NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.169.14 Active Moloch
Name Response Post-Analysis Lookup
fareits.com 172.67.169.14
HEAD 403 http://fareits.com/76.exe
REQUEST
RESPONSE
GET 403 http://fareits.com/76.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49171 -> 172.67.169.14:80 2022482 ET MALWARE JS/Nemucod requesting EXE payload 2016-02-01 A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts