NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.250.199.78 Active Moloch
157.240.215.35 Active Moloch
164.124.101.2 Active Moloch
207.246.80.14 Active Moloch
208.95.112.1 Active Moloch
88.99.66.31 Active Moloch
GET 200 https://www.facebook.com/
REQUEST
RESPONSE
GET 200 https://www.facebook.com/
REQUEST
RESPONSE
GET 200 https://script.google.com/macros/s/AKfycbyeDUociDSMjODhy_ZapM5zzyoJ3zrch9n5IUJeKIM3UQOEtZs/exec?loc=KR&app=Staoism&payoutcents=0.08&ver=3.5&ip=175.208.134.150
REQUEST
RESPONSE
GET 200 https://iplogger.org/18hh57
REQUEST
RESPONSE
GET 200 http://ip-api.com/json/
REQUEST
RESPONSE
GET 200 http://uyyge5w3ye.2ihsfa.com/api/fbtime
REQUEST
RESPONSE
POST 200 http://uyyge5w3ye.2ihsfa.com/api/?sid=92468&key=165d0df49d4f7de7b67582d2a0345a1b
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49204 -> 157.240.215.35:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49209 -> 142.250.199.78:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49210 -> 88.99.66.31:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49198 -> 208.95.112.1:80 2022082 ET POLICY External IP Lookup ip-api.com Device Retrieving External IP Address Detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49204
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Facebook, Inc., CN=*.facebook.com 06:27:21:15:a3:58:11:72:d2:44:44:19:3b:af:00:15:4b:f5:e0:e2
TLSv1
192.168.56.101:49209
142.250.199.78:443
C=US, O=Google Trust Services, CN=GTS CA 1O1 C=US, ST=California, L=Mountain View, O=Google LLC, CN=*.google.com ac:5a:54:aa:08:75:e8:ab:c8:02:46:e1:33:46:73:67:77:2e:3f:39
TLSv1
192.168.56.101:49210
88.99.66.31:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA CN=*.iplogger.org 55:1e:13:99:46:1c:67:40:a3:48:7f:38:0d:16:e7:51:f4:c4:43:cb

Snort Alerts

No Snort Alerts