Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
postal-26.ioomoo.xyz | 79.134.225.103 |
- UDP Requests
-
-
192.168.56.102:52062 164.124.101.2:53
-
192.168.56.102:52336 164.124.101.2:53
-
192.168.56.102:64995 164.124.101.2:53
-
192.168.56.102:137 192.168.56.255:137
-
192.168.56.102:138 192.168.56.255:138
-
192.168.56.102:49152 239.255.255.250:3702
-
192.168.56.102:49164 239.255.255.250:1900
-
52.231.114.183:123 192.168.56.102:123
-
No traffic
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49171 -> 79.134.225.103:6443 | 906200098 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (BitRAT) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.102:49171 79.134.225.103:6443 |
CN=remotecert | CN=remotecert | bf:c7:8d:1e:b6:63:1b:f1:75:50:47:4f:f4:35:1b:96:20:7e:98:f3 |
Snort Alerts
No Snort Alerts