NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
91.92.243.32 Active Moloch
Name Response Post-Analysis Lookup
voucher-01-static.com 91.92.243.32
GET 200 http://voucher-01-static.com/rkei/1085.txt
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 91.92.243.32:80 -> 192.168.56.101:49161 2400012 ET DROP Spamhaus DROP Listed Traffic Inbound group 13 Misc Attack

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts