NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.250.199.78 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
drive.google.com 142.250.76.142
GET 0 https://drive.google.com/uc?export=download&id=1Ovbe1se3Rh9WH1LYT1ob1ngpdtjJW1yF&confirm=t
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49175 -> 142.250.199.78:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49175
142.250.199.78:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.google.com 08:73:2c:18:30:14:52:c3:ca:3e:02:79:65:b4:fe:90:ac:3f:3e:33

Snort Alerts

No Snort Alerts