Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
bakad.qqfarmer.com.cn | 116.255.160.63 | |
images.qqfarmer.com.cn | 61.160.192.103 | |
down.qqfarmer.com.cn | 180.101.203.232 | |
ad.qqfarmer.com.cn | 8.210.224.3 |
- TCP Requests
-
-
192.168.56.103:49170 58.218.215.167:80down.qqfarmer.com.cn
-
192.168.56.103:49176 58.218.215.167:80down.qqfarmer.com.cn
-
192.168.56.103:49171 61.160.192.103:80images.qqfarmer.com.cn
-
192.168.56.103:49172 61.160.192.103:80images.qqfarmer.com.cn
-
192.168.56.103:49173 61.160.192.103:80images.qqfarmer.com.cn
-
192.168.56.103:49174 61.160.192.103:80images.qqfarmer.com.cn
-
192.168.56.103:49164 8.210.224.3:80ad.qqfarmer.com.cn
-
192.168.56.103:49166 8.210.224.3:80ad.qqfarmer.com.cn
-
192.168.56.103:49167 8.210.224.3:80ad.qqfarmer.com.cn
-
192.168.56.103:49168 8.210.224.3:80ad.qqfarmer.com.cn
-
192.168.56.103:49169 8.210.224.3:80ad.qqfarmer.com.cn
-
192.168.56.103:49178 8.210.224.3:80ad.qqfarmer.com.cn
-
POST
200
http://ad.qqfarmer.com.cn/login.php?id=p&r=0.368447953602299
REQUEST
RESPONSE
BODY
POST /login.php?id=p&r=0.368447953602299 HTTP/1.1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 18
Cache-control: no-cache
Pragma: no-cache
Host: ad.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Expires: 0
Vary: Accept-Encoding
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.4.45
Set-Cookie: ZDEDebuggerPresent=php,phtml,php3; path=/
Set-Cookie: t=1725008963
Set-Cookie: coll=cdata%3Al%2C%22
Set-Cookie: sig=%2CQ%3D%22
Set-Cookie: websig=%2CQ%3D%22
Set-Cookie: p1=%2Cdt%3D%22
Set-Cookie: p2=%2Cft%3D%22
Set-Cookie: cdata_1=%22%2Cot%3D%22
Set-Cookie: height=Number%28%22
Set-Cookie: 6F631063=1.540
Date: Fri, 30 Aug 2024 09:09:23 GMT
Content-Length: 1945
POST
200
http://ad.qqfarmer.com.cn/login.php?id=v&r=0.494936139322817
REQUEST
RESPONSE
BODY
POST /login.php?id=v&r=0.494936139322817 HTTP/1.1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Cache-control: no-cache
Pragma: no-cache
Cookie: ZDEDebuggerPresent=php,phtml,php3; t=1725008963; coll=cdata%3Al%2C%22; sig=%2CQ%3D%22; websig=%2CQ%3D%22; p1=%2Cdt%3D%22; p2=%2Cft%3D%22; cdata_1=%22%2Cot%3D%22; height=Number%28%22; 6F631063=1.540
Host: ad.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html
Content-Encoding: gzip
Expires: 0
Vary: Accept-Encoding
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.4.45
Set-Cookie: ZDEDebuggerPresent=php,phtml,php3; path=/
Date: Fri, 30 Aug 2024 09:09:23 GMT
Content-Length: 517
POST
200
http://ad.qqfarmer.com.cn/login.php?id=n&r=0.480842764023691
REQUEST
RESPONSE
BODY
POST /login.php?id=n&r=0.480842764023691 HTTP/1.1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Cache-control: no-cache
Pragma: no-cache
Cookie: ZDEDebuggerPresent=php,phtml,php3; t=1725008963; coll=cdata%3Al%2C%22; sig=%2CQ%3D%22; websig=%2CQ%3D%22; p1=%2Cdt%3D%22; p2=%2Cft%3D%22; cdata_1=%22%2Cot%3D%22; height=Number%28%22; 6F631063=1.540
Host: ad.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Expires: 0
Vary: Accept-Encoding
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.4.45
Set-Cookie: ZDEDebuggerPresent=php,phtml,php3; path=/
Date: Fri, 30 Aug 2024 09:09:23 GMT
Content-Length: 586
POST
200
http://ad.qqfarmer.com.cn/login.php?id=l&r=0.560313974739984
REQUEST
RESPONSE
BODY
POST /login.php?id=l&r=0.560313974739984 HTTP/1.1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Cache-control: no-cache
Pragma: no-cache
Cookie: ZDEDebuggerPresent=php,phtml,php3; t=1725008963; coll=cdata%3Al%2C%22; sig=%2CQ%3D%22; websig=%2CQ%3D%22; p1=%2Cdt%3D%22; p2=%2Cft%3D%22; cdata_1=%22%2Cot%3D%22; height=Number%28%22; 6F631063=1.540
Host: ad.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Expires: 0
Vary: Accept-Encoding
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.4.45
Set-Cookie: ZDEDebuggerPresent=php,phtml,php3; path=/
Date: Fri, 30 Aug 2024 09:09:23 GMT
Content-Length: 492
POST
200
http://ad.qqfarmer.com.cn/login.php?id=x&r=0.44646016205661
REQUEST
RESPONSE
BODY
POST /login.php?id=x&r=0.44646016205661 HTTP/1.1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 0
Cache-control: no-cache
Pragma: no-cache
Cookie: ZDEDebuggerPresent=php,phtml,php3; t=1725008963; coll=cdata%3Al%2C%22; sig=%2CQ%3D%22; websig=%2CQ%3D%22; p1=%2Cdt%3D%22; p2=%2Cft%3D%22; cdata_1=%22%2Cot%3D%22; height=Number%28%22; 6F631063=1.540
Host: ad.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Cache-Control: no-cache, must-revalidate
Pragma: no-cache
Content-Type: text/html; charset=utf-8
Content-Encoding: gzip
Expires: 0
Vary: Accept-Encoding
Server: Microsoft-IIS/8.5
X-Powered-By: PHP/5.4.45
Set-Cookie: ZDEDebuggerPresent=php,phtml,php3; path=/
Date: Fri, 30 Aug 2024 09:09:23 GMT
Content-Length: 891
GET
200
http://down.qqfarmer.com.cn/libeay32_0626_5f86d65a1686e6bb031048d04bb3fe04.xml?r=0.313291363418102
REQUEST
RESPONSE
BODY
GET /libeay32_0626_5f86d65a1686e6bb031048d04bb3fe04.xml?r=0.313291363418102 HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: down.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Server: Tengine
Content-Type: text/xml
Content-Length: 496922
Connection: keep-alive
Date: Fri, 30 Aug 2024 08:46:08 GMT
x-oss-request-id: 66D186CF1A4B233039918635
x-oss-cdn-auth: success
Accept-Ranges: bytes
x-oss-object-type: Normal
x-oss-storage-class: Standard
Content-MD5: X4bWWhaG5rsDEEjQS7P+BA==
x-oss-server-time: 68
Via: cache26.l2cn3125[0,0,304-0,H], cache50.l2cn3125[1,0], kunlun8.cn192[68,71,200-0,H], kunlun2.cn192[73,0]
Vary: Accept-Encoding
Last-Modified: Fri, 26 Jun 2020 03:04:23 GMT
x-oss-hash-crc64ecma: 9482847611575531544
Content-Encoding: gzip
Age: 1396
Ali-Swift-Global-Savetime: 1725007568
X-Cache: HIT TCP_REFRESH_HIT dirn:9:747702563
X-Swift-SaveTime: Fri, 30 Aug 2024 09:09:24 GMT
X-Swift-CacheTime: 3600
Timing-Allow-Origin: *
EagleId: 3adad01617250089642841580e
GET
200
http://images.qqfarmer.com.cn/504486-20170712112840415-1890262410.gif
REQUEST
RESPONSE
BODY
GET /504486-20170712112840415-1890262410.gif HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: images.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Server: Tengine
Content-Type: image/gif
Content-Length: 5062
Connection: keep-alive
Date: Fri, 30 Aug 2024 08:15:10 GMT
x-oss-request-id: 66D17F8E2A751933394FEE88
x-oss-cdn-auth: success
Accept-Ranges: bytes
x-oss-object-type: Normal
x-oss-storage-class: Standard
Content-MD5: /CZL5c/9Cf1Hj6oTA5CzNA==
x-oss-server-time: 151
Via: cache34.l2cn3125[0,0,304-0,H], cache33.l2cn3125[1,0], kunlun3.cn6425[0,0,200-0,H], kunlun2.cn6425[2,0]
ETag: "FC264BE5CFFD09FD478FAA130390B334"
Last-Modified: Thu, 28 Jun 2018 03:19:03 GMT
x-oss-hash-crc64ecma: 9052107043407144084
Age: 3254
Ali-Swift-Global-Savetime: 1725005710
X-Cache: HIT TCP_MEM_HIT dirn:-2:-2
X-Swift-SaveTime: Fri, 30 Aug 2024 08:19:33 GMT
X-Swift-CacheTime: 86137
Timing-Allow-Origin: *
EagleId: 3da0c00c17250089641426416e
GET
200
http://images.qqfarmer.com.cn/504486-20162218235650745-1529273276.gif
REQUEST
RESPONSE
BODY
GET /504486-20162218235650745-1529273276.gif HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: images.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Server: Tengine
Content-Type: image/gif
Content-Length: 2160
Connection: keep-alive
Date: Fri, 30 Aug 2024 07:11:49 GMT
x-oss-request-id: 66D170B41344D1343018E53D
x-oss-cdn-auth: success
Accept-Ranges: bytes
x-oss-object-type: Normal
x-oss-storage-class: Standard
Content-MD5: YeK/EdPd6FMipRniN/OYDQ==
x-oss-server-time: 108
Via: cache4.l2cn3125[0,0,304-0,H], cache22.l2cn3125[1,0], kunlun4.cn6425[0,0,200-0,H], kunlun5.cn6425[1,0]
ETag: "61E2BF11D3DDE85322A519E237F3980D"
Last-Modified: Sun, 12 May 2019 13:10:31 GMT
x-oss-hash-crc64ecma: 13667867086006073534
Age: 7055
Ali-Swift-Global-Savetime: 1725001909
X-Cache: HIT TCP_MEM_HIT dirn:-2:-2
X-Swift-SaveTime: Fri, 30 Aug 2024 07:18:00 GMT
X-Swift-CacheTime: 86029
Timing-Allow-Origin: *
EagleId: 3da0c00f17250089642952730e
GET
200
http://images.qqfarmer.com.cn/hongbao_nav.gif
REQUEST
RESPONSE
BODY
GET /hongbao_nav.gif HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: images.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Server: Tengine
Content-Type: image/gif
Content-Length: 1980
Connection: keep-alive
Date: Fri, 30 Aug 2024 06:04:52 GMT
x-oss-request-id: 66D161049935E33131C51AB9
x-oss-cdn-auth: success
Accept-Ranges: bytes
x-oss-object-type: Normal
x-oss-storage-class: Standard
Content-MD5: BRrk2j5JLrrICiLiTiQxzw==
x-oss-server-time: 162
Via: cache55.l2cn3125[0,0,304-0,H], cache6.l2cn3125[0,0], kunlun3.cn6425[0,0,200-0,H], kunlun3.cn6425[2,0]
ETag: "051AE4DA3E492EBAC80A22E24E2431CF"
Last-Modified: Sat, 04 Aug 2018 10:57:07 GMT
x-oss-hash-crc64ecma: 6152460185966649345
Age: 11072
Ali-Swift-Global-Savetime: 1724997892
X-Cache: HIT TCP_MEM_HIT dirn:-2:-2
X-Swift-SaveTime: Fri, 30 Aug 2024 06:07:01 GMT
X-Swift-CacheTime: 86271
Timing-Allow-Origin: *
EagleId: 3da0c00d17250089644398755e
GET
200
http://images.qqfarmer.com.cn/504486-20161218235650745-1529273276.gif
REQUEST
RESPONSE
BODY
GET /504486-20161218235650745-1529273276.gif HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: images.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Server: Tengine
Content-Type: image/gif
Content-Length: 2300
