NetWork | ZeroBOX

Network Analysis

IP Address Status Action
103.100.211.218 Active Moloch
154.221.26.108 Active Moloch
164.124.101.2 Active Moloch
GET 200 http://us.imgjeoigaa.com/sts/imagc.jpg
REQUEST
RESPONSE
GET 200 http://aa.imgjeoogbb.com/check/safe
REQUEST
RESPONSE
POST 200 http://aa.imgjeoogbb.com/check/?sid=144266&key=9905c940269e74e12bc7b18ce6ca2d14
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49165 -> 154.221.26.108:80 2045057 ET MALWARE Win32/Fabookie.ek CnC Request M4 (GET) A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts