NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
188.68.205.12 Active Moloch
208.95.112.1 Active Moloch
5.188.119.76 Active Moloch
54.161.74.126 Active Moloch
54.86.152.187 Active Moloch
GET 200 http://checkip.amazonaws.com/
REQUEST
RESPONSE
GET 200 http://ip-api.com/json/175.208.134.150
REQUEST
RESPONSE
GET 200 http://checkip.amazonaws.com/
REQUEST
RESPONSE
GET 200 http://ip-api.com/json/175.208.134.150
REQUEST
RESPONSE
GET 200 http://5.188.119.76/updhdl?method=get
REQUEST
RESPONSE
GET 200 http://5.188.119.76/updhdl?method=get
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49167 -> 208.95.112.1:80 2022082 ET POLICY External IP Lookup ip-api.com Device Retrieving External IP Address Detected
TCP 192.168.56.101:49176 -> 208.95.112.1:80 2022082 ET POLICY External IP Lookup ip-api.com Device Retrieving External IP Address Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts