NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.22.18.188 Active Moloch
164.124.101.2 Active Moloch
172.217.25.14 Active Moloch
172.67.9.138 Active Moloch
Name Response Post-Analysis Lookup
icanhazip.com 104.22.19.188
GET 200 http://icanhazip.com/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49809 -> 172.67.9.138:80 2017398 ET POLICY IP Check Domain (icanhazip. com in HTTP Host) Attempted Information Leak

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts