NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
23.105.131.228 Active Moloch
31.3.244.76 Active Moloch
GET 200 http://itisalllove.servepics.com/georgia/city/reason.exe
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.103:58465 -> 164.124.101.2:53 2028698 ET POLICY DNS Query to DynDNS Domain *.servepics .com Potentially Bad Traffic
TCP 31.3.244.76:80 -> 192.168.56.103:49168 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
UDP 192.168.56.103:63128 -> 8.8.8.8:53 2028677 ET POLICY DNS Query to DynDNS Domain *.3utilities .com Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts