NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
192.3.243.150 Active Moloch
198.12.119.208 Active Moloch
Name Response Post-Analysis Lookup
serverftp.online 198.12.119.208
GET 200 http://192.3.243.150/windows/n/IE_NET.vbs
REQUEST
RESPONSE
GET 200 http://serverftp.online/imgs/bat_native.jpeg
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49162 -> 192.3.243.150:80 2027260 ET INFO Dotted Quad Host VBS Request Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts