NetWork | ZeroBOX

Network Analysis

IP Address Status Action
185.172.128.90 Active Moloch
164.124.101.2 Active Moloch
188.165.164.184 Active Moloch
209.148.85.151 Active Moloch
34.117.118.44 Active Moloch
91.121.12.127 Active Moloch
94.247.28.156 Active Moloch
94.247.28.26 Active Moloch
94.247.31.19 Active Moloch
GET 308 http://ip-addr.es/
REQUEST
RESPONSE
GET 200 http://myexternalip.com/raw
REQUEST
RESPONSE
GET 308 http://ip-addr.es/
REQUEST
RESPONSE
GET 200 http://myexternalip.com/raw
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 185.172.128.90:80 -> 192.168.56.101:49163 2400032 ET DROP Spamhaus DROP Listed Traffic Inbound group 33 Misc Attack
TCP 192.168.56.101:49163 -> 188.165.164.184:80 2020105 ET INFO HTTP Request for External IP Check (ip-addr .es) Device Retrieving External IP Address Detected
TCP 192.168.56.101:49171 -> 188.165.164.184:80 2020105 ET INFO HTTP Request for External IP Check (ip-addr .es) Device Retrieving External IP Address Detected
TCP 192.168.56.101:49164 -> 34.117.118.44:80 2019980 ET POLICY External IP Check myexternalip.com Device Retrieving External IP Address Detected
TCP 192.168.56.101:49172 -> 34.117.118.44:80 2019980 ET POLICY External IP Check myexternalip.com Device Retrieving External IP Address Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts