Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.smartagriafrica.info |
CNAME
smartagriafrica.info
|
15.197.148.33 |
www.chonggonzalez.com |
CNAME
chonggonzalez.com
|
195.35.38.87 |
www.zloomux.com |
CNAME
shops.myshopify.com
|
23.227.38.74 |
www.getmangarock.com |
- TCP Requests
-
-
192.168.56.101:49172 15.197.148.33:80www.smartagriafrica.info
-
192.168.56.101:49173 15.197.148.33:80www.smartagriafrica.info
-
192.168.56.101:49168 195.35.38.87:80www.chonggonzalez.com
-
192.168.56.101:49169 195.35.38.87:80www.chonggonzalez.com
-
192.168.56.101:49170 23.227.38.74:80www.zloomux.com
-
192.168.56.101:49171 23.227.38.74:80www.zloomux.com
-
GET
301
http://www.chonggonzalez.com/bp31/?4hIPNx=i8xMAsplts1fVWIwWOiZyKMG3HcPF0/pv9lT+CaFwPb7cSw7ejwLK6p2kEZsPcoFVhe8fhoh&nfut_l=xPJx_6jp&sql=1
REQUEST
RESPONSE
BODY
GET /bp31/?4hIPNx=i8xMAsplts1fVWIwWOiZyKMG3HcPF0/pv9lT+CaFwPb7cSw7ejwLK6p2kEZsPcoFVhe8fhoh&nfut_l=xPJx_6jp&sql=1 HTTP/1.1
Host: www.chonggonzalez.com
Connection: close
HTTP/1.1 301 Moved Permanently
Connection: close
content-type: text/html
content-length: 707
date: Mon, 13 Nov 2023 22:55:53 GMT
server: LiteSpeed
location: https://www.chonggonzalez.com/bp31/?4hIPNx=i8xMAsplts1fVWIwWOiZyKMG3HcPF0/pv9lT+CaFwPb7cSw7ejwLK6p2kEZsPcoFVhe8fhoh&nfut_l=xPJx_6jp&sql=1
platform: hostinger
content-security-policy: upgrade-insecure-requests
POST
301
http://www.chonggonzalez.com/bp31/
REQUEST
RESPONSE
BODY
POST /bp31/ HTTP/1.1
Host: www.chonggonzalez.com
Connection: close
Content-Length: 42824
Cache-Control: no-cache
Origin: http://www.chonggonzalez.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.chonggonzalez.com/bp31/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 301 Moved Permanently
Connection: close
content-type: text/html
content-length: 707
date: Mon, 13 Nov 2023 22:55:55 GMT
server: LiteSpeed
location: https://www.chonggonzalez.com/bp31/
platform: hostinger
content-security-policy: upgrade-insecure-requests
GET
403
http://www.zloomux.com/bp31/?4hIPNx=vvPW/2Pd5QHeIEBGm8G0+Ony9yXqUyBfOyFfBG0rKYjwD4sgiUzqNaP2HxjG8nxDdvZI64Qs&nfut_l=xPJx_6jp&sql=1
REQUEST
RESPONSE
BODY
GET /bp31/?4hIPNx=vvPW/2Pd5QHeIEBGm8G0+Ony9yXqUyBfOyFfBG0rKYjwD4sgiUzqNaP2HxjG8nxDdvZI64Qs&nfut_l=xPJx_6jp&sql=1 HTTP/1.1
Host: www.zloomux.com
Connection: close
HTTP/1.1 403 Forbidden
Date: Mon, 13 Nov 2023 22:56:34 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4518
Connection: close
X-Frame-Options: SAMEORIGIN
Referrer-Policy: same-origin
Cache-Control: max-age=15
Expires: Mon, 13 Nov 2023 22:56:48 GMT
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=Z6C28dR6wR30xySh%2F%2BXcV%2FbO1OTZuG1KI%2F%2F92EqLfAYjpTXDvquETvucRuwRo4oInSRVQ0bDQNj8nEL0AHNiKG8v8GTnwMqHlS25kDhjqpUaCuvH3wf1F5ro2oqsEyiuGQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Server-Timing: cfRequestDuration;dur=6.000042
Server: cloudflare
CF-RAY: 825a9bd479ce351a-ICN
alt-svc: h3=":443"; ma=86400
POST
404
http://www.zloomux.com/bp31/
REQUEST
RESPONSE
BODY
POST /bp31/ HTTP/1.1
Host: www.zloomux.com
Connection: close
Content-Length: 42824
Cache-Control: no-cache
Origin: http://www.zloomux.com
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.zloomux.com/bp31/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
HTTP/1.1 404 Not Found
Date: Mon, 13 Nov 2023 22:56:36 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
X-Sorting-Hat-PodId: -1
Vary: Accept-Encoding
Vary: Accept
X-Frame-Options: DENY
Server-Timing: processing;dur=11
X-Shopify-Stage: production
Content-Security-Policy: frame-ancestors 'none'; report-uri /csp-report?source%5Baction%5D=not_found&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=storefront_section%2Fshop&source%5Bsection%5D=storefront&source%5Buuid%5D=db8035cd-72da-4473-9203-7babda32c7a6
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 1; mode=block; report=/xss-report?source%5Baction%5D=not_found&source%5Bapp%5D=Shopify&source%5Bcontroller%5D=storefront_section%2Fshop&source%5Bsection%5D=storefront&source%5Buuid%5D=db8035cd-72da-4473-9203-7babda32c7a6
X-Dc: gcp-asia-northeast3,gcp-us-east1,gcp-us-east1
Content-Encoding: gzip
X-Request-ID: db8035cd-72da-4473-9203-7babda32c7a6
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=PhKjUwd8pFRJX6MDG3nhXnV%2BUSpyznMKKh%2BdKobFqqRAWtZ0GmswFfPaUKCjMkyzKW3VEOD7MxI9qpgW%2F7N5kjx9XYelxJfDE7byZX2X6GAgxsosoizIg%2FXP4rt9Iw1F1Q%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0.01,"report_to":"cf-nel","max_age":604800}
Server-Timing: cfRequestDuration;dur=582.000017
Server: cloudflare
CF-RAY: 825a9be0f9a8c171-ICN
alt-svc: h3=":443"; ma=86400
GET
403
http://www.smartagriafrica.info/bp31/?4hIPNx=OJ1wdLQJPVHT7VM7DL9mTUJRAG8pTY12NlK6t8ps5ocpXXUVXYvRwMmTQlbyJ47ya7gchoZP&nfut_l=xPJx_6jp&sql=1
REQUEST
RESPONSE
BODY
GET /bp31/?4hIPNx=OJ1wdLQJPVHT7VM7DL9mTUJRAG8pTY12NlK6t8ps5ocpXXUVXYvRwMmTQlbyJ47ya7gchoZP&nfut_l=xPJx_6jp&sql=1 HTTP/1.1
Host: www.smartagriafrica.info
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Mon, 13 Nov 2023 22:56:54 GMT
Content-Type: text/html
Content-Length: 291
Connection: close
ETag: "65271109-123"
POST
0
http://www.smartagriafrica.info/bp31/
REQUEST
RESPONSE
BODY
POST /bp31/ HTTP/1.1
Host: www.smartagriafrica.info
Connection: close
Content-Length: 42824
Cache-Control: no-cache
Origin: http://www.smartagriafrica.info
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Content-Type: application/x-www-form-urlencoded
Accept: */*
Referer: http://www.smartagriafrica.info/bp31/
Accept-Language: en-US
Accept-Encoding: gzip, deflate
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49168 -> 195.35.38.87:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49170 -> 23.227.38.74:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.101:49172 -> 15.197.148.33:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts