NetWork | ZeroBOX

Network Analysis

IP Address Status Action
154.92.16.100 Active Moloch
38.181.25.204 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.
GET 200 http://154.92.16.100/Admin/Admin.html
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 154.92.16.100:80 -> 192.168.56.101:49161 2045860 ET HUNTING Rejetto HTTP File Sever Response A Network Trojan was detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49164
38.181.25.204:5858
CN=VenomRAT Server/OU=qwqdanchun/O=VenomRAT By qwqdanchun/L=SH/C=CN CN=VenomRAT 99:21:ce:1f:4b:a8:82:59:70:ee:2e:47:8d:31:77:8b:95:52:aa:23
TLSv1
192.168.56.101:49174
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49167
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49165
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49177
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49168
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49166
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49169
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49170
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49176
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49172
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49179
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49180
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49175
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49171
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49173
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49178
38.181.25.204:5858
None None None
TLSv1
192.168.56.101:49181
38.181.25.204:5858
None None None

Snort Alerts

No Snort Alerts