NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
2.59.254.18 Active Moloch
34.102.136.180 Active Moloch
38.53.14.81 Active Moloch
94.156.6.225 Active Moloch
GET 200 http://2.59.254.18/_errorpages/defounderzx.exe
REQUEST
RESPONSE
GET 200 http://www.sdxgwnkf.cfd/fd62/?JjUdE2=ghnUtiMEyEw2O5h1P7vo9Byhe/usWh543+65PpmWc9PRh4YewV0BtpdKaxjHtlCT/jMo+a/V&t8o=FrFL&sql=1
REQUEST
RESPONSE
POST 0 http://www.sdxgwnkf.cfd/fd62/
REQUEST
RESPONSE
POST 0 http://www.sdxgwnkf.cfd/fd62/
REQUEST
RESPONSE
GET 403 http://www.soc34m.com/fd62/?JjUdE2=xn0HKfGIZzHBtebtM2PJoTiRmP7tmvS0K83HwlewIFGHtZl2UfwiPMnZWATjhy2Ku2mJdV27&t8o=FrFL&sql=1
REQUEST
RESPONSE
POST 0 http://www.soc34m.com/fd62/
REQUEST
RESPONSE
POST 0 http://www.soc34m.com/fd62/
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
192.168.56.103 164.124.101.2 3
192.168.56.103 164.124.101.2 3

IRC traffic

No IRC requests performed.

Snort Alerts

No Snort Alerts