NetWork | ZeroBOX

Network Analysis

IP Address Status Action
116.62.214.53 Active Moloch
118.178.125.54 Active Moloch
118.24.85.16 Active Moloch
124.223.105.161 Active Moloch
139.196.217.38 Active Moloch
164.124.101.2 Active Moloch
18.138.132.100 Active Moloch
38.147.189.238 Active Moloch
47.96.87.99 Active Moloch
47.97.204.105 Active Moloch
47.98.133.194 Active Moloch
60.12.184.62 Active Moloch
Name Response Post-Analysis Lookup
qbuniplugin.html5.qq.com 43.135.106.117
p0.qhimg.com 54.192.175.113
game.kde.qq.com 129.226.103.24
aegis.qq.com 43.137.221.145
www.baidu.com 119.63.197.139
api.bilibili.com 164.52.44.50
live.bilibili.com 164.52.47.54
pcwup.imtt.qq.com 14.22.9.100
wn.pos.baidu.com 182.61.200.11
dns.google 8.8.4.4
dgss0.bdstatic.com 45.113.192.82
ss0.baidu.com 185.10.104.109
live-s3m.mediav.com 111.174.12.100
ssxd.mediav.com 112.65.69.51
hw-v2-web-player-tracker.biliapi.net 101.91.136.148
b60ec859c86b068d2351ce983cebdb01.rdt.tfogc.com 175.4.55.182
b33fca1920f4832d8e3dfbf4c7432b50.rdt.tfogc.com 113.141.160.48
pcupd.com 139.196.217.38
46accc8a55ff111839e2072af218a509.rdt.tfogc.com 183.214.144.4
hotlist.imtt.qq.com 43.154.240.245
xy120x209x212x19xy.mcdn.bilivideo.cn 120.209.212.19
s1.mdvdns.com 112.65.69.52
hm.baidu.com 111.45.3.198
cpro.baidustatic.com 220.169.152.38
r3---sn-j5o7dn7e.gvt1-cn.com 113.108.239.196
mbd.baidu.com 103.235.47.212
www.google.com 142.250.76.132
rpt.gdt.qq.com 43.159.118.117
optimizationguide-pa.googleapis.com 172.217.161.234
novel.html5.qq.com 129.226.107.80
sc0.hao123img.com 58.254.180.65
9d215ea2cab88371652c1ef094554b8f.rdt.tfogc.com 183.214.144.2
snowflake.qq.com 43.129.2.170
wup.imtt.qq.com 43.154.240.161
cm.bilibili.com 164.52.47.54
max-l.mediav.com 180.163.247.134
sofire.baidu.com 36.110.192.107
jx.cdn.qhstatic.com 104.192.108.192
dhrest.2345.com 180.163.196.140
www.bilibili.com 164.52.44.50
adsmind.gdtimg.com 211.152.132.216
v.qq.com 23.7.212.166
imgcdn.toutiaoyule.com 111.47.229.228
puui.qpic.cn 23.210.247.59
st.tencent-cloud.com 211.152.132.216
dhps.2345.com 180.163.203.99
static.res.qq.com 36.250.242.247
183ac55a26eb8ed3211e476f89a40d34.rdt.tfogc.com 111.4.66.14
dhrest-static.2345.com 180.163.147.217
m4.publicimg.browser.qq.com 43.152.15.45
www.2345.com 163.181.22.236
cdn.nfa.qq.com 42.177.83.82
gss0.bdstatic.com 45.113.192.82
arms-retcode.aliyuncs.com 47.96.83.41
ckmap.mediav.com 180.163.247.134
bd-js1.2345.com 112.25.90.131
35d956a39c11b2a14f588d401b8eb2ea.rdt.tfogc.com 183.95.181.108
mc.minibai.com 118.24.85.16
6252cfceac8fd2546906f4522c07fff2.rdt.tfogc.com 219.144.77.71
d9bfba694e0c428248140c78286d3793.rdt.tfogc.com 58.19.46.75
h.trace.qq.com 129.226.102.234
lupic.cdn.bcebos.com 60.188.66.35
f7.baidu.com 103.235.45.243
hector.baidu.com 39.156.68.81
xy117x158x188x37xy.mcdn.bilivideo.cn 117.158.188.37
i2.hdslb.com 122.10.154.135
www-cdn.2345cdn.net 180.163.207.108
otheve.beacon.qq.com 129.226.106.210
ss1.baidu.com 185.10.104.109
v.gdt.qq.com 43.159.118.117
s3m4.fenxi.com 175.6.254.74
7b42f7424e8c39d30019cf95ef41ef02.rdt.tfogc.com 175.4.55.179
cn-sccd-cu-01-09.bilivideo.com 101.206.209.10
www.aliyunpay.shop 118.178.125.54
daohang.qq.com 43.154.240.84
hectorstatic.baidu.com 113.142.207.38
vr.gdt.qq.com 43.159.118.117
tv.puui.qpic.cn 38.60.181.35
daohang.browser.qq.com 43.154.240.84
ca8ac9a6f86c4d42a7e731d17aa125db.rdt.tfogc.com 113.141.160.228
web.50bangzh.com 180.101.190.124
pos.baidu.com 103.235.46.94
pbaccess.video.qq.com 43.155.124.103
content-autofill.googleapis.com 142.250.206.202
www.591888.vip 38.147.189.238
oth.str.beacon.qq.com 14.22.9.180
www.aliyunpay.shop 118.178.125.54
pss.bdstatic.com 103.235.45.242
newtab.browser.qq.com 43.135.106.42
bdb4e1d1d90392c080815d268dfe7f87.rdt.tfogc.com 183.214.52.52
dss2.bdstatic.com 185.10.104.109
search.sogoucdn.com 43.159.81.60
0a0a389bc8b2293cdc7b734e9cf84e2f.rdt.tfogc.com 113.141.160.198
accounts.google.com 64.233.188.84
vfiles.gtimg.cn 211.152.132.216
beacon.cdn.qq.com 211.152.132.208
index-api.2345.com 180.101.190.124
vd6.l.qq.com 129.226.107.33
t12.baidu.com 111.225.213.36
sfp.safe.baidu.com 36.110.219.204
pb.sogou.com 36.155.166.212
data.ab.qq.com 43.154.254.142
s3m6.mdvdns.com 104.192.108.23
api.live.bilibili.com 164.52.47.54
as1.m.hao123.com 42.81.8.130
code.bdstatic.com 103.235.45.242
ipsad.l.qq.com 43.129.2.69
6ad41852c351bbdf31590130781c1f5c.rdt.tfogc.com 175.153.180.110
passport-plugin.hao184.com 61.170.80.232
sapi-wzdh.2345.com 47.102.123.53
publiclog.zhiyan.tencent-cloud.net 121.14.77.149
zj-cn-live-comet.chat.bilibili.com 47.103.12.10
b.bdstatic.com 117.68.52.48
256c3d9bfaf9b50b26a3007eed50f82a.rdt.tfogc.com 111.4.66.8
passport.baidu.com 45.113.194.250
www-stream.2345cdn.net 163.181.22.205
checkip.amazonaws.com 52.221.143.66
clientservices.googleapis.com 142.250.198.3
www.hao123.com 103.235.46.98
hmcdn.baidu.com 124.239.243.48
eclick.baidu.com 111.206.208.190
kde.qq.com 129.226.103.169
i.news.qq.com 38.60.181.105
topnews.imtt.qq.com 101.32.212.153
quickstart.imtt.qq.com 129.226.103.233
3924a2b0e8a2c4ef0b5b941a5d29f50f.rdt.tfogc.com 183.214.52.49
430df5a0d910a183ce55ba9aa34a065f.rdt.tfogc.com 111.4.66.17
data.bilibili.com 164.52.0.98
trpcpb.imtt.qq.com 129.226.107.205
ltscsy.qq.com 116.162.208.149
pcbrowser.dd.qq.com 111.3.90.95
iwan.video.qq.com 124.156.190.80
webrtcpunch.video.qq.com 119.147.179.227
www.hao774.com 61.170.79.225
apd-ugcvlive.apdcdn.tc.qq.com 211.152.132.216
config.ab.qq.com 43.159.234.88
b0218760c889395ec69a3305b7ab05fa.rdt.tfogc.com 183.214.52.58
sofire.bdstatic.com 60.190.116.48
s3m6.fenxi.com 61.170.81.233
www.sogou.com 119.28.109.132

POST 200 https://mc.minibai.com/api/gv1/push
REQUEST
RESPONSE
GET 200 https://checkip.amazonaws.com/
REQUEST
RESPONSE
GET 200 http://pcupd.com/tfsoft/xftd/v2/ctf/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49183 -> 118.24.85.16:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49166 -> 124.223.105.161:8902 2027262 ET INFO Dotted Quad Host ZIP Request Potentially Bad Traffic
TCP 192.168.56.101:49166 -> 124.223.105.161:8902 2027262 ET INFO Dotted Quad Host ZIP Request Potentially Bad Traffic
TCP 192.168.56.101:49196 -> 18.138.132.100:443 2054155 ET INFO Observed External IP Lookup Domain (checkip .amazonaws .com) in TLS SNI Device Retrieving External IP Address Detected
TCP 192.168.56.101:49196 -> 18.138.132.100:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49196 -> 18.138.132.100:443 2054155 ET INFO Observed External IP Lookup Domain (checkip .amazonaws .com) in TLS SNI Device Retrieving External IP Address Detected
UDP 192.168.56.101:55146 -> 164.124.101.2:53 2054140 ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com) Device Retrieving External IP Address Detected
UDP 192.168.56.101:60411 -> 164.124.101.2:53 2052580 ET INFO DNS Query to Alibaba Cloud CDN Domain (aliyuncs .com) Misc activity

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49183
118.24.85.16:443
C=US, O=DigiCert, Inc., CN=RapidSSL Global TLS RSA4096 SHA256 2022 CA1 CN=*.minibai.com 40:08:fa:f7:f6:1a:17:0c:aa:c1:99:5b:de:37:59:0c:0e:41:db:cd
TLSv1
192.168.56.101:49196
18.138.132.100:443
C=US, O=Amazon, CN=Amazon RSA 2048 M03 CN=checkip.amazonaws.com 3b:5d:c1:80:5a:4e:53:16:ce:0b:31:80:0c:26:91:07:c7:5b:0d:d0

Snort Alerts

No Snort Alerts