NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.207.254.70 Active Moloch
121.254.136.57 Active Moloch
145.14.144.197 Active Moloch
145.14.145.163 Active Moloch
164.124.101.2 Active Moloch
192.124.249.111 Active Moloch
199.79.53.17 Active Moloch
GET 410 https://royalinteriorsdesign.000webhostapp.com/wp-admin/hkgyeqNXL/
REQUEST
RESPONSE
GET 404 http://meeting.nmconline.org/wp-content/pgynuy3gyq-qib01-12349/
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.102:51405 -> 164.124.101.2:53 2026657 ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) Not Suspicious Traffic
TCP 192.168.56.102:49174 -> 192.124.249.111:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.102:53778 -> 164.124.101.2:53 2026657 ET INFO Observed Free Hosting Domain (*.000webhostapp .com in DNS Lookup) Not Suspicious Traffic
UDP 192.168.56.102:65226 -> 164.124.101.2:53 2027871 ET INFO Observed DNS Query to .fit TLD Potentially Bad Traffic
TCP 192.168.56.102:49169 -> 199.79.53.17:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49173 -> 145.14.145.163:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 145.14.145.163:443 -> 192.168.56.102:49173 2026658 ET INFO Observed SSL Cert for Free Hosting Domain (*.000webhostapp .com) Not Suspicious Traffic
TCP 192.168.56.102:49175 -> 192.124.249.111:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49169
199.79.53.17:443
C=US, O=Let's Encrypt, CN=R3 CN=honeybearlane.com 48:61:d5:23:5c:0c:49:87:79:74:43:59:31:f7:ee:ee:0f:01:b8:e0
TLSv1
192.168.56.102:49173
145.14.145.163:443
C=US, O=DigiCert, Inc., CN=RapidSSL Global TLS RSA4096 SHA256 2022 CA1 CN=*.000webhostapp.com 92:99:1e:ec:b2:e4:c2:e2:e3:d4:05:9d:5a:31:cb:db:3e:69:12:5c

Snort Alerts

No Snort Alerts