NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.247.82.91 Active Moloch
154.85.239.101 Active Moloch
164.124.101.2 Active Moloch
31.184.217.9 Active Moloch
91.184.0.100 Active Moloch
GET 404 http://www.hatterascharters.com/s26y/?xVJtG4Th=cvNALa4IK27Ro6rtXOeXYUfpmrm3HoImnwXbSTSK6JETCyzPBx85LajqaSCh8zKc7b3z2v0K&1bw=L6Adp0nXjfjLdR2p
REQUEST
RESPONSE
GET 301 http://www.nikol-beauty.ru/s26y/?xVJtG4Th=zNa4SwDr0KBpy31l5KYIDaXbaS4SRxFhmO4CadMaCoCUEqg240jhfCVWHeE/FLPBCdnN9g63&1bw=L6Adp0nXjfjLdR2p
REQUEST
RESPONSE
GET 403 http://www.drain-pipe-cleaning-81784.com/s26y/?xVJtG4Th=xifof8+AcnXYXdMQ3P6+Gp6nTFK1K7BHbiRnlOZOb5nZkb3/gR0wuwfXLP1X2cmFaGUzIp/v&1bw=L6Adp0nXjfjLdR2p
REQUEST
RESPONSE
GET 404 http://www.thereallifeguild.app/s26y/?xVJtG4Th=ztcHOa7slkLvMVmIwFVD+MxqaM7ohUfwpwKohan9eDFMAOiKstevJtoFNxACBjZ48g0ugAFk&1bw=L6Adp0nXjfjLdR2p
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49168 -> 104.247.82.91:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49168 -> 104.247.82.91:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49167 -> 31.184.217.9:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49168 -> 104.247.82.91:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49167 -> 31.184.217.9:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49167 -> 31.184.217.9:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 91.184.0.100:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 91.184.0.100:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 91.184.0.100:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 154.85.239.101:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 154.85.239.101:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 154.85.239.101:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts