NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
168.119.93.163 Active Moloch
Name Response Post-Analysis Lookup
pastebin.pl 168.119.93.163
GET 200 https://pastebin.pl/view/raw/ae498e11
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49164 -> 168.119.93.163:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.102:49164
168.119.93.163:443
C=US, O=Let's Encrypt, CN=R3 CN=www.pastebin.pl ff:45:61:83:ce:77:e8:60:14:12:ec:bd:a7:7e:6b:36:46:f6:56:06

Snort Alerts

No Snort Alerts