NetWork | ZeroBOX

Network Analysis

IP Address Status Action
116.255.160.63 Active Moloch
164.124.101.2 Active Moloch
58.218.215.167 Active Moloch
61.160.192.103 Active Moloch
8.210.224.3 Active Moloch
POST 200 http://ad.qqfarmer.com.cn/login.php?id=p&r=0.368447953602299
REQUEST
RESPONSE
POST 200 http://ad.qqfarmer.com.cn/login.php?id=v&r=0.494936139322817
REQUEST
RESPONSE
POST 200 http://ad.qqfarmer.com.cn/login.php?id=n&r=0.480842764023691
REQUEST
RESPONSE
POST 200 http://ad.qqfarmer.com.cn/login.php?id=l&r=0.560313974739984
REQUEST
RESPONSE
POST 200 http://ad.qqfarmer.com.cn/login.php?id=x&r=0.44646016205661
REQUEST
RESPONSE
GET 200 http://down.qqfarmer.com.cn/libeay32_0626_5f86d65a1686e6bb031048d04bb3fe04.xml?r=0.313291363418102
REQUEST
RESPONSE
GET 200 http://images.qqfarmer.com.cn/504486-20170712112840415-1890262410.gif
REQUEST
RESPONSE
GET 200 http://images.qqfarmer.com.cn/504486-20162218235650745-1529273276.gif
REQUEST
RESPONSE
GET 200 http://images.qqfarmer.com.cn/hongbao_nav.gif
REQUEST
RESPONSE
GET 200 http://images.qqfarmer.com.cn/504486-20161218235650745-1529273276.gif
REQUEST
RESPONSE
GET 200 http://down.qqfarmer.com.cn/ssleay32_0626_e503921a6061251302cb45772cb75f42.xml?r=0.329597188392654
REQUEST
RESPONSE
GET 200 http://ad.qqfarmer.com.cn/xml/encrypt.js?r=0.952554038958624
REQUEST
RESPONSE

ICMP traffic

Source Destination ICMP Type Data
192.168.56.103 116.255.160.63 8 #
116.255.160.63 192.168.56.103 0 #
192.168.56.103 8.210.224.3 8 #
8.210.224.3 192.168.56.103 0 #

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 58.218.215.167:80 -> 192.168.56.103:49170 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 58.218.215.167:80 -> 192.168.56.103:49176 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts