NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.250.66.105 Active Moloch
142.250.66.129 Active Moloch
164.124.101.2 Active Moloch
172.217.31.233 Active Moloch
67.199.248.14 Active Moloch
GET 200 https://kyahogysammajhnailagrahiat1.blogspot.com/p/og1-1.html
REQUEST
RESPONSE
GET 200 https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
REQUEST
RESPONSE
GET 200 https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js
REQUEST
RESPONSE
GET 200 https://www.blogger.com/dyn-css/authorization.css?targetBlogID=8965474558532949541&zx=c284ae92-b0d2-4f96-8852-ffc3b557f602
REQUEST
RESPONSE
GET 200 https://www.blogger.com/static/v1/jsbin/186635561-comment_from_post_iframe.js
REQUEST
RESPONSE
GET 200 https://www.blogger.com/static/v1/widgets/963277127-widgets.js
REQUEST
RESPONSE
GET 200 https://resources.blogblog.com/img/icon18_edit_allbkg.gif
REQUEST
RESPONSE
GET 200 https://resources.blogblog.com/blogblog/data/1kt/simple/body_gradient_tile_light.png
REQUEST
RESPONSE
GET 200 https://www.blogger.com/img/share_buttons_20_3.png
REQUEST
RESPONSE
GET 200 https://resources.blogblog.com/blogblog/data/1kt/simple/gradients_light.png
REQUEST
RESPONSE
GET 301 http://bitly.com/qtyiwedhjkabdhsagbdhnsavbd
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49174 -> 142.250.66.129:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49175 -> 142.250.66.105:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49181 -> 172.217.31.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49176 -> 142.250.66.105:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49177 -> 172.217.31.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49174
142.250.66.129:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=misc-sni.blogspot.com fc:db:2e:5e:8f:df:23:25:9a:03:2f:a3:eb:58:73:23:f5:30:86:76
TLSv1
192.168.56.103:49175
142.250.66.105:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b
TLSv1
192.168.56.103:49181
172.217.31.233:443
None None None
TLSv1
192.168.56.103:49176
142.250.66.105:443
None None None
TLSv1
192.168.56.103:49177
172.217.31.233:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b

Snort Alerts

No Snort Alerts