NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.179.217 Active Moloch
184.168.119.55 Active Moloch
GET 404 http://oopscokir.com/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49176 -> 172.67.179.217:80 2032086 ET MALWARE Win32/IcedID Request Cookie A Network Trojan was detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.101:49169
184.168.119.55:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=avestainfratech.com df:8e:b4:c2:31:11:f0:2f:6a:95:27:bc:a4:2a:7e:67:b9:a3:6c:c7

Snort Alerts

No Snort Alerts