11/13-01:27:37.445195 [**] [1:3000006:99] E3[rb] BotHunter MALWARE executable upload [**] [Classification: Misc activity] [Priority: 3] {TCP} 61.94.9.129:53514 -> 192.168.1.220:445 11/13-01:27:37.612843 [**] [1:299998:1] E2[rb] SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 61.94.9.129:53514 -> 192.168.1.220:445 11/13-01:27:37.612843 [**] [1:21390:5] E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 61.94.9.129:53514 -> 192.168.1.220:445 11/13-01:27:39.400266 [**] [1:299998:1] E2[rb] SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 61.94.9.129:53514 -> 192.168.1.220:445 11/13-01:27:39.400266 [**] [1:21390:5] E2[rb] REGISTERED FREE SHELLCODE x86 inc ebx NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 61.94.9.129:53514 -> 192.168.1.220:445 11/13-01:27:42.033429 [**] [1:2007726:2] E3[rb] ET ATTACK RESPONSE Unusual FTP Server Banner on High Port (StnyFtpd) [**] [Classification: A Network Trojan was detected] [Priority: 1] {TCP} 61.94.9.129:47973 -> 192.168.1.220:1027 11/13-01:27:53.562357 [**] [1:2000427:9] E3[rb] ET POLICY PE EXE Install Windows file download [**] [Classification: Misc activity] [Priority: 3] {TCP} 61.94.9.129:54490 -> 192.168.1.220:68