NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
3.33.130.190 Active Moloch
34.149.87.45 Active Moloch
GET 200 http://www.8129k.vip/btrd/?s0=n0ab3tuoNW8ou3x27TJdb8ResHeKX67jajlVBlqqkiip2P8oXoFhViJTkjsI+JgL2Gr/K3fV&sZODWF=8pH8ULV
REQUEST
RESPONSE
GET 301 http://www.practicalpoppers.com/btrd/?s0=4sBrGMfWzW1lDsA3tsoeMOTII6sovB2juCtH8oSZyCnKVOcauW78A1MA2pRA0N3X3cw6QLB1&sZODWF=8pH8ULV
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.103:49167 -> 3.33.130.190:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected
TCP 192.168.56.103:49170 -> 34.149.87.45:80 2031412 ET MALWARE FormBook CnC Checkin (GET) Malware Command and Control Activity Detected

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts