NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
192.169.223.13 Active Moloch
34.215.222.250 Active Moloch
51.254.41.57 Active Moloch
99.83.162.16 Active Moloch
POST 301 http://www.dreamcashbuyers.com/p2io/
REQUEST
RESPONSE
GET 301 http://www.dreamcashbuyers.com/p2io/?OH2LRV=H0m9fF/7YLmrrfUIC4653EpAABAppk+gPA36EdDaEoCMlE2zCVYj52aQtiOQLLDBcMq8ZjGa&_jqp3=mvRxvPC0EdzH
REQUEST
RESPONSE
POST 200 http://www.sonderbach.net/p2io/
REQUEST
RESPONSE
GET 200 http://www.sonderbach.net/p2io/?OH2LRV=2ax3GqWpRrSdWZvs+TKAK3bdHNL66UJyZbfAdtPO/FaZGfOa/v3aE89kJzgFOPU2QDwHTbD5&_jqp3=mvRxvPC0EdzH
REQUEST
RESPONSE
POST 0 http://www.zmzcrossrt.xyz/p2io/
REQUEST
RESPONSE
GET 301 http://www.zmzcrossrt.xyz/p2io/?OH2LRV=tbodHACq9TgEm1QCflemmH955SxRRtof3zi2445TBfF16F/HFiIOFPSeH8a5z8Uvje9sxZdT&_jqp3=mvRxvPC0EdzH
REQUEST
RESPONSE
POST 503 http://www.centergolosinas.com/p2io/
REQUEST
RESPONSE
GET 400 http://www.centergolosinas.com/p2io/?OH2LRV=r2GsjHfE9bHmJvLFmfqM84hqAY3LnZYXU2evLvxsfUtrrcQFCKudTC+PxzRKMZm48G9NrLWy&_jqp3=mvRxvPC0EdzH
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
192.168.56.101 164.124.101.2 3
192.168.56.101 164.124.101.2 3
192.168.56.101 164.124.101.2 3
192.168.56.101 164.124.101.2 3
192.168.56.101 164.124.101.2 3
192.168.56.101 164.124.101.2 3

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49211 -> 99.83.162.16:80 2031088 ET HUNTING Request to .XYZ Domain with Minimal Headers Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts