06/20-00:14:03.923196 [**] [1:3000005:99] E3[rb] BotHunter MALWARE executable upload [**] [Classification: Misc activity] [Priority: 3] {TCP} 213.22.28.122:9351 -> 192.168.1.247:139 06/20-00:14:03.944682 [**] [1:299998:1] E2[rb] SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 213.22.28.122:9351 -> 192.168.1.247:139 06/20-00:14:03.944682 [**] [1:21390:5] E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 213.22.28.122:9351 -> 192.168.1.247:139 06/20-00:14:03.965670 [**] [1:299998:1] E2[rb] SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 213.22.28.122:9351 -> 192.168.1.247:139 06/20-00:14:03.965670 [**] [1:21390:5] E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 213.22.28.122:9351 -> 192.168.1.247:139 06/20-00:14:05.800935 [**] [1:2001683:3] E3[rb] BLEEDING-EDGE Malware Windows executable sent from remote host [**] [Priority: 0] {TCP} 213.22.28.122:9984 -> 192.168.1.247:1028 06/20-00:14:05.800935 [**] [1:5001684:99] E3[rb] BotHunter Malware Windows executable (PE) sent from remote host [**] [Priority: 0] {TCP} 213.22.28.122:9984 -> 192.168.1.247:1028 06/20-00:14:14.704625 [**] [1:2404013:1142] E4[rb] ET DROP Known Bot C&C Server Traffic (group 14) [**] [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 192.168.1.247:1030 -> 72.10.172.211:8080 06/20-00:14:34.690793 [**] [1:2404011:1142] E4[rb] ET DROP Known Bot C&C Server Traffic (group 12) [**] [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 192.168.1.247:1032 -> 67.43.236.66:8080 06/20-00:15:56.182314 [**] [1:2000355:4] E4[rb] ET POLICY IRC authorization message [**] [Classification: Misc activity] [Priority: 3] {TCP} 83.68.16.6:5190 -> 192.168.1.247:1034 06/20-00:16:36.658214 [**] [1:2406021:43] E4[rb] ET rbN Known Russian Business Network Monitored Domains (17) [**] [Classification: Misc Attack] [Priority: 2] {TCP} 67.43.236.66:10324 -> 192.168.1.247:1036 06/20-00:16:38.342821 [**] [1:2000355:4] E4[rb] ET POLICY IRC authorization message [**] [Classification: Misc activity] [Priority: 3] {TCP} 83.68.16.6:5190 -> 192.168.1.247:1037 06/20-00:18:51.727165 [**] [1:2406021:43] E4[rb] ET rbN Known Russian Business Network Monitored Domains (17) [**] [Classification: Misc Attack] [Priority: 2] {TCP} 67.43.236.66:10324 -> 192.168.1.247:1039