Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:13:00 | Win2K-f | 219.167.104.234 (PLALA.OR.JP): PLALA NETWORKS INC, THANJAVUR, TAMIL NADU, IN. |
209.250.232.240:7000 | US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp irc 25 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 32 | b4ad631671 [Firefox:11 hits: 04-29 to 05-19] |
5890f017cc [0] | ASM:Graph |
StarForce| | lines=28 | trace |
T:00:39:00 | Win2K-f | 87.123.169.214 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, DE. |
209.250.232.240:7000 | US:scorti1.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 25 lines |
Yeah : 1.8 profile |
none | summary tarball |
22 of 32 | dc8e1c63cd [Firefox:91 hits: 12-27 to 05-18] |
e0eb8646ee [0] | ASM:Graph |
none|none | lines=601 embedded dns |
trace |
T:00:50:00 | Win2K-f | 62.205.185.92 (CORBINA.NET): MCN-CUSTOMERS, MOSCOW, MOSKVA, RU. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
01:49:00 | WinXP | 203.196.65.116 (KAGACABLE.NE.JP): KAGA CABLE TELEVISION CO.LTD, JP. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1292 hits: 12-31 to 05-19] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
02:28:00 | Win2K-f | 81.195.108.238 (-): GRACHEVA YULIYA PETROVNA, MOSCOW, MOSKVA, RU. (100Mbps) |
84.244.5.183:2345 | US:wow.blackirc.us SE:tap.radioprishtina.net |
445 | pcap | raw alerts ruleset |
http irc 38 lines |
Yeah : 1.3 profile |
none | summary tarball |
14 of 32 | 69474721cb NEW |
none[none] | none:none |
none|none | none | none |
02:39:00 | WinXP | 59.120.87.122 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:597 hits: 07-11 to 05-19] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
03:14:00 | Win2K-f | 89.106.108.40 (-): OPTILINK, BG. |
209.250.232.240:7000 | US:hail.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1344 hits: 04-27 to 05-19] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
03:57:00 | WinXP | 75.89.54.80 (ALLTEL.NET): WINDSTREAM - COMMERCE, COMMERCE, GEORGIA, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 | 43306fc684 [Firefox: 6 hits: 12-28 to 05-05] |
59fc5b2b93 [0] | ASM:Graph |
PolyEnE| | lines=60 | trace | |
05:22:00 | WinXP | 85.240.194.117 (DSL.TELEPAC.PT): PT.COM - COMUNICACOES INTERACTIVAS S.A, LEIRIA, LEIRIA, PT. (DSL) |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | cf7bb33fb2 [Firefox: 7 hits: 03-11 to 05-04] |
3040889c26 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
05:42:00 | WinXP | 67.37.40.98 (AMERITECH.NET): DIAL POOL - TNT2.KALAMAZOO.MI.AMERITECH.NET, STEVENSVILLE, MICHIGAN, US. (DIAL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:2991 hits: 12-31 to 05-19] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:12:00 | WinXP | 202.221.174.230 (BMOBILE.NE.JP): JAPAN COMMUNICATION INC, TOKYO, TOKYO, JP. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b [Firefox:709 hits: 05-01 to 05-19] |
462a7be171 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:52:00 | WinXP | 122.53.223.145 (PLDT.NET): IPG, PH. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:07:00 | WinXP | 117.98.36.228 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | EU:siliconfireware.ru US:searchportal.information.com GB:new.egg.com :wpad US:208.73.212.12:80 DE:212.227.111.29:80 DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http http 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
23 of 32 | 7fb51ea621 NEW |
none[none] | none:none |
none|none | none | none |
T:07:45:00 | WinXP | 189.42.166.143 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
85.114.137.60:65520 | DE:proxim.ircgalaxy.pl DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad DE:dl2.teenpassage.com IL:ymq.a1001186.wrs.mcboo.com IL:wr.mcboo.com IL:194.90.224.86:80 GB:195.92.84.198:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
http http irc 131 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 21 of 32 26 of 32 |
33deed5eaa NEW 54df1dbf7e [Firefox: 2 hits: 05-15 to 05-16] 790bdf0298 NEW |
none[none] 54df1dbf7e[1] none [none] |
none:none ASM:Graph none:none |
none|none StarForce| none|none |
none lines=6 none |
none trace none |
T:07:53:00 | WinXP | 124.106.10.72 (-): QCYC7300I03_CONSUMER, MANILA, MANILA, PH. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 1e5df7ba74 [Firefox:16 hits: 03-24 to 05-18] |
a5331b711f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
07:58:00 | WinXP | 70.112.247.252 (RR.COM): ROAD RUNNER HOLDCO LLC, CEDAR PARK, TEXAS, US. |
n/a | DE:siliconfireware.ru GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1022 hits: 05-01 to 05-19] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:08:05:00 | WinXP | 211.215.32.49 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
09:41:00 | WinXP | 91.67.88.134 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1292 hits: 12-31 to 05-19] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
10:13:00 | Win2K-f | 91.64.55.112 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:14:00 | WinXP | 82.160.229.95 (EC.PL): TELEKOMUNIKACJA KOLEJOWA SP. Z O.O, PL. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:14:00 | Win2K-f | 91.64.208.251 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :www.google.com :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:21:00 | WinXP | 212.233.211.44 (-): NTL, FR. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:22:00 | WinXP | 91.1.198.46 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, DE. |
n/a | :f.unicat.org :www.google.com 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:22:00 | WinXP | 91.65.74.36 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:24:00 | Win2K-f | 85.85.223.86 (CLIENTES.EUSKALTEL.ES): EUSKALTEL, ES. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:24:00 | WinXP | 41.214.130.117 (-): . |
n/a | :www.google.com | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:24:00 | WinXP | 88.134.194.130 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:25:00 | Win2K-f | 89.27.246.35 (KIELNET.NET): RECHENZENTRUM KIEL, KIEL, SCHLESWIG-HOLSTEIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:26:00 | Win2K-f | 85.85.223.86 (CLIENTES.EUSKALTEL.ES): EUSKALTEL, ES. |
n/a | :www.google.com | 445 | pcap | raw alerts ruleset |
other 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:29:00 | Win2K-f | 91.1.198.46 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:31:00 | Win2K-f | 91.66.10.208 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:32:00 | WinXP | 91.64.5.51 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :f.unicat.org :www.google.com 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:33:00 | WinXP | 91.67.148.94 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:42:00 | Win2K-f | 89.136.39.102 (UPCNET.RO): ASTRAL UPC TIMISOARA, TIMISOARA, TIMIS, RO. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:43:00 | Win2K-f | 82.66.100.119 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | :www.google.com | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:45:00 | Win2K-f | 91.64.5.51 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:10:51:00 | WinXP | 60.47.224.107 (PLALA.OR.JP): PLALA NETWORKS INC, CHITOSE, HOKKAIDO, JP. |
n/a | :www.google.com | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:57:00 | Win2K-f | 89.35.204.203 (RAKNETSOFT.RO): SC RAKNET SOFT SRL, PLOIESTI, PRAHOVA, RO. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
10:58:00 | WinXP | 91.65.58.138 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
20 of 32 | b6eaa3f885 NEW |
none[none] | none:none |
none|none | none | none |
T:10:58:00 | Win2K-f | 91.65.177.231 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
10:59:00 | WinXP | 89.204.193.222 (O2.IE): O2 IRELAND MOBILE PHONE OPERATOR, IE. |
n/a | DE:proxim.ircgalaxy.pl UA:citi-bank.ru :www.google.com EU:kidos-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 34187b60d1 NEW |
none[none] | none:none |
none|none | none | none |
T:11:06:00 | Win2K-f | 93.124.38.190 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
69.42.216.90:9890 | :f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:11:11:00 | WinXP | 82.240.174.182 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp irc 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
11:18:00 | Win2K-f | 91.64.208.251 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:11:19:00 | Win2K-f | 91.65.58.138 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
11:23:00 | WinXP | 91.65.57.15 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | :www.google.com | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:25:00 | Win2K-f | 70.100.252.14 (FRONTIERNET.NET): FRONTIER COMMUNICATIONS OF AMERICA INC, SHAWANO, WISCONSIN, US. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:30:00 | WinXP | 12.215.129.196 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, ANKENY, IOWA, US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
11:35:00 | Win2K-f | 91.152.6.57 (ELISA-LAAJAKAISTA.FI): ELISA-ADSL, ESPOO, ETELA-SUOMEN LAANI, FI. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
