NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
51.38.126.82 Active Moloch
54.37.204.238 Active Moloch
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE
GET 206 http://downloads.bablosoft.com/distr/FastExecuteScriptProtected64/25.4.1/FastExecuteScriptProtected.x64.zip
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.103:52760 -> 164.124.101.2:53 2054224 ET INFO Browser Automation Toolkit in DNS Lookup (bablosoft .com) Potential Corporate Privacy Violation
UDP 192.168.56.103:50800 -> 164.124.101.2:53 2054224 ET INFO Browser Automation Toolkit in DNS Lookup (bablosoft .com) Potential Corporate Privacy Violation
UDP 192.168.56.103:50800 -> 164.124.101.2:53 2036703 ET MALWARE Observed DNS Query to bablosoft Domain (downloads .bablosoft .com) Potentially Bad Traffic
TCP 192.168.56.103:49220 -> 51.38.126.82:443 2054225 ET INFO Browser Automation Toolkit in TLS SNI (bablosoft .com) Potential Corporate Privacy Violation
TCP 192.168.56.103:49219 -> 51.38.126.82:443 2054225 ET INFO Browser Automation Toolkit in TLS SNI (bablosoft .com) Potential Corporate Privacy Violation
TCP 51.38.126.82:443 -> 192.168.56.103:49220 2036686 ET INFO Observed Bablosoft BAS Related SSL Cert (bablosoft .com) Potentially Bad Traffic
TCP 51.38.126.82:443 -> 192.168.56.103:49219 2036686 ET INFO Observed Bablosoft BAS Related SSL Cert (bablosoft .com) Potentially Bad Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.103:49220
51.38.126.82:443
C=US, O=Let's Encrypt, CN=R10 CN=bablosoft.com 40:31:e7:5f:f4:76:a4:66:67:6c:c6:d0:15:9f:6a:ab:be:5c:e1:1e
TLS 1.2
192.168.56.103:49219
51.38.126.82:443
C=US, O=Let's Encrypt, CN=R10 CN=bablosoft.com 40:31:e7:5f:f4:76:a4:66:67:6c:c6:d0:15:9f:6a:ab:be:5c:e1:1e

Snort Alerts

No Snort Alerts