description-logo Description

This indicates an attempt to access Tor2web.
Tor2web is a proxy network that allows regular web users to access published websites that are masked by Tor's hidden service without using a Tor client.
Some malwares, such as Vawtrak, uses Tor2web to connect to C&C servers

affected-products-logoAffected Products

Tor2web

Impact logoImpact

Unexpected network communication

Technology

Browser-Based, Network-Protocol, Client-Server, Peer-to-Peer, Cloud-Based, Mobile-Device

Behavior

  • Evasive
  • Tunneling

Version Updates

Date Version Detail
2020-02-20 15.781 Sig Added
2019-07-11 14.647 Sig Added
2019-05-14 14.613 Sig Added