NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.18.10.39 Active Moloch
104.18.11.39 Active Moloch
117.18.232.200 Active Moloch
13.107.246.49 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
GET 302 https://go.microsoft.com/fwlink/?linkid=850289&tfm=.NETFramework,Version=v4.6.1&processName=Svc_host.exe&platform=0009&osver=5&isServer=0
REQUEST
RESPONSE
GET 302 http://go.microsoft.com/fwlink/?prd=11324&pver=4.5&sbp=AppLaunch&plcid=0x409&o1=.NETFramework,Version=v4.6.1&processName=Svc_host.exe&platform=0009&osver=5&isServer=0
REQUEST
RESPONSE
GET 200 http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
REQUEST
RESPONSE
GET 200 http://cacerts.digicert.com/DigiCertGlobalRootG2.crt
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49842 -> 13.107.246.49:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49838 -> 23.197.161.201:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49841 -> 13.107.246.49:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49842
13.107.246.49:443
C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 05 C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=dotnet.microsoft.com 84:70:00:ee:f5:ad:e7:a8:ba:80:02:e9:4b:27:5e:77:75:3b:31:d8
TLSv1
192.168.56.102:49838
23.197.161.201:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 C=US, ST=WA, L=Redmond, O=Microsoft Corporation, OU=Microsoft Corporation, CN=go.microsoft.com 88:c7:2f:7b:17:dd:89:49:46:0b:a2:3f:1b:26:80:82:24:cf:0b:58
TLSv1
192.168.56.102:49841
13.107.246.49:443
C=US, O=Microsoft Corporation, CN=Microsoft Azure TLS Issuing CA 05 C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=dotnet.microsoft.com 84:70:00:ee:f5:ad:e7:a8:ba:80:02:e9:4b:27:5e:77:75:3b:31:d8

Snort Alerts

No Snort Alerts