NetWork | ZeroBOX

Network Analysis

IP Address Status Action
146.59.209.152 Active Moloch
164.124.101.2 Active Moloch
192.0.78.24 Active Moloch
GET 301 http://www.illuminati4me.com/btrd/?XB64XRIP=Q3kWi+9T/dHMca9G7DTYQaSHZDljXDmr3SofoM0gc2X08uuBa26GyxCTZUnwgLp1nNqssc/W&Sb=M4_TiVj0
REQUEST
RESPONSE
GET 301 http://www.toulouse.gold/btrd/?XB64XRIP=C9MKbEJ42g9S0MCpcUewgohkksZhTB/BdRb4Z/jCobVWG7RtmOeI1/6J7rJ1m23I813d/GU/&Sb=M4_TiVj0
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49165 -> 192.0.78.24:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 146.59.209.152:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts