NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
208.67.222.222 Active Moloch
88.119.169.96 Active Moloch
Name Response Post-Analysis Lookup
myip.opendns.com
ttzcloud.com 88.119.169.96
222.222.67.208.in-addr.arpa
PTR dns.umbrella.com
PTR dns.opendns.com
PTR resolver1.opendns.com
myip.opendns.com
resolver1.opendns.com 208.67.222.222
POST 100 http://ttzcloud.com/upload.php
REQUEST
RESPONSE
POST 100 http://ttzcloud.com/upload.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.102:63711 -> 208.67.222.222:53 2023472 ET POLICY External IP Lookup Domain (myip .opendns .com in DNS lookup) Device Retrieving External IP Address Detected
UDP 192.168.56.102:63712 -> 208.67.222.222:53 2023472 ET POLICY External IP Lookup Domain (myip .opendns .com in DNS lookup) Device Retrieving External IP Address Detected
TCP 192.168.56.102:49187 -> 88.119.169.96:80 2046820 ET MALWARE [ANY.RUN] Konni.APT Exfiltration A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts