Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
bitbucket.org | 104.192.141.1 | |
pastebin.com | 104.23.98.190 | |
sanctam.net | 185.65.135.248 | |
pool.minexmr.com | 51.254.84.37 |
- UDP Requests
-
-
192.168.56.102:58318 164.124.101.2:53
-
192.168.56.102:60922 164.124.101.2:53
-
192.168.56.102:62770 164.124.101.2:53
-
192.168.56.102:62824 164.124.101.2:53
-
192.168.56.102:63203 164.124.101.2:53
-
192.168.56.102:65038 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:65041 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
GET
200
https://bitbucket.org/Sanctam/sanctam/raw/0ceb71c1535ed3e19820cb4ba88d04169dbe5ca6/includes/xmrig
REQUEST
RESPONSE
BODY
GET /Sanctam/sanctam/raw/0ceb71c1535ed3e19820cb4ba88d04169dbe5ca6/includes/xmrig HTTP/1.1
Host: bitbucket.org
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Security-Policy-Report-Only: script-src 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 'self' http: https: https://d301sr5gafysq2.cloudfront.net; style-src 'self' 'unsafe-inline' https://aui-cdn.atlassian.com https://d301sr5gafysq2.cloudfront.net; report-uri https://web-security-reports.services.atlassian.com/csp-report/bb-website; default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *; connect-src bitbucket.org *.bitbucket.org bb-inf.net *.bb-inf.net id.atlassian.com analytics.atlassian.com as.atlassian.com api-private.stg.atlassian.com api-private.atlassian.com cofs.staging.public.atl-paas.net cofs.prod.public.atl-paas.net intake.opbeat.com api.media.atlassian.com api.segment.io xid.statuspage.io xid.atlassian.com xid.sourcetreeapp.com bam.nr-data.net bam-cell.nr-data.net sentry.io bqlf8qjztdtr.statuspage.io https://d301sr5gafysq2.cloudfront.net; object-src about:; base-uri 'self'
Server: nginx
X-Usage-Quota-Remaining: 997043.540
Vary: Authorization, Accept-Language, Origin
X-Usage-Request-Cost: 2986.10
Cache-Control: max-age=900
Content-Type: application/octet-stream
X-B3-TraceId: 7a6af74e89f88e8f
X-Usage-Output-Ops: 0
X-Dc-Location: Micros
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Date: Thu, 05 Aug 2021 08:46:02 GMT
bbr1repopath: /opt/micros/data/cvs/vp1144/data/d-737/r-91420737
X-Usage-User-Time: 0.086167
X-Usage-System-Time: 0.003416
X-Served-By: c8d6fd6215b2
Content-Language: en
X-View-Name: bitbucket.apps.repo2.views.filebrowse_raw
Accept-Ranges: bytes
ETag: "eefb0ce9e7b08cd6f331b8131e1a8250"
X-Static-Version: 960c989028f2
X-Render-Time: 0.104151964188
Content-Disposition: attachment
Connection: keep-alive
X-Usage-Input-Ops: 0
X-Request-Count: 2119
X-Frame-Options: SAMEORIGIN
Last-Modified: Wed, 28 Jul 2021 10:28:11 GMT
X-Version: 960c989028f2
X-Cache-Info: caching
Content-Length: 2047532
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49168 -> 185.65.135.248:58899 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49169 -> 104.192.141.1:443 | 906200022 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49172 -> 104.23.98.190:443 | 906200070 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (CoinMiner) | undefined |
UDP 192.168.56.102:62824 -> 164.124.101.2:53 | 2024789 | ET POLICY DNS request for Monero mining pool | A Network Trojan was detected |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.102:49168 185.65.135.248:58899 |
C=US, O=Let's Encrypt, CN=R3 | CN=sanctam.net | 38:bc:f2:94:62:8a:02:9e:90:64:d5:0f:bc:00:83:12:36:86:2c:2a |
TLS 1.2 192.168.56.102:49169 104.192.141.1:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 Extended Validation Server CA | unknown=Private Organization, unknown=US, unknown=Delaware, serialNumber=3928449, C=US, ST=California, L=San Francisco, O=Atlassian, Inc., OU=Bitbucket, CN=bitbucket.org | 4e:6a:4c:3b:82:15:ef:df:97:38:5e:50:ef:b9:86:42:84:3b:89:f0 |
TLS 1.3 192.168.56.102:49172 104.23.98.190:443 |
None | None | None |
Snort Alerts
No Snort Alerts