Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
01:01:00 | WinXP | 116.59.11.44 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:618 hits: 07-11 to 06-04] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:01:39:00 | Win2K-f | 4.238.19.29 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ORLANDO, FLORIDA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
02:24:00 | WinXP | 4.238.19.29 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ORLANDO, FLORIDA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:09:00 | WinXP | 59.105.10.163 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3024 hits: 12-31 to 06-05] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace | |
T:03:22:00 | WinXP | 92.17.45.218 (-): CARPHONE WAREHOUSE BROADBAND SERVICES, UK. |
222.177.11.165:8885 | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 9 hits: 05-31 to 06-05] |
47300e90ee [0] | none:none |
none|none | none | trace |
03:39:00 | WinXP | 61.231.176.119 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
03:47:00 | Win2K-f | 92.17.45.218 (-): CARPHONE WAREHOUSE BROADBAND SERVICES, UK. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox: 9 hits: 05-31 to 06-05] |
47300e90ee [0] | none:none |
none|none | none | trace |
T:04:51:00 | Win2K-f | 61.221.158.167 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, KAOHSIUNG, KAO-HSIUNG, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 242 lines |
Yeah : 0.8 profile |
none | summary tarball |
24 of 32 | fbacdd87c0 NEW |
none[4] | none:none |
none|none | none | trace | |
T:05:03:00 | WinXP | 216.10.170.176 (WISPNET.NET): WISPNET LLC, WILSON, NORTH CAROLINA, US. |
n/a | EU:siliconfireware.ru US:searchportal.information.com RU:www.bbin.ru RU:www.binbank.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http http 25 lines |
Yeah : 0.8 profile |
none | summary tarball |
24 of 32 | a378d8efd7 NEW |
none[4] | none:none |
ASPack| | none | trace |
05:13:00 | Win2K-f | 61.229.43.202 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2635 hits: 12-31 to 06-05] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
05:52:00 | Win2K-f | 201.35.206.67 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:qtas.net SE:dzuc.net SE:84.244.5.183:2345 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
6 of 32 | bcdf9ccd48 NEW |
bcdf9ccd48 [1] | ASM:Graph |
none|none | lines=37 | trace |
T:06:28:00 | WinXP | 88.204.145.43 (DIALUP.ITTE.KZ): INTERNATIONAL AND TRUNK TELEPHONE EXCHANGE, KZ. |
209.250.232.240:7000 | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp irc 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 32 | 639a247ece [Firefox:32 hits: 04-28 to 05-18] |
29d53eec72 [0] | ASM:Graph |
StarForce| | lines=132 | trace |
07:38:00 | WinXP | 4.229.18.66 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DETROIT, MICHIGAN, US. (DIAL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5492326493 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:07:58:00 | WinXP | 130.94.243.120 (VERIO.NET): NTT AMERICA INC, ENGLEWOOD, COLORADO, US. |
72.10.172.218:3838 | CA:haiys.eiheihre3.com :sisxteen.oihduhdd.net CA:mypal.urpal43sourpalhuh.com CA:72.10.172.218:3838 CA:72.10.172.218:7763 |
135 | pcap | raw alerts ruleset |
other 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:59:00 | Win2K-f | 117.6.126.175 (ADSL.VIETTEL.VN): VIETEL CORPORATION, HANOI, HA NOI, VN. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | a2a036466a [Firefox:263 hits: 05-05 to 06-01] |
none[4] | none:none |
none|none | none | trace |
08:00:00 | WinXP | 130.94.243.120 (VERIO.NET): NTT AMERICA INC, ENGLEWOOD, COLORADO, US. |
72.10.172.218:7763 | :nagoo.nagitiriheiwu.net CA:mypal.urpal43sourpalhuh.com :sisxteen.oihduhdd.net CA:72.10.172.218:7763 |
135 | pcap | raw alerts ruleset |
other 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:27:00 | Win2K-f | 82.247.251.140 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | bae5bb7315 NEW |
none[4] | none:none |
none|none | none | trace |
T:09:31:00 | Win2K-f | 92.10.82.69 (-): CARPHONE WAREHOUSE BROADBAND SERVICES, UK. |
209.250.232.240:7000 | US:hail.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 31 | 8a133be75e [Firefox: 2 hits: 05-05 to 05-11] |
none[4] | none:none |
none|none | none | trace |
09:33:00 | WinXP | 89.218.249.176 (ADSL.ONLINE.KZ): KAZAKHTELECOM DATA NETWORK ADMINISTRATION, KZ. |
209.250.232.240:7000 | US:scorti1.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 32 20 of 31 |
531b05c9d7 NEW af98fe0c94 [Firefox:73 hits: 04-27 to 05-22] |
none[4] 480d076a0a[0] |
none:none ASM:Graph |
none|none ASProtect| |
none lines=422 embedded dns |
trace trace |
09:33:00 | WinXP | 4.154.93.3 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, WOODSTOCK, GEORGIA, US. (DIAL) |
n/a | DE:siliconfireware.ru RU:www.bbin.ru RU:www.binbank.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1035 hits: 05-01 to 06-05] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
09:53:00 | Win2K-f | 202.61.46.157 (WOL.NET.PK): CYBERSOFT TECHNOLOGIES PLC, LAHORE, PUNJAB, PK. |
n/a | DE:flu.flutp.com | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:18:00 | WinXP | 89.152.220.34 (-): TVCABO PORTUGAL S.A, LISBON, LISBOA, PT. |
209.250.232.240:7000 | US:hail.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1495 hits: 04-27 to 06-01] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
T:10:18:00 | WinXP | 200.226.102.122 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
10:27:00 | WinXP | 190.84.8.127 (CABLE.NET.CO): TV CABLE S.A, SANTAFé DE BOGOTá, DISTRITO CAPITAL, CO. (DSL) |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
18 of 32 | 7e28dac8de [Firefox:26 hits: 04-27 to 05-23] |
none[4] | none:none |
none|none | none | trace |
10:33:00 | WinXP | 196.28.249.13 (-): AFRINIC, BF. |
209.250.232.240:7000 | :proxim.ircgalaxy.pl US:hail.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 31 | 36d24c4769 [Firefox: 2 hits: 05-05 to 05-08] |
none[4] | none:none |
none|none | none | trace |
T:10:35:00 | Win2K-f | 77.29.232.140 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1495 hits: 04-27 to 06-01] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
10:56:00 | WinXP | 122.52.28.247 (PLDT.NET): IPG, PH. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1495 hits: 04-27 to 06-01] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
T:11:32:00 | WinXP | 89.152.81.62 (-): TVCABO PORTUGAL S.A, LISBON, LISBOA, PT. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 28 | 43aaa8723f [Firefox: 2 hits: 05-01 to 06-01] |
none[4] | none:none |
none|none | none | trace |
T:11:33:00 | Win2K-f | 201.35.206.67 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:qtas.net SE:dzuc.net SE:84.244.5.183:2345 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
6 of 32 | bcdf9ccd48 NEW |
bcdf9ccd48 [1] | ASM:Graph |
none|none | lines=37 | trace |
T:11:42:00 | Win2K-f | 85.174.4.85 (RUNEXT.COM): PROVIDER LOCAL REGISTRY, RU. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1495 hits: 04-27 to 06-01] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
12:00:00 | WinXP | 86.109.34.20 (AZADNET.NET): AZADNET COUNTRY WISE ADSL SERVICES, TEHRAN, TEHRAN, IR. |
n/a | DE:siliconfireware.ru GB:new.egg.com :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1035 hits: 05-01 to 06-05] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:12:39:00 | WinXP | 85.176.101.28 (ALICEDSL.DE): HANSENET-ADSL, HAMBURG, HAMBURG, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:04:00 | Win2K-f | 88.134.217.189 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
14:05:00 | Win2K-f | 91.65.252.218 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:14:06:00 | Win2K-f | 194.63.137.62 (LOZE.NET): UNIKAL LTD, SOFIA, SOFIYA, BG. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:14:06:00 | Win2K-f | 92.48.61.142 (IKBCC.COM): EU-ZZ, UK. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
14:07:00 | Win2K-f | 93.124.38.190 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
14:11:00 | WinXP | 118.20.78.55 (-): . |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 0e30aefa58 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
14:12:00 | Win2K-f | 212.233.198.6 (-): NTL, FR. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
14:15:00 | WinXP | 89.169.144.142 (-): MOSINFOLINE, RU. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:14:17:00 | WinXP | 82.160.229.148 (EC.PL): TELEKOMUNIKACJA KOLEJOWA SP. Z O.O, PL. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:19:00 | WinXP | 88.195.77.86 (INET.FI): BROADBAND ACCESS POOL, FI. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru EU:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 31 | 4ab5b0788c [Firefox: 3 hits: 04-21 to 05-07] |
272da55ef8 [0] | ASM:Graph |
PolyEnE| | lines=114 | trace |
14:19:00 | WinXP | 82.247.165.147 (PROXAD.NET): PROXAD / FREE SAS, CHAMBERY, RHONE-ALPES, FR. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:14:22:00 | Win2K-f | 78.149.138.174 (OPALTELECOM.NET): OPAL TELECOMMUNICATIONS INTERNET SERVICE PROVIDER, UK. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:24:00 | Win2K-f | 91.67.118.160 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:26:00 | Win2K-f | 41.220.16.114 (TELONE.CO.ZW): AFRINIC, ZW. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:14:26:00 | WinXP | 91.65.143.94 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 32 | 6686b0fe5f NEW |
none[4] | none:none |
ASProtect| | none | trace |
T:14:37:00 | Win2K-f | 118.20.78.55 (-): . |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 0e30aefa58 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
14:41:00 | WinXP | 122.122.34.243 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 0dbfaa395e NEW |
none[4] | none:none |
tElock| | none | trace | |
14:50:00 | WinXP | 88.134.86.90 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:14:51:00 | WinXP | 89.174.30.141 (COM.PL): TELBESKID-NOWY_SACZ, PL. (DSL) |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp irc 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
23 of 32 | 5b484187db NEW |
none[4] | none:none |
ASProtect| | none | trace |
T:14:54:00 | Win2K-f | 91.67.163.185 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:15:01:00 | Win2K-f | 88.134.86.90 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:15:13:00 | WinXP | 41.220.16.114 (TELONE.CO.ZW): AFRINIC, ZW. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:271 hits: 03-31 to 06-01] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
T:15:23:00 | Win2K-f | 82.240.225.146 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:48:00 | WinXP | 212.200.172.237 (KRSTARICA.NET): KRSTARICA-NET, CS. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3024 hits: 12-31 to 06-05] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
16:22:00 | Win2K-f | 61.228.152.70 (PRESTONAUTO.COM): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2635 hits: 12-31 to 06-05] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
16:42:00 | Win2K-f | 85.69.0.16 (BDX.MODULONET.FR): BORDEAUX CABLE MODEM USERS, ROUEN, HAUTE-NORMANDIE, FR. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2635 hits: 12-31 to 06-05] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:16:49:00 | WinXP | 4.235.159.15 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SPRING HILL, FLORIDA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:403 hits: 12-31 to 06-05] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:18:09:00 | WinXP | 218.173.229.63 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 23c6886399 [Firefox: 2 hits: 06-03 to 06-03] |
none[4] | none:none |
PolyEnE| | none | trace |
T:19:22:00 | WinXP | 216.51.154.15 (NETINS.NET): ELLSWORTH COOP TELEPHONE, IOWA, US. (DIAL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3024 hits: 12-31 to 06-05] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:20:06:00 | WinXP | 75.177.22.11 (RR.COM): ROAD RUNNER HOLDCO LLC, GREENSBORO, NORTH CAROLINA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1315 hits: 12-31 to 06-05] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
21:36:00 | WinXP | 62.11.158.139 (DIALUP.TISCALI.IT): TISCALI ITALIA SPA, CAGLIARI, SARDEGNA, IT. (DIAL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com :wpad US:208.73.212.12:80 DE:212.227.111.29:80 DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:454 hits: 05-04 to 06-03] |
9bbdd086c5 [0] | ASM:Graph |
ASPack| | lines=186 embedded dns |
trace |