NetWork | ZeroBOX

Network Analysis

IP Address Status Action
128.140.35.86 Active Moloch
118.107.7.166 Active Moloch
193.134.208.217 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.
GET 200 http://118.107.7.166/azu/64.bin
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49162 -> 118.107.7.166:80 2018052 ET MALWARE Zbot Generic URI/Header Struct .bin A Network Trojan was detected
TCP 192.168.56.101:49162 -> 118.107.7.166:80 2018752 ET MALWARE Generic .bin download from Dotted Quad A Network Trojan was detected
TCP 118.107.7.166:80 -> 192.168.56.101:49162 2045860 ET HUNTING Rejetto HTTP File Sever Response A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts