NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.250.207.67 Active Moloch
142.250.66.78 Active Moloch
142.251.220.99 Active Moloch
162.0.217.30 Active Moloch
164.124.101.2 Active Moloch
172.217.24.100 Active Moloch
172.217.24.74 Active Moloch
172.217.25.3 Active Moloch
172.217.27.13 Active Moloch
34.104.35.123 Active Moloch
HEAD 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
GET 206 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
GET 206 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
GET 206 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
GET 206 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
GET 206 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jewvegtcs2qdew3nlzz4kvsjqm_9.44.0/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.44.0_all_pywouuhjzu3khiqqvvfs2jt53q.crx3
REQUEST
RESPONSE
HEAD 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/cxpsjblnoxgjoqggdsbvujtof4_58/khaoiebndkojlmppeemjhbpbandiljpe_58_win_advr4ucepztwtigvw3fduftsvbeq.crx3
REQUEST
RESPONSE
GET 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/cxpsjblnoxgjoqggdsbvujtof4_58/khaoiebndkojlmppeemjhbpbandiljpe_58_win_advr4ucepztwtigvw3fduftsvbeq.crx3
REQUEST
RESPONSE
HEAD 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/g6v7tvx6ixuzstk5etcqebphhq_7954/hfnkpimlhhgieaddgfemjhofmfblmnib_7954_all_adj2i674lrtcwrqqfhv37vujcaya.crx3
REQUEST
RESPONSE
GET 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/g6v7tvx6ixuzstk5etcqebphhq_7954/hfnkpimlhhgieaddgfemjhofmfblmnib_7954_all_adj2i674lrtcwrqqfhv37vujcaya.crx3
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49167 -> 162.0.217.30:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49171 -> 162.0.217.30:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49169 -> 162.0.217.30:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49170 -> 162.0.217.30:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 162.0.217.30:443 -> 192.168.56.102:49172 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.102:49173 -> 162.0.217.30:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49166 -> 162.0.217.30:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.102:49192
172.217.27.13:443
None None None
TLS 1.3
192.168.56.102:49193
172.217.24.100:443
None None None
TLS 1.3
192.168.56.102:49196
172.217.24.74:443
None None None
TLS 1.3
192.168.56.102:49198
172.217.25.3:443
None None None
TLS 1.3
192.168.56.102:49197
172.217.25.3:443
None None None
TLS 1.3
192.168.56.102:49200
142.250.207.67:443
None None None
TLS 1.3
192.168.56.102:49191
142.251.220.99:443
None None None
TLS 1.3
192.168.56.102:49201
142.250.66.78:443
None None None
TLS 1.3
192.168.56.102:49194
172.217.24.100:443
None None None
TLS 1.3
192.168.56.102:49214
142.251.220.99:443
None None None
TLS 1.3
192.168.56.102:49204
162.0.217.30:443
None None None
TLS 1.3
192.168.56.102:49205
162.0.217.30:443
None None None
TLS 1.3
192.168.56.102:49241
172.217.25.3:443
None None None
TLS 1.3
192.168.56.102:49242
216.58.203.67:443
None None None
UNDETERMINED
192.168.56.102:49199
172.217.25.3:443
None None None

Snort Alerts

No Snort Alerts