NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.94.22 Active Moloch
117.18.232.200 Active Moloch
13.107.21.200 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
40.126.35.128 Active Moloch
40.126.52.147 Active Moloch
GET 302 https://tootirrruahapowsadassa.com/
REQUEST
RESPONSE
GET 200 https://www.bing.com/
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/hceflue5sqxkKta9dP3R-IFtPuY.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/MDr1f9aJs4rBVf1F5DAtlALvweY.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/svI82uPNFRD54V4bMLaeahXQXBI.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/a282eRIAnHsW_URoyogdzsukm_o.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/th?id=OHR.ForteNossa_ROW5471382887_1920x1080.jpg&rf=LaDigue_1920x1080.jpg&pid=hp
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/B0oC6BX98v6fWz1fuvaeRm9bOak.png
REQUEST
RESPONSE
GET 200 https://www.bing.com/sa/simg/favicon-2x.ico
REQUEST
RESPONSE
GET 200 https://www.bing.com/fd/ls/l?IG=5CE5C6755B1C41608FDC05E01F4F69BE&CID=3DA4ADCCE9E26E2535F1BD9EE8A96FE1&Type=Event.CPT&DATA={"pp":{"S":"L","FC":-1,"BC":-1,"SE":-1,"TC":-1,"H":1024,"BP":1321,"CT":1428,"IL":1},"ad":[-1,-1,1365,899,1365,899,1]}&P=SERP&DA=HKGE01
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx?
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/nD3Dxxt3XsvojhRsXFq3RJI2wTE.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/2ajnlX1juJQ_Nu80sW46BDUL1-A.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/swyt_VnIjJDWZW5KEq7a8l_1AEw.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/Dta1_Or8JEDr20O5LJEJy7sv1z0.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/P3LN8DHh0udC9Pbh8UHnw5FJ8R8.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/n8-O_KIRNSMPFWQWrGjn0BRH6SM.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/MstqcgNaYngCBavkktAoSE0--po.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/ozS3T0fsBUPZy4zlY0UX_e0TUwY.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/eaMqCdNxIXjLc0ATep7tsFkfmSA.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/RXZtj0lYpFm5XDPMpuGSsNG8i9I.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/6sxhavkE4_SZHA_K4rwWmg67vF0.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/FvkosEDIbuCPhD1mwLAN-LJ7Coc.gz.js
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx?
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/Xp-HPHGHOZznHBwdn7OWdva404Y.gz.js
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx?
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx?
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/_ofc7e4WqqkT9lPqQJykFP4vxq4.gz.js
REQUEST
RESPONSE
GET 200 https://login.microsoftonline.com/common/oauth2/authorize?client_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e34c7&response_type=id_token+code&nonce=1642c1fe-e198-47e5-9747-498e4aa08f82&redirect_uri=https%3a%2f%2fwww.bing.com%2forgid%2fidtoken%2fconditional&scope=openid&response_mode=form_post&msafed=0&prompt=none&state=%7b%22ig%22%3a%225CE5C6755B1C41608FDC05E01F4F69BE%22%7d
REQUEST
RESPONSE
GET 200 https://www.bing.com/rp/pCNhfy2VQinsKZ9KIqxtGogwDv0.gz.js
REQUEST
RESPONSE
GET 200 https://www.bing.com/ipv6test/test?FORM=MONITR
REQUEST
RESPONSE
GET 200 https://www2.bing.com/ipv6test/test
REQUEST
RESPONSE
POST 200 https://www.bing.com/orgid/idtoken/conditional
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx
REQUEST
RESPONSE
GET 302 https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1623293620&rver=6.0.5286.0&wp=MBI_SSL&wreply=https:%2F%2fwww.bing.com%2Fsecure%2FPassport.aspx%3Fpopup%3D1%26ssl%3D1&lc=1042&id=264960&checkda=1
REQUEST
RESPONSE
GET 200 https://www.bing.com/secure/Passport.aspx?popup=1&ssl=1
REQUEST
RESPONSE
GET 200 https://www.bing.com/fd/ls/l?IG=5CE5C6755B1C41608FDC05E01F4F69BE&CID=3DA4ADCCE9E26E2535F1BD9EE8A96FE1&TYPE=Event.ClientInst&DATA=%5B%7B%22T%22%3A%22CI.Init%22%2C%22TS%22%3A1623293605101%2C%22Name%22%3A%22Base%22%2C%22FID%22%3A%22CI%22%7D%2C%7B%22width%22%3A%221365%22%2C%22T%22%3A%22CI.Info%22%2C%22TS%22%3A1623293605101%2C%22Name%22%3A%22W%22%2C%22FID%22%3A%22BRW%22%7D%2C%7B%22height%22%3A%22899%22%2C%22T%22%3A%22CI.Info%22%2C%22TS%22%3A1623293605101%2C%22Name%22%3A%22M%22%2C%22FID%22%3A%22BRH%22%7D%2C%7B%22T%22%3A%22CI.Info%22%2C%22TS%22%3A1623293605101%2C%22Name%22%3A%221%22%2C%22FID%22%3A%22Mutation%22%7D%2C%7B%22T%22%3A%22CI.Info%22%2C%22TS%22%3A1623293605101%2C%22Name%22%3A%224%22%2C%22FID%22%3A%22DM%22%7D%2C%7B%22RTT%22%3A%221623293601353%22%2C%22T%22%3A%22CI.Init%22%2C%22TS%22%3A1623293605425%2C%22Name%22%3A%22ClientPerf%22%2C%22FID%22%3A%22HP%22%7D%2C%7B%22w%22%3A%221365%22%2C%22h%22%3A%221024%22%2C%22dpr%22%3A%220%22%2C%22T%22%3A%22CI.Init%22%2C%22TS%22%3A1623293605425%2C%22Name%22%3A%22ClientScreen%22%2C%22FID%22%3A%22HP%22%7D%2C%7B%22Time%22%3A4106%2C%22T%22%3A%22CI.Latency%22%2C%22TS%22%3A1623293605459%2C%22Name%22%3A%22sBoxTime%22%2C%22FID%22%3A%22HP%22%7D%2C%7B%22T%22%3A%22CI.ClientInst%22%2C%22TS%22%3A1623293605719%2C%22Name%22%3A%22OrgId%22%2C%22FID%22%3A%22NoSignInAttempt%22%7D%5D
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx
REQUEST
RESPONSE
POST 204 https://www.bing.com/fd/ls/lsp.aspx
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49811 -> 104.21.94.22:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49813 -> 204.79.197.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49814 -> 204.79.197.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49812 -> 104.21.94.22:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49817 -> 204.79.197.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49821 -> 204.79.197.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49818 -> 204.79.197.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49820 -> 204.79.197.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49822 -> 40.126.52.147:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49826 -> 40.126.35.128:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 117.18.232.200:443 -> 192.168.56.102:49832 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.102:49825 -> 13.107.21.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49823 -> 40.126.52.147:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49827 -> 40.126.35.128:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49824 -> 13.107.21.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49830 -> 117.18.232.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49831 -> 117.18.232.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49811
104.21.94.22:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 7c:d3:63:d6:73:77:09:13:7a:43:c3:09:90:c4:66:17:64:41:3d:7e
TLSv1
192.168.56.102:49813
204.79.197.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49814
204.79.197.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49812
104.21.94.22:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 7c:d3:63:d6:73:77:09:13:7a:43:c3:09:90:c4:66:17:64:41:3d:7e
TLSv1
192.168.56.102:49817
204.79.197.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49821
204.79.197.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49818
204.79.197.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49820
204.79.197.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49822
40.126.52.147:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=stamp2.login.microsoftonline.com de:dd:3b:3d:85:a0:f1:06:e2:75:76:3c:8d:12:93:4c:ef:32:50:22
TLSv1
192.168.56.102:49826
40.126.35.128:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=graph.windows.net 3a:72:af:8b:75:8e:65:e6:76:63:b2:c8:42:cd:8b:1b:fd:2e:02:51
TLSv1
192.168.56.102:49825
13.107.21.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f
TLSv1
192.168.56.102:49823
40.126.52.147:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=stamp2.login.microsoftonline.com de:dd:3b:3d:85:a0:f1:06:e2:75:76:3c:8d:12:93:4c:ef:32:50:22
TLSv1
192.168.56.102:49827
40.126.35.128:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=graph.windows.net 3a:72:af:8b:75:8e:65:e6:76:63:b2:c8:42:cd:8b:1b:fd:2e:02:51
TLSv1
192.168.56.102:49824
13.107.21.200:443
C=US, O=Microsoft Corporation, CN=Microsoft RSA TLS CA 01 CN=www.bing.com 29:b4:ed:e7:1f:1c:1b:12:99:6c:9b:1e:27:75:ac:01:25:15:77:1f

Snort Alerts

No Snort Alerts