NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
171.103.189.118 Active Moloch
179.42.137.104 Active Moloch
179.42.137.106 Active Moloch
18.139.111.104 Active Moloch
202.183.12.124 Active Moloch
27.50.163.123 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.

No traffic

ICMP traffic

Source Destination ICMP Type Data
45.172.196.46 192.168.56.101 11
45.172.196.46 192.168.56.101 11
45.172.196.46 192.168.56.101 11
45.172.196.46 192.168.56.101 11
45.172.196.46 192.168.56.101 11
45.172.196.46 192.168.56.101 11

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49206 -> 202.183.12.124:443 2028401 ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex Unknown Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts