NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
168.119.93.163 Active Moloch
Name Response Post-Analysis Lookup
pastebin.pl 168.119.93.163
GET 200 https://pastebin.pl/view/raw/af4dd2e8
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49163 -> 168.119.93.163:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.102:49163
168.119.93.163:443
C=US, O=Let's Encrypt, CN=R3 CN=www.pastebin.pl ac:45:0d:b9:ff:83:11:c8:c5:12:c5:2f:cd:cb:f0:77:cd:f9:9f:3e

Snort Alerts

No Snort Alerts