NetWork | ZeroBOX

Network Analysis

IP Address Status Action
137.226.34.45 Active Moloch
145.239.136.129 Active Moloch
178.33.36.64 Active Moloch
199.195.253.180 Active Moloch
84.240.60.234 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.

No traffic

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 199.195.253.180:9000 -> 192.168.56.101:49170 2520069 ET TOR Known Tor Exit Node Traffic group 70 Misc Attack
TCP 199.195.253.180:9000 -> 192.168.56.101:49170 2522069 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 70 Misc Attack
TCP 178.33.36.64:8080 -> 192.168.56.101:49175 2522257 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 258 Misc Attack
TCP 145.239.136.129:8080 -> 192.168.56.101:49171 2522193 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 194 Misc Attack
TCP 84.240.60.234:9001 -> 192.168.56.101:49172 2522787 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 788 Misc Attack
TCP 137.226.34.45:9008 -> 192.168.56.101:49174 2522169 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 170 Misc Attack
TCP 137.226.34.45:9008 -> 192.168.56.101:49182 2522169 ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 170 Misc Attack

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.101:49170
199.195.253.180:9000
None None None
TLS 1.3
192.168.56.101:49175
178.33.36.64:8080
None None None
TLS 1.3
192.168.56.101:49171
145.239.136.129:8080
None None None
TLS 1.3
192.168.56.101:49172
84.240.60.234:9001
None None None
TLS 1.3
192.168.56.101:49177
178.33.36.64:8080
None None None
TLS 1.3
192.168.56.101:49174
137.226.34.45:9008
None None None
TLS 1.3
192.168.56.101:49180
178.33.36.64:8080
None None None
TLS 1.3
192.168.56.101:49178
137.226.34.45:9008
None None None
TLS 1.3
192.168.56.101:49182
137.226.34.45:9008
None None None

Snort Alerts

No Snort Alerts