NetWork | ZeroBOX

Network Analysis

IP Address Status Action
15.197.148.33 Active Moloch
164.124.101.2 Active Moloch
195.35.38.87 Active Moloch
23.227.38.74 Active Moloch
GET 301 http://www.chonggonzalez.com/bp31/?4hIPNx=i8xMAsplts1fVWIwWOiZyKMG3HcPF0/pv9lT+CaFwPb7cSw7ejwLK6p2kEZsPcoFVhe8fhoh&nfut_l=xPJx_6jp&sql=1
REQUEST
RESPONSE
POST 301 http://www.chonggonzalez.com/bp31/
REQUEST
RESPONSE
GET 403 http://www.zloomux.com/bp31/?4hIPNx=vvPW/2Pd5QHeIEBGm8G0+Ony9yXqUyBfOyFfBG0rKYjwD4sgiUzqNaP2HxjG8nxDdvZI64Qs&nfut_l=xPJx_6jp&sql=1
REQUEST
RESPONSE
POST 404 http://www.zloomux.com/bp31/
REQUEST
RESPONSE
GET 403 http://www.smartagriafrica.info/bp31/?4hIPNx=OJ1wdLQJPVHT7VM7DL9mTUJRAG8pTY12NlK6t8ps5ocpXXUVXYvRwMmTQlbyJ47ya7gchoZP&nfut_l=xPJx_6jp&sql=1
REQUEST
RESPONSE
POST 0 http://www.smartagriafrica.info/bp31/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49168 -> 195.35.38.87:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49170 -> 23.227.38.74:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49172 -> 15.197.148.33:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts