NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.88.107 Active Moloch
148.72.212.87 Active Moloch
164.124.101.2 Active Moloch
34.102.136.180 Active Moloch
64.190.62.111 Active Moloch
GET 200 http://xwjhdjylqeypyltby.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-F0B9031A116A776EF4F18E20AECDBB2E.html
REQUEST
RESPONSE
GET 404 http://www.quickpanservice.com/sdh/?SX=y5cqxa77+AzBROKzMsTrIDm1XGDKnAIMB97uCo/qYIumddtded2s56bPIwzEZhPk3ULMotqK&iN=-ZOdphi8CHVl
REQUEST
RESPONSE
GET 403 http://www.presidentbyedon.com/sdh/?SX=KdJhW/ysedK9xREwvCkMpge8LXzGTauJG371skuO2KFaPP8o3bVYyAWgdfSH3bziwWoQaaql&iN=-ZOdphi8CHVl
REQUEST
RESPONSE
GET 302 http://www.zuhut.com/sdh/?SX=ectCVgCES89nnfH8J8iYd77qN2c4e7jLJtv7I+uZeVKHXsuWgpUE3WypoBoF7cwZqoELbi2G&iN=-ZOdphi8CHVl
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.101:62324 -> 164.124.101.2:53 2025106 ET INFO DNS Query for Suspicious .ml Domain Potentially Bad Traffic
TCP 192.168.56.101:49207 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 148.72.212.87:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 148.72.212.87:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 148.72.212.87:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 64.190.62.111:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 64.190.62.111:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 64.190.62.111:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts