NetWork | ZeroBOX

Network Analysis

IP Address Status Action
121.254.136.27 Active Moloch
142.250.204.99 Active Moloch
142.250.207.77 Active Moloch
142.250.66.131 Active Moloch
142.250.66.142 Active Moloch
142.250.66.67 Active Moloch
142.251.220.4 Active Moloch
142.251.222.195 Active Moloch
142.251.222.202 Active Moloch
164.124.101.2 Active Moloch
172.67.198.220 Active Moloch
35.190.80.1 Active Moloch
GET 404 https://synerhu.ru/uplcv?utm_term=bad+boys+for+life+2020+torrent
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49168 -> 172.67.198.220:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.102:49167 -> 172.67.198.220:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49168
172.67.198.220:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=synerhu.ru 0e:e1:e1:4f:ed:d3:9d:06:1e:86:79:f7:3e:44:2b:fc:9c:b5:67:7c
TLSv1
192.168.56.102:49167
172.67.198.220:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=synerhu.ru 0e:e1:e1:4f:ed:d3:9d:06:1e:86:79:f7:3e:44:2b:fc:9c:b5:67:7c
TLS 1.3
192.168.56.102:49190
142.250.204.99:443
None None None
TLS 1.3
192.168.56.102:49182
142.250.207.77:443
None None None
TLS 1.3
192.168.56.102:49184
142.251.220.4:443
None None None
TLS 1.3
192.168.56.102:49183
142.251.220.4:443
None None None
TLS 1.3
192.168.56.102:49186
142.250.66.67:443
None None None
TLS 1.3
192.168.56.102:49195
172.67.198.220:443
None None None
TLS 1.3
192.168.56.102:49193
142.250.66.142:443
None None None
TLS 1.3
192.168.56.102:49188
142.250.204.99:443
None None None
TLS 1.3
192.168.56.102:49196
35.190.80.1:443
None None None
TLS 1.3
192.168.56.102:49189
142.250.204.99:443
None None None
TLS 1.3
192.168.56.102:49200
142.250.66.131:443
None None None
TLS 1.3
192.168.56.102:49192
142.251.222.195:443
None None None
TLS 1.3
192.168.56.102:49185
142.251.220.4:443
None None None
TLS 1.3
192.168.56.102:49187
142.251.222.202:443
None None None

Snort Alerts

No Snort Alerts