Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 31, 2023, 10:19 p.m. | May 31, 2023, 10:21 p.m. |
-
-
svchost.exe C:\Windows\system32\svchost.exe
2752 -
svchost.exe C:\Windows\system32\svchost.exe
2820 -
svchost.exe C:\Windows\system32\svchost.exe
3036 -
svchost.exe C:\Windows\system32\svchost.exe
2264
-
IP Address | Status | Action |
---|---|---|
103.168.172.217 | Active | Moloch |
103.168.172.221 | Active | Moloch |
103.191.209.76 | Active | Moloch |
103.224.182.241 | Active | Moloch |
103.224.212.221 | Active | Moloch |
103.224.212.222 | Active | Moloch |
103.4.16.43 | Active | Moloch |
104.18.40.43 | Active | Moloch |
104.196.26.65 | Active | Moloch |
104.20.123.68 | Active | Moloch |
104.20.221.29 | Active | Moloch |
104.20.54.214 | Active | Moloch |
104.21.1.213 | Active | Moloch |
104.21.19.68 | Active | Moloch |
104.21.23.9 | Active | Moloch |
104.21.234.121 | Active | Moloch |
104.21.235.32 | Active | Moloch |
104.21.25.200 | Active | Moloch |
104.21.26.154 | Active | Moloch |
104.21.32.240 | Active | Moloch |
104.21.43.163 | Active | Moloch |
104.21.48.207 | Active | Moloch |
104.21.49.75 | Active | Moloch |
104.21.52.126 | Active | Moloch |
104.21.55.224 | Active | Moloch |
104.21.62.182 | Active | Moloch |
104.21.68.7 | Active | Moloch |
104.21.73.143 | Active | Moloch |
104.21.77.146 | Active | Moloch |
104.21.79.166 | Active | Moloch |
104.21.79.244 | Active | Moloch |
104.21.8.75 | Active | Moloch |
104.21.88.198 | Active | Moloch |
104.21.89.126 | Active | Moloch |
104.218.10.254 | Active | Moloch |
104.26.1.82 | Active | Moloch |
104.26.13.244 | Active | Moloch |
104.26.15.53 | Active | Moloch |
104.26.2.14 | Active | Moloch |
104.26.3.124 | Active | Moloch |
107.180.58.31 | Active | Moloch |
107.180.98.101 | Active | Moloch |
107.186.187.147 | Active | Moloch |
108.167.164.216 | Active | Moloch |
108.170.12.50 | Active | Moloch |
109.71.54.22 | Active | Moloch |
118.27.125.181 | Active | Moloch |
121.254.136.27 | Active | Moloch |
122.128.109.107 | Active | Moloch |
128.204.134.138 | Active | Moloch |
128.8.10.90 | Active | Moloch |
13.225.131.58 | Active | Moloch |
13.248.169.48 | Active | Moloch |
133.125.38.187 | Active | Moloch |
135.125.108.170 | Active | Moloch |
135.181.73.98 | Active | Moloch |
136.243.147.81 | Active | Moloch |
137.118.26.67 | Active | Moloch |
141.193.213.20 | Active | Moloch |
142.250.152.27 | Active | Moloch |
142.250.66.51 | Active | Moloch |
147.154.3.56 | Active | Moloch |
15.197.142.173 | Active | Moloch |
151.101.2.132 | Active | Moloch |
153.120.34.73 | Active | Moloch |
153.122.170.15 | Active | Moloch |
153.122.24.177 | Active | Moloch |
154.203.14.100 | Active | Moloch |
154.213.117.166 | Active | Moloch |
157.112.176.4 | Active | Moloch |
157.112.182.239 | Active | Moloch |
157.7.107.38 | Active | Moloch |
157.7.107.88 | Active | Moloch |
157.7.231.224 | Active | Moloch |
159.89.244.183 | Active | Moloch |
162.241.233.114 | Active | Moloch |
162.43.120.128 | Active | Moloch |
164.124.101.2 | Active | Moloch |
164.90.244.158 | Active | Moloch |
164.92.82.47 | Active | Moloch |
165.160.13.20 | Active | Moloch |
165.160.15.20 | Active | Moloch |
165.227.252.190 | Active | Moloch |
170.82.174.30 | Active | Moloch |
172.67.128.139 | Active | Moloch |
172.67.142.169 | Active | Moloch |
172.67.143.148 | Active | Moloch |
172.67.146.154 | Active | Moloch |
172.67.148.147 | Active | Moloch |
172.67.148.35 | Active | Moloch |
172.67.150.50 | Active | Moloch |
172.67.158.251 | Active | Moloch |
172.67.163.101 | Active | Moloch |
172.67.164.178 | Active | Moloch |
172.67.165.62 | Active | Moloch |
172.67.184.30 | Active | Moloch |
172.67.186.153 | Active | Moloch |
172.67.189.227 | Active | Moloch |
172.67.189.68 | Active | Moloch |
172.67.193.133 | Active | Moloch |
172.67.196.145 | Active | Moloch |
172.67.198.26 | Active | Moloch |
172.67.201.26 | Active | Moloch |
172.67.206.199 | Active | Moloch |
172.67.70.223 | Active | Moloch |
172.67.73.176 | Active | Moloch |
172.67.97.62 | Active | Moloch |
173.205.126.33 | Active | Moloch |
173.231.184.124 | Active | Moloch |
173.254.28.29 | Active | Moloch |
174.129.25.170 | Active | Moloch |
178.249.70.75 | Active | Moloch |
18.177.67.59 | Active | Moloch |
18.197.121.220 | Active | Moloch |
183.181.82.14 | Active | Moloch |
183.90.232.24 | Active | Moloch |
185.106.129.180 | Active | Moloch |
185.129.138.60 | Active | Moloch |
185.151.30.147 | Active | Moloch |
185.163.45.187 | Active | Moloch |
185.237.66.112 | Active | Moloch |
185.253.212.22 | Active | Moloch |
185.31.76.90 | Active | Moloch |
185.42.105.162 | Active | Moloch |
185.53.177.50 | Active | Moloch |
185.76.64.25 | Active | Moloch |
185.80.51.179 | Active | Moloch |
188.165.133.163 | Active | Moloch |
188.166.152.188 | Active | Moloch |
188.94.254.88 | Active | Moloch |
192.124.249.10 | Active | Moloch |
192.124.249.12 | Active | Moloch |
192.124.249.13 | Active | Moloch |
192.124.249.14 | Active | Moloch |
192.124.249.15 | Active | Moloch |
192.124.249.20 | Active | Moloch |
192.124.249.9 | Active | Moloch |
192.169.149.78 | Active | Moloch |
192.203.230.10 | Active | Moloch |
192.241.158.94 | Active | Moloch |
192.252.154.18 | Active | Moloch |
192.252.159.165 | Active | Moloch |
192.36.148.17 | Active | Moloch |
192.5.5.241 | Active | Moloch |
192.58.128.30 | Active | Moloch |
192.64.150.164 | Active | Moloch |
192.99.226.184 | Active | Moloch |
193.0.14.129 | Active | Moloch |
193.166.255.171 | Active | Moloch |
193.70.68.254 | Active | Moloch |
194.143.194.23 | Active | Moloch |
195.128.140.29 | Active | Moloch |
195.78.66.50 | Active | Moloch |
198.1.81.28 | Active | Moloch |
198.100.146.220 | Active | Moloch |
198.185.159.144 | Active | Moloch |
198.209.253.30 | Active | Moloch |
198.54.117.242 | Active | Moloch |
199.34.228.78 | Active | Moloch |
199.59.243.223 | Active | Moloch |
202.172.28.187 | Active | Moloch |
202.172.28.89 | Active | Moloch |
202.254.236.40 | Active | Moloch |
202.53.77.146 | Active | Moloch |
203.210.102.34 | Active | Moloch |
204.11.56.48 | Active | Moloch |
204.15.134.44 | Active | Moloch |
204.79.197.212 | Active | Moloch |
205.149.134.32 | Active | Moloch |
205.178.189.131 | Active | Moloch |
206.191.152.37 | Active | Moloch |
207.180.198.201 | Active | Moloch |
208.109.214.162 | Active | Moloch |
208.80.123.104 | Active | Moloch |
208.97.178.138 | Active | Moloch |
210.140.73.39 | Active | Moloch |
211.1.226.67 | Active | Moloch |
211.13.196.162 | Active | Moloch |
213.186.33.16 | Active | Moloch |
213.186.33.17 | Active | Moloch |
213.186.33.40 | Active | Moloch |
216.177.137.32 | Active | Moloch |
216.69.141.67 | Active | Moloch |
217.160.0.131 | Active | Moloch |
217.160.0.179 | Active | Moloch |
217.19.237.54 | Active | Moloch |
217.19.254.22 | Active | Moloch |
217.69.139.150 | Active | Moloch |
217.74.161.133 | Active | Moloch |
217.79.248.38 | Active | Moloch |
219.94.128.87 | Active | Moloch |
219.94.129.97 | Active | Moloch |
221.132.33.88 | Active | Moloch |
23.185.0.4 | Active | Moloch |
23.227.38.32 | Active | Moloch |
23.227.38.74 | Active | Moloch |
23.236.62.147 | Active | Moloch |
23.239.201.14 | Active | Moloch |
27.0.174.59 | Active | Moloch |
3.130.253.23 | Active | Moloch |
3.140.13.188 | Active | Moloch |
3.19.116.195 | Active | Moloch |
3.64.163.50 | Active | Moloch |
3.65.101.129 | Active | Moloch |
3.94.41.167 | Active | Moloch |
31.15.12.103 | Active | Moloch |
34.102.136.180 | Active | Moloch |
34.117.168.233 | Active | Moloch |
34.197.121.219 | Active | Moloch |
34.205.242.146 | Active | Moloch |
34.224.10.110 | Active | Moloch |
35.154.163.204 | Active | Moloch |
35.169.15.168 | Active | Moloch |
35.172.94.1 | Active | Moloch |
35.214.171.193 | Active | Moloch |
35.230.155.43 | Active | Moloch |
37.59.243.164 | Active | Moloch |
39.99.233.155 | Active | Moloch |
43.246.117.171 | Active | Moloch |
43.255.29.192 | Active | Moloch |
45.142.176.225 | Active | Moloch |
46.19.218.80 | Active | Moloch |
46.242.238.60 | Active | Moloch |
47.91.167.60 | Active | Moloch |
47.91.170.222 | Active | Moloch |
49.12.155.123 | Active | Moloch |
49.212.180.178 | Active | Moloch |
49.212.232.113 | Active | Moloch |
49.212.235.175 | Active | Moloch |
49.212.235.59 | Active | Moloch |
49.212.243.77 | Active | Moloch |
5.134.13.210 | Active | Moloch |
5.189.171.125 | Active | Moloch |
5.196.166.214 | Active | Moloch |
51.159.3.117 | Active | Moloch |
51.79.51.72 | Active | Moloch |
52.0.29.214 | Active | Moloch |
52.19.230.145 | Active | Moloch |
52.200.51.73 | Active | Moloch |
52.211.245.146 | Active | Moloch |
52.219.142.72 | Active | Moloch |
52.219.176.112 | Active | Moloch |
52.71.57.184 | Active | Moloch |
54.161.222.85 | Active | Moloch |
54.194.190.151 | Active | Moloch |
54.212.145.129 | Active | Moloch |
54.217.118.81 | Active | Moloch |
54.39.198.18 | Active | Moloch |
59.106.13.169 | Active | Moloch |
59.106.19.204 | Active | Moloch |
60.43.154.138 | Active | Moloch |
61.200.81.23 | Active | Moloch |
62.122.170.171 | Active | Moloch |
62.122.190.121 | Active | Moloch |
62.75.216.107 | Active | Moloch |
62.75.216.137 | Active | Moloch |
62.75.251.116 | Active | Moloch |
63.251.106.25 | Active | Moloch |
64.125.133.18 | Active | Moloch |
64.18.191.61 | Active | Moloch |
65.52.128.33 | Active | Moloch |
66.226.70.66 | Active | Moloch |
66.94.119.160 | Active | Moloch |
67.195.12.38 | Active | Moloch |
67.21.93.229 | Active | Moloch |
69.163.218.51 | Active | Moloch |
69.163.239.62 | Active | Moloch |
70.39.251.249 | Active | Moloch |
72.44.93.236 | Active | Moloch |
74.125.23.27 | Active | Moloch |
74.208.215.145 | Active | Moloch |
74.208.236.101 | Active | Moloch |
75.2.18.233 | Active | Moloch |
75.2.70.75 | Active | Moloch |
75.2.95.235 | Active | Moloch |
76.223.35.103 | Active | Moloch |
76.74.184.61 | Active | Moloch |
77.68.50.105 | Active | Moloch |
77.72.4.226 | Active | Moloch |
77.78.104.3 | Active | Moloch |
79.124.76.247 | Active | Moloch |
79.96.161.192 | Active | Moloch |
79.96.32.254 | Active | Moloch |
80.74.154.6 | Active | Moloch |
80.82.115.227 | Active | Moloch |
80.93.82.33 | Active | Moloch |
81.2.194.241 | Active | Moloch |
82.201.61.230 | Active | Moloch |
82.208.6.9 | Active | Moloch |
83.167.255.150 | Active | Moloch |
83.223.113.46 | Active | Moloch |
85.128.196.22 | Active | Moloch |
85.159.66.62 | Active | Moloch |
85.233.160.146 | Active | Moloch |
86.105.245.69 | Active | Moloch |
87.230.93.218 | Active | Moloch |
88.86.118.82 | Active | Moloch |
89.107.169.125 | Active | Moloch |
89.161.136.188 | Active | Moloch |
89.161.163.246 | Active | Moloch |
89.31.143.1 | Active | Moloch |
91.201.52.102 | Active | Moloch |
91.216.241.100 | Active | Moloch |
91.229.22.126 | Active | Moloch |
92.204.129.113 | Active | Moloch |
93.187.206.66 | Active | Moloch |
93.188.2.51 | Active | Moloch |
94.130.146.206 | Active | Moloch |
95.174.22.233 | Active | Moloch |
96.127.180.42 | Active | Moloch |
96.91.204.114 | Active | Moloch |
99.86.207.125 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49347 104.21.48.207:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=orlyhotel.com | e2:6a:a3:38:06:70:1a:37:9d:5b:43:8b:8b:80:2a:ca:c9:d1:f5:80 |
TLSv1 192.168.56.103:49452 91.229.22.126:443 |
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=GeoTrust RSA CA 2018 | C=PL, ST=Mazowieckie, L=Warszawa, O=Komenda Glowna Policji, CN=*.policja.gov.pl | 3d:fe:e4:18:9c:81:af:dd:a8:f5:e3:51:55:cb:6e:5e:89:7f:65:e2 |
TLSv1 192.168.56.103:49323 104.21.48.207:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=orlyhotel.com | e2:6a:a3:38:06:70:1a:37:9d:5b:43:8b:8b:80:2a:ca:c9:d1:f5:80 |
TLSv1 192.168.56.103:49462 172.67.193.133:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 28:54:2c:72:71:1b:3f:88:07:e2:1d:7b:6c:1b:7f:45:bc:7e:fe:1c |
TLSv1 192.168.56.103:49412 172.67.164.178:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=clinicasanluis.com.co | 2c:9b:70:ca:8b:31:34:df:fc:f9:d8:75:89:12:7f:09:c3:66:60:80 |
TLSv1 192.168.56.103:49441 104.21.52.126:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 04:c9:15:e0:a1:18:74:04:16:cb:98:fd:73:56:cf:7d:99:35:cb:75 |