NetWork | ZeroBOX

Network Analysis

IP Address Status Action
172.67.188.154 Active Moloch
164.124.101.2 Active Moloch
198.185.159.145 Active Moloch
34.102.136.180 Active Moloch
GET 403 http://www.mavericksone.com/kzk9/?t8rpHju=rq48oJmZB+Nu8FT21DdkZ2f0m8hZKYephRx+62F2ipzmwypzXmASC0Qg8KcLbyIjdv5SQP2s&9r7T-=K4k0
REQUEST
RESPONSE
GET 400 http://www.laserobsession.com/kzk9/?t8rpHju=BoVX2CJQF+p2iHk60DuMcLQVHEJppVREEjkDd/abHZBR2v0p57VFG8usKR1c/aYG9RLvWw3m&9r7T-=K4k0
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49204 -> 198.185.159.145:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 198.185.159.145:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49204 -> 198.185.159.145:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49203 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49203 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49203 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts