Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
pastebin.com | 172.67.19.24 |
GET
200
https://pastebin.com/raw/2qX4CwaY
REQUEST
RESPONSE
BODY
GET /raw/2qX4CwaY HTTP/1.1
Host: pastebin.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Mon, 10 Jun 2024 22:36:08 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
x-frame-options: DENY
x-content-type-options: nosniff
x-xss-protection: 1;mode=block
cache-control: public, max-age=1801
CF-Cache-Status: MISS
Last-Modified: Mon, 10 Jun 2024 22:36:08 GMT
Server: cloudflare
CF-RAY: 891cd6a65e3529d4-FUK
GET
200
http://147.45.47.81/xmrig.exe
REQUEST
RESPONSE
BODY
GET /xmrig.exe HTTP/1.1
Host: 147.45.47.81
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 10 Jun 2024 22:36:09 GMT
Content-Type: application/octet-stream
Content-Length: 8251392
Last-Modified: Fri, 17 May 2024 16:26:03 GMT
Connection: keep-alive
ETag: "6647851b-7de800"
Accept-Ranges: bytes
GET
200
http://147.45.47.81/WinRing0x64.sys
REQUEST
RESPONSE
BODY
GET /WinRing0x64.sys HTTP/1.1
Host: 147.45.47.81
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 10 Jun 2024 22:36:09 GMT
Content-Type: application/octet-stream
Content-Length: 14544
Last-Modified: Fri, 17 May 2024 16:26:03 GMT
Connection: keep-alive
ETag: "6647851b-38d0"
Accept-Ranges: bytes
GET
200
http://147.45.47.81/WatchDog.exe
REQUEST
RESPONSE
BODY
GET /WatchDog.exe HTTP/1.1
Host: 147.45.47.81
HTTP/1.1 200 OK
Server: nginx/1.18.0 (Ubuntu)
Date: Mon, 10 Jun 2024 22:36:12 GMT
Content-Type: application/octet-stream
Content-Length: 63488
Last-Modified: Fri, 17 May 2024 16:26:03 GMT
Connection: keep-alive
ETag: "6647851b-f800"
Accept-Ranges: bytes
ICMP traffic
No ICMP traffic performed.
IRC traffic
Command | Params | Type |
---|---|---|
MODE | RandomX mode: auto, fast, light | client |
VERSION | >= 15 | client |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLS 1.2 192.168.56.103:49178 172.67.19.24:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=pastebin.com | 51:a9:80:ce:77:62:b2:72:d2:05:30:60:fd:f4:39:60:f3:7d:ac:16 |
Snort Alerts
No Snort Alerts