NetWork | ZeroBOX

Network Analysis

IP Address Status Action
168.138.162.78 Active Moloch
164.124.101.2 Active Moloch
Name Response Post-Analysis Lookup
s4.gtsystems.hu 185.6.188.137
GET 200 http://168.138.162.78/output//resources.xml
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output//client/update.exe
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output//client/7z.dll
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output//client/SevenZipSharp.dll
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output//client/System.Windows.Interactivity.dll
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output//resources.xml
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/updates/update_1.7z
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/custom.dll
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/ability.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/achievement.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/assistant.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/cabal.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/caz.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/change_shape.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/cont.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/cont2.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/data.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/destroy.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/extra_obj.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/global.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/help.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/item.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/keymap.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/klog.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/mapinfo.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/market.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/maze.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/mob.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/mobex.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/quest.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/smob.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/title.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/usersetting.dat
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/FX/EFX/Arms/skull_13_keep.efx
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/FX/EFX/Arms/skull_13_keep_15.efx
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/FX/EFX/buff/mbuff_keep__888.efx
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/FX/SRC/ebm/skull_13_keep_r.ebm
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/FX/SRC/ebm/skull_13_keep_r2.ebm
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/FX/SRC/ebm/skull_13_keep_r3.ebm
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Item/arms/Skull_13_keep.EBM
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Item/bike/bike_46.ebm
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/achievement_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/cabal_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/caz_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/cont2_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/cont_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/extra_obj_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/help.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/keymap_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/klog.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/language.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/script.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/script_msg.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Language/English/tip.enc
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Map/world_01.mcl
REQUEST
RESPONSE
GET 200 http://168.138.162.78/output/client/Data/Object/Character/man8.ech
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49162 -> 168.138.162.78:80 2016141 ET INFO Executable Download from dotted-quad Host Potentially Bad Traffic
TCP 168.138.162.78:80 -> 192.168.56.102:49162 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 168.138.162.78:80 -> 192.168.56.102:49162 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic
TCP 168.138.162.78:80 -> 192.168.56.102:49162 2021076 ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response Potentially Bad Traffic
TCP 192.168.56.102:49167 -> 168.138.162.78:80 2027250 ET INFO Dotted Quad Host DLL Request Potentially Bad Traffic
TCP 168.138.162.78:80 -> 192.168.56.102:49167 2014819 ET INFO Packed Executable Download Misc activity
TCP 168.138.162.78:80 -> 192.168.56.102:49167 2018959 ET POLICY PE EXE or DLL Windows file download HTTP Potential Corporate Privacy Violation
TCP 168.138.162.78:80 -> 192.168.56.102:49167 2016538 ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download Potentially Bad Traffic
TCP 168.138.162.78:80 -> 192.168.56.102:49167 2015744 ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging) Misc activity
TCP 192.168.56.102:49162 -> 168.138.162.78:80 2027250 ET INFO Dotted Quad Host DLL Request Potentially Bad Traffic
TCP 192.168.56.102:49162 -> 168.138.162.78:80 2027250 ET INFO Dotted Quad Host DLL Request Potentially Bad Traffic
TCP 192.168.56.102:49162 -> 168.138.162.78:80 2027250 ET INFO Dotted Quad Host DLL Request Potentially Bad Traffic

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts