Network Analysis
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
No traffic
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.101:49171 -> 139.196.72.155:8080 | 2404304 | ET CNC Feodo Tracker Reported CnC Server group 5 | A Network Trojan was detected |
TCP 192.168.56.101:49170 -> 194.9.172.107:8080 | 2404311 | ET CNC Feodo Tracker Reported CnC Server group 12 | A Network Trojan was detected |
TCP 192.168.56.101:49171 -> 139.196.72.155:8080 | 2028401 | ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex | Unknown Traffic |
TCP 192.168.56.101:49172 -> 139.196.72.155:8080 | 2028401 | ET JA3 Hash - Possible Malware - Various Trickbot/Kovter/Dridex | Unknown Traffic |
TCP 139.196.72.155:8080 -> 192.168.56.101:49173 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
No Snort Alerts