NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.253.212.34 Active Moloch
107.161.183.42 Active Moloch
149.202.90.163 Active Moloch
162.241.61.218 Active Moloch
162.241.87.244 Active Moloch
164.124.101.2 Active Moloch
18.136.132.202 Active Moloch
191.252.105.201 Active Moloch
200.98.245.52 Active Moloch
67.227.152.156 Active Moloch
GET 404 https://hartlepooltaxi.co.uk/TaxiShop/modules/coreupdater/views/js/bbKt3OpktVRAFni.php
REQUEST
RESPONSE
GET 404 https://www.vidroboxbirigui.com.br/posts/GqlwMINB3GC.php
REQUEST
RESPONSE
GET 403 https://www.eloyfestas.com.br/posts/EwyU0Hv3aBAST.php
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
192.168.56.101 164.124.101.2 3

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49203 -> 103.253.212.34:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 103.253.212.34:443 -> 192.168.56.101:49206 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49208 -> 162.241.61.218:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.101:57460 -> 164.124.101.2:53 2025105 ET INFO DNS Query for Suspicious .ga Domain Potentially Bad Traffic
TCP 192.168.56.101:49219 -> 18.136.132.202:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49224 -> 67.227.152.156:443 2025109 ET INFO Suspicious Domain (*.ga) in TLS SNI Potentially Bad Traffic
TCP 192.168.56.101:49224 -> 67.227.152.156:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49229 -> 191.252.105.201:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 107.161.183.42:443 -> 192.168.56.101:49217 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 67.227.152.156:443 -> 192.168.56.101:49225 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 162.241.61.218:443 -> 192.168.56.101:49210 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49216 -> 107.161.183.42:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 162.241.87.244:443 -> 192.168.56.101:49232 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 18.136.132.202:443 -> 192.168.56.101:49221 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49230 -> 162.241.87.244:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.101:61479 -> 164.124.101.2:53 2027868 ET INFO Observed DNS Query to .work TLD Potentially Bad Traffic
TCP 192.168.56.101:49209 -> 162.241.61.218:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49220 -> 18.136.132.202:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49223 -> 67.227.152.156:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49205 -> 103.253.212.34:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49212 -> 149.202.90.163:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49213 -> 191.252.105.201:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49215 -> 107.161.183.42:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49231 -> 162.241.87.244:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49229
191.252.105.201:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=eloyfestas.com.br c5:14:0e:74:ba:24:10:31:c5:6a:6c:37:f3:28:55:65:37:7c:61:f0
TLSv1
192.168.56.101:49212
149.202.90.163:443
C=US, O=Let's Encrypt, CN=R3 CN=hartlepooltaxi.modmania.co.uk a5:6a:8e:22:2f:94:f8:0e:1a:ed:43:2b:c0:7d:64:f4:88:81:b3:11
TLSv1
192.168.56.101:49213
191.252.105.201:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=vidroboxbirigui.com.br 02:08:0e:83:18:21:a5:b4:e8:a4:51:a1:12:df:3a:4d:4d:68:8e:3c

Snort Alerts

No Snort Alerts