NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
192.227.183.170 Active Moloch
23.227.38.74 Active Moloch
34.117.168.233 Active Moloch
81.15.164.73 Active Moloch
GET 200 http://192.227.183.170/mac/Vjnlyrbubz.bmp
REQUEST
RESPONSE
GET 403 http://www.hairbeaut.com/my28/?tTrt=Z/Z6Arx1VCI9n74vNfgOCtq1Nvi5iqCc3v4eVZsSpctSG3WfskTR2Rhn3Jm7D6abzFYjLyvf&1bYxY=mTft4pW
REQUEST
RESPONSE
GET 301 http://www.higano-fe2.com/my28/?tTrt=mcTUPOx97ZGy3B1+Y10xg/YclV7skAllQt7bmTx94Z4J9v14rMahHZ489fA1cRLy0Vm9O80A&1bYxY=mTft4pW
REQUEST
RESPONSE
GET 404 http://www.dublinsroofer.com/my28/?tTrt=51zqh11ZnE0J95jzs/wGDEJtELzJg9P8LLhHidBFbDs0I39E36di5y94pzpzHyK8vzrJeU0w&1bYxY=mTft4pW
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 192.227.183.170:80 2030384 ET HUNTING Suspicious Terse Request for .bmp Potentially Bad Traffic
TCP 192.168.56.103:49169 -> 23.227.38.74:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 23.227.38.74:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49169 -> 23.227.38.74:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49171 -> 81.15.164.73:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49171 -> 81.15.164.73:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49171 -> 81.15.164.73:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 34.117.168.233:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 34.117.168.233:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 34.117.168.233:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts