NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.20.3.235 Active Moloch
146.59.154.106 Active Moloch
163.172.154.142 Active Moloch
164.124.101.2 Active Moloch

No traffic

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.103:50800 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
TCP 192.168.56.103:49163 -> 104.20.3.235:443 906200068 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (CoinMiner) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.103:49164
163.172.154.142:10343
None None None
TLS 1.3
192.168.56.103:49162
146.59.154.106:10343
None None None
TLS 1.3
192.168.56.103:49163
104.20.3.235:443
None None None

Snort Alerts

No Snort Alerts