Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
pastebin.com | 104.20.67.143 |
GET
200
https://pastebin.com/raw/ZRRRiwsq
REQUEST
RESPONSE
BODY
GET /raw/ZRRRiwsq HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 20 Nov 2023 00:55:17 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: EXPIRED
Last-Modified: Sun, 19 Nov 2023 22:06:56 GMT
Server: cloudflare
CF-RAY: 828cb9fc9fa22eff-LAX
GET
200
http://45.15.156.116/xmrig.exe
REQUEST
RESPONSE
BODY
GET /xmrig.exe HTTP/1.1
Host: 45.15.156.116
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 20 Nov 2023 00:55:18 GMT
Content-Type: application/octet-stream
Content-Length: 8251392
Last-Modified: Tue, 14 Nov 2023 16:09:50 GMT
Connection: keep-alive
ETag: "65539bce-7de800"
Accept-Ranges: bytes
GET
200
http://45.15.156.116/WinRing0x64.sys
REQUEST
RESPONSE
BODY
GET /WinRing0x64.sys HTTP/1.1
Host: 45.15.156.116
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 20 Nov 2023 00:55:18 GMT
Content-Type: application/octet-stream
Content-Length: 14544
Last-Modified: Tue, 14 Nov 2023 16:09:50 GMT
Connection: keep-alive
ETag: "65539bce-38d0"
Accept-Ranges: bytes
GET
200
http://45.15.156.116/WatchDog.exe
REQUEST
RESPONSE
BODY
GET /WatchDog.exe HTTP/1.1
Host: 45.15.156.116
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 20 Nov 2023 00:55:22 GMT
Content-Type: application/octet-stream
Content-Length: 63488
Last-Modified: Tue, 14 Nov 2023 16:09:49 GMT
Connection: keep-alive
ETag: "65539bcd-f800"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
Command | Params | Type |
---|---|---|
MODE | RandomX mode: auto, fast, light | client |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49185 104.20.67.143:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 55:c8:82:61:30:05:42:80:db:47:5e:d0:66:b5:df:ac:14:5b:19:6f |
Snort Alerts
No Snort Alerts