NetWork | ZeroBOX

Network Analysis

IP Address Status Action
154.221.19.146 Active Moloch
164.124.101.2 Active Moloch
39.109.117.57 Active Moloch
GET 200 http://us.imgjeoigaa.com/sts/imagc.jpg
REQUEST
RESPONSE
GET 200 http://as.imgjeoigaa.com/check/safe
REQUEST
RESPONSE
POST 200 http://as.imgjeoigaa.com/check/?sid=842934&key=941465ecfb3fb7d6fe5d647e70e67cf6
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49165 -> 39.109.117.57:80 2045057 ET MALWARE Win32/Fabookie.ek CnC Request M4 (GET) A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts