Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

20 May 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:13:00 Win2K-f 219.167.104.234 (PLALA.OR.JP):
PLALA NETWORKS INC,
THANJAVUR, TAMIL NADU, IN.
209.250.232.240:7000 US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
irc
25 lines
Yeah : 1.8
profile
none summary
tarball
18 of 32 b4ad631671
[Firefox:11 hits: 04-29 to 05-19]
5890f017cc [0] ASM:Graph
StarForce| lines=28 trace
T:00:39:00 Win2K-f 87.123.169.214 (VERSANET.DE):
VERSATEL DEUTSCHLAND DYNAMIC POOL,
DE.
209.250.232.240:7000 US:scorti1.dns2go.com 445 pcap raw alerts
ruleset
ftp
irc
25 lines
Yeah : 1.8
profile
none summary
tarball
22 of 32 dc8e1c63cd
[Firefox:91 hits: 12-27 to 05-18]
e0eb8646ee [0] ASM:Graph
none|none lines=601
embedded dns
trace
T:00:50:00 Win2K-f 62.205.185.92 (CORBINA.NET):
MCN-CUSTOMERS,
MOSCOW, MOSKVA, RU.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
01:49:00 WinXP 203.196.65.116 (KAGACABLE.NE.JP):
KAGA CABLE TELEVISION CO.LTD,
JP. (DSL)
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1292 hits: 12-31 to 05-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
02:28:00 Win2K-f 81.195.108.238 (-):
GRACHEVA YULIYA PETROVNA,
MOSCOW, MOSKVA, RU. (100Mbps)
84.244.5.183:2345 US:wow.blackirc.us
SE:tap.radioprishtina.net
445 pcap raw alerts
ruleset
http
irc
38 lines
Yeah : 1.3
profile
none summary
tarball
14 of 32 69474721cb
NEW
none[none] none:none
none|none none none
02:39:00 WinXP 59.120.87.122 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:597 hits: 07-11 to 05-19]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
03:14:00 Win2K-f 89.106.108.40 (-):
OPTILINK,
BG.
209.250.232.240:7000 US:hail.dns2go.com 445 pcap raw alerts
ruleset
ftp
20 lines
Yeah : 1.3
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1344 hits: 04-27 to 05-19]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
03:57:00 WinXP 75.89.54.80 (ALLTEL.NET):
WINDSTREAM - COMMERCE,
COMMERCE, GEORGIA, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
30 of 32 43306fc684
[Firefox: 6 hits: 12-28 to 05-05]
59fc5b2b93 [0] ASM:Graph
PolyEnE| lines=60 trace
05:22:00 WinXP 85.240.194.117 (DSL.TELEPAC.PT):
PT.COM - COMUNICACOES INTERACTIVAS S.A,
LEIRIA, LEIRIA, PT. (DSL)
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
31 of 32 cf7bb33fb2
[Firefox: 7 hits: 03-11 to 05-04]
3040889c26 [0] ASM:Graph
PolyEnE| lines=68 trace
05:42:00 WinXP 67.37.40.98 (AMERITECH.NET):
DIAL POOL - TNT2.KALAMAZOO.MI.AMERITECH.NET,
STEVENSVILLE, MICHIGAN, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:2991 hits: 12-31 to 05-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:06:12:00 WinXP 202.221.174.230 (BMOBILE.NE.JP):
JAPAN COMMUNICATION INC,
TOKYO, TOKYO, JP.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 3ae357d17b
[Firefox:709 hits: 05-01 to 05-19]
462a7be171 [0] ASM:Graph
PolyEnE| lines=73 trace
T:06:52:00 WinXP 122.53.223.145 (PLDT.NET):
IPG,
PH.
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:07:07:00 WinXP 117.98.36.228 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a EU:siliconfireware.ru
US:searchportal.information.com
GB:new.egg.com
:wpad
US:208.73.212.12:80
DE:212.227.111.29:80
DE:217.11.54.126:80
445 pcap raw alerts
ruleset
http
http
http
http
27 lines
Yeah : 1.3
profile
none summary
tarball
23 of 32 7fb51ea621
NEW
none[none] none:none
none|none none none
T:07:45:00 WinXP 189.42.166.143 (BRASILTELECOM.NET.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR.
85.114.137.60:65520 DE:proxim.ircgalaxy.pl
DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
GB:welcome3.smile.co.uk
:wpad
DE:dl2.teenpassage.com
IL:ymq.a1001186.wrs.mcboo.com
IL:wr.mcboo.com
IL:194.90.224.86:80
GB:195.92.84.198:80
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
http
http
irc
131 lines
Yeah : 1.8
profile
none summary
tarball
29 of 32
21 of 32
26 of 32
33deed5eaa
NEW
54df1dbf7e
[Firefox: 2 hits: 05-15 to 05-16]
790bdf0298
NEW
none[none]
54df1dbf7e[1]
none [none]
none:none
ASM:Graph
none:none
none|none
StarForce|
none|none
none
lines=6
none
none
trace
none
T:07:53:00 WinXP 124.106.10.72 (-):
QCYC7300I03_CONSUMER,
MANILA, MANILA, PH.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 1e5df7ba74
[Firefox:16 hits: 03-24 to 05-18]
a5331b711f [0] ASM:Graph
PolyEnE| lines=68 trace
07:58:00 WinXP 70.112.247.252 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CEDAR PARK, TEXAS, US.
n/a DE:siliconfireware.ru
GB:welcome3.smile.co.uk
:wpad
GB:195.92.84.198:80
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1022 hits: 05-01 to 05-19]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
T:08:05:00 WinXP 211.215.32.49 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
09:41:00 WinXP 91.67.88.134 (SUPERKABEL.DE):
KABEL DEUTSCHLAND BREITBAND SERVICE GMBH,
DE.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1292 hits: 12-31 to 05-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
10:13:00 Win2K-f 91.64.55.112 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:14:00 WinXP 82.160.229.95 (EC.PL):
TELEKOMUNIKACJA KOLEJOWA SP. Z O.O,
PL.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:14:00 Win2K-f 91.64.208.251 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :www.google.com
:f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:21:00 WinXP 212.233.211.44 (-):
NTL,
FR.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:22:00 WinXP 91.1.198.46 (T-IPCONNECT.DE):
DEUTSCHE TELEKOM AG,
DE.
n/a :f.unicat.org
:www.google.com
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:22:00 WinXP 91.65.74.36 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:24:00 Win2K-f 85.85.223.86 (CLIENTES.EUSKALTEL.ES):
EUSKALTEL,
ES.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:24:00 WinXP 41.214.130.117 (-):
.
n/a :www.google.com 445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:24:00 WinXP 88.134.194.130 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:10:25:00 Win2K-f 89.27.246.35 (KIELNET.NET):
RECHENZENTRUM KIEL,
KIEL, SCHLESWIG-HOLSTEIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:10:26:00 Win2K-f 85.85.223.86 (CLIENTES.EUSKALTEL.ES):
EUSKALTEL,
ES.
n/a :www.google.com 445 pcap raw alerts
ruleset
other
3 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:29:00 Win2K-f 91.1.198.46 (T-IPCONNECT.DE):
DEUTSCHE TELEKOM AG,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:31:00 Win2K-f 91.66.10.208 (SUPERKABEL.DE):
KABEL DEUTSCHLAND BREITBAND SERVICE GMBH,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:32:00 WinXP 91.64.5.51 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :f.unicat.org
:www.google.com
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:33:00 WinXP 91.67.148.94 (SUPERKABEL.DE):
KABEL DEUTSCHLAND BREITBAND SERVICE GMBH,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:42:00 Win2K-f 89.136.39.102 (UPCNET.RO):
ASTRAL UPC TIMISOARA,
TIMISOARA, TIMIS, RO.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:43:00 Win2K-f 82.66.100.119 (PROXAD.NET):
PROXAD / FREE SAS,
PARIS, ILE-DE-FRANCE, FR.
n/a :www.google.com 445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:10:45:00 Win2K-f 91.64.5.51 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:10:51:00 WinXP 60.47.224.107 (PLALA.OR.JP):
PLALA NETWORKS INC,
CHITOSE, HOKKAIDO, JP.
n/a :www.google.com 445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:57:00 Win2K-f 89.35.204.203 (RAKNETSOFT.RO):
SC RAKNET SOFT SRL,
PLOIESTI, PRAHOVA, RO.
n/a   445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:58:00 WinXP 91.65.58.138 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
20 of 32 b6eaa3f885
NEW
none[none] none:none
none|none none none
T:10:58:00 Win2K-f 91.65.177.231 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org 445 pcap raw alerts
ruleset
ftp
irc
21 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
10:59:00 WinXP 89.204.193.222 (O2.IE):
O2 IRELAND MOBILE PHONE OPERATOR,
IE.
n/a DE:proxim.ircgalaxy.pl
UA:citi-bank.ru
:www.google.com
EU:kidos-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
32 of 32 34187b60d1
NEW
none[none] none:none
none|none none none
T:11:06:00 Win2K-f 93.124.38.190 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
69.42.216.90:9890 :f.unicat.org 445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:11:11:00 WinXP 82.240.174.182 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
irc
27 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
11:18:00 Win2K-f 91.64.208.251 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:11:19:00 Win2K-f 91.65.58.138 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org 445 pcap raw alerts
ruleset
ftp
irc
27 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
11:23:00 WinXP 91.65.57.15 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
n/a :www.google.com 445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:11:25:00 Win2K-f 70.100.252.14 (FRONTIERNET.NET):
FRONTIER COMMUNICATIONS OF AMERICA INC,
SHAWANO, WISCONSIN, US.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:11:30:00 WinXP 12.215.129.196 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
ANKENY, IOWA, US.
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
11:35:00 Win2K-f 91.152.6.57 (ELISA-LAAJAKAISTA.FI):
ELISA-ADSL,
ESPOO, ETELA-SUOMEN LAANI, FI.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
11 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
11:50:00 Win2K-f 70.100.252.14 (FRONTIERNET.NET):
FRONTIER COMMUNICATIONS OF AMERICA INC,
SHAWANO, WISCONSIN, US.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:13:22:00 Win2K-f 93.124.38.190 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:209 hits: 03-31 to 05-18]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:13:41:00 WinXP 202.221.175.41 (BMOBILE.NE.JP):
JAPAN COMMUNICATION INC,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
none 1a9d6615d6
NEW
none[none] none:none
none|none none none
T:13:46:00 WinXP 86.135.94.186 (BTCENTRALPLUS.COM):
BT-CENTRAL-PLUS,
LONDON, ENGLAND, UK.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
31 of 32 1898e66cd2
NEW
none[none] none:none
none|none none none
T:14:14:00 WinXP 72.40.33.1 (MINDSPRING.COM):
EARTHLINK INC,
ORLANDO, FLORIDA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
14:38:00 WinXP 82.240.225.146 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
16:32:00 WinXP 92.40.88.200 (IKBCC.COM):
EU-ZZ,
UK.
n/a DE:proxim.ircgalaxy.pl
DE:85.114.137.60:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
28 of 32 dc9b45c892
NEW
none[none] none:none
none|none none none
16:54:00 WinXP 87.60.79.20 (IP.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
DK.
n/a DE:proxim.ircgalaxy.pl
US:mx1.hotmail.com
US:mailin-04.mx.aol.com
SE:ftp.icq.com
US:yutunrz.1dumb.com
US:mailin-03.mx.aol.com
US:http.icq.com.edgesuite.net
UA:citi-bank.ru
UA:194.54.90.246:80
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
http
http
19 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33 ef95595bfc
NEW
none[none] none:none
none|none none none
T:18:04:00 Win2K-f 195.168.13.93 (GROUP4FALCK.SK):
GTS INEC S.R.O,
BRATISLAVA, BRATISLAVSKY, SK.
84.244.5.183:2345 DE:flu.flutp.com
DE:tui.tuipo.net
SE:scl.jullope.com
445 pcap raw alerts
ruleset
http
irc
9 lines
Yeah : 1.8
profile
none summary
tarball
none
none
6dcbfb09f1
NEW
8ddcad441c
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
18:55:00 WinXP 218.216.94.164 (ODN.NE.JP):
SOFTBANK TELECOM CORP,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:597 hits: 07-11 to 05-19]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
19:20:00 WinXP 69.183.189.244 (SNET.NET):
PPPOX POOL - BRAS11.MRDNCT 050405-1245,
NORWALK, CONNECTICUT, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:597 hits: 07-11 to 05-19]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
19:25:00 WinXP 66.74.236.19 (RR.COM):
ROAD RUNNER HOLDCO LLC,
ORANGE, CALIFORNIA, US.
n/a RU:moscow-advokat.ru
:lulea.se.eu.undernet.org
NO:london.uk.eu.undernet.org
SE:coins.dal.net
:washington.dc.us.undernet.org
SE:ced.dal.net
US:lia.zanet.net
:caen.fr.eu.undernet.org
SE:ozbytes.dal.net
SE:broadway.ny.us.dal.net
SE:qis.md.us.dal.net
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
29 of 29 55fe9d9ade
[Firefox:46 hits: 05-03 to 04-29]
4bce6c4887 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:19:25:00 WinXP 66.74.236.19 (RR.COM):
ROAD RUNNER HOLDCO LLC,
ORANGE, CALIFORNIA, US.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
29 of 29 55fe9d9ade
[Firefox:46 hits: 05-03 to 04-29]
4bce6c4887 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:20:49:00 WinXP 130.13.153.233 (QWEST.NET):
QWEST BROADBAND SERVICES INC,
PHOENIX, ARIZONA, US.
85.114.137.60:65520 DE:proxim.ircgalaxy.pl
DE:dl2.teenpassage.com
IL:ymq.a1001186.wrs.mcboo.com
IL:wr.mcboo.com
IL:194.90.224.86:80
445 pcap raw alerts
ruleset
ftp
irc
http
72 lines
Yeah : 1.3
profile
none summary
tarball
27 of 32
21 of 32
26 of 32
194254331b
NEW
54df1dbf7e
[Firefox: 2 hits: 05-15 to 05-16]
790bdf0298
NEW
f38db584e0 [0]
54df1dbf7e[1]
none [none]
ASM:Graph
ASM:Graph
none:none
StarForce|
StarForce|
none|none
lines=94
embedded dns
lines=6
none
trace
trace
none
20:52:00 Win2K-f 130.13.153.233 (QWEST.NET):
QWEST BROADBAND SERVICES INC,
PHOENIX, ARIZONA, US.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 194254331b
NEW
f38db584e0 [0] ASM:Graph
StarForce| lines=94
embedded dns
trace
21:07:00 WinXP 58.90.237.227 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:597 hits: 07-11 to 05-19]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
21:57:00 Win2K-f 130.13.201.174 (QWEST.NET):
QWEST BROADBAND SERVICES INC,
PHOENIX, ARIZONA, US.
n/a DE:proxim.ircgalaxy.pl
DE:85.114.137.60:65520
445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
29 of 32 ed26600cae
NEW
none[none] none:none
none|none none none