NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
54.230.176.24 Active Moloch
GET 206 https://product-details.mozilla.org/1.0/firefox_versions.json
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49164 -> 54.230.176.24:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49164
54.230.176.24:443
C=US, O=Amazon, CN=Amazon RSA 2048 M01 CN=product-details.mozilla.org e9:f8:03:a4:e1:6f:d5:ec:46:21:f9:10:29:45:9b:85:f5:b4:87:e0

Snort Alerts

No Snort Alerts