NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.133.111.149 Active Moloch
164.124.101.2 Active Moloch
78.129.249.105 Active Moloch
GET 200 http://103.133.111.149/Gee_remcos%202020_eborUv118.bin
REQUEST
RESPONSE
GET 200 http://103.133.111.149/Gee_remcos%202020_eborUv118.bin
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49208 -> 103.133.111.149:80 2018752 ET MALWARE Generic .bin download from Dotted Quad A Network Trojan was detected
TCP 192.168.56.101:49202 -> 103.133.111.149:80 2018752 ET MALWARE Generic .bin download from Dotted Quad A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts