NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.218.59 Active Moloch
208.91.197.39 Active Moloch
209.99.40.222 Active Moloch
GET 200 http://www.anaxita.com/dyh6/?FF=e1sV4iIAm3W+2fgt/yVAOOjF2UsGa3xT/dFBxHCILvFkdpke+8w/hijfuvnxAUXgv57PQqkt&llsp=fTRHzt4hzn4XCf
REQUEST
RESPONSE
GET 200 http://www.kathleenmock.net/dyh6/?FF=veXVV/uO8eWr4vGl5Lx83Gc/HQMwKmi+0wt1MNsVBzL0bCXgx5AM9CNKvNHpO1tgXHV/L8ov&llsp=fTRHzt4hzn4XCf
REQUEST
RESPONSE
GET 404 http://www.ximmgepn.xyz/dyh6/?FF=m7mJBtGCnG5TVc4ReSyQMy3V1N6/PuooX2bCSHJ2SWOIS/9VaOV1f0BewfqRdnYc7h+DW27G&llsp=fTRHzt4hzn4XCf
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49170 -> 172.67.218.59:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 172.67.218.59:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 172.67.218.59:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 172.67.218.59:80 2031088 ET HUNTING Request to .XYZ Domain with Minimal Headers Potentially Bad Traffic
TCP 192.168.56.103:49168 -> 209.99.40.222:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49168 -> 209.99.40.222:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49168 -> 209.99.40.222:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 208.91.197.39:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 208.91.197.39:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 208.91.197.39:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts