NetWork | ZeroBOX

Network Analysis

IP Address Status Action
15.197.142.173 Active Moloch
164.124.101.2 Active Moloch
192.185.174.189 Active Moloch
38.40.165.98 Active Moloch
91.234.46.212 Active Moloch
GET 200 http://msspaper.cf/g/Wdxvm_Hftibzaj.jpg
REQUEST
RESPONSE
GET 403 http://www.watchmyreview.com/s4s9/?O2Jtm6=pO4G8F5XhHdgoakjO+KbcMdVhIQvAJuaWdxwbDKeC5pGjwTJDCRMpSlcGnLuwLUEIuWN8tJd&nH=IBZX4lehiRzP
REQUEST
RESPONSE
GET 301 http://www.putovanjazasve.com/s4s9/?O2Jtm6=GJbS3NWQNS4Cv8Qcz6xHMdWkYSsxKn7XewBXM8M8Fia8SvRFCTv0AWSgpADKdBznsVNcPc89&nH=IBZX4lehiRzP
REQUEST
RESPONSE
GET 200 http://www.mb314.com/s4s9/?O2Jtm6=nDxabHWVYTlrTQ5oFUVlf+yaMH/xzZN5UT/OalRp/RO99Ug0nsP5MYzlSzrasbtJ0Ral5wP1&nH=IBZX4lehiRzP
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.101:55871 -> 164.124.101.2:53 2025107 ET INFO DNS Query for Suspicious .cf Domain Potentially Bad Traffic
TCP 192.168.56.101:49162 -> 192.185.174.189:80 2031092 ET HUNTING Request to .CF Domain with Minimal Headers Potentially Bad Traffic
TCP 192.168.56.101:49170 -> 15.197.142.173:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49171 -> 91.234.46.212:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 15.197.142.173:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49171 -> 91.234.46.212:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49171 -> 91.234.46.212:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 15.197.142.173:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49172 -> 38.40.165.98:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49172 -> 38.40.165.98:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49172 -> 38.40.165.98:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts