NetWork | ZeroBOX

Network Analysis

IP Address Status Action
141.125.157.19 Active Moloch
164.124.101.2 Active Moloch
23.227.38.74 Active Moloch
91.184.0.200 Active Moloch
45.33.6.223 Active Moloch
GET 308 http://www.eshopkhaliji.store/muti/?8p=PenW7MtlXSrvxOPA1PJj8U2jUUvXlhwVh1FpwKQCNXiCStQ1MIBfQTqa3m2cpudHTvQpU++Q&4h=vTxdQD-PSRspeX7&sql=1
REQUEST
RESPONSE
POST 0 http://www.eshopkhaliji.store/muti/
REQUEST
RESPONSE
POST 0 http://www.eshopkhaliji.store/muti/
REQUEST
RESPONSE
GET 404 http://www.caxars.store/muti/?8p=vAkEv8VlD6HvoJ7OTZ3UyhPmsIwewVN5MI8wV+ea/g1itgmvOaYSZ0nMfK3GudfMXpkuz2fr&4h=vTxdQD-PSRspeX7&sql=1
REQUEST
RESPONSE
POST 404 http://www.caxars.store/muti/
REQUEST
RESPONSE
POST 404 http://www.caxars.store/muti/
REQUEST
RESPONSE
GET 403 http://www.shopadamsstore.com/muti/?8p=rUMPbDi9V+hLkBWFtVE1y7T4O5kE79Gi8Nwpb3xjlkSgEF4tpwDWlQ4hDt2c39K6jtdDQHz5&4h=vTxdQD-PSRspeX7&sql=1
REQUEST
RESPONSE
POST 0 http://www.shopadamsstore.com/muti/
REQUEST
RESPONSE
POST 0 http://www.shopadamsstore.com/muti/
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49168 -> 91.184.0.200:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49171 -> 23.227.38.74:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49165 -> 141.125.157.19:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49172 -> 23.227.38.74:80 2031413 ET MALWARE FormBook CnC Checkin (POST) M2 Malware Command and Control Activity Detected
TCP 192.168.56.103:49166 -> 141.125.157.19:80 2031413 ET MALWARE FormBook CnC Checkin (POST) M2 Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts