NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
5.255.127.177 Active Moloch
Name Response Post-Analysis Lookup
ddsdata.net 5.255.127.177
POST 100 http://ddsdata.net/upload.php
REQUEST
RESPONSE
POST 100 http://ddsdata.net/upload.php
REQUEST
RESPONSE
POST 100 http://ddsdata.net/upload.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49181 -> 5.255.127.177:80 2046820 ET MALWARE [ANY.RUN] Konni.APT Exfiltration A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts