Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
mogimall.com | 183.111.199.219 |
HEAD
200
https://mogimall.com/pds/mogimall/giftorder/giftorder.exe
REQUEST
RESPONSE
BODY
HEAD /pds/mogimall/giftorder/giftorder.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
Host: mogimall.com
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 21 Apr 2025 03:02:24 GMT
Content-Type: application/x-msdownload
Content-Length: 1362432
Connection: keep-alive
Last-Modified: Tue, 23 Jul 2024 10:25:26 GMT
ETag: "14ca00-61de7947dda49"
Accept-Ranges: bytes
GET
200
https://mogimall.com/pds/mogimall/giftorder/giftorder.exe
REQUEST
RESPONSE
BODY
GET /pds/mogimall/giftorder/giftorder.exe HTTP/1.1
User-Agent: AutoHotkey
Host: mogimall.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 21 Apr 2025 03:02:25 GMT
Content-Type: application/x-msdownload
Content-Length: 1362432
Connection: keep-alive
Last-Modified: Tue, 23 Jul 2024 10:25:26 GMT
ETag: "14ca00-61de7947dda49"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49162 -> 183.111.199.219:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49164 -> 183.111.199.219:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49162 183.111.199.219:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA | CN=mogimall.com | 7b:ee:76:73:30:74:b9:01:f6:da:ff:d2:21:4f:a1:81:15:14:40:9f |
TLSv1 192.168.56.101:49164 183.111.199.219:443 |
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA | CN=mogimall.com | 7b:ee:76:73:30:74:b9:01:f6:da:ff:d2:21:4f:a1:81:15:14:40:9f |
Snort Alerts
No Snort Alerts