Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.mediafire.com | 104.16.114.74 | |
poslisoubor.cz | 109.71.208.62 | |
download2268.mediafire.com | 199.91.155.9 |
- TCP Requests
-
-
192.168.56.101:49169 104.16.114.74:443www.mediafire.com
-
192.168.56.101:49174 109.71.208.62:80poslisoubor.cz
-
192.168.56.101:49170 199.91.155.9:443download2268.mediafire.com
-
192.168.56.101:49171 199.91.155.9:443download2268.mediafire.com
-
192.168.56.101:49177 41.216.183.3:56001
-
192.168.56.101:49166 94.154.172.166:80
-
192.168.56.101:49172 94.154.172.166:80
-
GET
302
https://www.mediafire.com/file_premium/p3wr1k36iwfjl7y/Backup_Guide.pdf/file
REQUEST
RESPONSE
BODY
GET /file_premium/p3wr1k36iwfjl7y/Backup_Guide.pdf/file HTTP/1.1
Host: www.mediafire.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Date: Wed, 31 Jul 2024 05:42:15 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://download2268.mediafire.com/ogfbejoaa2mgPAG58zkfcCL0Hqfa3AuXXyKAkyuMbaVF15Uv9ubNfVqF5rs9nn9js5VaSVdds402XMXtCeRL_ubNCOyrUc9wJUcn9KkIitOdcSwUj-1PWnwrik_mz1geKH4s5T2jS52B-swbskwNuwZbh_bE85wzxJ9oLo2h6m3_PZc/p3wr1k36iwfjl7y/Backup_Guide.pdf
CF-Ray: 8abb439b89fb305c-ICN
CF-Cache-Status: DYNAMIC
Access-Control-Allow-Origin: https://www.mediafire.com
Set-Cookie: ukey=0za4ekkwj4fg0qktrxuymupj7jh6royk; expires=Sun, 31-Jul-2044 05:42:15 GMT; Max-Age=631152000; path=/; domain=.mediafire.com; HttpOnly
Strict-Transport-Security: max-age=0
access-control-allow-methods: OPTIONS, POST, GET
alt-svc: h3=":443"; ma=86400
x-mf-env: liveApi
x-mf-fe: mf1
Set-Cookie: __cf_bm=po2RZfgRKabdCIY751Dqi6Sr2uLK2dzCOgGx83k2UXU-1722404535-1.0.1.1-vAAkVnAVdKCR3s1gfH0fnAzzhLw2ZYhWd4UIU3GpjF67GpGbonDWGZFqVWWANhgM65C76j_jb7feQ9s.7ZSNjQ; path=/; expires=Wed, 31-Jul-24 06:12:15 GMT; domain=.mediafire.com; HttpOnly; Secure
Server: cloudflare
GET
200
http://94.154.172.166/rwrv/3007f.hta
REQUEST
RESPONSE
BODY
GET /rwrv/3007f.hta HTTP/1.1
Accept: */*
Accept-Language: ko-KR
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.2; .NET4.0C; .NET4.0E)
Host: 94.154.172.166
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 31 Jul 2024 05:42:13 GMT
Server: Apache/2.4.38 (Debian)
Last-Modified: Tue, 30 Jul 2024 13:26:51 GMT
ETag: "528d-61e76ee335612"
Accept-Ranges: bytes
Content-Length: 21133
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/hta
GET
200
http://94.154.172.166/rwrv/23.exe
REQUEST
RESPONSE
BODY
GET /rwrv/23.exe HTTP/1.1
Host: 94.154.172.166
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 31 Jul 2024 05:42:17 GMT
Server: Apache/2.4.38 (Debian)
Last-Modified: Tue, 30 Jul 2024 13:22:09 GMT
ETag: "7000-61e76dd5ebed3"
Accept-Ranges: bytes
Content-Length: 28672
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/x-msdos-program
GET
200
http://poslisoubor.cz/gf.php?33f6c54a9a525e2c37453931c2aadebe/9.txt
REQUEST
RESPONSE
BODY
GET /gf.php?33f6c54a9a525e2c37453931c2aadebe/9.txt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: poslisoubor.cz
HTTP/1.1 200 OK
Date: Wed, 31 Jul 2024 05:42:03 GMT
Server: Apache/2.4.38 (Debian)
X-Powered-By: PHP/5.6.40-0+deb8u5
Content-Disposition: attachment; filename="9.txt"
Content-Transfer-Encoding: binary
Content-Length: 494592
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: application/download
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49169 104.16.114.74:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA | C=US, ST=Texas, O=MEDIAFIRE, LLC, CN=*.mediafire.com | 8b:fa:81:04:17:18:84:c4:3e:8e:d5:89:ad:d6:5d:bd:9a:df:84:da |
TLSv1 192.168.56.101:49177 41.216.183.3:56001 |
CN=Rlofxutfz | CN=Rlofxutfz | 58:60:84:11:c2:61:e1:a9:6f:bb:95:ea:4a:07:95:10:c4:6f:7f:4f |
Snort Alerts
No Snort Alerts