Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:06:00 | WinXP | 119.17.99.51 (-): . |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 3f5ec58a6b [Firefox:26 hits: 04-24 to 06-02] |
4a77430a59 [0] | ASM:Graph |
PolyEnE| | lines=70 | trace |
T:00:10:00 | WinXP | 119.17.99.51 (-): . |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 3f5ec58a6b [Firefox:26 hits: 04-24 to 06-02] |
4a77430a59 [0] | ASM:Graph |
PolyEnE| | lines=70 | trace |
T:00:51:00 | Win2K-f | 89.111.221.129 (TEOL.NET): TEOL-NET-DIALUP-POOL, BANJA LUKA, REPUBLIKA SRPSKA, BA. (DIAL) |
n/a | US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
19 of 30 | 93282471f7 [Firefox:20 hits: 04-28 to 05-21] |
95951dee58 [0] | ASM:Graph |
ASProtect| | lines=0 | trace |
T:01:34:00 | Win2K-f | 122.118.20.97 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
19 of 32 | 890fb4fa10 [Firefox:47 hits: 12-27 to 06-01] |
b9c7f08a57 [0] | ASM:Graph |
ASProtect| | lines=393 embedded dns |
trace |
01:46:00 | WinXP | 82.230.162.15 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:14:00 | Win2K-f | 151.118.176.44 (QWEST.NET): QWEST BROADBAND, PHOENIX, ARIZONA, US. |
66.252.13.227:6667 | :proxim.ircgalaxy.pl US:4949.zerx-virus.biz **:0.0.0.10:1433 **:0.0.0.11:1433 **:0.0.0.12:1433 **:0.0.0.13:1433 **:0.0.0.14:1433 **:0.0.0.15:1433 **:0.0.0.16:1433 **:0.0.0.17:1433 **:0.0.0.18:1433 **:0.0.0.19:1433 **:0.0.0.1:1433 **:0.0.0.20:1433 **:0.0.0.21:1433 **:0.0.0.2:1433 **:0.0.0.3:1433 **:0.0.0.4:1433 **:0.0.0.5:1433 **:0.0.0.6:1433 **:0.0.0.7:1433 **:0.0.0.8:1433 **:0.0.0.9:1433 |
135 | pcap | raw alerts ruleset |
irc 538 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | ce537f8a8e NEW |
none[4] | none:none |
none|none | none | trace |
T:02:25:00 | Win2K-f | 211.213.67.182 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
02:34:00 | WinXP | 93.81.42.80 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
209.250.232.240:7000 | US:scorti1.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 31 | af98fe0c94 [Firefox:74 hits: 04-27 to 06-06] |
480d076a0a [0] | ASM:Graph |
ASProtect| | lines=422 embedded dns |
trace |
03:46:00 | WinXP | 88.195.77.86 (INET.FI): BROADBAND ACCESS POOL, FI. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 31 | 4ab5b0788c [Firefox: 4 hits: 04-21 to 06-06] |
272da55ef8 [0] | ASM:Graph |
PolyEnE| | lines=114 | trace |
T:04:48:00 | Win2K-f | 92.11.37.184 (-): CARPHONE WAREHOUSE BROADBAND SERVICES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | d12e4a3f7d NEW |
none[4] | none:none |
none|none | none | trace | |
T:05:15:00 | WinXP | 122.120.8.188 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
217.170.244.2:443 | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 31 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2638 hits: 12-31 to 06-06] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
05:19:00 | WinXP | 85.24.168.47 (BAHNHOF.SE): BAHNHOF INTERNET AB, SE. |
n/a | CN:hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:63 hits: 05-29 to 06-05] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
T:05:36:00 | Win2K-f | 119.94.163.49 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 106 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:11:00 | WinXP | 221.245.131.189 (UCOM.NE.JP): N-KG, KAWASAKI, KANAGAWA, JP. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:619 hits: 07-11 to 06-06] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
06:15:00 | WinXP | 4.248.239.80 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOUISA, VIRGINIA, US. (DIAL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:284 hits: 05-01 to 06-05] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
T:07:24:00 | WinXP | 84.53.213.89 (ELCOM.RU): JSC CENTERTELECOM, RU. (DIAL) |
n/a | US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
12 of 31 | ab48a97a5d [Firefox: 7 hits: 12-28 to 05-21] |
81e9c5d188 [0] | ASM:Graph |
ASProtect| | lines=419 embedded dns |
trace |
07:25:00 | Win2K-f | 116.206.60.254 (-): MOBIF WIRELESS BROADBAND SDN. BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. |
n/a | US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | f30c325342 NEW |
none[4] | none:none |
none|none | none | trace |
07:40:00 | WinXP | 89.207.67.103 (-): JOINT STOCK COMPANY SVYAZIST, RU. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
07:48:00 | WinXP | 118.8.188.54 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:619 hits: 07-11 to 06-06] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
07:53:00 | WinXP | 78.144.32.77 (-): OPAL TELECOM DSL, LONDON, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
07:57:00 | Win2K-f | 41.212.203.184 (-): . |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1499 hits: 04-27 to 06-06] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
T:08:16:00 | Win2K-f | 91.144.78.131 (MEGATHERM.HU): ANTENNA TAVKOZLESI, BUDAPEST, BUDAPEST, HU. |
n/a | US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
19 of 32 | 69059a59e5 NEW |
none[4] | none:none |
StarForce| | none | trace |
T:08:27:00 | WinXP | 78.176.238.138 (SMYTHECRAMER.COM): TELEKOM, TR. |
n/a | :proxim.ircgalaxy.pl US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 32 | 85f06e20ac NEW |
none[4] | none:none |
none|none | none | trace |
08:28:00 | Win2K-f | 79.81.10.202 (G-M-I.NET): EU-ZZ, UK. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 31 | 0ca18d1183 [Firefox: 3 hits: 04-27 to 05-14] |
none[4] | none:none |
none|none | none | trace |
T:08:35:00 | WinXP | 216.54.173.190 (TWTELECOM.NET): TIME WARNER TELECOM INC, VIRGINIA BEACH, VIRGINIA, US. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:619 hits: 07-11 to 06-06] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
08:39:00 | WinXP | 122.26.238.137 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:619 hits: 07-11 to 06-06] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:09:24:00 | Win2K-f | 71.103.108.120 (VERIZON.NET): VERIZON INTERNET SERVICES INC, WHITTIER, CALIFORNIA, US. (DSL) |
n/a | US:qtas.net SE:dzuc.net SE:84.244.5.183:2345 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 32 | a50330e92d NEW |
a50330e92d [1] | ASM:Graph |
none|none | lines=10 | trace |
T:10:19:00 | WinXP | 195.206.43.167 (-): BAYKALWESTCOM NETWORK, IRKUTSK, IRKUTSKAYA OBLAST', RU. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
20 of 33 | 4f0719aad0 NEW |
none[4] | none:none |
StarForce| | none | trace |
T:10:33:00 | Win2K-f | 88.87.239.166 (KABELSZATNET-2002.HU): KABELSZATNET-2002 KFT. PAPA, HU. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
10:37:00 | Win2K-f | 79.81.10.139 (G-M-I.NET): EU-ZZ, UK. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 31 | 0ca18d1183 [Firefox: 3 hits: 04-27 to 05-14] |
none[4] | none:none |
none|none | none | trace |
10:49:00 | WinXP | 201.47.136.203 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 4c27e2165f [Firefox: 3 hits: 09-05 to 10-30] |
none[4] | none:none |
PolyEnE| | none | trace |
10:51:00 | Win2K-f | 89.232.196.206 (ISURGUT.RU): OPEN JOINT-STOCK COMPANY URALSVIAZINFORM BRANCH OF THE KHANTYMANSIYSK REGION, RU. (DIAL) |
n/a | CN:hail2.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 5ee4121e1e [Firefox:63 hits: 05-29 to 06-05] |
51c1525417 [0] | none:none |
Obsidium| | none | trace |
11:28:00 | Win2K-f | 84.180.109.45 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, CHEMNITZ, SACHSEN, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 36db555136 NEW |
none[4] | none:none |
none|none | none | trace | |
T:11:43:00 | WinXP | 201.4.103.232 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
209.250.232.240:7000 | US:hail.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1499 hits: 04-27 to 06-06] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
T:11:52:00 | Win2K-f | 189.49.116.128 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 32 | 53b36ec898 NEW |
none[4] | none:none |
none|none | none | trace | |
T:12:19:00 | WinXP | 216.249.8.86 (PATHCOM.COM): PATHWAY COMMUNICATIONS, TORONTO, ONTARIO, CA. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com EU:ebookfinaltrash.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1037 hits: 05-01 to 06-06] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:12:46:00 | Win2K-f | 69.124.71.125 (OPTONLINE.NET): OPTIMUM ONLINE (CABLEVISION SYSTEMS), BRONX, NEW YORK, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:06:00 | Win2K-f | 98.140.228.155 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:08:00 | WinXP | 123.200.35.226 (TCN-CATV.NE.JP): TOKYO CABLE NETWORK. INC, TOKYO, TOKYO, JP. |
n/a | DE:siliconfireware.ru :wpad GB:welcome3.smile.co.uk GB:195.92.84.198:80 DE:212.227.111.29:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:455 hits: 05-04 to 06-06] |
9bbdd086c5 [0] | ASM:Graph |
ASPack| | lines=186 embedded dns |
trace |
T:13:30:00 | Win2K-f | 170.51.158.102 (COM.AR): CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A, AR. |
209.250.232.240:7000 | US:scorti1.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
14 of 32 | 8f367186c3 [Firefox:86 hits: 12-27 to 05-22] |
01a06977c4 [0] | ASM:Graph |
TXT2COM| | lines=0 | trace |
T:14:12:00 | WinXP | 62.120.59.44 (-): EUNET, FR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3027 hits: 12-31 to 06-06] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:42:00 | Win2K-f | 201.252.164.235 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1499 hits: 04-27 to 06-06] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
15:18:00 | Win2K-f | 88.246.60.122 (TTNET.NET.TR): TT ADSL-METEKSAN DINAMIK_ACI, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | :hail2.dns2go.com CN:222.177.11.165:8885 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 31 | 6c4c3242ba [Firefox:11 hits: 05-31 to 06-06] |
47300e90ee [0] | none:none |
none|none | none | trace |
15:51:00 | WinXP | 92.40.238.7 (IKBCC.COM): EU-ZZ, UK. |
n/a | :proxim.ircgalaxy.pl EU:siliconfireware.ru GB:welcome3.smile.co.uk :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 32 | b33fe0a961 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:16:10:00 | Win2K-f | 93.108.121.62 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:209.250.232.240:7000 |
445 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1499 hits: 04-27 to 06-06] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
T:17:07:00 | WinXP | 88.31.96.230 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), ES. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3027 hits: 12-31 to 06-06] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:32:00 | WinXP | 125.192.10.101 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:619 hits: 07-11 to 06-06] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
17:36:00 | WinXP | 72.186.158.182 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 0eee786e20 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
17:50:00 | WinXP | 201.252.200.175 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3027 hits: 12-31 to 06-06] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
17:55:00 | WinXP | 218.173.224.210 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 23c6886399 [Firefox: 3 hits: 06-03 to 06-06] |
none[4] | none:none |
PolyEnE| | none | trace |
18:34:00 | WinXP | 202.224.83.200 (ENJOY.NE.JP): DEODEO INTERNET SERVICE(DEODEO CORPORATION), JP. |
n/a | DE:siliconfireware.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:455 hits: 05-04 to 06-06] |
9bbdd086c5 [0] | ASM:Graph |
ASPack| | lines=186 embedded dns |
trace |
18:53:00 | WinXP | 4.226.54.219 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DALLAS, TEXAS, US. (DIAL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3027 hits: 12-31 to 06-06] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:19:03:00 | Win2K-f | 24.84.52.42 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:32:00 | WinXP | 200.191.153.146 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
18 of 32 | b4ad631671 [Firefox:14 hits: 04-29 to 05-30] |
5890f017cc [0] | ASM:Graph |
StarForce| | lines=28 | trace | |
T:21:47:00 | WinXP | 4.229.204.172 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MUSKEGON, MICHIGAN, US. (DIAL) |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1316 hits: 12-31 to 06-06] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:23:09:00 | Win2K-f | 78.39.224.186 (-): INFORMATION TECHNOLOGY COMPANY (ITC), IR. |
209.250.232.240:7000 | US:hail.dns2go.com FR:members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1499 hits: 04-27 to 06-06] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
23:19:00 | WinXP | 217.184.1.50 (MEDIAWAYS.NET): VARIOUS ONLINE SERVICES, BERLIN, BERLIN, DE. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:404 hits: 12-31 to 06-06] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace |