NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.228.50.241 Active Moloch
104.21.88.107 Active Moloch
156.252.105.54 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
34.102.136.180 Active Moloch
GET 200 http://xwjhdjylqeypyltby.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-998AD455AE20AC4E10E6C6B9224D736E.html
REQUEST
RESPONSE
GET 301 http://www.earthnetic.com/blm/?CP=KzhYmWwGBnJd9H2lHorqD8QKOlNsse9QX1sd99Ls1hbzoykJM+qEq+3dk7Q4isYsubov0k0A&nN=Sxl0iBPp_L-dz
REQUEST
RESPONSE
GET 403 http://www.gitaffiliate.com/blm/?CP=uGGFK5UhCUKCnxC8Ud3ctgC6smvju6fhPlsyozAq6N0+YsN3Ijt/fdCkzzIRsY7zE/Ms1iOw&nN=Sxl0iBPp_L-dz
REQUEST
RESPONSE
GET 403 http://www.bikesofthefuture.com/blm/?CP=/F5EKGShKdzfOo6rJYC+yT+3/JcfBVJwv5RL9ncNjH3yKsLZXD1n5t9v2CeczytC3Ib20Ua8&nN=Sxl0iBPp_L-dz
REQUEST
RESPONSE
GET 302 http://www.checkoutmyimages.com/blm/?CP=Q/TZM269arV1IgVCnNh5odBPYQN+T2CQDjPOdzfx5C4l4+ZW41HZ5pGmZWA/UFRbxZr4YpCv&nN=Sxl0iBPp_L-dz
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.102:57660 -> 164.124.101.2:53 2025106 ET INFO DNS Query for Suspicious .ml Domain Potentially Bad Traffic
TCP 192.168.56.102:49816 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49816 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49816 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49815 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49815 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49815 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49817 -> 156.252.105.54:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49817 -> 156.252.105.54:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49817 -> 156.252.105.54:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49814 -> 103.228.50.241:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49814 -> 103.228.50.241:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49814 -> 103.228.50.241:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts