NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
193.122.6.168 Active Moloch
198.46.174.164 Active Moloch
GET 200 http://198.46.174.164/118/vbc.exe
REQUEST
RESPONSE
GET 200 http://checkip.dyndns.org/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 198.46.174.164:80 2016141 ET INFO Executable Download from dotted-quad Host A Network Trojan was detected
TCP 192.168.56.103:49162 -> 198.46.174.164:80 2035207 ET MALWARE MSIL/GenKryptik.FQRH Download Request A Network Trojan was detected
TCP 192.168.56.103:49162 -> 198.46.174.164:80 2019714 ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile Potentially Bad Traffic
TCP 198.46.174.164:80 -> 192.168.56.103:49162 2022050 ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 A Network Trojan was detected
TCP 192.168.56.103:49169 -> 193.122.6.168:80 2039190 ET MALWARE 404/Snake/Matiex Keylogger Style External IP Check A Network Trojan was detected
TCP 192.168.56.103:49169 -> 193.122.6.168:80 2021378 ET POLICY External IP Lookup - checkip.dyndns.org Device Retrieving External IP Address Detected
TCP 192.168.56.103:49169 -> 193.122.6.168:80 2042688 ET INFO DYNAMIC_DNS HTTP Request to a *.dyndns .org Domain Potentially Bad Traffic
TCP 198.46.174.164:80 -> 192.168.56.103:49162 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 198.46.174.164:80 -> 192.168.56.103:49162 2022051 ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M2 A Network Trojan was detected
TCP 198.46.174.164:80 -> 192.168.56.103:49162 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
UDP 192.168.56.103:52760 -> 164.124.101.2:53 2042687 ET INFO DYNAMIC_DNS Query to a *.dyndns .org Domain Potentially Bad Traffic
UDP 192.168.56.103:52760 -> 164.124.101.2:53 2012758 ET INFO DYNAMIC_DNS Query to *.dyndns. Domain Misc activity

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts