NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
164.124.101.2 Active Moloch
44.238.138.209 Active Moloch
GET 200 https://linksharing.samsungcloud.com/cuTdhqX2XLpd
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/css/layout.css?ver=21012103
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/jquery/jquery-2.2.0.min.js
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/common/moment.min.js
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/jquery/jquery.numeric.min.js
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/app/sharelink.js?ver=21042209
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/common/handlebars.min-latest.js
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/common/handlebars.helper.js
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/common/remoteshare.prototype.js?ver=20061701
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/js/app/remoteshare.js?ver=20070601
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/images/share_link.png
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/images/category/category_ic_apk.png
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/images/Samsung_Orig_Wordmark_BLACK_RGB.png
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/images/share_link_32.png
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/images/category/category_ic_broken.png
REQUEST
RESPONSE
GET 200 https://linksharing.samsungcloud.com/resources/images/loadingbar.gif
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49164 -> 44.238.138.209:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 44.238.138.209:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49176 -> 117.18.232.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49169 -> 44.238.138.209:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 117.18.232.200:443 -> 192.168.56.101:49178 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49168 -> 44.238.138.209:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49170 -> 44.238.138.209:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49177 -> 117.18.232.200:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49165 -> 44.238.138.209:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49167
44.238.138.209:443
None None None
TLSv1
192.168.56.101:49164
44.238.138.209:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA C=KR, unknown=16677, ST=Gyeonggi-do, L=Suwon-si, unknown=Yeongtong-gu, unknown=129, Samsung-ro, Yeongtong-gu, O=Samsung Electronics Co., Ltd., OU=Cloud Operation Group, CN=*.samsungcloud.com e0:9f:8e:31:31:3d:6e:12:30:05:bd:a7:49:16:3f:02:0b:cc:db:8c
TLSv1
192.168.56.101:49169
44.238.138.209:443
None None None
TLSv1
192.168.56.101:49168
44.238.138.209:443
None None None
TLSv1
192.168.56.101:49170
44.238.138.209:443
None None None
TLSv1
192.168.56.101:49165
44.238.138.209:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Organization Validation Secure Server CA C=KR, unknown=16677, ST=Gyeonggi-do, L=Suwon-si, unknown=Yeongtong-gu, unknown=129, Samsung-ro, Yeongtong-gu, O=Samsung Electronics Co., Ltd., OU=Cloud Operation Group, CN=*.samsungcloud.com e0:9f:8e:31:31:3d:6e:12:30:05:bd:a7:49:16:3f:02:0b:cc:db:8c

Snort Alerts

No Snort Alerts