NetWork | ZeroBOX

Network Analysis

IP Address Status Action
117.18.232.200 Active Moloch
164.124.101.2 Active Moloch
185.212.47.65 Active Moloch
45.155.249.172 Active Moloch
78.138.9.136 Active Moloch
79.132.130.230 Active Moloch
GET 200 http://185.212.47.65/zerotohero/CqWrYX36XwWQ_2BrhS/mzLEl4vFf/xc4vWmEcWAJ9YFRyVKFO/ttNPV1ulfC_2FpRAGEU/1GwPDdK1QdBxInNimrN51p/Z3ahmcuTfYBo7/Kaj8dPd2/9mf_2B4_2B44IFDmcnO_2Ft/cbq2K326U1/jZ5r_2FXzmP3hUR7N/1DixZEqKIs7T/V2_2B7W4R8n/ojByzLKN1qA5e2/xatnfWr5qeXVvqV9Ka_2B/7CLEyBcLLr3EDHwN/3rLPjXlm7dduxz8/TEh4z8Yn6bC8oMLEXG/lAd_2FiD0/mxl7zdJF6HzdACUwM/uWM8.asi
REQUEST
RESPONSE
GET 200 http://185.212.47.65/zerotohero/FgCIjqtD1C/AwnB0CDuorKMa8ksR/aEjpUJvisd_2/Fyx44HzwuYS/aidnq9yd8pDT0T/NgYDWyI2Ai5P5qt99QXPi/jA4E2_2Be_2Fc_2B/bWcqxXdiMKAL8KE/sbgN6r4ltId_2FpN0E/aiXKEXHHY/JjdAPnfNd6AGi1C5E1Wt/28f2aD9M9R2djADKBs7/7fthFgqmYQikGHLfwk_2BJ/LuUAzChbRGzy5/njcVwo6H/TC5tR2nJz_2FwX_2B29eAaL/7KU1y1ngiw/OR811oN4ZmZuRfEi1/bMuIgBALfI6hYvF/gvDV.asi
REQUEST
RESPONSE
GET 200 http://45.155.249.172/zerotohero/_2F9FQStc6JLbSb0Aim/PmWWdoN5TseiAoeGXSCnHb/f3siUJm7sSMxf/G9bKoZCp/ToUTRIpO5loaw7dvIdLqAPz/Y_2FdMlaiS/sRpdSgA1rXRn2REvx/OLgHjV7rVkqr/hqKS0oziEAU/o8RF8RZV1PhOYn/3_2FI28IdRnnl1Pa_2BsI/QMarYG2EhXrJaYdB/mioJ96K9ci_2BTK/nI2nf8CFXQPE62qv02/Tw141ih4C/rGxEkCJU_2FoY51LZTFZ/JDcDUjJ1Nfm3nZTbACQ/t335aBNiwUI0fSDh/WyzuLFz.asi
REQUEST
RESPONSE
GET 200 http://45.155.249.172/zerotohero/NQ4F2P317cVzNCxLOhg1F/8zo2PkPH0JNTkVQD/5KFUhh5g_2BqmC_/2F12sKc7QNCiIt8Y9Q/0gkTj71es/KP_2B3LuudW8CcWsZxc0/DZrsp9UbGxLuWnZHnIL/gpU7b2Ia1zgtxAn_2FLHVS/_2FqgZrYisxlR/kVcu_2BN/3o_2BJNwhL0UcCmviyxJN_2/FJdZ77WQgG/SpaJfTloxBssHKkJS/a_2FL7B4Vl6U/2EqyTD0mKiB/kh_2FocONHpHdL/5ewrs5O8oDLjrCJpWwXFV/RZffz9rgwAJcvl3D/uvmJZnLesLqNZl7/rdtQ8vt4wMbESjvt_/2FxX.asi
REQUEST
RESPONSE
GET 200 http://78.138.9.136/zerotohero/o3Qw3IIKAJX3J/UqAt8bW_/2BUZ0UoeiySDNS6_2FUW2wA/3hFn7Sl4kN/ftoKvV5fG4Hlj1TSU/x9EtzVflg8DH/M2gdAUaDeoM/xHn0zpZ5tqgQxS/UIfCGC7fdX4cy165VPzjU/qFkYEqLUusHWmxl1/03Oe4374cOZpI_2/BpUlT2zKKRN2ct1ni8/Kyaip_2FL/RdYQJnJxCQC9LMM9KItd/rGuDDOExo8f1GlIaTy_/2FY2axb2jutNFLTc8FH2gt/2NCOwCjYICOIB/thzeHDY5/OMSNh7TmOBdBV10AHn/U.asi
REQUEST
RESPONSE
GET 200 http://78.138.9.136/zerotohero/tVgvWq4_2/BvU_2B3JHn6rBZN_2F78/kvXaeOFxBvKlMcTqcE9/hW9zLHBjbqaNPH3AUetC7h/3jB4YK94wFnF_/2FLCTLTl/OQOh_2BEMlq9kORiGRX3UGM/4XDgo2LSPA/QU2PjXw5cS1FKeqzx/NSRV7tkllKkn/06MFyAN39Zz/4Vhliec7utGGCr/lxOgXn9vBfQjzB42cyR6M/jOG9REVRM2tybo10/JzR8Z2liDNL0xrJ/wCNgVlEXFNrLtvbD23/Ci_2BRGWl/fc1PXbvpNet_2F5vOd3J/14nskWbz3d_2F/UU9f.asi
REQUEST
RESPONSE
GET 200 http://79.132.130.230/zerotohero/h2pES8vvQ9Dvo3V/hlcSi0l1F9v5LWGLOU/lNLO_2Bf9/1ZUnyh2KkRK_2BK_2FkT/B1qvcsMLsENIIKY07e_/2BBJkDPX88nUBOmNkxpsAL/daYERlvY44cCV/bb5JGPTp/wxiwu6MqPi13_2BBhBKtdcy/2XJp_2Fubp/UWOfmfkpHbfwbD_2F/AnrdfTwDxB49/3p5ljWW0mVB/kNUkbjfVuy_2FS/gZnIixUlWrtIET_2B6yPH/BGzrFLgAm1zI1rE5/NqlChuR_2B6Px8F/XpdH_2FRUoOGbXz3eG/hUrQfJr34qTs7V_2FIaI_2/F.asi
REQUEST
RESPONSE
GET 200 http://79.132.130.230/zerotohero/Y_2FSqUCXDqJ0i_2FAiCDUu/MYNX7B7heM/GrHKHAHhAJfZZnZLY/ZUN96plx1WtO/Yh5YpB2GQS9/ytHVCw6X6Am2me/_2BZa2gFxOKYo42X_2Bis/uHG_2Bh_2FCRyy1j/HJA3PTfuKn2mM_2/Bo6tNqNWvmwJZgUS3_/2F_2B4Q6T/YQUg16lQ1UYirz_2F3Td/dSpdyVyoXNK9gGKMgaY/pdYE5MFY9TQzkXVlCy9KAT/iuujSOGfSd9zm/l99IR7CG/RCtkfs_2FtsvJqfOZpahaQ8/lJE8rw9jHb/81KiC8i2/EDCzwKNK/_2FgN.asi
REQUEST
RESPONSE
GET 200 http://79.132.130.230/zerotohero/J_2FsnJcuBz7ISKZ/7yjFKK2ZjJUJF0c/4lQRo6T1DnNr4kYV5G/lapFedOu2/PSf_2BBx3S0scfjDFFdp/sbBPjxI0AXVwXA1O_2F/w5gYNLVyDOldLOd_2FoAsp/ofci1W_2BGxqp/dSahW4x5/SD_2Bvv0dL0_2FkhXU6ldx5/83ouXZGs4J/yNzEw7V31EiOeqpr8/3s6ziH104BCw/iJDCp7r6yvM/ecSlA9BwncFOHW/KL4f0g4TikWiKFj6x01xn/JXpInaNgsXT_2Bza/fDi4X844IybUwY7/J9aoupFGv_2Bxj8SiO/adKKLFnpEvrIf2_/2FG1kLm.asi
REQUEST
RESPONSE
GET 200 http://79.132.130.230/zerotohero/mdPSIyIkqr1RaBA606yd/7lOoa9x_2F0JudJY5_2/BoI9NqeqO3W7h_2BJycshU/am8kAnvTovBLt/6GFuxlV8/Gzl_2F18zkUa4KcCypu43ZE/2IY6Vqza0M/x81isIVB6eMI72ihh/aimsSr7RxjsG/aALRWJb8SZ2/lM03TOYfbuRZmL/Tm_2FAfgkdO6imvN8FOYF/WiFzR0dhr9iymNe3/yB_2FCDb_2B_2Bx/1suMDMDn8T1iBqi7RM/677p_2Fx4/VnzhkvEcTCuWzJhcmuUD/gu0hujFj_2BFX9yMt2M/iEEoucXiRQ8gFz_2F0LbLq/Ufc4_2Fgi/XgDDD.asi
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49167 -> 185.212.47.65:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49167 -> 185.212.47.65:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49172 -> 78.138.9.136:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49172 -> 78.138.9.136:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49176 -> 79.132.130.230:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49176 -> 79.132.130.230:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49168 -> 185.212.47.65:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49168 -> 185.212.47.65:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49174 -> 79.132.130.230:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49174 -> 79.132.130.230:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49169 -> 45.155.249.172:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49169 -> 45.155.249.172:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 45.155.249.172:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 45.155.249.172:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49173 -> 79.132.130.230:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49173 -> 79.132.130.230:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected
TCP 192.168.56.101:49175 -> 79.132.130.230:80 2033203 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M1 (_2B) Malware Command and Control Activity Detected
TCP 192.168.56.101:49175 -> 79.132.130.230:80 2033204 ET MALWARE Ursnif Variant CnC Beacon - URI Struct M2 (_2F) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts