NetWork | ZeroBOX

Network Analysis

IP Address Status Action
151.101.128.119 Active Moloch
164.124.101.2 Active Moloch
50.87.175.234 Active Moloch
GET 301 http://www.rooferseeker.com/fkt8/?U0DH=EUKcnevpoIFYjcsRmAGwn3c0LWoZ/fq5OZCSty5/9j3SIgqd6FToqOn+bDwDAegpVR+I12Fn&Ufux_8=0T0lqHm
REQUEST
RESPONSE
GET 301 http://www.evcopic.xyz/fkt8/?U0DH=l51O+Y4cCKvDB3Sz1r4GeqolGx4DEwR6GImuEnTKGI0l9KX+rdpTwi+K0qPg0BpuxfSCIkO7&Ufux_8=0T0lqHm
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49167 -> 151.101.128.119:80 2031088 ET HUNTING Request to .XYZ Domain with Minimal Headers Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts