NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
5.61.61.168 Active Moloch
65.21.105.85 Active Moloch
81.177.141.85 Active Moloch
Name Response Post-Analysis Lookup
ne.komaiasowu.ru 81.177.141.85
GET 200 http://ne.komaiasowu.ru/
REQUEST
RESPONSE
GET 404 http://65.21.105.85/barell.exe
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
81.177.141.85 192.168.56.102 3

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49169 -> 65.21.105.85:80 2016141 ET INFO Executable Download from dotted-quad Host A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts