NetWork | ZeroBOX

Network Analysis

IP Address Status Action
107.178.245.252 Active Moloch
162.241.224.131 Active Moloch
164.124.101.2 Active Moloch
184.168.131.241 Active Moloch
GET 301 http://www.liveyourmaverick.com/gz92/?wPT=GT0v1A3P0Wo01tn8aEVPdEKMGa27ABb6rwCD6aQ3acm9u+/FCvMWQnF1J5nq1GrsfOQ/roqE&oXN=6lXd02jp
REQUEST
RESPONSE
GET 301 http://www.benvenutoqui.com/gz92/?wPT=2wbwf/0XTDTlOy+JXK0H3VKZklYIa6iQS9nAdKl5Qbk+iaYvuq4CQJRQa05WJzSTgPcgyDfZ&oXN=6lXd02jp
REQUEST
RESPONSE
GET 301 http://www.mcgrudersfitness.com/gz92/?wPT=HdqjPEY9Rfu+aEeJAE6UNHawoElrodkwHbiBzE2NkYUOKlxn2k/XZs7wlcf35PTHZbYJ5c6F&oXN=6lXd02jp
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49204 -> 162.241.224.131:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 162.241.224.131:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 162.241.224.131:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49203 -> 107.178.245.252:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49203 -> 107.178.245.252:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49203 -> 107.178.245.252:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49205 -> 184.168.131.241:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49205 -> 184.168.131.241:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49205 -> 184.168.131.241:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts