NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.73.97 Active Moloch
164.124.101.2 Active Moloch
172.67.209.71 Active Moloch
GET 301 https://freegeoip.app/xml/
REQUEST
RESPONSE
GET 404 https://ipbase.com/xml/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49163 -> 104.21.73.97:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.103:64894 -> 164.124.101.2:53 2036560 ET INFO External IP Lookup Domain Domain in DNS Lookup (ipbase .com) Potentially Bad Traffic
TCP 192.168.56.103:49164 -> 172.67.209.71:443 2036561 ET INFO Observed External IP Lookup Domain (ipbase .com in TLS SNI) Potentially Bad Traffic
TCP 192.168.56.103:49164 -> 172.67.209.71:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49163
104.21.73.97:443
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 CN=freegeoip.app c0:39:22:a5:ab:70:fc:41:fb:5a:a7:05:42:53:6a:f9:23:be:8b:89
TLSv1
192.168.56.103:49164
172.67.209.71:443
C=US, O=Google Trust Services, CN=WE1 CN=ipbase.com fc:09:7a:de:bd:0b:8f:40:75:31:bd:ac:0d:dc:c8:86:94:db:7d:cf

Snort Alerts

No Snort Alerts