NetWork | ZeroBOX

Network Analysis

IP Address Status Action
109.176.30.246 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.

No traffic

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49165 -> 109.176.30.246:56002 2230002 SURICATA TLS invalid record type Generic Protocol Command Decode
TCP 192.168.56.101:49165 -> 109.176.30.246:56002 2230010 SURICATA TLS invalid record/traffic Generic Protocol Command Decode
TCP 192.168.56.101:49164 -> 109.176.30.246:56002 2230002 SURICATA TLS invalid record type Generic Protocol Command Decode
TCP 192.168.56.101:49165 -> 109.176.30.246:56002 2260002 SURICATA Applayer Detect protocol only one direction Generic Protocol Command Decode
TCP 192.168.56.101:49164 -> 109.176.30.246:56002 2230010 SURICATA TLS invalid record/traffic Generic Protocol Command Decode
TCP 192.168.56.101:49164 -> 109.176.30.246:56002 2260002 SURICATA Applayer Detect protocol only one direction Generic Protocol Command Decode
TCP 109.176.30.246:56002 -> 192.168.56.101:49164 2230002 SURICATA TLS invalid record type Generic Protocol Command Decode
TCP 109.176.30.246:56002 -> 192.168.56.101:49164 2230010 SURICATA TLS invalid record/traffic Generic Protocol Command Decode
TCP 109.176.30.246:56002 -> 192.168.56.101:49164 2035595 ET MALWARE Generic AsyncRAT Style SSL Cert Domain Observed Used for C2 Detected
TCP 109.176.30.246:56002 -> 192.168.56.101:49165 2230002 SURICATA TLS invalid record type Generic Protocol Command Decode
TCP 109.176.30.246:56002 -> 192.168.56.101:49165 2230010 SURICATA TLS invalid record/traffic Generic Protocol Command Decode
TCP 109.176.30.246:56002 -> 192.168.56.101:49165 2035595 ET MALWARE Generic AsyncRAT Style SSL Cert Domain Observed Used for C2 Detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49165
109.176.30.246:56002
CN=Hfoqppvo CN=Hfoqppvo 21:78:ba:55:44:74:2f:b6:df:5e:ca:2b:c8:5e:52:be:4d:90:f0:65
TLSv1
192.168.56.101:49164
109.176.30.246:56002
CN=Hfoqppvo CN=Hfoqppvo 21:78:ba:55:44:74:2f:b6:df:5e:ca:2b:c8:5e:52:be:4d:90:f0:65

Snort Alerts

No Snort Alerts