NetWork | ZeroBOX

Network Analysis

IP Address Status Action
108.62.118.124 Active Moloch
117.18.232.200 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.
GET 200 http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
173.208.126.13 192.168.56.103 3
173.208.126.13 192.168.56.103 3
173.208.126.13 192.168.56.103 3
173.208.126.17 192.168.56.103 3
173.208.126.17 192.168.56.103 3
173.208.126.17 192.168.56.103 3
173.208.126.17 192.168.56.103 3
173.208.126.17 192.168.56.103 3
173.208.126.17 192.168.56.103 3

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49165 -> 108.62.118.124:443 2404301 ET CNC Feodo Tracker Reported CnC Server group 2 A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts