NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.177.240 Active Moloch
Name Response Post-Analysis Lookup
auntberry.xyz 104.21.67.155
HEAD 200 https://auntberry.xyz/pe/start/index.php?a=2910&p=4134&t=50784292
REQUEST
RESPONSE
GET 200 https://auntberry.xyz/pe/start/index.php?a=2910&p=4134&t=50784292
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49164 -> 172.67.177.240:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49164
172.67.177.240:443
C=US, O=Google Trust Services, CN=WE1 CN=auntberry.xyz 57:d6:90:3c:ab:9e:4e:4b:bc:5f:e9:08:a7:22:28:d6:59:f3:aa:f8

Snort Alerts

No Snort Alerts