NetWork | ZeroBOX

Network Analysis

IP Address Status Action
144.172.65.58 Active Moloch
154.211.4.240 Active Moloch
164.124.101.2 Active Moloch
172.217.24.115 Active Moloch
GET 403 http://www.sagemarlin.com/4hc5/?ETUTzJu=tnE9MOQ00nvUG52k2PEJ6LCN/o5/DE1FN6NfjKIUkwnk1cDdV9wwqkCICz01rybBvk+yXrcK&DxoHW=VDKPcDdPwnEd1V
REQUEST
RESPONSE
GET 301 http://www.wzmatics.com/4hc5/?ETUTzJu=ZiyK7zNAvHInllj0cd7rkvUuUvXCAzs8N7im8yG2jaA0EmIYIWtmNG/kZbe9TfEQka9v17XU&DxoHW=VDKPcDdPwnEd1V
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49168 -> 172.217.24.115:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49167 -> 144.172.65.58:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts