NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
142.250.204.68 Active Moloch
142.251.222.206 Active Moloch
164.124.101.2 Active Moloch
216.58.203.67 Active Moloch
74.125.23.84 Active Moloch
GET 303 https://www.youtube.com/account
REQUEST
RESPONSE
GET 302 https://accounts.google.com/ServiceLogin?service=youtube&uilel=3&passive=true&continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Dko%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=ko
REQUEST
RESPONSE
GET 302 https://accounts.google.com/InteractiveLogin?continue=https://www.youtube.com/signin?action_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Dko%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=ko&passive=true&service=youtube&uilel=3&ifkv=ARZ0qKKXo7ZF9PtGz47baT8UVWdFT0eYzdn5It88GOwmzA_LWU4tMF7c7RwCmN7IKO4ExzugA_5g9A
REQUEST
RESPONSE
GET 200 https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Dko%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=ko&ifkv=ARZ0qKK-VHHnZwpNm7p5uN6Dl_ZvvZmCoYYXn02kHS5p_HaZ7ePY9EYzutDBHK0NXYfixHOOw7mtlw&passive=true&service=youtube&uilel=3&flowName=WebLiteSignIn&flowEntry=ServiceLogin&dsh=S-553555903%3A1711326027463105
REQUEST
RESPONSE
GET 200 https://accounts.google.com/_/bscframe
REQUEST
RESPONSE
GET 200 https://ssl.gstatic.com/images/branding/googlelogo/2x/googlelogo_color_74x24dp.png
REQUEST
RESPONSE
GET 204 https://accounts.google.com/generate_204?vBL53Q
REQUEST
RESPONSE
GET 302 https://accounts.google.com/favicon.ico
REQUEST
RESPONSE
GET 304 https://www.google.com/favicon.ico
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49166 -> 142.251.222.206:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49170 -> 74.125.23.84:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49171 -> 74.125.23.84:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49172 -> 216.58.203.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 142.251.222.206:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49176 -> 74.125.23.84:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49175 -> 74.125.23.84:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49173 -> 216.58.203.67:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49177 -> 142.250.204.68:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49178 -> 142.250.204.68:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49166
142.251.222.206:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.google.com 23:75:5e:3d:ea:9f:a0:42:86:8d:14:ae:43:04:f0:b2:91:0b:da:cf
TLSv1
192.168.56.101:49170
74.125.23.84:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=accounts.google.com 89:5f:a0:36:ad:7d:38:10:5b:58:71:f2:d2:8b:75:99:05:74:ed:fd
TLSv1
192.168.56.101:49171
74.125.23.84:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=accounts.google.com 89:5f:a0:36:ad:7d:38:10:5b:58:71:f2:d2:8b:75:99:05:74:ed:fd
TLSv1
192.168.56.101:49172
216.58.203.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com f3:56:10:42:a8:3c:bf:f5:89:9c:4c:c0:f8:e3:dc:c4:1c:e9:34:9e
TLSv1
192.168.56.101:49167
142.251.222.206:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.google.com 23:75:5e:3d:ea:9f:a0:42:86:8d:14:ae:43:04:f0:b2:91:0b:da:cf
TLSv1
192.168.56.101:49176
74.125.23.84:443
None None None
TLSv1
192.168.56.101:49175
74.125.23.84:443
None None None
TLSv1
192.168.56.101:49173
216.58.203.67:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=*.gstatic.com f3:56:10:42:a8:3c:bf:f5:89:9c:4c:c0:f8:e3:dc:c4:1c:e9:34:9e
TLSv1
192.168.56.101:49177
142.250.204.68:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=www.google.com 32:a3:19:7a:6b:d5:c7:5e:ca:7c:c8:08:79:14:56:fd:fc:3e:06:f0
TLSv1
192.168.56.101:49178
142.250.204.68:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 CN=www.google.com 32:a3:19:7a:6b:d5:c7:5e:ca:7c:c8:08:79:14:56:fd:fc:3e:06:f0

Snort Alerts

No Snort Alerts