NetWork | ZeroBOX

Network Analysis

IP Address Status Action
108.177.125.84 Active Moloch
142.250.204.110 Active Moloch
142.250.206.234 Active Moloch
142.250.76.131 Active Moloch
142.250.76.142 Active Moloch
142.251.222.195 Active Moloch
164.124.101.2 Active Moloch
172.217.161.225 Active Moloch
172.217.24.78 Active Moloch
172.217.24.97 Active Moloch
172.217.25.170 Active Moloch
172.217.25.174 Active Moloch
172.217.27.36 Active Moloch
172.217.27.46 Active Moloch
211.114.64.12 Active Moloch
216.58.200.228 Active Moloch
34.104.35.123 Active Moloch
45.33.6.223 Active Moloch

POST 200 https://update.googleapis.com/service/update2
REQUEST
RESPONSE
POST 200 https://update.googleapis.com/service/update2?cup2key=12:n6EyV-uvoCaVgxFxDQet4WSYiBFRf-2C5HNBwb81dao&cup2hreq=1617e93f4cc0a87c8eec0ba442964150753038fe712f2774cc7d587abbdc23fd
REQUEST
RESPONSE
POST 200 https://update.googleapis.com/service/update2
REQUEST
RESPONSE
HEAD 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome/czao2hrvpk5wgqrkz4kks5r734_109.0.5414.120/109.0.5414.120_chrome_installer.exe
REQUEST
RESPONSE
GET 200 http://edgedl.me.gvt1.com/edgedl/release2/chrome/czao2hrvpk5wgqrkz4kks5r734_109.0.5414.120/109.0.5414.120_chrome_installer.exe
REQUEST
RESPONSE
HEAD 200 http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYTBmQUFZUHRkSkgtb01uSGNvRHZ2Tm5HQQ/1.0.0.15_llkgjffcdpffmhiakmfcdcblohccpfmo.crx
REQUEST
RESPONSE
GET 200 http://edgedl.me.gvt1.com/edgedl/chromewebstore/L2Nocm9tZV9leHRlbnNpb24vYmxvYnMvYTBmQUFZUHRkSkgtb01uSGNvRHZ2Tm5HQQ/1.0.0.15_llkgjffcdpffmhiakmfcdcblohccpfmo.crx
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49245 -> 172.217.24.227:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49246 -> 172.217.24.227:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 34.104.35.123:80 -> 192.168.56.101:49250 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 34.104.35.123:80 -> 192.168.56.101:49250 2014520 ET INFO EXE - Served Attached HTTP Misc activity
TCP 192.168.56.101:49339 -> 172.217.24.227:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49344 -> 8.8.8.8:443 2047866 ET INFO Observed Google DNS over HTTPS Domain (dns .google in TLS SNI) Misc activity

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.101:49245
172.217.24.227:443
C=US, O=Google Trust Services, CN=WR2 CN=upload.video.google.com 87:a0:28:7a:78:8a:cb:af:25:26:65:fb:d1:da:f0:82:e6:66:7c:71
TLS 1.2
192.168.56.101:49246
172.217.24.227:443
C=US, O=Google Trust Services, CN=WR2 CN=upload.video.google.com 87:a0:28:7a:78:8a:cb:af:25:26:65:fb:d1:da:f0:82:e6:66:7c:71
TLS 1.3
192.168.56.101:49328
142.250.204.110:443
None None None
TLS 1.3
192.168.56.101:49327
142.251.222.195:443
None None None
TLS 1.3
192.168.56.101:49329
216.58.203.67:443
None None None
TLS 1.3
192.168.56.101:49332
211.114.64.12:443
None None None
TLS 1.3
192.168.56.101:49334
216.58.200.228:443
None None None
TLS 1.3
192.168.56.101:49336
142.251.222.195:443
None None None
TLS 1.3
192.168.56.101:49340
172.217.27.46:443
None None None
TLS 1.2
192.168.56.101:49339
172.217.24.227:443
C=US, O=Google Trust Services, CN=WR2 CN=upload.video.google.com 87:a0:28:7a:78:8a:cb:af:25:26:65:fb:d1:da:f0:82:e6:66:7c:71
TLS 1.3
192.168.56.101:49342
172.217.24.78:443
None None None
TLS 1.3
192.168.56.101:49331
216.58.200.228:443
None None None
TLS 1.3
192.168.56.101:49348
142.250.206.234:443
None None None
TLS 1.3
192.168.56.101:49352
142.250.76.131:443
None None None
TLS 1.3
192.168.56.101:49345
8.8.4.4:443
None None None
TLS 1.3
192.168.56.101:49344
8.8.8.8:443
None None None
TLS 1.3
192.168.56.101:49346
8.8.8.8:443
None None None
TLS 1.3
192.168.56.101:49349
142.250.76.142:443
None None None
TLS 1.3
192.168.56.101:49350
172.217.25.174:443
None None None
TLS 1.3
192.168.56.101:49351
172.217.25.170:443
None None None
TLS 1.3
192.168.56.101:49326
172.217.27.36:443
None None None
TLS 1.3
192.168.56.101:49330
108.177.125.84:443
None None None
TLS 1.3
192.168.56.101:49343
172.217.24.97:443
None None None
UNDETERMINED
192.168.56.101:49338
142.251.222.195:443
None None None
UNDETERMINED
192.168.56.101:49333
216.58.200.228:443
None None None
UNDETERMINED
192.168.56.101:49337
142.251.222.195:443
None None None

Snort Alerts

No Snort Alerts