Connection: keep-alive
Date: Fri, 30 Aug 2024 07:01:23 GMT
x-oss-request-id: 66D16E43CC8CEC32364731D0
x-oss-cdn-auth: success
Accept-Ranges: bytes
x-oss-object-type: Normal
x-oss-storage-class: Standard
Content-MD5: 813LfUU1TCGIJ8bwAXa5QA==
x-oss-server-time: 73
Via: cache20.l2cn3125[0,0,304-0,H], cache17.l2cn3125[1,0], kunlun4.cn6425[0,0,200-0,H], kunlun4.cn6425[1,0]
ETag: "F35DCB7D45354C218827C6F00176B940"
Last-Modified: Thu, 28 Jun 2018 03:19:04 GMT
x-oss-hash-crc64ecma: 17205359839196295625
Age: 7681
Ali-Swift-Global-Savetime: 1725001283
X-Cache: HIT TCP_MEM_HIT dirn:-2:-2
X-Swift-SaveTime: Fri, 30 Aug 2024 07:02:26 GMT
X-Swift-CacheTime: 86337
Timing-Allow-Origin: *
EagleId: 3da0c00e17250089645924239e
GET
200
http://down.qqfarmer.com.cn/ssleay32_0626_e503921a6061251302cb45772cb75f42.xml?r=0.329597188392654
REQUEST
RESPONSE
BODY
GET /ssleay32_0626_e503921a6061251302cb45772cb75f42.xml?r=0.329597188392654 HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: down.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Server: Tengine
Content-Type: text/xml
Content-Length: 134699
Connection: keep-alive
Date: Fri, 30 Aug 2024 08:46:08 GMT
x-oss-request-id: 66D186D068CDBA3037E06EB9
x-oss-cdn-auth: success
Accept-Ranges: bytes
x-oss-object-type: Normal
x-oss-storage-class: Standard
Content-MD5: 5QOSGmBhJRMCy0V3LLdfQg==
x-oss-server-time: 34
Via: cache6.l2cn3125[0,0,304-0,H], cache30.l2cn3125[1,0], kunlun8.cn192[21,22,200-0,H], kunlun7.cn192[25,0]
Vary: Accept-Encoding
Last-Modified: Fri, 26 Jun 2020 03:04:25 GMT
x-oss-hash-crc64ecma: 8302182771432485799
Content-Encoding: gzip
Age: 1397
Ali-Swift-Global-Savetime: 1725007568
X-Cache: HIT TCP_REFRESH_HIT dirn:10:104973502
X-Swift-SaveTime: Fri, 30 Aug 2024 09:09:25 GMT
X-Swift-CacheTime: 3600
Timing-Allow-Origin: *
EagleId: 3adad01b17250089653341829e
GET
200
http://ad.qqfarmer.com.cn/xml/encrypt.js?r=0.952554038958624
REQUEST
RESPONSE
BODY
GET /xml/encrypt.js?r=0.952554038958624 HTTP/1.1
Connection: keep-alive
Cache-control: no-cache
Pragma: no-cache
Host: ad.qqfarmer.com.cn
Accept: */*
Accept-Encoding: gzip, deflate, identity
Accept-Language: zh-CN,zh;q=0.9
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
HTTP/1.1 200 OK
Content-Type: application/javascript
Content-Encoding: gzip
Last-Modified: Sat, 25 Jul 2020 12:28:31 GMT
Accept-Ranges: bytes
ETag: "8041281b7f62d61:0"
Vary: Accept-Encoding
Server: Microsoft-IIS/8.5
Date: Fri, 30 Aug 2024 09:09:25 GMT
Content-Length: 8584
ICMP traffic
Source | Destination | ICMP Type | Data |
---|---|---|---|
192.168.56.103 | 116.255.160.63 | 8 | # |
116.255.160.63 | 192.168.56.103 | 0 | # |
192.168.56.103 | 8.210.224.3 | 8 | # |
8.210.224.3 | 192.168.56.103 | 0 | # |
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 58.218.215.167:80 -> 192.168.56.103:49170 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
TCP 58.218.215.167:80 -> 192.168.56.103:49176 | 2018959 | ET POLICY PE EXE or DLL Windows file download HTTP | Potential Corporate Privacy Violation |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts