NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
157.240.215.14 Active Moloch
157.240.215.35 Active Moloch
164.124.101.2 Active Moloch
GET 200 https://www.facebook.com/recover/initiate/?ldata=AWdu9jOm_Vz9oxOyhcWwMT2sAbKJiix516xWvQ4nCxFV1S37siY3l3C6S3u4xp-ztme4ivBgdnsyWh9jVQyB5w4KqwpqCyrmf8PDliykkZ5tePO9XNgJoRexoC3Ux8seM3jcdm2gAR4E-JVJCU4MlYZ0ku5pkQ6e_COFE6k8BEMgzy8QIaNicxWpg5S6WGS50j5WBeDImWd6dBo12z5gW4MSVVFColbWx1xyDdVmG6kYG8YXmOnjOEzzUfTI-TBF9wRufqc-LFgmNiuR7Yo6Zl23
REQUEST
RESPONSE
GET 302 https://m.facebook.com/recover/initiate/?ldata=AWdu9jOm_Vz9oxOyhcWwMT2sAbKJiix516xWvQ4nCxFV1S37siY3l3C6S3u4xp-ztme4ivBgdnsyWh9jVQyB5w4KqwpqCyrmf8PDliykkZ5tePO9XNgJoRexoC3Ux8seM3jcdm2gAR4E-JVJCU4MlYZ0ku5pkQ6e_COFE6k8BEMgzy8QIaNicxWpg5S6WGS50j5WBeDImWd6dBo12z5gW4MSVVFColbWx1xyDdVmG6kYG8YXmOnjOEzzUfTI-TBF9wRufqc-LFgmNiuR7Yo6Zl23&_rdr
REQUEST
RESPONSE
GET 200 https://m.facebook.com/login/identify/?ctx=recover&c&multiple_results=0&from_login_screen=0&_rdr
REQUEST
RESPONSE
GET 200 https://static.xx.fbcdn.net/rsrc.php/v3/y8/r/k97pj8-or6s.png
REQUEST
RESPONSE
GET 302 https://facebook.com/security/hsts-pixel.gif?c=3.2
REQUEST
RESPONSE
GET 200 https://static.xx.fbcdn.net/rsrc.php/v3/y0/r/2xs6jaqwoaL.png
REQUEST
RESPONSE
GET 302 https://fbcdn.net/security/hsts-pixel.gif?c=2
REQUEST
RESPONSE
GET 200 https://fbsbx.com/security/hsts-pixel.gif
REQUEST
RESPONSE
GET 200 https://m.facebook.com/favicon.ico
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49164 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49168 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49165 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49169 -> 157.240.215.14:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49174 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49176 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49170 -> 157.240.215.14:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49171 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49173 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49172 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49177 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49183 -> 117.18.232.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49182 -> 117.18.232.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 117.18.232.200:443 -> 192.168.56.101:49184 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49164
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49167
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49168
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49165
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49169
157.240.215.14:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49174
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 27:b9:dd:09:c9:07:f5:90:c6:42:fd:67:ef:4f:93:65:15:d0:00:66
TLSv1
192.168.56.101:49176
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 27:b9:dd:09:c9:07:f5:90:c6:42:fd:67:ef:4f:93:65:15:d0:00:66
TLSv1
192.168.56.101:49170
157.240.215.14:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49173
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 27:b9:dd:09:c9:07:f5:90:c6:42:fd:67:ef:4f:93:65:15:d0:00:66
TLSv1
192.168.56.101:49172
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d
TLSv1
192.168.56.101:49177
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 27:b9:dd:09:c9:07:f5:90:c6:42:fd:67:ef:4f:93:65:15:d0:00:66
TLSv1
192.168.56.101:49171
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 66:13:03:69:73:73:d5:87:c7:75:a5:bf:ed:6b:03:e2:9c:98:26:1d

Snort Alerts

No Snort Alerts