NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.132.245 Active Moloch
185.144.31.44 Active Moloch
45.147.228.207 Active Moloch
GET 200 http://api.fuck-jp.ru/url64.txt
REQUEST
RESPONSE
GET 200 http://api.fuck-jp.ru/run64.txt
REQUEST
RESPONSE
GET 200 http://down.fuck-jp.ru/redis-server.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 172.67.132.245:80 -> 192.168.56.101:49213 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 192.168.56.101:49218 -> 185.144.31.44:8888 2024792 ET POLICY Cryptocurrency Miner Checkin Potential Corporate Privacy Violation
TCP 192.168.56.101:49221 -> 185.144.31.44:8888 2024792 ET POLICY Cryptocurrency Miner Checkin Potential Corporate Privacy Violation
TCP 192.168.56.101:49217 -> 185.144.31.44:8888 2024792 ET POLICY Cryptocurrency Miner Checkin Potential Corporate Privacy Violation
TCP 192.168.56.101:49223 -> 185.144.31.44:8888 2024792 ET POLICY Cryptocurrency Miner Checkin Potential Corporate Privacy Violation
TCP 192.168.56.101:49222 -> 185.144.31.44:8888 2024792 ET POLICY Cryptocurrency Miner Checkin Potential Corporate Privacy Violation

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts