NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.100.211.218 Active Moloch
154.221.31.191 Active Moloch
157.240.31.35 Active Moloch
164.124.101.2 Active Moloch
GET 302 https://www.facebook.com/ads/manager/account_settings/account_billing
REQUEST
RESPONSE
GET 200 https://www.facebook.com/login.php?next=https%3A%2F%2Fwww.facebook.com%2Fads%2Fmanager%2Faccount_settings%2Faccount_billing
REQUEST
RESPONSE
GET 200 http://bz.bbbeioaag.com/sts/cimage.jpg
REQUEST
RESPONSE
GET 200 http://count.iiagjaggg.com/check/safe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49165 -> 154.221.31.191:80 2003626 ET HUNTING Double User-Agent (User-Agent User-Agent) Potentially Bad Traffic
TCP 192.168.56.101:49164 -> 157.240.31.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49164
157.240.31.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com f4:81:be:d8:fb:b5:af:14:40:10:62:49:8d:5d:b8:26:b6:47:f1:65

Snort Alerts

No Snort Alerts