NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
142.250.204.73 Active Moloch
142.250.66.73 Active Moloch
164.124.101.2 Active Moloch
GET 200 https://www.blogger.com/static/v1/widgets/1667664774-css_bundle_v2.css
REQUEST
RESPONSE
GET 0 https://www.blogger.com/static/v1/jsbin/403901366-ieretrofit.js
REQUEST
RESPONSE
GET 200 https://www.blogger.com/dyn-css/authorization.css?targetBlogID=4561046081807244140&zx=31f586bd-8086-4cb5-94f1-2fdafcdbee5c
REQUEST
RESPONSE
GET 0 https://www.blogger.com/static/v1/widgets/807375071-widgets.js
REQUEST
RESPONSE
GET 200 https://resources.blogblog.com/blogblog/data/1kt/simple/gradients_light.png
REQUEST
RESPONSE
GET 200 https://resources.blogblog.com/blogblog/data/1kt/simple/body_gradient_tile_light.png
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49167 -> 142.250.204.73:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49166 -> 142.250.204.73:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49178 -> 117.18.232.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49170 -> 142.250.66.73:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49171 -> 142.250.66.73:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49172 -> 142.250.66.73:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49177 -> 117.18.232.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 117.18.232.200:443 -> 192.168.56.102:49179 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49167
142.250.204.73:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b
TLSv1
192.168.56.102:49166
142.250.204.73:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b
TLSv1
192.168.56.102:49170
142.250.66.73:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b
TLSv1
192.168.56.102:49171
142.250.66.73:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b
TLSv1
192.168.56.102:49172
142.250.66.73:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.blogger.com 76:d9:ed:9a:97:01:f9:eb:d2:fb:79:86:c4:64:4f:02:1a:32:16:3b

Snort Alerts

No Snort Alerts