NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
142.250.204.109 Active Moloch
142.250.66.35 Active Moloch
142.251.220.100 Active Moloch
164.124.101.2 Active Moloch
172.217.24.67 Active Moloch
GET 200 https://accounts.google.com/v3/signin/rejected?continue=https://maps.google.com/maps/timeline?hl%3Den_US&dsh=S-200849221:1685261298961203&flowEntry=ServiceLogin&flowName=GlifWebSignIn&hl=en_US&ifkv=Af_xneFIIJtTRe58HPGFsWTtfrakqcje0cZ-433jdEP0BKZL7UPra1y0wP_zfCKeCiJgl8SSqbPJOQ&rhlk=js&rrk=47
REQUEST
RESPONSE
GET 200 https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.FB9bt3Boo_A.es5.O/am=BznH4QM_CP-pzj_jk8MAAAAAAAAAAAALw06C/d=1/excm=_b,_r,_tp,rejectedview/ed=1/dg=0/wt=2/ujg=1/rs=AOaEmlF50LTc6xdo-R2TtLbFrnb79VTY7A/m=_b,_tp,_r
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/roboto/v18/KFOmCnqEu92Fr1Mu4mxM.woff
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmEU9fBBc-.woff
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmSU5fBBc-.woff
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmWUlfBBc-.woff
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/roboto/v18/KFOkCnqEu92Fr1MmgVxIIzQ.woff
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/googlesans/v14/4UaGrENHsxJlGDuGo1OIlL3Owpg.woff
REQUEST
RESPONSE
GET 200 https://fonts.gstatic.com/s/googlesans/v14/4UabrENHsxJlGDuGo1OIlLU94YtzCwA.woff
REQUEST
RESPONSE
GET 302 https://accounts.google.com/favicon.ico
REQUEST
RESPONSE
GET 304 https://www.google.com/favicon.ico
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49164 -> 142.250.204.109:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 142.250.66.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49165 -> 142.250.204.109:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49172 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49170 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49168 -> 142.250.66.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 117.18.232.200:443 -> 192.168.56.101:49187 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49176 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49174 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49181 -> 142.251.220.100:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49179 -> 142.250.204.109:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49185 -> 117.18.232.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49173 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49169 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49171 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49175 -> 172.217.24.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49178 -> 142.250.204.109:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49180 -> 142.251.220.100:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49186 -> 117.18.232.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49164
142.250.204.109:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=accounts.google.com 6c:c9:34:01:32:00:11:f3:7a:e2:aa:fc:7c:e3:13:17:3d:17:71:8a
TLSv1
192.168.56.101:49167
142.250.66.35:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49165
142.250.204.109:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=accounts.google.com 6c:c9:34:01:32:00:11:f3:7a:e2:aa:fc:7c:e3:13:17:3d:17:71:8a
TLSv1
192.168.56.101:49172
172.217.24.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49170
172.217.24.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49168
142.250.66.35:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49176
172.217.24.67:443
None None None
TLSv1
192.168.56.101:49174
172.217.24.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49181
142.251.220.100:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=www.google.com 48:e3:15:66:fc:ea:15:bf:d2:34:c1:dd:60:d4:23:a3:63:57:89:8d
TLSv1
192.168.56.101:49179
142.250.204.109:443
None None None
TLSv1
192.168.56.101:49173
172.217.24.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49169
172.217.24.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49171
172.217.24.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com a3:09:cb:6c:64:76:4b:58:32:d1:21:3e:f4:65:1f:de:58:22:8f:d6
TLSv1
192.168.56.101:49175
172.217.24.67:443
None None None
TLSv1
192.168.56.101:49178
142.250.204.109:443
None None None
TLSv1
192.168.56.101:49180
142.251.220.100:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=www.google.com 48:e3:15:66:fc:ea:15:bf:d2:34:c1:dd:60:d4:23:a3:63:57:89:8d

Snort Alerts

No Snort Alerts