NetWork | ZeroBOX

Network Analysis

IP Address Status Action
164.124.101.2 Active Moloch
208.95.112.1 Active Moloch
92.255.85.2 Active Moloch
Name Response Post-Analysis Lookup
ip-api.com 208.95.112.1
GET 200 http://92.255.85.2/qx.exe
REQUEST
: GET /qx.exe HTTP/1.1
Host: 92.255.85.2
Connection: Keep-Alive
RESPONSE
: HTTP/1.1 200 OK
Content-Type: application/octet-stream
Last-Modified: Wed, 02 Apr 2025 10
Accept-Ranges: bytes
ETag: "46ce3f19b8a3db1
Server: Microsoft-IIS/10.0
Date: Fri, 04 Apr 2025 00
Content-Length: 55296
GET 200 http://ip-api.com/line
REQUEST
: GET /line HTTP/1.1
Host: ip-api.com
Connection: Keep-Alive
RESPONSE
: HTTP/1.1 200 OK
Date: Fri, 04 Apr 2025 00
Content-Type: text/plain; charset=utf-8
Content-Length: 126
Access-Control-Allow-Origin: *
X-Ttl: 60
X-Rl: 44

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Snort Alerts

No Snort Alerts