NetWork | ZeroBOX

Network Analysis

IP Address Status Action
142.250.66.83 Active Moloch
164.124.101.2 Active Moloch
192.64.113.210 Active Moloch
34.102.136.180 Active Moloch
50.62.172.157 Active Moloch
91.195.240.94 Active Moloch
GET 403 http://www.newstodayupdate.com/b2c0/?FVWt=ngE3zTESEmF1TlzaI1JtRqVv6LVi69c0ageAEF+ggQEJgbQkBMu6yGJsOdi7lkxHgRVmVRi9&uRmXV=kjFPdLKXqZLtWb
REQUEST
RESPONSE
GET 301 http://www.vi88.info/b2c0/?FVWt=9nW/OVHQ1XpTvpMusTdL+d4k59iYmTaoVhYIWL8vz0e2o7OkRPl/Jeq3QN9xrgEGq3IVy9cv&uRmXV=kjFPdLKXqZLtWb
REQUEST
RESPONSE
GET 301 http://www.hi-loentertainment.com/b2c0/?FVWt=h+tO3E4hFG1yu4TvmYvKfGb/NE9o5KfVZIH68S7yQPQpykMulMHmlhWQj/t5Jr0vsQ0T8HVV&uRmXV=kjFPdLKXqZLtWb
REQUEST
RESPONSE
GET 301 http://www.miaintervista.com/b2c0/?FVWt=U8O6kRJAqCrKAzN8h3rSiV6YS3+F71/8oy2ywOxlTPPEAAUY03Ods+UYspTxL8ni9w1lhzNG&uRmXV=kjFPdLKXqZLtWb
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49172 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49172 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49172 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49173 -> 142.250.66.83:80 2221045 SURICATA HTTP Unexpected Request body Generic Protocol Command Decode
TCP 192.168.56.103:49174 -> 192.64.113.210:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49174 -> 192.64.113.210:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49174 -> 192.64.113.210:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49175 -> 50.62.172.157:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49175 -> 50.62.172.157:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49175 -> 50.62.172.157:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts