NetWork | ZeroBOX

Network Analysis

IP Address Status Action
1.12.242.71 Active Moloch
104.168.46.107 Active Moloch
158.101.44.242 Active Moloch
164.124.101.2 Active Moloch
GET 200 http://104.168.46.107/219/vbc.exe
REQUEST
RESPONSE
GET 200 http://checkip.dyndns.org/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 104.168.46.107:80 2016141 ET INFO Executable Download from dotted-quad Host A Network Trojan was detected
TCP 192.168.56.103:49162 -> 104.168.46.107:80 2035207 ET MALWARE MSIL/GenKryptik.FQRH Download Request A Network Trojan was detected
TCP 192.168.56.103:49162 -> 104.168.46.107:80 2019714 ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile Potentially Bad Traffic
TCP 104.168.46.107:80 -> 192.168.56.103:49162 2022050 ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 A Network Trojan was detected
UDP 192.168.56.103:52760 -> 164.124.101.2:53 2042687 ET INFO DYNAMIC_DNS Query to a *.dyndns .org Domain Potentially Bad Traffic
UDP 192.168.56.103:52760 -> 164.124.101.2:53 2012758 ET INFO DYNAMIC_DNS Query to *.dyndns. Domain Misc activity
TCP 104.168.46.107:80 -> 192.168.56.103:49162 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 104.168.46.107:80 -> 192.168.56.103:49162 2022051 ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M2 A Network Trojan was detected
TCP 104.168.46.107:80 -> 192.168.56.103:49162 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 104.168.46.107:80 -> 192.168.56.103:49162 2022050 ET MALWARE Likely Evil EXE download from dotted Quad by MSXMLHTTP M1 A Network Trojan was detected
TCP 192.168.56.103:49167 -> 158.101.44.242:80 2039190 ET MALWARE 404/Snake/Matiex Keylogger Style External IP Check A Network Trojan was detected
TCP 192.168.56.103:49167 -> 158.101.44.242:80 2021378 ET POLICY External IP Lookup - checkip.dyndns.org Device Retrieving External IP Address Detected
TCP 192.168.56.103:49167 -> 158.101.44.242:80 2042688 ET INFO DYNAMIC_DNS HTTP Request to a *.dyndns .org Domain Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts