NetWork | ZeroBOX

Network Analysis

IP Address Status Action
111.90.156.84 Active Moloch
164.124.101.2 Active Moloch
185.239.243.112 Active Moloch
208.95.112.1 Active Moloch
34.117.59.81 Active Moloch
GET 200 https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sb=1
REQUEST
RESPONSE
GET 200 https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sb=1
REQUEST
RESPONSE
GET 200 https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm&sd=1
REQUEST
RESPONSE
GET 200 https://whatsmyipaddress.biz/?address=6dd8da1fb15460cf6fd20f30217fcc4d9b15c671&format=92&type=235dOXMm
REQUEST
RESPONSE
GET 200 http://ip-api.com/line/?fields=hosting
REQUEST
RESPONSE
GET 200 http://ifconfig.me/ip
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49175 -> 208.95.112.1:80 2022082 ET POLICY External IP Lookup ip-api.com Device Retrieving External IP Address Detected
UDP 192.168.56.102:52336 -> 164.124.101.2:53 2027863 ET INFO Observed DNS Query to .biz TLD Potentially Bad Traffic
TCP 192.168.56.102:49171 -> 111.90.156.84:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 185.239.243.112:21 -> 192.168.56.102:49183 2260002 SURICATA Applayer Detect protocol only one direction Generic Protocol Command Decode
TCP 192.168.56.102:49169 -> 111.90.156.84:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49176 -> 111.90.156.84:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49181 -> 34.117.59.81:80 2026718 ET POLICY External IP Lookup Domain (ifconfig .me) Device Retrieving External IP Address Detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.102:49171
111.90.156.84:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=whatsmyipaddress.biz dd:ea:81:1d:37:20:c7:42:33:a9:63:10:94:3c:5f:4f:bd:6e:5c:c3
TLS 1.2
192.168.56.102:49169
111.90.156.84:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=whatsmyipaddress.biz dd:ea:81:1d:37:20:c7:42:33:a9:63:10:94:3c:5f:4f:bd:6e:5c:c3
TLS 1.2
192.168.56.102:49176
111.90.156.84:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=whatsmyipaddress.biz dd:ea:81:1d:37:20:c7:42:33:a9:63:10:94:3c:5f:4f:bd:6e:5c:c3

Snort Alerts

No Snort Alerts