NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
176.97.64.174 Active Moloch
Name Response Post-Analysis Lookup
stvse.com 176.97.64.174
POST 100 http://stvse.com/upload.php
REQUEST
RESPONSE
POST 100 http://stvse.com/upload.php
REQUEST
RESPONSE
POST 100 http://stvse.com/upload.php
REQUEST
RESPONSE
POST 100 http://stvse.com/upload.php
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49180 -> 176.97.64.174:80 2046820 ET MALWARE [ANY.RUN] Konni.APT Exfiltration A Network Trojan was detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts