Brute Ratel C4 Detected – 18[.]193[.]241[.]248:443

Brute Ratel C4 Detection Alerts

The Information provided at the time of posting was detected as “Brute Ratel C4”. Depending on when you are viewing this article, it may no longer be the case and could be determined as being a false positive. Please do your own additional validation. – RedPacket Security

TimeStamp 2022-07-25T15:34:30.700361

brute ratel c4
Brute Ratel C4

Cloud Information

ProviderAmazon
Regioneu-central-1
ServiceAMAZON
ASNAS16509

Domain Information

Domainsink.wf

HTTP Information

Redirects
Headers Hash-2139866268
Host18[.]193[.]241[.]248
HTML404 file not found
HTML Hash-1957161625
Location/
RobotsN/A
Robots HashN/A
Security TXTN/A
Security TXT HashN/A
Servernginx/1.18.0 (Ubuntu)
SitemapN/A
Sitemap hashN/A
Status200
TitleN/A

Location Information

Area CodeN/A
CityFrankfurt am Main
Country CodeDE
Country NameGermany
Latitude50.11552
Longitude8.68417
Region CodeN/A

SSL Information

Cert Fingerprint SHA1699ee5994211f811af6374140193bc9054f15d46
Cert Fingerprint SHA256a1f2388dab76fbefd425d148ec40e0d1a72b72c6c4cc8cd414bc21c8bbfa2bae
IssuerAmazon
Subject CNink.wf
ExpiredN/A
CipherECDHE-RSA-AES128-GCM-SHA256
Version

Tag Information

Tagscloud
Tags
TagsN/A
TagsN/A

Host Information

OSN/A
Transporttcp
DataHTTP/1.1 200 OK Date: Mon, 25 Jul 2022 15:34:30 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 18 Connection: keep-alive Server: nginx/1.18.0 (Ubuntu)
Port443
IP18[.]193[.]241[.]248


A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon using the button below

Digital Patreon Wordmark FieryCoralv2

To keep up to date follow us on the below channels.

join
Click Above for Telegram
discord
Click Above for Discord
reddit
Click Above for Reddit