11:50:00 | Win2K-f | 70.100.252.14 (FRONTIERNET.NET): FRONTIER COMMUNICATIONS OF AMERICA INC, SHAWANO, WISCONSIN, US. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:22:00 | Win2K-f | 93.124.38.190 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:209 hits: 03-31 to 05-18] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:13:41:00 | WinXP | 202.221.175.41 (BMOBILE.NE.JP): JAPAN COMMUNICATION INC, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | 1a9d6615d6 NEW |
none[none] | none:none |
none|none | none | none | |
T:13:46:00 | WinXP | 86.135.94.186 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 1898e66cd2 NEW |
none[none] | none:none |
none|none | none | none |
T:14:14:00 | WinXP | 72.40.33.1 (MINDSPRING.COM): EARTHLINK INC, ORLANDO, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:38:00 | WinXP | 82.240.225.146 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:32:00 | WinXP | 92.40.88.200 (IKBCC.COM): EU-ZZ, UK. |
n/a | DE:proxim.ircgalaxy.pl DE:85.114.137.60:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
28 of 32 | dc9b45c892 NEW |
none[none] | none:none |
none|none | none | none |
16:54:00 | WinXP | 87.60.79.20 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | DE:proxim.ircgalaxy.pl US:mx1.hotmail.com US:mailin-04.mx.aol.com SE:ftp.icq.com US:yutunrz.1dumb.com US:mailin-03.mx.aol.com US:http.icq.com.edgesuite.net UA:citi-bank.ru UA:194.54.90.246:80 DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
http http 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | ef95595bfc NEW |
none[none] | none:none |
none|none | none | none |
T:18:04:00 | Win2K-f | 195.168.13.93 (GROUP4FALCK.SK): GTS INEC S.R.O, BRATISLAVA, BRATISLAVSKY, SK. |
84.244.5.183:2345 | DE:flu.flutp.com DE:tui.tuipo.net SE:scl.jullope.com |
445 | pcap | raw alerts ruleset |
http irc 9 lines |
Yeah : 1.8 profile |
none | summary tarball |
none none |
6dcbfb09f1 NEW 8ddcad441c NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
18:55:00 | WinXP | 218.216.94.164 (ODN.NE.JP): SOFTBANK TELECOM CORP, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:597 hits: 07-11 to 05-19] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
19:20:00 | WinXP | 69.183.189.244 (SNET.NET): PPPOX POOL - BRAS11.MRDNCT 050405-1245, NORWALK, CONNECTICUT, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:597 hits: 07-11 to 05-19] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
19:25:00 | WinXP | 66.74.236.19 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, CALIFORNIA, US. |
n/a | RU:moscow-advokat.ru :lulea.se.eu.undernet.org NO:london.uk.eu.undernet.org SE:coins.dal.net :washington.dc.us.undernet.org SE:ced.dal.net US:lia.zanet.net :caen.fr.eu.undernet.org SE:ozbytes.dal.net SE:broadway.ny.us.dal.net SE:qis.md.us.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 55fe9d9ade [Firefox:46 hits: 05-03 to 04-29] |
4bce6c4887 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:19:25:00 | WinXP | 66.74.236.19 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, CALIFORNIA, US. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 55fe9d9ade [Firefox:46 hits: 05-03 to 04-29] |
4bce6c4887 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:20:49:00 | WinXP | 130.13.153.233 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
85.114.137.60:65520 | DE:proxim.ircgalaxy.pl DE:dl2.teenpassage.com IL:ymq.a1001186.wrs.mcboo.com IL:wr.mcboo.com IL:194.90.224.86:80 |
445 | pcap | raw alerts ruleset |
ftp irc http 72 lines |
Yeah : 1.3 profile |
none | summary tarball |
27 of 32 21 of 32 26 of 32 |
194254331b NEW 54df1dbf7e [Firefox: 2 hits: 05-15 to 05-16] 790bdf0298 NEW |
f38db584e0 [0] 54df1dbf7e[1] none [none] |
ASM:Graph ASM:Graph none:none |
StarForce| StarForce| none|none |
lines=94 embedded dns lines=6 none |
trace trace none |
20:52:00 | Win2K-f | 130.13.153.233 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | 194254331b NEW |
f38db584e0 [0] | ASM:Graph |
StarForce| | lines=94 embedded dns |
trace | |
21:07:00 | WinXP | 58.90.237.227 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:597 hits: 07-11 to 05-19] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
21:57:00 | Win2K-f | 130.13.201.174 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | DE:proxim.ircgalaxy.pl DE:85.114.137.60:65520 |
445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 32 | ed26600cae NEW |
none[none] | none:none |
none|none | none | none |