Click to jump to signature section
Source: https://selmanc.com/h4ba4.js | Avira URL Cloud: Label: malware |
Source: Network traffic | Suricata IDS: 2823606 - Severity 1 - ETPRO EXPLOIT_KIT Possible Evil Redirect Leading to EK Dec 04 2016 : 45.60.87.23:443 -> 192.168.2.4:49745 |
Source: Network traffic | Suricata IDS: 2823606 - Severity 1 - ETPRO EXPLOIT_KIT Possible Evil Redirect Leading to EK Dec 04 2016 : 45.60.87.23:443 -> 192.168.2.4:49746 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.22.50.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.22.50.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.22.50.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.22.50.131 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /delinian-group-trading-companies HTTP/1.1Host: www.delinian.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWJIYLWA=5074a744e2e3d891814e9a2dace20bd4,719d34d31c8e3a6e6fffd425f7e032f3 HTTP/1.1Host: www.delinian.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.delinian.com/delinian-group-trading-companiesAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWHANEDL=2945055864369694847,11727602495403559037,5347358072124856151,371675 HTTP/1.1Host: www.delinian.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.delinian.com/delinian-group-trading-companiesAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWJIYLWA=5074a744e2e3d891814e9a2dace20bd4,719d34d31c8e3a6e6fffd425f7e032f3 HTTP/1.1Host: www.delinian.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWHANEDL=2945055864369694847,11727602495403559037,5347358072124856151,371675 HTTP/1.1Host: www.delinian.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.delinian.com/delinian-group-trading-companiesAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /delinian-group-trading-companies HTTP/1.1Host: www.delinian.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.delinian.com/delinian-group-trading-companiesAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWHANEDL=2945055864369694847,11727602495403559037,5347358072124856151,371675 HTTP/1.1Host: www.delinian.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /delinian-group-trading-companies HTTP/1.1Host: www.delinian.comConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.delinian.com/delinian-group-trading-companiesAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWHANEDL=2945055864369694847,11727602495403559037,5347358072124856151,371675 HTTP/1.1Host: www.delinian.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg== |
Source: global traffic | HTTP traffic detected: GET /_Incapsula_Resource?SWKMTFSR=1&e=0.31691393376743515 HTTP/1.1Host: www.delinian.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.delinian.com/delinian-group-trading-companiesAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: visid_incap_2876573=jhg7h7sPQGiwBsiQp1+nPGp8YWcAAAAAQUIPAAAAAACwUn/BLu/3QdG9XT9aB+i7; incap_ses_1844_2876573=gkg4d4tj9T1P/EmLcDSXGWp8YWcAAAAAD9ll3DEsmMIXpXs/urG/tg==; ___utmvc=Ic+UQzzpkQ7FnML00S6rGI1IusluNBF93vCxq/JjmKfWRGqylgZN2kZkkT9NIUpI6Nuqjj9Pk1NV5ZJlRQQr/iAYR+4yg0xYJWZL8NB/cRirBYND5/Cl2F6APCZcb6O3kVT7zwoZatsBT31jWczXGK61YUPp3WamAfJZLcHPuLat1dwrktCd1nfSjUn37JLKn0YLR4Ir5yY9lVuXGNjIZ+dG3o90UGS1AvwBJjBpnHVzHe2T5nZqoqgdW6z/kOobSkL7TehFYqIJVbJ44bdHTqGNwueSZF8WP8h0m6yj4FiKMEmSnzzxdqGNqCbLu2yuo1bsBsEmcaj9GRaETLsmvBMdIueTd07NYthyjE18One3kxVwIXPSRQXOBQycG6fSfhv01T2sNPJ95BuPg0hV4slcItJNsQIC1KHopa9A3It71AvDRY4LvQzAy+s7MfD6KaDk1N/rjuRpacTEqxUDTof5mHmcpC5e8Yz0/4imoQx81y7tqAOHw9kEnHWdWva6xDLAIQdN+Lwaf+o1+zsVRTDT2sBkIUZakn4zEVS2ZUU+VU02rCu1osQwE2zysO7BnYog8LE8MCk4LG4U3NPukFRbx1l/cAWkgdcXqNzkXBzsal0aR3RP8BYioRsGs4OhrZV3MwBtnb+iEjzar4qfod+EEcF1HqCz0Nrbnzhp3g4AtSAjlUYu5/DcyIwLd0mVNGDrY5neHT3RZprE3g834LAkJ1BIIzeJqoRstWc+7WH1H9ldS9wgHZERjMUe1q+1udEQQUvk3+OZstvA+vAATuMSY+6ta9/WCI/85O24TyvDJxF6qJdiefWocWpTMnMEVbQ3aDrPPfwgfoW2RZVStgllS0+3Ny97MIY6qlUHGP3K1rl1w84t1/o5cbBZz/ntgUPUjqAyLpijX/bQGhIHu+nWRYjnK7VZ4DvrJxhHB3Im5qqDY+uD1XVnUuR8NCCxyJFmGPpK2aEKjQA1FAGeWmHTuoX+YnKt8kVp4omGd817Nlp3v79LnJMiGU46rG7LsuxEkPPhBci9rj3QQ9A8tTcpy5+8VBtRoEjdZ4AWN1JV89cR4z4ZLGrptorDMGOLi1liwitHCGRi0hj4jzPoMirklrV/0GlVNtXClSTqOV+4srXVgeT3vG4u24K/rtn7kgzqrHDV5ru9eh1hCUxJob01YGPWcs05EDmH/TAMs6ine6mPEGOp0QdrHPuJYeYOJhfnpb9aw1cx7FfFVJqWV2wxAo72TrXOHdHokbnmeJFZbmHdPnFkUU44tbW0HRqhY6OhAACG4JpegByu6ZubHlFGHficXdx35/Vl6N+tuf/JcpkGkgvJHBE7LOlk7phJnYmXmsUN0saJbOLqAEVIvW086bGH+X2ijs4+9L8tOjBoA3GzfNCeBEQQvvTghWxCojz3id2CRRfLeQyHCNH6jxpG+2vKJr9t2sCh4mlpsvwYlencsX1SGXM2gUV4ks3gfFuNgT7cp4rpbL77zX16rKnz8sgmPqHhynhujk5Gb+P8Gl+SymhcbedYZTP94Eo1bBGr6UDVQyIiwWhIRq0J0MWVFZbHQcGIV6akamEDK8QL2ig1bD1LKJlySZdi1A2R2DlhPiP9gyYDGIILcLEINOcZ5S8wG/3MXcuyGguYMOuZv9KVpnZNuMm |