NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.250.71.193 Active Moloch
164.124.101.2 Active Moloch
GET 200 https://drive.usercontent.google.com/download?id=1XEWUwFdhz83ez1WgfQ4Lj72TbJhKq3zU&export=download
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49165 -> 142.250.71.193:443 906200022 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.103:49165
142.250.71.193:443
C=US, O=Google Trust Services, CN=WR2 CN=*.usercontent.google.com d2:11:90:31:49:cf:e9:1f:a2:f0:f1:d3:26:92:15:27:7b:54:cc:35

Snort Alerts

No Snort Alerts