Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
hdhdshdhdhgds.000webhostapp.com | 145.14.145.179 | |
sharepaste.net | 172.67.166.167 |
GET
200
https://hdhdshdhdhgds.000webhostapp.com/BASE64.devil
REQUEST
RESPONSE
BODY
GET /BASE64.devil HTTP/1.1
Host: hdhdshdhdhgds.000webhostapp.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 24 Nov 2021 01:55:50 GMT
Content-Length: 295596
Connection: keep-alive
Last-Modified: Mon, 22 Nov 2021 13:20:07 GMT
Accept-Ranges: bytes
Server: awex
X-Xss-Protection: 1; mode=block
X-Content-Type-Options: nosniff
X-Request-ID: 884eff5fe41f902fd94e7787abc73d25
GET
200
https://sharepaste.net/raw/5lhtwcgyem
REQUEST
RESPONSE
BODY
GET /raw/5lhtwcgyem HTTP/1.1
Host: sharepaste.net
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 24 Nov 2021 01:55:57 GMT
Content-Type: text/plain; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
cache-control: no-cache, private
x-ratelimit-limit: 60
x-ratelimit-remaining: 59
set-cookie: XSRF-TOKEN=eyJpdiI6IlN6OGo1V0hrSVEwTmVnMkFNemNER0E9PSIsInZhbHVlIjoiYWdnaFhMb2hZditvc2dXbHRMSmM1aWo4Kys1SU5rK1l1WkYzY1FFZVNCRzROWTMrQUJ1ZHZoSmR0eW5ZWFBZaSIsIm1hYyI6IjdlZmU4ZWNhYjkzOWJlNzZkNTU0MTY3MDU5NzNiY2FmMTNkNGYxNDM3YjhlMjg3OTk0MzA1M2ZlNTQxNWMzZjcifQ%3D%3D; expires=Wed, 24-Nov-2021 03:55:56 GMT; Max-Age=7200; path=/; secure
set-cookie: sharepaste_session=eyJpdiI6IjAyRnZ6YUpjNzBjc3RUclhWR2NNNnc9PSIsInZhbHVlIjoiRnJPS2g1QU9cLytzY0dnbk5MRXFFc3BWWG1vVlwvWGs3UkFoODNtaVJcL205MmJadFJaaWU3TEhFUlZvTk5UandnNSIsIm1hYyI6ImNkZjcxMGViOWE1OWIyM2Y1MjllNDE4MGYwOWVkYjkzNDU5YTMwZTllMTc2ZjliZWI1NWM4YTdkZjVmNmYwMWQifQ%3D%3D; expires=Wed, 24-Nov-2021 03:55:56 GMT; Max-Age=7200; path=/; httponly; secure
vary: Accept-Encoding
CF-Cache-Status: DYNAMIC
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=%2FS9xHA2u3C60TbwWa1VmnB3Tz6cnhIVh%2BraEVEgPFcavTJqNGcXA0mIwScrob2rnqX0gPEedlItLYyoM2hSzFaLjJSYy2UGa6a87gFhV65sFB4bOZgjlSTE9Uo8j19%2FDmQ%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 6b2f04969888aea3-KIX
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400, h3-28=":443"; ma=86400, h3-27=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:55871 -> 164.124.101.2:53 | 2026657 | ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) | Not Suspicious Traffic |
TCP 192.168.56.101:49164 -> 145.14.144.222:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49162 -> 145.14.144.222:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 145.14.144.222:443 -> 192.168.56.101:49164 | 2026658 | ET INFO Observed SSL Cert for Free Hosting Domain (*.000webhostapp .com) | Not Suspicious Traffic |
TCP 192.168.56.101:49165 -> 104.21.16.59:443 | 906200056 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 145.14.144.222:443 -> 192.168.56.101:49162 | 2026658 | ET INFO Observed SSL Cert for Free Hosting Domain (*.000webhostapp .com) | Not Suspicious Traffic |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49164 145.14.144.222:443 |
C=US, O=DigiCert Inc, CN=RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1 | CN=*.000webhostapp.com | f3:1b:b7:47:29:59:39:c1:91:7d:b4:61:da:4d:ec:0d:8c:e1:e7:c1 |
TLSv1 192.168.56.101:49162 145.14.144.222:443 |
C=US, O=DigiCert Inc, CN=RapidSSL TLS DV RSA Mixed SHA256 2020 CA-1 | CN=*.000webhostapp.com | f3:1b:b7:47:29:59:39:c1:91:7d:b4:61:da:4d:ec:0d:8c:e1:e7:c1 |
TLSv1 192.168.56.101:49165 104.21.16.59:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 44:bc:3a:4c:73:20:3d:c0:4d:a1:36:6d:87:3c:02:3f:79:fb:d7:e8 |
Snort Alerts
No Snort Alerts