NetWork | ZeroBOX

Network Analysis

IP Address Status Action
104.21.67.52 Active Moloch
164.124.101.2 Active Moloch
94.130.50.78 Active Moloch
GET 301 http://www.keymuscatgroups.com/bp31/?yVMpQTlP=yNiC01S4ovnvJ+4O8UQILoBOncymYWrbdHgK3FAKeJB65Mx698O5TOrqAYEBEx6+IzqV5xYJ&1bz=ofrLp
REQUEST
RESPONSE
GET 0 http://www.shop-pravaonline.online/bp31/?yVMpQTlP=Uqza8+9L64sRJc+c2iCGCqwjPe7m2xZwn2Ag66Dpm3Yoyn941TYF9FYKVDiYLzEfUp+bSjyL&1bz=ofrLp
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49166 -> 104.21.67.52:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.101:49165 -> 94.130.50.78:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts