NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.64.90 Active Moloch
164.124.101.2 Active Moloch
184.168.117.217 Active Moloch
GET 404 http://oopscokir.com/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49175 -> 104.21.64.90:80 2032086 ET MALWARE Win32/IcedID Request Cookie A Network Trojan was detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.101:49169
184.168.117.217:443
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority CN=moashraya.com f5:4f:f0:43:5d:87:29:b9:67:28:34:e9:f9:c2:a3:5d:38:79:d1:55

Snort Alerts

No Snort Alerts