NetWork | ZeroBOX

Network Analysis

IP Address Status Action
121.78.88.79 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
miracle.designsoup.co.kr 121.78.88.79
GET 404 http://miracle.designsoup.co.kr/user/views/resort/controller/css/update/list.php?query=1
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49165 -> 121.78.88.79:80 2033012 ET MALWARE Suspected Kimsuky Activity (GET) A Network Trojan was detected
TCP 192.168.56.102:49165 -> 121.78.88.79:80 2033597 ET MALWARE Kimsuky Related Script Activity (GET) A Network Trojan was detected
TCP 192.168.56.102:49165 -> 121.78.88.79:80 2045182 ET MALWARE Suspected DPRK APT Related Activity (GET) A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts