NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.80.99 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
wlnrar.shop 172.67.177.42
POST 200 https://wlnrar.shop/json.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49166 -> 104.21.80.99:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.103:49166
104.21.80.99:443
C=US, O=Google Trust Services, CN=WE1 CN=wlnrar.shop c3:1e:19:20:23:a4:65:b7:fb:17:e6:2e:ea:ed:ba:88:88:97:78:7e

Snort Alerts

No Snort Alerts