NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.11.173 Active Moloch
154.212.104.55 Active Moloch
164.124.101.2 Active Moloch
45.33.6.223 Active Moloch
85.159.66.93 Active Moloch
POST 301 http://www.treeremovalkingwood.com/dyeb/
REQUEST
RESPONSE
GET 301 http://www.treeremovalkingwood.com/dyeb/?2lH7=ot2zVt7gYiYVRQ9vvNmBHR7+ThDbtsc5ek8bGz74xX5U1doydBpcmiSkVy8u8MuUFpWdZPDPZrAoOHnwm5gEHBkymeZFezCBl1qs2nQ=&vVy=lpZFPvqgan42T
REQUEST
RESPONSE
GET 200 http://www.sqlite.org/2019/sqlite-dll-win32-x86-3280000.zip
REQUEST
RESPONSE
POST 0 http://www.sk676.com/dyeb/
REQUEST
RESPONSE
POST 0 http://www.sk676.com/dyeb/
REQUEST
RESPONSE
GET 200 http://www.sk676.com/dyeb/?2lH7=eRDn4OYLwGAFOe+oMCQszUCYwMg+uVi8ZbKWpPBz42pRqgBZU372Jy+dcILn2QiWfPdOhu0Hdz7kmVVrr+zaLBc9OSgj6EJ8eLn4AGY=&vVy=lpZFPvqgan42T
REQUEST
RESPONSE
POST 404 http://www.gullsteam.com/dyeb/
REQUEST
RESPONSE
POST 404 http://www.gullsteam.com/dyeb/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49171 -> 85.159.66.93:80 2031413 ET MALWARE FormBook CnC Checkin (POST) M2 Malware Command and Control Activity Detected
TCP 192.168.56.103:49173 -> 85.159.66.93:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49173 -> 85.159.66.93:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49173 -> 85.159.66.93:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 104.21.11.173:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 104.21.11.173:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 104.21.11.173:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 154.212.104.55:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 154.212.104.55:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 154.212.104.55:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49168 -> 154.212.104.55:80 2031413 ET MALWARE FormBook CnC Checkin (POST) M2 Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts