NetWork | ZeroBOX

Network Analysis

IP Address Status Action
119.161.15.251 Active Moloch
119.161.16.11 Active Moloch
164.124.101.2 Active Moloch
GET 307 https://dl-mail.ymail.com/ws/download/mailboxes/@.id==VjN-JPTkH0IKMOeQ4l_fsOCI0QATxLNRGTv3aIkYarV_TKFLYcXIdqvvnC4LaQc8ks-_jONYRiG2iGqGRvuP2lTXQg/messages/@.id==ANk1W0gqsg07ZElmNwBCaGHMBoo/content/parts/@.id==1/raw?appid=YMailNorrin&ymreqid=6053e7f5-407c-91aa-1ce7-e4002b013800&token=uDdRaaIpkxJyV0akyTfVtC7n1FhmsdJB7bDv_XH6K6bCQOXFxgkBkwEAZNsu-_QFvV_5i5_L4E4NWtq013TBfcZCGX32myhohFrRcQRPMX0YejtWOpAjLBddP6PWGYs9&error=https%3A%2F%2Fmail.yahoo.com%2Fd%2Fiframemsg%3Fid%3Ddownload-3341020975
REQUEST
RESPONSE
GET 401 https://apis.mail.yahoo.com/ws/v3/mailboxes/@.id==VjN-JPTkH0IKMOeQ4l_fsOCI0QATxLNRGTv3aIkYarV_TKFLYcXIdqvvnC4LaQc8ks-_jONYRiG2iGqGRvuP2lTXQg/messages/@.id==ANk1W0gqsg07ZElmNwBCaGHMBoo/content/parts/@.id==1/refresh?appid=YMailNorrin&ymreqid=6053e7f5-407c-91aa-1ce7-e4002b013800&error=https%3A%2F%2Fmail.yahoo.com%2Fd%2Fiframemsg%3Fid%3Ddownload-3341020975
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49165 -> 119.161.15.251:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 119.161.16.11:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49164 -> 119.161.15.251:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49166 -> 119.161.16.11:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49166
119.161.16.11:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Sunnyvale, O=Oath Holdings Inc., CN=*.api.fantasysports.yahoo.com 6e:2f:30:b9:a3:fc:58:90:e8:a6:e6:0f:b5:08:0e:63:1d:59:94:f0
TLSv1
192.168.56.101:49167
119.161.16.11:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Sunnyvale, O=Oath Holdings Inc., CN=*.api.fantasysports.yahoo.com 6e:2f:30:b9:a3:fc:58:90:e8:a6:e6:0f:b5:08:0e:63:1d:59:94:f0
TLSv1
192.168.56.101:49165
119.161.15.251:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Sunnyvale, O=Oath Holdings Inc., CN=*.api.fantasysports.yahoo.com 6e:2f:30:b9:a3:fc:58:90:e8:a6:e6:0f:b5:08:0e:63:1d:59:94:f0
TLSv1
192.168.56.101:49164
119.161.15.251:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Sunnyvale, O=Oath Holdings Inc., CN=*.api.fantasysports.yahoo.com 6e:2f:30:b9:a3:fc:58:90:e8:a6:e6:0f:b5:08:0e:63:1d:59:94:f0

Snort Alerts

No Snort Alerts