NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
164.124.101.2 Active Moloch
23.41.113.9 Active Moloch
61.111.21.172 Active Moloch
61.111.21.173 Active Moloch
GET 200 http://x1.i.lencr.org/
REQUEST
RESPONSE
GET 200 http://x1.i.lencr.org/
REQUEST
RESPONSE
GET 200 http://x1.i.lencr.org/
REQUEST
RESPONSE
GET 200 http://x1.i.lencr.org/
REQUEST
RESPONSE
GET 200 http://x1.i.lencr.org/
REQUEST
RESPONSE
GET 200 http://x1.i.lencr.org/
REQUEST
RESPONSE
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.172 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3
61.111.21.173 192.168.56.101 3

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49171 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49173 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49168 -> 61.111.21.173:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49174 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49172 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49167 -> 61.111.21.173:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49166 -> 61.111.21.173:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49182 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49170 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49169 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49179 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49180 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49181 -> 61.111.21.172:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49171
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49174
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49172
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49173
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49167
61.111.21.173:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 CN=*.pointshop.co.kr 93:f2:1a:8f:b1:ee:1c:32:6d:0d:e4:7f:67:b1:7b:c1:ac:35:67:04
TLSv1
192.168.56.101:49166
61.111.21.173:443
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1 CN=*.pointshop.co.kr 93:f2:1a:8f:b1:ee:1c:32:6d:0d:e4:7f:67:b1:7b:c1:ac:35:67:04
TLSv1
192.168.56.101:49182
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49170
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49169
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49179
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49180
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e
TLSv1
192.168.56.101:49181
61.111.21.172:443
C=US, O=Let's Encrypt, CN=R10 CN=www.coinstore.kr e5:74:81:77:51:0f:42:de:81:60:2c:36:0c:76:98:81:8e:50:0a:5e

Snort Alerts

No Snort Alerts