NetWork | ZeroBOX

Network Analysis

IP Address Status Action
136.243.102.227 Active Moloch
162.0.239.145 Active Moloch
164.124.101.2 Active Moloch
2.59.254.18 Active Moloch
45.33.6.223 Active Moloch
64.225.91.73 Active Moloch
GET 200 http://2.59.254.18/_errorpages/ghostzx.exe
REQUEST
RESPONSE
POST 200 http://www.local-masterfab.pro/m6vg/
REQUEST
RESPONSE
GET 200 http://www.sqlite.org/2017/sqlite-dll-win32-x86-3190000.zip
REQUEST
RESPONSE
GET 200 http://www.local-masterfab.pro/m6vg/?3e4VFiK=qlsSz55dMEDh80zakVPbHjaF8j4oNypzrjIj/nO5OsiiIMQ4OCb3eb3/aciAfJPzlTtsA232D702JdziOuhcEJIUeFVyn6zrybpmvBo=&FFb=fqnK4mKb5F
REQUEST
RESPONSE
POST 404 http://www.sonokiz.xyz/m6vg/
REQUEST
RESPONSE
GET 404 http://www.sonokiz.xyz/m6vg/?3e4VFiK=OU8I4t4PJh7jLwKM8g7zNLnIXKzFYO4EOKNLYn2/07El/+gDHE38bA7ufp76Z7q9f8ZNVj+wQy/7gIPBvltigVtQEDdIb2L6NYl27Fw=&FFb=fqnK4mKb5F
REQUEST
RESPONSE
POST 404 http://www.belatofo.com/m6vg/
REQUEST
RESPONSE
GET 404 http://www.belatofo.com/m6vg/?3e4VFiK=zU2i1DyrLTvj8GmsZ3o7R6kW1xY2b3weixFFYEzXXEr/gEIBiemlOi0xftl7Tao5JEAa7dRSygfLZB5gXWVWN+Vv06aLmgNr2ZdGEQw=&FFb=fqnK4mKb5F
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
192.168.56.101 164.124.101.2 3

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts