NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.21.221 Active Moloch
172.67.200.215 Active Moloch
164.124.101.2 Active Moloch
172.67.167.212 Active Moloch
Name Response Post-Analysis Lookup
utorrent-servers.xyz 172.67.167.212
GET 200 http://utorrent-servers.xyz/ABCD1234.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49200 -> 172.67.167.212:80 2022896 ET HUNTING SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 A Network Trojan was detected
TCP 192.168.56.101:49200 -> 172.67.167.212:80 2031088 ET HUNTING Request to .XYZ Domain with Minimal Headers Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts