Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
pool.hashvault.pro | 125.253.92.50 | |
pastebin.com | 104.20.67.143 |
GET
200
https://pastebin.com/raw/GUqDzHQW
REQUEST
RESPONSE
BODY
GET /raw/GUqDzHQW HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: pastebin.com
HTTP/1.1 200 OK
Date: Mon, 02 May 2022 00:26:15 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: HIT
Age: 140
Last-Modified: Mon, 02 May 2022 00:23:55 GMT
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Server: cloudflare
CF-RAY: 704c9fd96bd980a7-NRT
GET
200
https://pastebin.com/raw/GUqDzHQW
REQUEST
RESPONSE
BODY
GET /raw/GUqDzHQW HTTP/1.1
Accept: */*
User-Agent: CertUtil URL Agent
Host: pastebin.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Mon, 02 May 2022 00:26:18 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: MISS
Last-Modified: Mon, 02 May 2022 00:26:18 GMT
Expect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"
Server: cloudflare
CF-RAY: 704c9fe16e98342c-NRT
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:62062 -> 164.124.101.2:53 | 2036289 | ET COINMINER CoinMiner Domain in DNS Lookup (pool .hashvault .pro) | Crypto Currency Mining Activity Detected |
TCP 192.168.56.101:49167 -> 172.67.34.170:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49168 -> 172.67.34.170:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.3 192.168.56.101:49190 125.253.92.50:80 |
None | None | None |
TLSv1 192.168.56.101:49167 172.67.34.170:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | bd:df:4f:1e:29:53:16:4a:b9:cc:a1:42:93:1c:0b:c0:f8:4c:a4:cd |
TLSv1 192.168.56.101:49168 172.67.34.170:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | bd:df:4f:1e:29:53:16:4a:b9:cc:a1:42:93:1c:0b:c0:f8:4c:a4:cd |
Snort Alerts
No Snort Alerts