NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.209.101.233 Active Moloch
103.72.4.166 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
61.135.169.121 Active Moloch
Name Response Post-Analysis Lookup
date-flash.com 103.209.101.233
GET 200 https://103.72.4.166:8443/images/logo_max.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
POST 200 https://103.72.4.166:8443/user/CheckLogin?ticket=C75j6UbqNtpG-jKQRdQ62w
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 https://103.72.4.166:8443/images/logo.png
REQUEST
RESPONSE
GET 200 http://61.135.169.121/
REQUEST
RESPONSE
HEAD 301 http://date-flash.com/temp.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49805 -> 61.135.169.121:80 2024897 ET USER_AGENTS Go HTTP Client User-Agent Misc activity
TCP 192.168.56.102:49809 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49810 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49815 -> 103.209.101.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49821 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49823 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49824 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49825 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49826 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49828 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49829 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 103.209.101.233:443 -> 192.168.56.102:49816 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.102:49827 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49811 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49822 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic
TCP 192.168.56.102:49830 -> 103.72.4.166:8443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49809
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49810
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49821
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49823
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49824
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49825
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49826
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49828
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49829
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49827
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49811
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1
TLSv1
192.168.56.102:49822
103.72.4.166:8443
C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn C=CN, ST=Beijing, O=BeiJing Baidu Netcom Science Technology Co., Ltd, OU=service operation department, CN=www.baidu.cn f6:57:8e:d1:8d:a0:aa:74:59:26:a9:09:e6:81:dc:ca:56:ee:cf:b1

Snort Alerts

No Snort Alerts