NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.210.34 Active Moloch
209.17.116.163 Active Moloch
23.227.38.74 Active Moloch
98.137.244.37 Active Moloch
GET 404 http://www.gardeniaresort.com/nk6l/?AjR=6/L4S21g8RxaMOTPSfOWzfLlNnBIzAq4oR6J+9+RtmoRzP6TihvPvjh2BMZgYhIfV2DHyUbE&KtkPc=Ab805b4ps2kTRvUp
REQUEST
RESPONSE
GET 404 http://www.createacarepack.com/nk6l/?AjR=oZdYOW+6uh2zuK8xWj0B160nPucVBdi4gaKHGG9IIOI6c6Yjw1TqFMfqhZNBk2mWOnf10lQ/&KtkPc=Ab805b4ps2kTRvUp
REQUEST
RESPONSE
GET 0 http://www.gigasupplies.com/nk6l/?AjR=sMbkpEIa78TqkLB5rpiwDTFtc4P6BDcndICnHPV2jTzFq+m6JFJtgH1maSSXDo0SxR7/Ebcw&KtkPc=Ab805b4ps2kTRvUp
REQUEST
RESPONSE
GET 400 http://www.rthearts.com/nk6l/?AjR=aQJ/5obTpOHNVgnCvNgrcEt00DsX5EewgNz5JOfO7ljBuP/TG6sC4VyDa90vv4w4T6a/FBxt&KtkPc=Ab805b4ps2kTRvUp
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49167 -> 98.137.244.37:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49167 -> 98.137.244.37:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49167 -> 98.137.244.37:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49168 -> 23.227.38.74:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49168 -> 23.227.38.74:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49168 -> 23.227.38.74:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49166 -> 172.67.210.34:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49166 -> 172.67.210.34:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49166 -> 172.67.210.34:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49169 -> 209.17.116.163:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49169 -> 209.17.116.163:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49169 -> 209.17.116.163:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts