt&lN68=VTRPbxUh6tHTgV
REQUEST
RESPONSE
BODY
GET /t6tg/?hB9=3b8u1mK8VHbHBfK/UsLoDkPDaVA31KqbuvBNGor4kXVmAL21gM7ZM3KDEr8Jm2Spn741Hpzt&lN68=VTRPbxUh6tHTgV HTTP/1.1
Host: www.lobby138.monster
Connection: close
HTTP/1.1 200 OK
date: Mon, 30 Oct 2023 22:42:59 GMT
content-type: text/html; charset=UTF-8
transfer-encoding: chunked
vary: Accept-Encoding
x-powered-by: PHP/8.1.17
expires: Mon, 26 Jul 1997 05:00:00 GMT
cache-control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
pragma: no-cache
x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANnylWw2vLY4hUn9w06zQKbhKBfvjFUCsdFlb6TdQhxb9RXWXuI4t31c+o8fYOv/s8q1LGPga3DE1L/tHU4LENMCAwEAAQ==_HDp2pnBHAK/hjv4IekoDNwOjw1CnPPFKCkzlFpkHRNGCGr1c1NbjGSkNmpqOv5fFAgF8U8+lar5ZRqgeJNr3og==
last-modified: Mon, 30 Oct 2023 22:42:59 GMT
x-cache-miss-from: parking-697977dd84-w289q
server: NginX
connection: close
GET
404
http://www.ssongg13026.cfd/t6tg/?hB9=Nmqux/666XlLtJ3WEKzUk3EHj+ftlkJxJixPq7eQ/k8b2WLLehoT1axEI2nKmBLwOwlBSnRz&lN68=VTRPbxUh6tHTgV
REQUEST
RESPONSE
BODY
GET /t6tg/?hB9=Nmqux/666XlLtJ3WEKzUk3EHj+ftlkJxJixPq7eQ/k8b2WLLehoT1axEI2nKmBLwOwlBSnRz&lN68=VTRPbxUh6tHTgV HTTP/1.1
Host: www.ssongg13026.cfd
Connection: close
HTTP/1.1 404 Not Found
Server: nginx
Date: Mon, 30 Oct 2023 22:43:37 GMT
Content-Type: text/html
Content-Length: 146
Connection: close
GET
301
http://www.fem-studio.com/t6tg/?hB9=wO01AVbbXSVLf6qO03SX5K+SMOPGPZyPLFmMZ0U48re65Y/5ubB6fIycEVvycH59j+ia3nP/&lN68=VTRPbxUh6tHTgV
REQUEST
RESPONSE
BODY
GET /t6tg/?hB9=wO01AVbbXSVLf6qO03SX5K+SMOPGPZyPLFmMZ0U48re65Y/5ubB6fIycEVvycH59j+ia3nP/&lN68=VTRPbxUh6tHTgV HTTP/1.1
Host: www.fem-studio.com
Connection: close
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Mon, 30 Oct 2023 22:43:58 GMT
Content-Type: text/html
Content-Length: 162
Connection: close
Location: https://www.fem-studio.com/t6tg/?hB9=wO01AVbbXSVLf6qO03SX5K+SMOPGPZyPLFmMZ0U48re65Y/5ubB6fIycEVvycH59j+ia3nP/&lN68=VTRPbxUh6tHTgV
X-ac: 3.nrt _bur BYPASS
GET
301
http://www.g7bety.com/t6tg/?hB9=tJCug8916Nk3qwpVWxazfba7U2UvaJXJwG1WTz0cOvag2M7/5zn5sibdV7VYkPm4YwuRNFZo&lN68=VTRPbxUh6tHTgV
REQUEST
RESPONSE
BODY
GET /t6tg/?hB9=tJCug8916Nk3qwpVWxazfba7U2UvaJXJwG1WTz0cOvag2M7/5zn5sibdV7VYkPm4YwuRNFZo&lN68=VTRPbxUh6tHTgV HTTP/1.1
Host: www.g7bety.com
Connection: close
HTTP/1.1 301 Moved Permanently
Date: Mon, 30 Oct 2023 22:44:18 GMT
Transfer-Encoding: chunked
Connection: close
Cache-Control: max-age=3600
Expires: Mon, 30 Oct 2023 23:44:18 GMT
Location: https://www.g7bety.com/t6tg/?hB9=tJCug8916Nk3qwpVWxazfba7U2UvaJXJwG1WTz0cOvag2M7/5zn5sibdV7VYkPm4YwuRNFZo&lN68=VTRPbxUh6tHTgV
Set-Cookie: __cf_bm=HIwe4YnXePutQASEgzPR2rMq3Ug5x0inrFhu5pAZRUE-1698705858-0-AWYnPOF02Ad54UwH2pRJkCscTn21Jlpy6S9p3lXq+Y1Hn9WupUg4eW300aYkgkKbZtl63Eccc+UI7yahOxWJGFE=; path=/; expires=Mon, 30-Oct-23 23:14:18 GMT; domain=.g7bety.com; HttpOnly
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=o58VxwTc37b5Iv1Z%2FPN3%2FB5Z8sRrB7MRi%2FxlpOI9SXcj0BsZEDxzrCxZG2XaK9mBCP4vfxNBSiBddwVcyERYZuMXpUvZkzG9DL9%2BaYUpl9fwhSGvkwO47JR9ZljUTCMWgg%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 81e72e9e4bed7cb6-LAX
alt-svc: h3=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49168 -> 192.0.78.185:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49169 -> 172.67.171.189:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49167 -> 101.32.68.183:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49166 -> 91.195.240.123:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts