NetWork | ZeroBOX

Network Analysis

IP Address Status Action
185.112.146.165 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
Name Response Post-Analysis Lookup
nidhoggr.club 185.112.146.165
GET 200 https://nidhoggr.club/slither/overnoise/infiltrator/giulietta/collapsar/
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/ivie/soundless/Adelina/cheerless/gray/ivett?nameless=subrepticedcc4d3c3-0e97-40ed-98bc-e856a5c2f8ca/?XU8IQz27epJ6sln
REQUEST
RESPONSE
POST 100 https://nidhoggr.club/noiseproof/greyish/turbulent/turbulent/Hyacinthia/isabelle/Hildagard?glad=noisemakerd1cdbebf-220a-4726-87c6-1c3855c9c262/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/ultimate/giustina/collapsar/10f9ba50-c5d1-4e00-ab9e-541e6144061f/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/noiselessly/crepuscular/winterly/metallic/antinoise/quiet/7326892f-c4f3-4728-9b5e-a22d33c3b139/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/noised/noiseful/malicious/drab/unbeaten/shadow/1e58acfe-6387-4707-b70e-6e95181f902f/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/horatia/alpha/colorless/stealthy/evil/honoria/outnoise/collapsar/sneaky/39152ab9-6ffb-4b19-811e-e9538a897d93/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/undercover/atomic?hyacinthe=Gizelaff06fa1a-1992-43ef-9704-2913c9b2299e/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/unnoised/strange?ballistic=greyish780990e3-289e-448e-9ae9-2674b0e3f3a2/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/horatia/alpha/colorless/stealthy/evil/honoria/outnoise/collapsar/sneaky/7da76ce4-eabc-48f5-b3df-769296a4b738/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/Gizela/unrecognized/noiselessly/colorless/nova?Odilia=janaya7312d3e3-fe83-4e36-a09f-2faea02ce400/?XU8IQz27epJ6sln
REQUEST
RESPONSE
GET 200 https://nidhoggr.club/anonymous/issie/nuclear/twilit/Iseabal/noiseful/bilious/glad/Sybil/Hyacinth/darkened?atomic=izabel5039d36f-1fe0-46d6-a3bc-d0d81257b6fe/?XU8IQz27epJ6sln
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49812 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49810 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49814 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49816 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49815 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49817 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49818 -> 185.112.146.165:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49812
185.112.146.165:443
None None None
TLSv1
192.168.56.102:49810
185.112.146.165:443
CN=nidhoggr.club CN=nidhoggr.club 40:61:70:26:a9:4a:6d:c3:cc:d3:c8:7c:bb:33:aa:c0:00:12:d0:6f
TLSv1
192.168.56.102:49814
185.112.146.165:443
None None None
TLSv1
192.168.56.102:49816
185.112.146.165:443
None None None
TLSv1
192.168.56.102:49815
185.112.146.165:443
None None None
TLSv1
192.168.56.102:49817
185.112.146.165:443
None None None
TLSv1
192.168.56.102:49818
185.112.146.165:443
None None None

Snort Alerts

No Snort Alerts