NetWork | ZeroBOX

Network Analysis

IP Address Status Action
107.148.132.109 Active Moloch
164.124.101.2 Active Moloch
184.154.216.162 Active Moloch
45.33.6.223 Active Moloch
GET 301 http://www.brick2theatercompany.org/jaux/?RA2Ffnn=icakqaRty6vlYpraZuLZDt8iqw6TAXaANP93WqO2tXnG28cx2yzbZzs/HE+K7qwLPazhHRQPHP7+Ft+vCQAGl34EUMiC/bZO7D7RKMw=&gLB=QULU5
REQUEST
RESPONSE
GET 200 http://www.sqlite.org/2017/sqlite-dll-win32-x86-3210000.zip
REQUEST
RESPONSE
POST 0 http://www.dwcmy.icu/jaux/
REQUEST
RESPONSE
POST 0 http://www.dwcmy.icu/jaux/
REQUEST
RESPONSE
GET 404 http://www.dwcmy.icu/jaux/?RA2Ffnn=dXzChEviWThMepFS/xxtUmXNQtBwn4KvgZ5ardr6ndysj8KT1gjetGIPwrBptW+hnPwvo+gRGgTDVleeJCFvAYnj9Conz55LaaEoVKU=&gLB=QULU5
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.102:56630 -> 164.124.101.2:53 2026888 ET INFO DNS Query for Suspicious .icu Domain Potentially Bad Traffic
TCP 192.168.56.102:49167 -> 107.148.132.109:80 2026887 ET INFO HTTP POST Request to Suspicious *.icu domain Potentially Bad Traffic
TCP 192.168.56.102:49167 -> 107.148.132.109:80 2031413 ET MALWARE FormBook CnC Checkin (POST) M2 Malware Command and Control Activity Detected
TCP 192.168.56.102:49168 -> 107.148.132.109:80 2026887 ET INFO HTTP POST Request to Suspicious *.icu domain Potentially Bad Traffic
TCP 192.168.56.102:49164 -> 184.154.216.162:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49164 -> 184.154.216.162:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49164 -> 184.154.216.162:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49169 -> 107.148.132.109:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49169 -> 107.148.132.109:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.102:49169 -> 107.148.132.109:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts