NetWork | ZeroBOX

Network Analysis

IP Address Status Action
141.8.192.151 Active Moloch
164.124.101.2 Active Moloch
58.218.215.138 Active Moloch
Name Response Post-Analysis Lookup
f0566304.xsph.ru 141.8.192.151
POST 200 http://f0566304.xsph.ru/collect.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49199 -> 141.8.192.151:80 2032531 ET HUNTING Observed POST to xsph .ru Domain Potentially Bad Traffic
TCP 192.168.56.101:49199 -> 141.8.192.151:80 2027108 ET HUNTING Suspicious Zipped Filename in Outbound POST Request (screenshot.) M2 A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts