NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.26.8.59 Active Moloch
164.124.101.2 Active Moloch
195.85.201.36 Active Moloch
GET 200 http://api.myip.com/
REQUEST
RESPONSE
GET 200 http://api.myip.com/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49161 -> 104.26.8.59:80 2031188 ET POLICY IP Check (myip .com) Potential Corporate Privacy Violation
TCP 192.168.56.103:49161 -> 104.26.8.59:80 2003492 ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0) Potentially Bad Traffic
TCP 192.168.56.103:49166 -> 104.26.8.59:80 2031188 ET POLICY IP Check (myip .com) Potential Corporate Privacy Violation
UDP 192.168.56.103:50800 -> 164.124.101.2:53 2027870 ET INFO Observed DNS Query to .world TLD Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts