NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.216.104 Active Moloch
178.128.124.245 Active Moloch
3.133.163.136 Active Moloch
GET 301 http://www.terrasombrafarms.com/m3n0/?kxl0drr=Lll3djfmpqf4gVsKwJ7EBNIIhBMOoCJsh2K73HLJEVynFnO3uZpJKx+f/nkW8ApCIX9e9JyW&jBZ4=KneX-
REQUEST
RESPONSE
GET 404 http://www.yourvert.com/m3n0/?kxl0drr=p+Rf1CG7FauHpJE9Y14QZTSs7HiMaFYzpVM6h2kAD3Nie/rbK1Hom73EVwMq0sJBPNaGWXc5&jBZ4=KneX-
REQUEST
RESPONSE
GET 301 http://www.ubique.works/m3n0/?kxl0drr=XY3fYCvwORbGPxtSxSQVDy8D/DgP/Q6U0jLqL/9Ze9Gbp745YUdIHr8LMFFepVyh6OzcG5cB&jBZ4=KneX-
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49205 -> 172.67.216.104:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 178.128.124.245:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49205 -> 172.67.216.104:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 178.128.124.245:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49205 -> 172.67.216.104:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49207 -> 178.128.124.245:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 3.133.163.136:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 3.133.163.136:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49206 -> 3.133.163.136:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts