NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
35.185.181.239 Active Moloch
GET 307 http://www.getmavin.com/ad6n/?p0G=OjJsxC4geh8I7FqpHa9UrgAH/E1KMhjJ+gcNVa/pzu129pZ482obDOVio5WqFRS9BSrfkXt2&DXEXx=X6jPuRePGH0PXF8P
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49170 -> 35.185.181.239:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 35.185.181.239:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 35.185.181.239:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts