Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

07 June 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
00:06:00 WinXP 119.17.99.51 (-):
.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 3f5ec58a6b
[Firefox:26 hits: 04-24 to 06-02]
4a77430a59 [0] ASM:Graph
PolyEnE| lines=70 trace
T:00:10:00 WinXP 119.17.99.51 (-):
.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 3f5ec58a6b
[Firefox:26 hits: 04-24 to 06-02]
4a77430a59 [0] ASM:Graph
PolyEnE| lines=70 trace
T:00:51:00 Win2K-f 89.111.221.129 (TEOL.NET):
TEOL-NET-DIALUP-POOL,
BANJA LUKA, REPUBLIKA SRPSKA, BA. (DIAL)
n/a US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
19 of 30 93282471f7
[Firefox:20 hits: 04-28 to 05-21]
95951dee58 [0] ASM:Graph
ASProtect| lines=0 trace
T:01:34:00 Win2K-f 122.118.20.97 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
19 of 32 890fb4fa10
[Firefox:47 hits: 12-27 to 06-01]
b9c7f08a57 [0] ASM:Graph
ASProtect| lines=393
embedded dns
trace
01:46:00 WinXP 82.230.162.15 (PROXAD.NET):
PROXAD / FREE SAS,
PARIS, ILE-DE-FRANCE, FR.
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:02:14:00 Win2K-f 151.118.176.44 (QWEST.NET):
QWEST BROADBAND,
PHOENIX, ARIZONA, US.
66.252.13.227:6667 :proxim.ircgalaxy.pl
US:4949.zerx-virus.biz
**:0.0.0.10:1433
**:0.0.0.11:1433
**:0.0.0.12:1433
**:0.0.0.13:1433
**:0.0.0.14:1433
**:0.0.0.15:1433
**:0.0.0.16:1433
**:0.0.0.17:1433
**:0.0.0.18:1433
**:0.0.0.19:1433
**:0.0.0.1:1433
**:0.0.0.20:1433
**:0.0.0.21:1433
**:0.0.0.2:1433
**:0.0.0.3:1433
**:0.0.0.4:1433
**:0.0.0.5:1433
**:0.0.0.6:1433
**:0.0.0.7:1433
**:0.0.0.8:1433
**:0.0.0.9:1433
135 pcap raw alerts
ruleset
irc
538 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33 ce537f8a8e
NEW
none[4] none:none
none|none none trace
T:02:25:00 Win2K-f 211.213.67.182 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
02:34:00 WinXP 93.81.42.80 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
209.250.232.240:7000 US:scorti1.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
21 lines
Yeah : 1.3
profile
none summary
tarball
20 of 31 af98fe0c94
[Firefox:74 hits: 04-27 to 06-06]
480d076a0a [0] ASM:Graph
ASProtect| lines=422
embedded dns
trace
03:46:00 WinXP 88.195.77.86 (INET.FI):
BROADBAND ACCESS POOL,
FI.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 31 4ab5b0788c
[Firefox: 4 hits: 04-21 to 06-06]
272da55ef8 [0] ASM:Graph
PolyEnE| lines=114 trace
T:04:48:00 Win2K-f 92.11.37.184 (-):
CARPHONE WAREHOUSE BROADBAND SERVICES,
UK.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 d12e4a3f7d
NEW
none[4] none:none
none|none none trace
T:05:15:00 WinXP 122.120.8.188 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
217.170.244.2:443  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
irc
31 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2638 hits: 12-31 to 06-06]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
05:19:00 WinXP 85.24.168.47 (BAHNHOF.SE):
BAHNHOF INTERNET AB,
SE.
n/a CN:hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:63 hits: 05-29 to 06-05]
51c1525417 [0] none:none
Obsidium| none trace
T:05:36:00 Win2K-f 119.94.163.49 (-):
.
n/a   135 pcap raw alerts
ruleset
other
106 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
06:11:00 WinXP 221.245.131.189 (UCOM.NE.JP):
N-KG,
KAWASAKI, KANAGAWA, JP. (100Mbps)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:619 hits: 07-11 to 06-06]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
06:15:00 WinXP 4.248.239.80 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
LOUISA, VIRGINIA, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:284 hits: 05-01 to 06-05]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
T:07:24:00 WinXP 84.53.213.89 (ELCOM.RU):
JSC CENTERTELECOM,
RU. (DIAL)
n/a US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
12 of 31 ab48a97a5d
[Firefox: 7 hits: 12-28 to 05-21]
81e9c5d188 [0] ASM:Graph
ASProtect| lines=419
embedded dns
trace
07:25:00 Win2K-f 116.206.60.254 (-):
MOBIF WIRELESS BROADBAND SDN. BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY.
n/a US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 f30c325342
NEW
none[4] none:none
none|none none trace
07:40:00 WinXP 89.207.67.103 (-):
JOINT STOCK COMPANY SVYAZIST,
RU.
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
07:48:00 WinXP 118.8.188.54 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:619 hits: 07-11 to 06-06]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
07:53:00 WinXP 78.144.32.77 (-):
OPAL TELECOM DSL,
LONDON, ENGLAND, UK.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
07:57:00 Win2K-f 41.212.203.184 (-):
.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1499 hits: 04-27 to 06-06]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
T:08:16:00 Win2K-f 91.144.78.131 (MEGATHERM.HU):
ANTENNA TAVKOZLESI,
BUDAPEST, BUDAPEST, HU.
n/a US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
19 of 32 69059a59e5
NEW
none[4] none:none
StarForce| none trace
T:08:27:00 WinXP 78.176.238.138 (SMYTHECRAMER.COM):
TELEKOM,
TR.
n/a :proxim.ircgalaxy.pl
US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
28 of 32 85f06e20ac
NEW
none[4] none:none
none|none none trace
08:28:00 Win2K-f 79.81.10.202 (G-M-I.NET):
EU-ZZ,
UK.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 31 0ca18d1183
[Firefox: 3 hits: 04-27 to 05-14]
none[4] none:none
none|none none trace
T:08:35:00 WinXP 216.54.173.190 (TWTELECOM.NET):
TIME WARNER TELECOM INC,
VIRGINIA BEACH, VIRGINIA, US.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:619 hits: 07-11 to 06-06]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
08:39:00 WinXP 122.26.238.137 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:619 hits: 07-11 to 06-06]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:09:24:00 Win2K-f 71.103.108.120 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
WHITTIER, CALIFORNIA, US. (DSL)
n/a US:qtas.net
SE:dzuc.net
SE:84.244.5.183:2345
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
2 of 32 a50330e92d
NEW
a50330e92d [1] ASM:Graph
none|none lines=10 trace
T:10:19:00 WinXP 195.206.43.167 (-):
BAYKALWESTCOM NETWORK,
IRKUTSK, IRKUTSKAYA OBLAST', RU.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
20 of 33 4f0719aad0
NEW
none[4] none:none
StarForce| none trace
T:10:33:00 Win2K-f 88.87.239.166 (KABELSZATNET-2002.HU):
KABELSZATNET-2002 KFT. PAPA,
HU.
n/a   445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:37:00 Win2K-f 79.81.10.139 (G-M-I.NET):
EU-ZZ,
UK.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 31 0ca18d1183
[Firefox: 3 hits: 04-27 to 05-14]
none[4] none:none
none|none none trace
10:49:00 WinXP 201.47.136.203 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 4c27e2165f
[Firefox: 3 hits: 09-05 to 10-30]
none[4] none:none
PolyEnE| none trace
10:51:00 Win2K-f 89.232.196.206 (ISURGUT.RU):
OPEN JOINT-STOCK COMPANY URALSVIAZINFORM BRANCH OF THE KHANTYMANSIYSK REGION,
RU. (DIAL)
n/a CN:hail2.dns2go.com 445 pcap raw alerts
ruleset
ftp
irc
26 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 5ee4121e1e
[Firefox:63 hits: 05-29 to 06-05]
51c1525417 [0] none:none
Obsidium| none trace
11:28:00 Win2K-f 84.180.109.45 (T-IPCONNECT.DE):
DEUTSCHE TELEKOM AG,
CHEMNITZ, SACHSEN, DE.
n/a   445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
30 of 32 36db555136
NEW
none[4] none:none
none|none none trace
T:11:43:00 WinXP 201.4.103.232 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
209.250.232.240:7000 US:hail.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
http
27 lines
Yeah : 1.3
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1499 hits: 04-27 to 06-06]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
T:11:52:00 Win2K-f 189.49.116.128 (BRASILTELECOM.NET.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR.
n/a   445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
28 of 32 53b36ec898
NEW
none[4] none:none
none|none none trace
T:12:19:00 WinXP 216.249.8.86 (PATHCOM.COM):
PATHWAY COMMUNICATIONS,
TORONTO, ONTARIO, CA. (DIAL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
EU:ebookfinaltrash.ru
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
4 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1037 hits: 05-01 to 06-06]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
T:12:46:00 Win2K-f 69.124.71.125 (OPTONLINE.NET):
OPTIMUM ONLINE (CABLEVISION SYSTEMS),
BRONX, NEW YORK, US.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:13:06:00 Win2K-f 98.140.228.155 (-):
.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:13:08:00 WinXP 123.200.35.226 (TCN-CATV.NE.JP):
TOKYO CABLE NETWORK. INC,
TOKYO, TOKYO, JP.
n/a DE:siliconfireware.ru
:wpad
GB:welcome3.smile.co.uk
GB:195.92.84.198:80
DE:212.227.111.29:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
[Firefox:455 hits: 05-04 to 06-06]
9bbdd086c5 [0] ASM:Graph
ASPack| lines=186
embedded dns
trace
T:13:30:00 Win2K-f 170.51.158.102 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
209.250.232.240:7000 US:scorti1.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
http
24 lines
Yeah : 1.3
profile
none summary
tarball
14 of 32 8f367186c3
[Firefox:86 hits: 12-27 to 05-22]
01a06977c4 [0] ASM:Graph
TXT2COM| lines=0 trace
T:14:12:00 WinXP 62.120.59.44 (-):
EUNET,
FR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3027 hits: 12-31 to 06-06]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:14:42:00 Win2K-f 201.252.164.235 (NET.AR):
APOLO -GOLD-TELECOM-PER,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1499 hits: 04-27 to 06-06]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
15:18:00 Win2K-f 88.246.60.122 (TTNET.NET.TR):
TT ADSL-METEKSAN DINAMIK_ACI,
ISTANBUL, ISTANBUL, TR. (DSL)
n/a :hail2.dns2go.com
CN:222.177.11.165:8885
445 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
15 of 31 6c4c3242ba
[Firefox:11 hits: 05-31 to 06-06]
47300e90ee [0] none:none
none|none none trace
15:51:00 WinXP 92.40.238.7 (IKBCC.COM):
EU-ZZ,
UK.
n/a :proxim.ircgalaxy.pl
EU:siliconfireware.ru
GB:welcome3.smile.co.uk
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 32 b33fe0a961
NEW
none[4] none:none
PolyEnE| none trace
T:16:10:00 Win2K-f 93.108.121.62 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a US:hail.dns2go.com
US:scorti1.dns2go.com
US:209.250.232.240:7000
445 pcap raw alerts
ruleset
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1499 hits: 04-27 to 06-06]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
T:17:07:00 WinXP 88.31.96.230 (RIMA-TDE.NET):
TELEFONICA MOVILES ESPANA (NCC#2007041930),
ES.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3027 hits: 12-31 to 06-06]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:17:32:00 WinXP 125.192.10.101 (MESH.AD.JP):
NEC CORPORATION,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:619 hits: 07-11 to 06-06]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
17:36:00 WinXP 72.186.158.182 (RR.COM):
ROAD RUNNER HOLDCO LLC,
TAMPA, FLORIDA, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 0eee786e20
NEW
none[4] none:none
PolyEnE| none trace
17:50:00 WinXP 201.252.200.175 (NET.AR):
APOLO -GOLD-TELECOM-PER,
BUENOS AIRES, BUENOS AIRES, AR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3027 hits: 12-31 to 06-06]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
17:55:00 WinXP 218.173.224.210 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 23c6886399
[Firefox: 3 hits: 06-03 to 06-06]
none[4] none:none
PolyEnE| none trace
18:34:00 WinXP 202.224.83.200 (ENJOY.NE.JP):
DEODEO INTERNET SERVICE(DEODEO CORPORATION),
JP.
n/a DE:siliconfireware.ru
:wpad
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
[Firefox:455 hits: 05-04 to 06-06]
9bbdd086c5 [0] ASM:Graph
ASPack| lines=186
embedded dns
trace
18:53:00 WinXP 4.226.54.219 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DALLAS, TEXAS, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3027 hits: 12-31 to 06-06]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:19:03:00 Win2K-f 24.84.52.42 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
BURNABY, BRITISH COLUMBIA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
21:32:00 WinXP 200.191.153.146 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
18 of 32 b4ad631671
[Firefox:14 hits: 04-29 to 05-30]
5890f017cc [0] ASM:Graph
StarForce| lines=28 trace
T:21:47:00 WinXP 4.229.204.172 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
MUSKEGON, MICHIGAN, US. (DIAL)
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1316 hits: 12-31 to 06-06]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:23:09:00 Win2K-f 78.39.224.186 (-):
INFORMATION TECHNOLOGY COMPANY (ITC),
IR.
209.250.232.240:7000 US:hail.dns2go.com
FR:members.lycos.co.uk
445 pcap raw alerts
ruleset
ftp
irc
23 lines
Yeah : 1.3
profile
none summary
tarball
21 of 32 5f78ff609d
[Firefox:1499 hits: 04-27 to 06-06]
d4a06bdc3a [0] ASM:Graph
none|none lines=4 trace
23:19:00 WinXP 217.184.1.50 (MEDIAWAYS.NET):
VARIOUS ONLINE SERVICES,
BERLIN, BERLIN, DE.
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:404 hits: 12-31 to 06-06]
048df78048 [0] ASM:Graph
none|none lines=61 trace