NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
172.67.150.87 Active Moloch
185.83.214.222 Active Moloch
45.33.6.223 Active Moloch
POST 301 http://www.bookingshop01.top/hnmu/
REQUEST
RESPONSE
GET 301 http://www.bookingshop01.top/hnmu/?zNts=PAkg1urm7N9AVeASEKiY0GMQCzBOtYt4wERqVQow/jdQ5NqazHSv+YEC2ee5pD3t/p5aHGQj+n8MoPHKBsOZlw3EOYcHEuSkqJKafkc=&PZpKO=y9dVejt2Kk4On
REQUEST
RESPONSE
GET 200 http://www.sqlite.org/2020/sqlite-dll-win32-x86-3310000.zip
REQUEST
RESPONSE
GET 200 http://www.sqlite.org/2017/sqlite-dll-win32-x86-3160000.zip
REQUEST
RESPONSE
GET 206 http://www.sqlite.org/2020/sqlite-dll-win32-x86-3310000.zip
REQUEST
RESPONSE
GET 200 http://www.sqlite.org/2019/sqlite-dll-win32-x86-3280000.zip
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.101:53004 -> 164.124.101.2:53 2023883 ET DNS Query to a *.top domain - Likely Hostile Potentially Bad Traffic
TCP 192.168.56.101:49169 -> 172.67.150.87:80 2023882 ET INFO HTTP Request to a *.top domain Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts