Brute Ratel C4 Detected – 213[.]199[.]35[.]149:443

Brute Ratel C4 Detection Alerts

The Information provided at the time of posting was detected as “Brute Ratel C4”. Depending on when you are viewing this article, it may no longer be the case and could be determined as being a false positive. Please do your own additional validation. – RedPacket Security

TimeStamp 2024-05-01T05:25:31.048106

brute ratel c4
Brute Ratel C4

Cloud Information

Provider
Region
Service
ASNAS51167

Domain Information

Domainsprox-ima.it

HTTP Information

Redirects
Headers Hash-723384840
Host213[.]199[.]35[.]149
HTML404 file not found
HTML Hash-1957161625
Location/
RobotsN/A
Robots HashN/A
Security TXTN/A
Security TXT HashN/A
Servernginx/1.18.0 (Ubuntu)
SitemapN/A
Sitemap hashN/A
Status200
TitleN/A

Location Information

Area CodeN/A
CityDüsseldorf
Country CodeDE
Country NameGermany
Latitude51.22172
Longitude6.77616
Region CodeNW

SSL Information

Cert Fingerprint SHA115fe010a96bd049a7bebcb74f1ef098378cd4605
Cert Fingerprint SHA256c5087f6eac850a32513e163a2494648fbe3fcdd82d57c5443969b724c7eb9b4a
IssuerLet’s Encrypt
Subject CNwww.prox-ima.it
ExpiredN/A
CipherTLS_AES_256_GCM_SHA384
Version

Tag Information

Tagsc2
Tags
TagsN/A
TagsN/A

Host Information

OSUbuntu
Transporttcp
DataHTTP/1.1 200 OK Server: nginx/1.18.0 (Ubuntu) Date: Wed, 01 May 2024 05:25:30 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: keep-alive
Port443
IP213[.]199[.]35[.]149

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.