NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.143.245 Active Moloch
Name Response Post-Analysis Lookup
whatismyipaddressnow.co 104.21.71.78
GET 200 https://whatismyipaddressnow.co/API/FETCH/filter.php?countryid=14&token=8dQdVXc6Djbw
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49162 -> 172.67.143.245:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49162
172.67.143.245:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=whatismyipaddressnow.co 9a:31:5d:96:f4:d0:54:91:a6:19:77:ea:b4:d8:e5:55:fb:ef:99:8b

Snort Alerts

No Snort Alerts