NetWork | ZeroBOX

Network Analysis

IP Address Status Action
154.197.176.84 Active Moloch
154.219.108.206 Active Moloch
155.159.13.39 Active Moloch
164.124.101.2 Active Moloch
GET 0 http://www.beniciabounce.com/ad6n/?5jUh=kzNXO8h1YN8AnvLHP5I8oYX1yHVe/anvSlt/z5s+jU3gUMQMHOhWJ++fuKIVbMy+UledLqNp&llxh=fTRld0QHk6980Xw
REQUEST
RESPONSE
GET 0 http://www.hxmgzczqdjs.com/ad6n/?5jUh=fERXM8BJAu/IsM9mOMSiABCKY4GsMiltugzIMIAPwKVu+54ym+ZIFqEd+CwLvF9uLqup/TTt&llxh=fTRld0QHk6980Xw
REQUEST
RESPONSE
GET 200 http://www.xxtjzmzzahg.com/ad6n/?5jUh=23Z2wFDgg6sCIHfc5XotNYOEpQGPtTRL3ouFqY3HDbJJRkAwKbwLBMp1Xtqmt5aYA+1GJlFq&llxh=fTRld0QHk6980Xw
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 155.159.13.39:80 -> 192.168.56.103:49166 2400015 ET DROP Spamhaus DROP Listed Traffic Inbound group 16 Misc Attack
TCP 192.168.56.103:49166 -> 155.159.13.39:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 155.159.13.39:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 155.159.13.39:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49165 -> 154.219.108.206:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49165 -> 154.219.108.206:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49165 -> 154.219.108.206:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49164 -> 154.197.176.84:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49164 -> 154.197.176.84:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49164 -> 154.197.176.84:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts