NetWork | ZeroBOX

Network Analysis

IP Address Status Action
116.67.103.155 Active Moloch
117.18.232.200 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
srtk.hometax.go.kr 116.67.103.155
GET 200 https://srtk.hometax.go.kr/download/rollups/seed.js
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/jquery-1.11.1.min.js
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/cri.css?v=1
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/components/enc-cp949-min.js
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/rollups/aes.js
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/cri_ems_nt.js?v=1
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/rollups/md5.js
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/img/security_pop_bt_close.png
REQUEST
RESPONSE
GET 200 https://srtk.hometax.go.kr/download/img/security_pop_ic_lock.png
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
8.8.8.8 192.168.56.101 0 abcdefghijklmnopqrstuvwabcdefghi

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49176 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49177 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49178 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49175 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49179 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49174 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49180 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49173 -> 116.67.103.155:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49177
116.67.103.155:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92
TLSv1
192.168.56.101:49176
116.67.103.155:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92
TLSv1
192.168.56.101:49178
116.67.103.155:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92
TLSv1
192.168.56.101:49175
116.67.103.155:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92
TLSv1
192.168.56.101:49179
116.67.103.155:443
None None None
TLSv1
192.168.56.101:49174
116.67.103.155:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92
TLSv1
192.168.56.101:49180
116.67.103.155:443
None None None
TLSv1
192.168.56.101:49173
116.67.103.155:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Extended Validation Secure Server CA serialNumber=102-83-01521, unknown=KR, unknown=Government Entity, C=KR, ST=Sejong, O=National Tax Service, CN=www.hometax.go.kr ad:c7:ba:35:01:64:a2:d8:57:ab:3a:46:65:c0:86:75:e4:5d:39:92

Snort Alerts

No Snort Alerts