NetWork | ZeroBOX

Network Analysis

IP Address Status Action
13.225.134.82 Active Moloch
142.250.196.131 Active Moloch
142.250.199.77 Active Moloch
142.250.207.78 Active Moloch
164.124.101.2 Active Moloch
172.67.223.135 Active Moloch
172.217.161.65 Active Moloch
172.217.26.35 Active Moloch
172.217.31.131 Active Moloch
193.70.47.128 Active Moloch
59.18.30.144 Active Moloch
59.18.44.80 Active Moloch
34.104.35.123 Active Moloch
35.83.118.206 Active Moloch
52.54.193.222 Active Moloch
65.8.17.57 Active Moloch
POST 200 https://flownetserv.com/service/update2
REQUEST
RESPONSE
POST 200 https://flownetserv.com/service/update2?cup2key=10:2041637316&cup2hreq=c44ca074fab98820e0ddea4abd5bbe7984d55eefb00cbc75bdb2c1c68dce87ec
REQUEST
RESPONSE
GET 200 https://soloyama.com/app.php?ping=f%3D1%26a%3D3100%26u%3Dfldk-20210619-4126222-fbchff02%26p%3Dpa%26ck%3D430179789257580636%2F
REQUEST
RESPONSE
POST 200 https://flownetserv.com/service/update2
REQUEST
RESPONSE
HEAD 200 http://flownetserv.com/static/media/build/Flow%20Browser%20-%20SearchBip/stable/win/x64/97856822509658/Setup.exe
REQUEST
RESPONSE
GET 200 http://flownetserv.com/static/media/build/Flow%20Browser%20-%20SearchBip/stable/win/x64/97856822509658/Setup.exe
REQUEST
RESPONSE
HEAD 200 http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFUTGhWQUViMUVlUQ/0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crx
REQUEST
RESPONSE
GET 206 http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYjFkQUFWdmlaXy12MHFUTGhWQUViMUVlUQ/0.57.44.2492_hnimpnehoodheedghdeeijklkeaacbdc.crx
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 172.67.223.135:80 -> 192.168.56.101:49221 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.168.56.101:49216 -> 172.67.223.135:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49217 -> 172.67.223.135:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49305 -> 193.70.47.128:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49315 -> 172.67.223.135:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.101:49216
172.67.223.135:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 58:02:7f:64:99:8c:33:d7:44:80:ce:b8:4a:40:da:1b:4a:2d:a5:52
TLS 1.2
192.168.56.101:49217
172.67.223.135:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 58:02:7f:64:99:8c:33:d7:44:80:ce:b8:4a:40:da:1b:4a:2d:a5:52
TLS 1.3
192.168.56.101:49300
142.250.199.77:443
None None None
TLS 1.3
192.168.56.101:49301
216.58.200.78:443
None None None
TLS 1.3
192.168.56.101:49304
59.18.44.80:443
None None None
TLS 1.3
192.168.56.101:49306
59.18.30.144:443
None None None
TLS 1.3
192.168.56.101:49307
142.250.207.78:443
None None None
TLSv1
192.168.56.101:49305
193.70.47.128:443
C=US, O=Let's Encrypt, CN=R3 CN=soloyama.com 2c:79:5b:29:8f:93:e2:61:60:7f:ba:5e:de:b3:cb:de:24:ef:0b:f2
TLS 1.3
192.168.56.101:49317
8.8.8.8:443
None None None
TLS 1.3
192.168.56.101:49308
65.8.17.57:443
None None None
TLS 1.3
192.168.56.101:49318
8.8.4.4:443
None None None
TLS 1.3
192.168.56.101:49319
142.250.196.131:443
None None None
TLS 1.3
192.168.56.101:49322
13.225.134.82:443
None None None
TLS 1.3
192.168.56.101:49321
172.217.161.65:443
None None None
TLS 1.3
192.168.56.101:49324
172.217.26.35:443
None None None
TLS 1.2
192.168.56.101:49310
35.83.118.206:443
C=US, O=Amazon, OU=Server CA 1B, CN=Amazon CN=mywot.com ae:ee:12:ae:1a:81:d0:1b:e1:c1:0a:da:d9:0c:33:ce:20:b1:e9:50
TLS 1.2
192.168.56.101:49311
52.54.193.222:443
C=US, O=Amazon, OU=Server CA 1B, CN=Amazon CN=mywot.com 7b:68:a6:5e:ec:e3:81:e6:28:1c:8e:a7:a2:95:28:21:86:b1:ec:df
TLS 1.2
192.168.56.101:49315
172.67.223.135:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com 58:02:7f:64:99:8c:33:d7:44:80:ce:b8:4a:40:da:1b:4a:2d:a5:52
TLS 1.3
192.168.56.101:49323
13.225.134.82:443
None None None
TLS 1.3
192.168.56.101:49302
216.58.200.78:443
None None None
TLS 1.3
192.168.56.101:49320
172.217.26.35:443
None None None
TLS 1.3
192.168.56.101:49325
172.217.31.131:443
None None None
UNDETERMINED
192.168.56.101:49309
35.83.118.206:443
None None None

Snort Alerts

No Snort Alerts