NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.45.72 Active Moloch
164.124.101.2 Active Moloch
172.67.143.39 Active Moloch
GET 200 http://collector-node.us/u
REQUEST
RESPONSE
POST 200 http://collector-gate03.xyz/collect.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49201 -> 104.21.45.72:80 2027108 ET HUNTING Suspicious Zipped Filename in Outbound POST Request (screenshot.) M2 A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts