NetWork | ZeroBOX

Network Analysis

IP Address Status Action
108.170.55.202 Active Moloch
162.55.60.2 Active Moloch
164.124.101.2 Active Moloch
208.91.199.224 Active Moloch
GET 200 http://showip.net/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49167 -> 162.55.60.2:80 2008987 ET POLICY IP Check Domain (showip in HTTP Host) Attempted Information Leak
TCP 208.91.199.224:587 -> 192.168.56.103:49169 2260002 SURICATA Applayer Detect protocol only one direction Generic Protocol Command Decode

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts