NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
222.139.155.85 Active Moloch
45.122.138.54 Active Moloch
Name Response Post-Analysis Lookup
www.152cs.com 222.139.155.85
GET 200 http://45.122.138.54/ads/4.jpg
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49200 -> 45.122.138.54:80 2008974 ET ADWARE_PUP User-Agent (Mozilla/4.0 (compatible)) Possibly Unwanted Program Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts