Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 17, 2024, 1:40 p.m. | June 17, 2024, 1:42 p.m. |
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.210.247.57 |
gay-domain.com | 172.67.154.227 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49170 -> 172.67.154.227:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49170 172.67.154.227:443 |
C=US, O=Let's Encrypt, CN=E6 | CN=gay-domain.com | 25:b3:bd:01:76:b5:3d:7a:e8:55:fd:61:e1:63:e4:30:5c:66:ec:c9 |
suspicious_features | POST method with no referer header | suspicious_request | POST https://gay-domain.com/licenseUser.php |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
request | POST https://gay-domain.com/licenseUser.php |
request | POST https://gay-domain.com/licenseUser.php |