NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
179.43.173.14 Active Moloch
185.225.19.137 Active Moloch
Name Response Post-Analysis Lookup
netcbin.info 185.225.19.137
GET 200 https://netcbin.info/August_lpIeHgg240.bin
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49201 -> 185.225.19.137:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49201
185.225.19.137:443
C=US, O=Let's Encrypt, CN=R3 CN=netcbin.info f8:ef:c3:29:e4:d9:fa:4c:a8:cb:c3:59:87:ba:69:5e:05:39:12:a5

Snort Alerts

No Snort Alerts