


HTTP traffic detected: GET / HTTP /1.1Accept : text/htm l, applica tion/xhtml +xml, imag e/jxr, */* Accept-Lan guage: en- USUser-Age nt: Mozill a/5.0 (Win dows NT 10. HTTP traffic detected: GET /favic on.ico HTT P/1.1User- Agent: Aut oItHost: w ww.vas-hos

8, */* q= 0.5Accept- Language: en-USUser- Agent: Moz illa/5.0 ( Windows NT 10.0 WOW 64 Triden t/7.0 rv: 11.0) like GeckoAcce pt-Encodin g: gzip, d eflateHost : ci.vas-h C onnection: Keep-Aliv e HTTP traffic detected: GET /heade r.gif HTTP /1.1Accept : image/pn g, image/s vg+xml, im age/jxr, i mage/* q=0. JA3 SSL client fingerprint seen in connection with other malware IP address seen in connection with other malware Standard Non-Application Layer Protocol 3
