NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.45.140.175 Active Moloch
164.124.101.2 Active Moloch
82.146.63.123 Active Moloch
Name Response Post-Analysis Lookup
moon-bot.org 82.146.63.123
GET 200 https://moon-bot.org/secret/verb.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49202 -> 82.146.63.123:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49202
82.146.63.123:443
C=US, O=Let's Encrypt, CN=R3 CN=moon-bot.org 08:67:8f:a9:e8:8b:88:18:60:5a:bb:f6:64:a6:6e:3a:75:86:0f:4b

Snort Alerts

No Snort Alerts