NetWork | ZeroBOX

Network Analysis

IP Address Status Action
123.206.44.194 Active Moloch
162.255.119.118 Active Moloch
164.124.101.2 Active Moloch
34.102.136.180 Active Moloch
34.80.190.141 Active Moloch
POST 0 http://www.viruswaarheid.club/p1nr/
REQUEST
RESPONSE
GET 302 http://www.viruswaarheid.club/p1nr/?AjR=5bJlupc6xb34bDBlIcNCs6/s3CZhfCPrV+jvRTcCmGNXsfZOWTkNxEbjIRjoEINWuvjAhau8&njn8dT=9rt0FPEHohgT
REQUEST
RESPONSE
POST 405 http://www.aaliyahchhabra.com/p1nr/
REQUEST
RESPONSE
GET 403 http://www.aaliyahchhabra.com/p1nr/?AjR=Od7bmnq1WRFk76F1ogkU4Mi+HONosEbzYL+WP8P50nM5a3VF2POZT1SyF5qsPepAKH1aqMJk&njn8dT=9rt0FPEHohgT
REQUEST
RESPONSE
POST 0 http://www.roq.media/p1nr/
REQUEST
RESPONSE
GET 0 http://www.roq.media/p1nr/?AjR=U3lPnqGjwXsrwhyp5sFY7nRVaxZeJb2XQUDL3p9c1JxeBujj/xnCy1hFpAyiVGcEQaCdUYMf&njn8dT=9rt0FPEHohgT
REQUEST
RESPONSE
POST 0 http://www.cydip.com/p1nr/
REQUEST
RESPONSE
GET 404 http://www.cydip.com/p1nr/?AjR=ZGaWET/m5aRCM9pakCj6ctG5V4spLUeE07bass/N5tQ/1dOLPCE7TRyiJFuh9iNzw4wcgE0D&njn8dT=9rt0FPEHohgT
REQUEST
RESPONSE
POST 405 http://www.unlimitedfp.com/p1nr/
REQUEST
RESPONSE
GET 403 http://www.unlimitedfp.com/p1nr/?AjR=ck6tzDHMirLRaCF0a9F3iHlzRV0lrjZg5pC5jzBkRAU3dlywyeIgUh5ApEd5/gzrFW3zzC5E&njn8dT=9rt0FPEHohgT
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49208 -> 34.80.190.141:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 34.80.190.141:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49208 -> 34.80.190.141:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 162.255.119.118:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 162.255.119.118:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 162.255.119.118:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49210 -> 123.206.44.194:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49210 -> 123.206.44.194:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49210 -> 123.206.44.194:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49212 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49212 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49212 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts