NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.94.135.216 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
ahsanulalam.buet.ac.bd 103.94.135.216
POST 200 http://ahsanulalam.buet.ac.bd/bvyukiu/index.php
REQUEST
RESPONSE
POST 200 http://ahsanulalam.buet.ac.bd/bvyukiu/index.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 103.94.135.216:80 -> 192.168.56.101:49204 2029136 ET MALWARE AZORult v3.3 Server Response M1 Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts