NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.16.230.132 Active Moloch
117.18.232.200 Active Moloch
164.124.101.2 Active Moloch
61.111.58.16 Active Moloch
61.111.58.34 Active Moloch
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://apps.identrust.com/roots/dstrootcax3.p7c
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49170 -> 104.16.230.132:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49169 -> 104.16.230.132:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49191 -> 104.16.230.132:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.101:59002 -> 164.124.101.2:53 2034552 ET POLICY Observed DNS Query to Commonly Abused Cloudflare Domain (trycloudflare .com) Potentially Bad Traffic
TCP 192.168.56.101:49192 -> 104.16.230.132:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49169
104.16.230.132:443
C=US, O=Let's Encrypt, CN=R3 CN=trycloudflare.com a3:f1:76:20:39:10:75:f8:d0:71:aa:22:34:05:7c:75:27:6a:51:4d
TLSv1
192.168.56.101:49170
104.16.230.132:443
C=US, O=Let's Encrypt, CN=R3 CN=trycloudflare.com a3:f1:76:20:39:10:75:f8:d0:71:aa:22:34:05:7c:75:27:6a:51:4d
TLSv1
192.168.56.101:49191
104.16.230.132:443
C=US, O=Let's Encrypt, CN=R3 CN=trycloudflare.com a3:f1:76:20:39:10:75:f8:d0:71:aa:22:34:05:7c:75:27:6a:51:4d
TLSv1
192.168.56.101:49192
104.16.230.132:443
C=US, O=Let's Encrypt, CN=R3 CN=trycloudflare.com a3:f1:76:20:39:10:75:f8:d0:71:aa:22:34:05:7c:75:27:6a:51:4d

Snort Alerts

No Snort Alerts