Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
www.xenarmor.com |
CNAME
xenarmor.com
|
69.64.94.128 |
GET
431
http://www.xenarmor.com/xen-check-portable-license.php?key=øÞÞ~nr%5DE%1C²%12a¸Bô%0D%17X0%1E&email=SDÌãéQa4i%19èQûþóuÀc;êf:Í5$×rAV&productid=5701
REQUEST
RESPONSE
BODY
GET /xen-check-portable-license.php?key=øÃÃ~Ânr%5DE%1C²%12a¸Bô%0D%17X0%1E&email=SDÃãéÂÂQa4i%19ÂèQÂÂûþóuÃc;êf:Ã5Â$ÃrAV&productid=5701 HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent: Software License Checker
Host: www.xenarmor.com
HTTP/1.1 431 Bad Request
Server: nginx
Date: Wed, 15 Mar 2023 03:06:33 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/8.0.28
Cache-Control: max-age=3600
Expires: Wed, 15 Mar 2023 04:06:33 GMT
Referrer-Policy:
Access-Control-Allow-Origin: *
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49168 -> 74.201.28.92:3569 | 906200095 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (BitRAT) | undefined |
TCP 192.168.56.103:49169 -> 74.201.28.92:3569 | 906200095 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (BitRAT) | undefined |
TCP 192.168.56.103:49175 -> 69.64.94.128:80 | 2030616 | ET POLICY XenArmor Password Recovery License Check | Potential Corporate Privacy Violation |
TCP 192.168.56.103:49201 -> 74.201.28.92:3569 | 906200095 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (BitRAT) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49168 74.201.28.92:3569 |
CN=B2tp | CN=B2tp | a9:51:15:4c:b3:e1:b0:c2:63:da:2f:13:57:33:e2:1f:69:4a:59:80 |
TLS 1.2 192.168.56.103:49169 74.201.28.92:3569 |
CN=B2tp | CN=B2tp | a9:51:15:4c:b3:e1:b0:c2:63:da:2f:13:57:33:e2:1f:69:4a:59:80 |
TLS 1.2 192.168.56.103:49201 74.201.28.92:3569 |
CN=B2tp | CN=B2tp | a9:51:15:4c:b3:e1:b0:c2:63:da:2f:13:57:33:e2:1f:69:4a:59:80 |
Snort Alerts
No Snort Alerts