Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

06 June 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
01:01:00 WinXP 116.59.11.44 (-):
MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:618 hits: 07-11 to 06-04]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:01:39:00 Win2K-f 4.238.19.29 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
ORLANDO, FLORIDA, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
02:24:00 WinXP 4.238.19.29 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
ORLANDO, FLORIDA, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:03:09:00 WinXP 59.105.10.163 (SEED.NET.TW):
DIGITAL UNITED I,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3024 hits: 12-31 to 06-05]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:03:22:00 WinXP 92.17.45.218 (-):
CARPHONE WAREHOUSE BROADBAND SERVICES,
UK.
222.177.11.165:8885 CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
irc
24 lines
Yeah : 1.3
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 9 hits: 05-31 to 06-05]
47300e90ee [0] none:none
none|none none trace
03:39:00 WinXP 61.231.176.119 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
03:47:00 Win2K-f 92.17.45.218 (-):
CARPHONE WAREHOUSE BROADBAND SERVICES,
UK.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
20 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox: 9 hits: 05-31 to 06-05]
47300e90ee [0] none:none
none|none none trace
T:04:51:00 Win2K-f 61.221.158.167 (HINET.NET):
DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
KAOHSIUNG, KAO-HSIUNG, TW.
n/a   135 pcap raw alerts
ruleset
other
242 lines
Yeah : 0.8
profile
none summary
tarball
24 of 32 fbacdd87c0
NEW
none[4] none:none
none|none none trace
T:05:03:00 WinXP 216.10.170.176 (WISPNET.NET):
WISPNET LLC,
WILSON, NORTH CAROLINA, US.
n/a EU:siliconfireware.ru
US:searchportal.information.com
RU:www.bbin.ru
RU:www.binbank.ru
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
http
25 lines
Yeah : 0.8
profile
none summary
tarball
24 of 32 a378d8efd7
NEW
none[4] none:none
ASPack| none trace
05:13:00 Win2K-f 61.229.43.202 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2635 hits: 12-31 to 06-05]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
05:52:00 Win2K-f 201.35.206.67 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a US:qtas.net
SE:dzuc.net
SE:84.244.5.183:2345
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
6 of 32 bcdf9ccd48
NEW
bcdf9ccd48 [1] ASM:Graph
none|none lines=37 trace
T:06:28:00 WinXP 88.204.145.43 (DIALUP.ITTE.KZ):
INTERNATIONAL AND TRUNK TELEPHONE EXCHANGE,
KZ.
209.250.232.240:7000 US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
irc
25 lines
Yeah : 1.3
profile
none summary
tarball
10 of 32 639a247ece
[Firefox:32 hits: 04-28 to 05-18]
29d53eec72 [0] ASM:Graph
StarForce| lines=132 trace
07:38:00 WinXP 4.229.18.66 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DETROIT, MICHIGAN, US. (DIAL)
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 5492326493
NEW
none[4] none:none
PolyEnE| none trace
T:07:58:00 WinXP 130.94.243.120 (VERIO.NET):
NTT AMERICA INC,
ENGLEWOOD, COLORADO, US.
72.10.172.218:3838 CA:haiys.eiheihre3.com
:sisxteen.oihduhdd.net
CA:mypal.urpal43sourpalhuh.com
CA:72.10.172.218:3838
CA:72.10.172.218:7763
135 pcap raw alerts
ruleset
other
1 line
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:07:59:00 Win2K-f 117.6.126.175 (ADSL.VIETTEL.VN):
VIETEL CORPORATION,
HANOI, HA NOI, VN.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 a2a036466a
[Firefox:263 hits: 05-05 to 06-01]
none[4] none:none
none|none none trace
08:00:00 WinXP 130.94.243.120 (VERIO.NET):
NTT AMERICA INC,
ENGLEWOOD, COLORADO, US.
72.10.172.218:7763 :nagoo.nagitiriheiwu.net
CA:mypal.urpal43sourpalhuh.com
:sisxteen.oihduhdd.net
CA:72.10.172.218:7763
135 pcap raw alerts
ruleset
other
1 line
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:08:27:00 Win2K-f 82.247.251.140 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 bae5bb7315
NEW
none[4] none:none
none|none none trace
T:09:31:00 Win2K-f 92.10.82.69 (-):
CARPHONE WAREHOUSE BROADBAND SERVICES,
UK.
209.250.232.240:7000 US:hail.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
http
25 lines
Yeah : 1.3
profile
none summary
tarball
25 of 31 8a133be75e
[Firefox: 2 hits: 05-05 to 05-11]
none[4] none:none
none|none none trace
09:33:00 WinXP 89.218.249.176 (ADSL.ONLINE.KZ):
KAZAKHTELECOM DATA NETWORK ADMINISTRATION,
KZ.
209.250.232.240:7000 US:scorti1.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
http
23 lines
Yeah : 1.3
profile
none summary
tarball
12 of 32
20 of 31
531b05c9d7
NEW
af98fe0c94
[Firefox:73 hits: 04-27 to 05-22]
none[4]
480d076a0a[0]
none:none
ASM:Graph
none|none
ASProtect|
none
lines=422
embedded dns
trace
trace
09:33:00 WinXP 4.154.93.3 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
WOODSTOCK, GEORGIA, US. (DIAL)
n/a DE:siliconfireware.ru
RU:www.bbin.ru
RU:www.binbank.ru
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
22 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1035 hits: 05-01 to 06-05]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
09:53:00 Win2K-f 202.61.46.157 (WOL.NET.PK):
CYBERSOFT TECHNOLOGIES PLC,
LAHORE, PUNJAB, PK.
n/a DE:flu.flutp.com 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:18:00 WinXP 89.152.220.34 (-):
TVCABO PORTUGAL S.A,
LISBON, LISBOA, PT.
209.250.232.240:7000 US:hail.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
http
24 lines
Yeah : 1.3
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1495 hits: 04-27 to 06-01]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
T:10:18:00 WinXP 200.226.102.122 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:27:00 WinXP 190.84.8.127 (CABLE.NET.CO):
TV CABLE S.A,
SANTAFé DE BOGOTá, DISTRITO CAPITAL, CO. (DSL)
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
18 of 32 7e28dac8de
[Firefox:26 hits: 04-27 to 05-23]
none[4] none:none
none|none none trace
10:33:00 WinXP 196.28.249.13 (-):
AFRINIC,
BF.
209.250.232.240:7000 :proxim.ircgalaxy.pl
US:hail.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 1.3
profile
none summary
tarball
28 of 31 36d24c4769
[Firefox: 2 hits: 05-05 to 05-08]
none[4] none:none
none|none none trace
T:10:35:00 Win2K-f 77.29.232.140 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1495 hits: 04-27 to 06-01]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
10:56:00 WinXP 122.52.28.247 (PLDT.NET):
IPG,
PH.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1495 hits: 04-27 to 06-01]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
T:11:32:00 WinXP 89.152.81.62 (-):
TVCABO PORTUGAL S.A,
LISBON, LISBOA, PT.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
25 of 28 43aaa8723f
[Firefox: 2 hits: 05-01 to 06-01]
none[4] none:none
none|none none trace
T:11:33:00 Win2K-f 201.35.206.67 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a US:qtas.net
SE:dzuc.net
SE:84.244.5.183:2345
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
6 of 32 bcdf9ccd48
NEW
bcdf9ccd48 [1] ASM:Graph
none|none lines=37 trace
T:11:42:00 Win2K-f 85.174.4.85 (RUNEXT.COM):
PROVIDER LOCAL REGISTRY,
RU.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1495 hits: 04-27 to 06-01]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
12:00:00 WinXP 86.109.34.20 (AZADNET.NET):
AZADNET COUNTRY WISE ADSL SERVICES,
TEHRAN, TEHRAN, IR.
n/a DE:siliconfireware.ru
GB:new.egg.com
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
24 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1035 hits: 05-01 to 06-05]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
T:12:39:00 WinXP 85.176.101.28 (ALICEDSL.DE):
HANSENET-ADSL,
HAMBURG, HAMBURG, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
4 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:14:04:00 Win2K-f 88.134.217.189 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
14:05:00 Win2K-f 91.65.252.218 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:14:06:00 Win2K-f 194.63.137.62 (LOZE.NET):
UNIKAL LTD,
SOFIA, SOFIYA, BG.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:14:06:00 Win2K-f 92.48.61.142 (IKBCC.COM):
EU-ZZ,
UK.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
14:07:00 Win2K-f 93.124.38.190 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
14:11:00 WinXP 118.20.78.55 (-):
.
n/a :proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
30 of 32 0e30aefa58
NEW
none[4] none:none
PolyEnE| none trace
14:12:00 Win2K-f 212.233.198.6 (-):
NTL,
FR.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
14:15:00 WinXP 89.169.144.142 (-):
MOSINFOLINE,
RU.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:14:17:00 WinXP 82.160.229.148 (EC.PL):
TELEKOMUNIKACJA KOLEJOWA SP. Z O.O,
PL.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:14:19:00 WinXP 88.195.77.86 (INET.FI):
BROADBAND ACCESS POOL,
FI.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
EU:kidos-bank.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
29 of 31 4ab5b0788c
[Firefox: 3 hits: 04-21 to 05-07]
272da55ef8 [0] ASM:Graph
PolyEnE| lines=114 trace
14:19:00 WinXP 82.247.165.147 (PROXAD.NET):
PROXAD / FREE SAS,
CHAMBERY, RHONE-ALPES, FR.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:14:22:00 Win2K-f 78.149.138.174 (OPALTELECOM.NET):
OPAL TELECOMMUNICATIONS INTERNET SERVICE PROVIDER,
UK.
n/a   445 pcap raw alerts
ruleset
ftp
11 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:14:24:00 Win2K-f 91.67.118.160 (SUPERKABEL.DE):
KABEL DEUTSCHLAND BREITBAND SERVICE GMBH,
DE.
n/a   445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
14:26:00 Win2K-f 41.220.16.114 (TELONE.CO.ZW):
AFRINIC,
ZW.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:14:26:00 WinXP 91.65.143.94 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
20 of 32 6686b0fe5f
NEW
none[4] none:none
ASProtect| none trace
T:14:37:00 Win2K-f 118.20.78.55 (-):
.
n/a :proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
30 of 32 0e30aefa58
NEW
none[4] none:none
PolyEnE| none trace
14:41:00 WinXP 122.122.34.243 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 0dbfaa395e
NEW
none[4] none:none
tElock| none trace
14:50:00 WinXP 88.134.86.90 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:14:51:00 WinXP 89.174.30.141 (COM.PL):
TELBESKID-NOWY_SACZ,
PL. (DSL)
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
irc
16 lines
Yeah : 1.3
profile
none summary
tarball
23 of 32 5b484187db
NEW
none[4] none:none
ASProtect| none trace
T:14:54:00 Win2K-f 91.67.163.185 (SUPERKABEL.DE):
KABEL DEUTSCHLAND BREITBAND SERVICE GMBH,
DE.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:15:01:00 Win2K-f 88.134.86.90 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
DE.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:15:13:00 WinXP 41.220.16.114 (TELONE.CO.ZW):
AFRINIC,
ZW.
69.42.216.90:9890 :f.unicat.org
69.42.216.90:9890
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
13 of 31 e8d4d8cde1
[Firefox:271 hits: 03-31 to 06-01]
fda109a6fd [0] ASM:Graph
ASProtect| lines=583
embedded dns
trace
T:15:23:00 Win2K-f 82.240.225.146 (PROXAD.NET):
PROXAD / FREE SAS,
NICE, PROVENCE-ALPES-COTE D'AZUR, FR.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:15:48:00 WinXP 212.200.172.237 (KRSTARICA.NET):
KRSTARICA-NET,
CS.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3024 hits: 12-31 to 06-05]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
16:22:00 Win2K-f 61.228.152.70 (PRESTONAUTO.COM):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2635 hits: 12-31 to 06-05]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
16:42:00 Win2K-f 85.69.0.16 (BDX.MODULONET.FR):
BORDEAUX CABLE MODEM USERS,
ROUEN, HAUTE-NORMANDIE, FR.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 0.8
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2635 hits: 12-31 to 06-05]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:16:49:00 WinXP 4.235.159.15 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
SPRING HILL, FLORIDA, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:403 hits: 12-31 to 06-05]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:18:09:00 WinXP 218.173.229.63 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 23c6886399
[Firefox: 2 hits: 06-03 to 06-03]
none[4] none:none
PolyEnE| none trace
T:19:22:00 WinXP 216.51.154.15 (NETINS.NET):
ELLSWORTH COOP TELEPHONE,
IOWA, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3024 hits: 12-31 to 06-05]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:20:06:00 WinXP 75.177.22.11 (RR.COM):
ROAD RUNNER HOLDCO LLC,
GREENSBORO, NORTH CAROLINA, US.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1315 hits: 12-31 to 06-05]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
21:36:00 WinXP 62.11.158.139 (DIALUP.TISCALI.IT):
TISCALI ITALIA SPA,
CAGLIARI, SARDEGNA, IT. (DIAL)
n/a EU:siliconfireware.ru
US:searchportal.information.com
:wpad
US:208.73.212.12:80
DE:212.227.111.29:80
DE:217.11.54.126:80
445 pcap raw alerts
ruleset
http
http
http
3 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
[Firefox:454 hits: 05-04 to 06-03]
9bbdd086c5 [0] ASM:Graph
ASPack| lines=186
embedded dns
trace