NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
23.227.38.74 Active Moloch
3.130.204.160 Active Moloch
34.102.136.180 Active Moloch
GET 403 http://www.thetickettruth.com/h3ha/?rV0DUb=0N4LokR9uiCoW7aRFco7zu6jSnArZAq/LdT3uUKltClmieJVsMX6zSQ0xE4ZJOTIuweed6/v&LvyX=oPqLWR
REQUEST
RESPONSE
GET 403 http://www.ninideal.com/h3ha/?rV0DUb=l48G0yINaYxqgykaZFR0+o6y+2Gncfxsk7XllhJUaLsbGJX4pYEG8eHhbMKu/vO3tGLkH7iz&LvyX=oPqLWR
REQUEST
RESPONSE
GET 302 http://www.lawnforcement.com/h3ha/?rV0DUb=uxyndyQPaEDVD5l1zaL85Yr6gdU9jXMbCquiDZq5iAsqBDW/y4tuDCOehvkX+wxi0vATA7Ae&LvyX=oPqLWR
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49171 -> 3.130.204.160:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49171 -> 3.130.204.160:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49171 -> 3.130.204.160:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 23.227.38.74:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 23.227.38.74:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 23.227.38.74:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49167 -> 34.102.136.180:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49167 -> 34.102.136.180:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49167 -> 34.102.136.180:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts