NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
177.106.216.53 Active Moloch
79.110.49.55 Active Moloch
GET 200 http://cryptersandtools.minhacasa.tv/e/e
REQUEST
RESPONSE
GET 200 http://79.110.49.55/aby.txt
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 79.110.49.55:80 -> 192.168.56.101:49166 2020425 ET EXPLOIT_KIT Unknown EK Landing Feb 16 2015 b64 3 M1 Exploit Kit Activity Detected
TCP 177.106.216.53:80 -> 192.168.56.101:49165 2029538 ET HUNTING EXE Base64 Encoded potential malware Misc activity

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts