Brute Ratel C4 Detected – 3[.]36[.]144[.]103:443

Brute Ratel C4 Detection Alerts

The Information provided at the time of posting was detected as “Brute Ratel C4”. Depending on when you are viewing this article, it may no longer be the case and could be determined as being a false positive. Please do your own additional validation. – RedPacket Security

TimeStamp 2024-04-01T19:29:50.279292

brute ratel c4
Brute Ratel C4

Cloud Information

ProviderAmazon
Regionap-northeast-2
ServiceEC2
ASNAS16509

Domain Information

Domainsamazonaws.com

HTTP Information

Redirects
Headers Hash-855300220
Host3[.]36[.]144[.]103
HTML404 file not found
HTML Hash-1957161625
Location/
RobotsN/A
Robots HashN/A
Security TXTN/A
Security TXT HashN/A
Servernginx/1.16.1
SitemapN/A
Sitemap hashN/A
Status200
TitleN/A

Location Information

Area CodeN/A
CityIncheon
Country CodeKR
Country NameKorea, Republic of
Latitude37.45646
Longitude126.70515
Region Code28

SSL Information

Cert Fingerprint SHA10f7aecb7f2b5ab9654f1b63b8529e5724943dc7a
Cert Fingerprint SHA2563772fa687b2140fd77fff6aa5da98e442c3f0ee2d64dcac2c2a419ce07083a84
IssuerLet’s Encrypt
Subject CNcommapi.gamemarket.kr
ExpiredN/A
CipherECDHE-RSA-AES256-GCM-SHA384
Version

Tag Information

Tagscloud
Tags
Tagseol-product
TagsN/A

Host Information

OSN/A
Transporttcp
DataHTTP/1.1 200 OK Server: nginx/1.16.1 Date: Mon, 01 Apr 2024 19:29:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 18 Connection: keep-alive Access-Control-Allow-Origin: * X-DNS-Prefetch-Control: off X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15552000; includeSubDomains X-Download-Options: noopen X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block ETag: W/”12-GiefXfQQN0O4I+wqaghDb99j/jA”
Port443
IP3[.]36[.]144[.]103

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.