Network Analysis
IP Address | Status | Action | VT | Location |
---|---|---|---|---|
No hosts contacted. |
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
No traffic
No traffic
No traffic
ICMP traffic
No ICMP traffic performed.
IRC traffic
No IRC requests performed.
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.168.203:54948 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD | Potentially Bad Traffic |
TCP 192.168.168.203:49240 -> 52.11.240.239:80 | 2850851 | ETPRO MALWARE Win32/Expiro.NDO CnC Activity | Malware Command and Control Activity Detected |
UDP 192.168.168.203:52244 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD | Potentially Bad Traffic |
TCP 52.11.240.239:80 -> 192.168.168.203:49240 | 2018141 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz | A Network Trojan was detected |
TCP 52.11.240.239:80 -> 192.168.168.203:49240 | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | A Network Trojan was detected |
UDP 192.168.168.203:57016 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD | Potentially Bad Traffic |
UDP 192.168.168.203:64726 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
Snort Alerts
Flow | SID | Message |
---|---|---|
UDP 192.168.168.203:54948 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD |
UDP 192.168.168.203:52244 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD |
UDP 192.168.168.203:57016 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD |
UDP 192.168.168.203:64726 -> 8.8.8.8:53 | 2027863 | ET INFO Observed DNS Query to .biz TLD |