NetWork | ZeroBOX

Network Analysis

IP Address Status Action
185.195.237.203 Active Moloch
162.55.60.2 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
showip.net 162.55.60.2
GET 200 http://showip.net/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49173 -> 162.55.60.2:80 2008987 ET POLICY IP Check Domain (showip in HTTP Host) Attempted Information Leak

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts