NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.194.128.170 Active Moloch
104.21.69.174 Active Moloch
164.124.101.2 Active Moloch
213.186.33.5 Active Moloch
GET 200 http://www.mtauratarnt.com/rs10/?C0D=pPtLjK+gsCF+gBeBSkx+WEjNRlgjs/QTeyOfbuiR2sOl/G3k+8MocAF2pTNT/vXnM1YvSeQw&QZ3=ehux_vXh401Xart
REQUEST
RESPONSE
GET 302 http://www.into-org.com/rs10/?C0D=+njUxLNT9hCOVJ3Lnug2QEI/7WyUV+ofb+5xay11NC0a753xJF4LqnCsTY0IVEvVOlnNjj+S&QZ3=ehux_vXh401Xart
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49166 -> 213.186.33.5:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49165 -> 104.21.69.174:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts