Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.jaliyahsboutique.site |
CNAME
jaliyahsboutique.site
|
62.72.50.217 |
www.rykuruh.cfd | ||
www.freightlizards.com |
CNAME
freightlizards.com
|
15.197.148.33 |
www.driftlessmenofthewoods.com | 66.96.162.130 |
- UDP Requests
-
-
192.168.56.103:50800 164.124.101.2:53
-
192.168.56.103:52760 164.124.101.2:53
-
192.168.56.103:53673 164.124.101.2:53
-
192.168.56.103:56613 164.124.101.2:53
-
192.168.56.103:62576 164.124.101.2:53
-
192.168.56.103:64894 164.124.101.2:53
-
192.168.56.103:137 192.168.56.101:137
-
192.168.56.103:137 192.168.56.102:137
-
192.168.56.103:137 192.168.56.255:137
-
192.168.56.103:138 192.168.56.255:138
-
192.168.56.103:50803 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.103:123
-
GET
302
http://www.driftlessmenofthewoods.com/tb8i/?Mfg=eqj5Z4ypABx4+RJiqSEL2pQMeiYVPR0bHgBfmB0KWoL2fjeQVwepQ8EqIXRbUYrWMehCRAoK&D6h4=O2JdRpPP8
REQUEST
RESPONSE
BODY
GET /tb8i/?Mfg=eqj5Z4ypABx4+RJiqSEL2pQMeiYVPR0bHgBfmB0KWoL2fjeQVwepQ8EqIXRbUYrWMehCRAoK&D6h4=O2JdRpPP8 HTTP/1.1
Host: www.driftlessmenofthewoods.com
Connection: close
HTTP/1.1 302 Found
Date: Thu, 16 Nov 2023 09:56:56 GMT
Content-Type: text/html; charset=iso-8859-1
Content-Length: 324
Connection: close
Server: Apache/2
Location: https://www.driftlessmenofthewoods.com/tb8i/?Mfg=eqj5Z4ypABx4+RJiqSEL2pQMeiYVPR0bHgBfmB0KWoL2fjeQVwepQ8EqIXRbUYrWMehCRAoK&D6h4=O2JdRpPP8
Cache-Control: max-age=3600
Expires: Thu, 16 Nov 2023 10:56:56 GMT
Age: 1
GET
403
http://www.freightlizards.com/tb8i/?Mfg=iDy6itdHrWaTfAWmWuh/mgzAS6tKx110PlwR6oB3LkHWhoHRuQXiu8dUVQqS4bUVZcTWjSMs&D6h4=O2JdRpPP8
REQUEST
RESPONSE
BODY
GET /tb8i/?Mfg=iDy6itdHrWaTfAWmWuh/mgzAS6tKx110PlwR6oB3LkHWhoHRuQXiu8dUVQqS4bUVZcTWjSMs&D6h4=O2JdRpPP8 HTTP/1.1
Host: www.freightlizards.com
Connection: close
HTTP/1.1 403 Forbidden
Server: openresty
Date: Thu, 16 Nov 2023 09:57:15 GMT
Content-Type: text/html
Content-Length: 150
Connection: close
GET
404
http://www.jaliyahsboutique.site/tb8i/?Mfg=AQaGQeJtSF7XURKecA8O7yr+NlX8zRsowlAtlkToCPVC5G43PHBjCbek0+SoUA10RQeLzaXp&D6h4=O2JdRpPP8
REQUEST
RESPONSE
BODY
GET /tb8i/?Mfg=AQaGQeJtSF7XURKecA8O7yr+NlX8zRsowlAtlkToCPVC5G43PHBjCbek0+SoUA10RQeLzaXp&D6h4=O2JdRpPP8 HTTP/1.1
Host: www.jaliyahsboutique.site
Connection: close
HTTP/1.1 404 Not Found
Connection: close
content-type: text/html
last-modified: Wed, 13 Sep 2023 02:00:36 GMT
etag: "999-650117c4-eea22b0581d97d03;;;"
accept-ranges: bytes
content-length: 2457
date: Thu, 16 Nov 2023 09:58:16 GMT
server: LiteSpeed
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49168 -> 62.72.50.217:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49167 -> 3.33.130.190:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49166 -> 66.96.162.130:80 | 2031412 | ET MALWARE FormBook CnC Checkin (GET) | Malware Command and Control Activity Detected |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts