NetWork | ZeroBOX

Network Analysis

IP Address Status Action
212.227.245.12 Active Moloch
85.215.173.244 Active Moloch
Name Response Post-Analysis Lookup
No hosts contacted.
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
POST 200 https://85.215.173.244/
REQUEST
RESPONSE
GET 200 http://212.227.245.12/c.aes
REQUEST
RESPONSE

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

Flow SID Signature Category
TCP 85.215.173.244:443 -> 192.168.56.101:49187 2037697 ET ATTACK_RESPONSE Havoc/Sliver Framework TLS Certificate Observed A Network Trojan was detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49187
85.215.173.244:443
C=US, ST=Connecticut, L=Norwalk, unknown=, unknown=2556, O=Synergy Co, CN=85.215.173.244 C=US, ST=Connecticut, L=Norwalk, unknown=, unknown=2556, O=Synergy Co, CN=85.215.173.244 6c:c5:54:c3:e2:0a:00:ac:3a:29:5a:b9:12:8c:c5:5c:56:88:dc:20

Snort Alerts

No Snort Alerts