NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
176.97.64.174 Active Moloch
Name Response Post-Analysis Lookup
sibbss.com 176.97.64.174
POST 100 http://sibbss.com/upload.php
REQUEST
RESPONSE
POST 100 http://sibbss.com/upload.php
REQUEST
RESPONSE
POST 100 http://sibbss.com/upload.php
REQUEST
RESPONSE
POST 100 http://sibbss.com/upload.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49176 -> 176.97.64.174:80 2046820 ET MALWARE [ANY.RUN] Konni.APT Exfiltration A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts