NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.155.92.58 Active Moloch
103.155.93.196 Active Moloch
104.244.42.1 Active Moloch
111.90.146.149 Active Moloch
144.202.76.47 Active Moloch
149.154.167.99 Active Moloch
162.0.210.44 Active Moloch
162.0.214.42 Active Moloch
162.159.135.233 Active Moloch
164.124.101.2 Active Moloch
172.67.176.198 Active Moloch
186.2.171.3 Active Moloch
188.225.87.175 Active Moloch
194.145.227.159 Active Moloch
2.56.59.42 Active Moloch
34.117.59.81 Active Moloch
37.0.8.119 Active Moloch
37.140.192.230 Active Moloch
45.133.1.107 Active Moloch
45.133.1.182 Active Moloch
52.216.26.67 Active Moloch
52.95.170.52 Active Moloch
77.88.55.60 Active Moloch
88.99.66.31 Active Moloch
92.61.46.213 Active Moloch
94.142.140.35 Active Moloch

GET 200 https://yandex.ru/
REQUEST
RESPONSE
GET 200 https://ipinfo.io/widget
REQUEST
RESPONSE
GET 200 https://cdn.discordapp.com/attachments/882087629896691744/894083102190764052/Cube_WW14.bmp
REQUEST
RESPONSE
GET 200 https://cdn.discordapp.com/attachments/891021838312931420/895238855698051082/PL_Client.bmp
REQUEST
RESPONSE
GET 200 https://ipinfo.io/widget
REQUEST
RESPONSE
GET 200 https://cdn.discordapp.com/attachments/882087629896691744/890166075864543242/installer_2021-09-21_16-31.bmp
REQUEST
RESPONSE
GET 200 https://cdn.discordapp.com/attachments/882087629896691744/890166081547825162/LivelyScreenRecLy2109.bmp
REQUEST
RESPONSE
GET 200 https://dc-repository.com/sfx_123_207.exe
REQUEST
RESPONSE
GET 200 https://www.listincode.com/
REQUEST
RESPONSE
GET 200 https://iplogger.org/14Jup7
REQUEST
RESPONSE
GET 200 https://publishersharef.s3.eu-north-1.amazonaws.com/Sharefolder.exe
REQUEST
RESPONSE
POST 100 https://connectini.net/Series/SuperNitou.php
REQUEST
RESPONSE
GET 200 http://45.133.1.182/proxies.txt
REQUEST
RESPONSE
POST 200 http://37.0.8.119/service/communication.php
REQUEST
RESPONSE
POST 200 http://37.0.8.119/service/communication.php
REQUEST
RESPONSE
GET 200 http://45.133.1.182/proxies.txt
REQUEST
RESPONSE
GET 200 http://37.0.8.119/base/api/statistics.php
REQUEST
RESPONSE
POST 200 http://37.0.8.119/base/api/getData.php
REQUEST
RESPONSE
POST 200 http://37.0.8.119/base/api/getData.php
REQUEST
RESPONSE
HEAD 200 http://45.133.1.107/download/NiceProcessX64.bmp
REQUEST
RESPONSE
GET 200 http://45.133.1.107/download/NiceProcessX64.bmp
REQUEST
RESPONSE
POST 200 http://37.0.8.119/base/api/getData.php
REQUEST
RESPONSE
HEAD 200 http://194.145.227.159/pub.php?pub=two
REQUEST
RESPONSE
HEAD 200 http://threesmallhills.com/pub3.exe
REQUEST
RESPONSE
HEAD 302 http://www.nqhobby.com/askhelp58/askinstall58.exe
REQUEST
RESPONSE
HEAD 200 http://ukcom.pw/adsli/md7_7dfj.exe
REQUEST
RESPONSE
HEAD 200 http://install-cb.ru/CalcCryptoInstalww.exe
REQUEST
RESPONSE
GET 200 http://threesmallhills.com/pub3.exe
REQUEST
RESPONSE
GET 200 http://ukcom.pw/adsli/md7_7dfj.exe
REQUEST
RESPONSE
GET 200 http://194.145.227.159/pub.php?pub=two
REQUEST
RESPONSE
HEAD 200 http://www.nqhobby.com/askinstall58.exe
REQUEST
RESPONSE
GET 200 http://install-cb.ru/CalcCryptoInstalww.exe
REQUEST
RESPONSE
GET 302 http://www.nqhobby.com/askhelp58/askinstall58.exe
REQUEST
RESPONSE
GET 200 http://www.nqhobby.com/askinstall58.exe
REQUEST
RESPONSE
GET 200 http://186.2.171.3/seemorebty/il.php?e=CsOtXVBhUjDrvtRgizng8F7v
REQUEST
RESPONSE
GET 200 http://www.iyiqian.com/
REQUEST
RESPONSE
POST 200 http://www.cjnovone.top/Home/Index/lkdinl
REQUEST
RESPONSE
HEAD 200 http://safialinks.com/Installer_Provider/ShareFolder.exe
REQUEST
RESPONSE
GET 200 http://safialinks.com/Installer_Provider/ShareFolder.exe
REQUEST
RESPONSE
POST 200 http://37.0.8.119/base/api/getData.php
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://safialinks.com/Widgets/FolderShare.exe
REQUEST
RESPONSE
GET 200 http://safialinks.com/xJRtjaHLw25uhP75sj4j5SDQa3dAyG/BestCPM/Soft_Manager_Cpm.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 149.154.167.99:443 -> 192.168.56.101:49199 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49204 -> 77.88.55.60:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49198 -> 149.154.167.99:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49202 -> 104.244.42.1:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49211 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49209 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49209 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49208 -> 34.117.59.81:443 2025331 ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) Device Retrieving External IP Address Detected
TCP 192.168.56.101:49208 -> 34.117.59.81:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49210 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 34.117.59.81:443 -> 192.168.56.101:49208 2025330 ET POLICY Possible External IP Lookup SSL Cert Observed (ipinfo.io) Device Retrieving External IP Address Detected
TCP 192.168.56.101:49210 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49213 -> 162.159.135.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49219 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49219 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49223 -> 162.159.135.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49237 -> 162.159.135.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49234 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49238 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49238 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49235 -> 172.67.176.198:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49235 -> 172.67.176.198:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49243 -> 172.67.176.198:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 172.67.176.198:80 -> 192.168.56.101:49243 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49220 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49220 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49242 -> 94.142.140.35:80 2019714 ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile Potentially Bad Traffic
TCP 45.133.1.107:80 -> 192.168.56.101:49226 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 45.133.1.107:80 -> 192.168.56.101:49226 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 192.168.56.101:49259 -> 92.61.46.213:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49259 -> 92.61.46.213:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49245 -> 172.67.176.198:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49250 -> 172.67.176.198:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49262 -> 92.61.46.213:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49221 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49225 -> 34.117.59.81:443 2025331 ET POLICY Possible External IP Lookup Domain Observed in SNI (ipinfo. io) Device Retrieving External IP Address Detected
TCP 192.168.56.101:49231 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49231 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49225 -> 34.117.59.81:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 34.117.59.81:443 -> 192.168.56.101:49225 2025330 ET POLICY Possible External IP Lookup SSL Cert Observed (ipinfo.io) Device Retrieving External IP Address Detected
TCP 192.168.56.101:49233 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49233 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.101:62902 -> 164.124.101.2:53 2016778 ET DNS Query to a *.pw domain - Likely Hostile Potentially Bad Traffic
TCP 192.168.56.101:49239 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49232 -> 162.159.135.233:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49232 -> 162.159.135.233:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49241 -> 162.159.135.233:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49268 -> 92.61.46.213:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49246 -> 111.90.146.149:80 2022896 ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 A Network Trojan was detected
TCP 192.168.56.101:49246 -> 111.90.146.149:80 2016777 ET INFO HTTP Request to a *.pw domain Potentially Bad Traffic
TCP 192.168.56.101:49246 -> 111.90.146.149:80 2022896 ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 A Network Trojan was detected
TCP 192.168.56.101:49246 -> 111.90.146.149:80 2016777 ET INFO HTTP Request to a *.pw domain Potentially Bad Traffic
TCP 192.168.56.101:49254 -> 92.61.46.213:80 2260000 SURICATA Applayer Mismatch protocol both directions Generic Protocol Command Decode
TCP 192.168.56.101:49254 -> 92.61.46.213:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 111.90.146.149:80 -> 192.168.56.101:49246 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 103.155.93.196:80 -> 192.168.56.101:49244 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.168.56.101:49253 -> 94.142.140.35:80 2019714 ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile Potentially Bad Traffic
TCP 94.142.140.35:80 -> 192.168.56.101:49253 2014819 ET INFO Packed Executable Download Misc activity
TCP 94.142.140.35:80 -> 192.168.56.101:49253 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.168.56.101:49280 -> 144.202.76.47:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 194.145.227.159:80 -> 192.168.56.101:49230 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 194.145.227.159:80 -> 192.168.56.101:49230 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 194.145.227.159:80 -> 192.168.56.101:49230 2014520 ET INFO EXE - Served Attached HTTP Misc activity
TCP 37.140.192.230:80 -> 192.168.56.101:49249 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.168.56.101:49286 -> 88.99.66.31:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49248 -> 52.95.170.52:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49272 -> 92.61.46.213:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 92.61.46.213:443 -> 192.168.56.101:49273 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
UDP 192.168.56.101:55667 -> 164.124.101.2:53 2023883 ET DNS Query to a *.top domain - Likely Hostile Potentially Bad Traffic
TCP 192.168.56.101:49311 -> 52.95.170.52:80 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49315 -> 188.225.87.175:80 2023882 ET INFO HTTP Request to a *.top domain Potentially Bad Traffic
TCP 192.168.56.101:49356 -> 52.95.170.52:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 162.0.214.42:80 -> 192.168.56.101:49359 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.168.56.101:49363 -> 88.99.66.31:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49361 -> 162.0.210.44:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 162.0.214.42:80 -> 192.168.56.101:49365 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 162.0.214.42:80 -> 192.168.56.101:49365 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic
TCP 162.0.214.42:80 -> 192.168.56.101:49365 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49204
77.88.55.60:443
C=RU, O=Yandex LLC, OU=Yandex Certification Authority, CN=Yandex CA C=RU, L=Moscow, OU=ITO, O=Yandex LLC, CN=*.yandex.az 2b:13:52:0c:b0:c6:8c:c9:e3:05:6e:11:91:74:4d:65:ce:3a:64:29
TLSv1
192.168.56.101:49208
34.117.59.81:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1D4 CN=ipinfo.io 9b:8a:7e:73:93:70:47:e8:1f:ef:b1:b9:f4:52:8b:2f:90:2c:85:2e
TLSv1
192.168.56.101:49213
162.159.135.233:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da
TLSv1
192.168.56.101:49223
162.159.135.233:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da
TLSv1
192.168.56.101:49237
162.159.135.233:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da
TLSv1
192.168.56.101:49250
172.67.176.198:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com f2:26:d9:07:c7:f6:18:ff:8c:b8:6c:92:e9:50:57:e4:a9:94:e5:0d
TLSv1
192.168.56.101:49225
34.117.59.81:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1D4 CN=ipinfo.io 9b:8a:7e:73:93:70:47:e8:1f:ef:b1:b9:f4:52:8b:2f:90:2c:85:2e
TLSv1
192.168.56.101:49241
162.159.135.233:443
None None None
TLSv1
192.168.56.101:49280
144.202.76.47:443
C=CN, O=TrustAsia Technologies, Inc., OU=Domain Validated SSL, CN=TrustAsia TLS RSA CA CN=listincode.com 84:23:95:42:66:09:11:39:0d:e6:22:7f:eb:b3:cc:79:dd:fa:36:ed
TLSv1
192.168.56.101:49286
88.99.66.31:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA CN=*.iplogger.org 55:1e:13:99:46:1c:67:40:a3:48:7f:38:0d:16:e7:51:f4:c4:43:cb
TLSv1
192.168.56.101:49356
52.95.170.52:443
C=US, O=Amazon, OU=Server CA 1B, CN=Amazon CN=*.s3.eu-north-1.amazonaws.com b3:55:b1:8b:e1:54:cd:a4:5a:94:dc:0f:a1:9a:da:9d:74:3e:22:d7
TLSv1
192.168.56.101:49361
162.0.210.44:443
C=CH, L=Schaffhausen, O=Plesk, CN=Plesk/emailAddress=info@plesk.com C=CH, L=Schaffhausen, O=Plesk, CN=Plesk/emailAddress=info@plesk.com 68:49:fa:d2:40:0d:bd:3f:c0:6e:bf:50:6f:a8:1c:a3:3e:f4:40:cf
TLSv1
192.168.56.101:49363
88.99.66.31:443
C=US, O=Let's Encrypt, CN=R3 CN=iplogger.com 01:03:e9:82:3a:f4:6d:5a:7f:e9:29:26:08:3c:f4:61:a7:b2:88:bb

Snort Alerts

No Snort Alerts