NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
157.240.215.14 Active Moloch
157.240.215.35 Active Moloch
164.124.101.2 Active Moloch
GET 200 https://www.facebook.com/3802211850064154
REQUEST
RESPONSE
GET 301 https://m.facebook.com/3802211850064154?_rdr
REQUEST
RESPONSE
GET 302 https://m.facebook.com/story.php?story_fbid=3802211850064154&id=100008261283165&_rdr
REQUEST
RESPONSE
GET 200 https://m.facebook.com/login.php?next=https%3A%2F%2Fm.facebook.com%2Fstory.php%3Fstory_fbid%3D3802211850064154%26id%3D100008261283165&refsrc=deprecated&_rdr
REQUEST
RESPONSE
GET 302 https://facebook.com/security/hsts-pixel.gif?c=3.2
REQUEST
RESPONSE
GET 200 https://static.xx.fbcdn.net/rsrc.php/v3/y8/r/k97pj8-or6s.png
REQUEST
RESPONSE
GET 200 https://static.xx.fbcdn.net/rsrc.php/v3/yc/r/ZXwOcP9E7mM.png
REQUEST
RESPONSE
GET 302 https://fbcdn.net/security/hsts-pixel.gif?c=2
REQUEST
RESPONSE
GET 200 https://fbsbx.com/security/hsts-pixel.gif
REQUEST
RESPONSE
GET 200 https://m.facebook.com/favicon.ico
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49169 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49168 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49171 -> 157.240.215.14:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49170 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49165 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49172 -> 157.240.215.14:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49181 -> 117.18.232.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49164 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49173 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49175 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49176 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49182 -> 117.18.232.200:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49174 -> 157.240.215.35:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 117.18.232.200:443 -> 192.168.56.101:49183 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49169
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49168
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49171
157.240.215.14:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49165
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49170
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49172
157.240.215.14:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49164
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49167
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com 63:4c:9e:25:64:c9:8f:f3:7b:2d:d0:9e:50:51:b6:08:3a:d5:e4:f6
TLSv1
192.168.56.101:49173
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 3e:95:2a:6e:4e:12:ce:56:7f:27:07:30:60:cd:a7:b9:5a:57:5b:2a
TLSv1
192.168.56.101:49175
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 3e:95:2a:6e:4e:12:ce:56:7f:27:07:30:60:cd:a7:b9:5a:57:5b:2a
TLSv1
192.168.56.101:49176
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 3e:95:2a:6e:4e:12:ce:56:7f:27:07:30:60:cd:a7:b9:5a:57:5b:2a
TLSv1
192.168.56.101:49174
157.240.215.35:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=DigiCert SHA2 High Assurance Server CA C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=fbcdn.net 3e:95:2a:6e:4e:12:ce:56:7f:27:07:30:60:cd:a7:b9:5a:57:5b:2a

Snort Alerts

No Snort Alerts