NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.28.91.20 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
www.mymatam.com
CNAME mymatam.com
103.28.91.20
GET 301 http://www.mymatam.com/fg58/?KzrtE=WpDF5rR8GhL85HDW55HvY2UzFumc4+CxavBF5rgmPNYEZf40Rr2HPxuZ1925OstCFu5iCPlj&p0G=kJEPdT4hIPU4hj
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49167 -> 103.28.91.20:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49167 -> 103.28.91.20:80 2031449 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49167 -> 103.28.91.20:80 2031453 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts