NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.251.220.33 Active Moloch
164.124.101.2 Active Moloch
172.217.24.78 Active Moloch
85.209.11.204 Active Moloch
GET 302 https://script.google.com/macros/s/AKfycbzq1CWyl36rt9O8a0Zlm5Z6LRB2igbns3CkTay10UBerGZv4zl389I1MOMTE8g-CKY/exec?xfgnxfgn&stream=5&ip=175.208.134.152&slots=0000&param=empty
REQUEST
RESPONSE
GET 200 https://script.googleusercontent.com/macros/echo?user_content_key=rq3I6Pvq31ESr42SRVFCcH8cBMrOvGfc9LjrAFAjXKqooXQVZnHoVSKZ49ywNUr7mn_h-t_4xp16ZbQUh0u7vYizKKleUSwSOJmA1Yb3SEsKFZqtv3DaNYcMrmhZHmUMWojr9NvTBuBLhyHCd5hHa0CRDStSlAiWe9EsIf9E4ZPsnymwtpgwALY3ZEKNbUPKTwCm-q5YBdK9ax9ulRNROyEZlBVHKdgUzc9XRB8G-pFIaTITfR7fJ9yLw_QwlOLh3sVTfjuTogDzV_l7Cl_ErHbadLHwSTw0RLfCUlcjW3aqDyDBdoyuR54_mWWztr2JN0ZmedBznvo&lib=MGiFI8QOoThWusP0Kv6sJRfccXc-Ar0ZC
REQUEST
RESPONSE
GET 200 http://85.209.11.204/ip.php
REQUEST
RESPONSE
GET 200 http://85.209.11.204/api/files/client/s51
REQUEST
RESPONSE
GET 200 http://85.209.11.204/api/files/client/s52
REQUEST
RESPONSE
GET 200 http://85.209.11.204/api/files/client/s53
REQUEST
RESPONSE
GET 200 http://85.209.11.204/api/files/client/s54
REQUEST
RESPONSE
GET 301 http://script.google.com/macros/s/AKfycbzq1CWyl36rt9O8a0Zlm5Z6LRB2igbns3CkTay10UBerGZv4zl389I1MOMTE8g-CKY/exec?xfgnxfgn&stream=5&ip=175.208.134.152&slots=0000&param=empty
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49170 -> 172.217.24.78:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.103:49171 -> 142.251.220.33:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49170
172.217.24.78:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.google.com fd:ee:45:21:a2:3c:95:82:9b:ba:3f:7a:59:3c:f6:c2:7b:c7:84:8f
TLSv1
192.168.56.103:49171
142.251.220.33:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.googleusercontent.com cb:bb:d8:fc:60:aa:94:8f:47:5c:88:bb:c3:30:22:92:26:d3:85:2f

Snort Alerts

No Snort Alerts