NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
45.143.201.4 Active Moloch
Name Response Post-Analysis Lookup
phila.ac.ug 45.143.201.4
GET 200 http://phila.ac.ug/azne_Rnnztqgs.bmp
REQUEST
RESPONSE
POST 200 http://phila.ac.ug/index.php
REQUEST
RESPONSE
POST 200 http://phila.ac.ug/index.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 45.143.201.4:80 2030384 ET HUNTING Suspicious Terse Request for .bmp Potentially Bad Traffic
TCP 45.143.201.4:80 -> 192.168.56.103:49165 2029138 ET MALWARE AZORult v3.3 Server Response M3 Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts