Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:26:00 | WinXP | 122.135.198.212 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | c8e3ba9069 NEW |
none[4] | none:none |
none|none | none | trace | |
T:00:47:00 | WinXP | 118.86.63.37 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3050 hits: 12-31 to 06-13] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:01:10:00 | Win2K-f | 122.42.84.176 (-): POWERCOMM, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 41 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:21:00 | WinXP | 220.144.227.191 (MESH.AD.JP): NEC CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:635 hits: 07-11 to 06-12] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:01:36:00 | Win2K-f | 222.239.34.242 (-): INCHON CABLE TV NAMDONG BROADCAST, INCHON, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:36:00 | WinXP | 70.62.193.159 (RR.COM): ROAD RUNNER HOLDCO LLC, MENTOR, OHIO, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:06:00 | WinXP | 4.240.27.154 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PHOENIX, ARIZONA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:09:00 | Win2K-f | 61.47.26.86 (ICSPACE.NET): PACIFIC INTERNET THAILAND, TH. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:24:00 | Win2K-f | 24.70.238.104 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KELOWNA, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:56:00 | WinXP | 193.249.181.126 (ABO.WANADOO.FR): WANADOO FRANCE, FR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Argh : 0.3 profile |
none | summary tarball |
32 of 32 | 03f912899b [Firefox:11 hits: 12-14 to 06-13] |
83893bd25d [0] | ASM:Graph |
none|none | lines=65 | trace | |
T:05:15:00 | WinXP | 69.153.245.135 (SWBELL.NET): PPPOX POOL - BRAS1 STLSMO, ST. LOUIS, MISSOURI, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com SE:kavkazcenter.com SE:kavkazcenter.net FI:kavkazchat.com US:chechenpress.info GB:chechenpress.co.uk :shaheeds.org :daymohk.info :chripress.org DK:marsho.dk US:www.jamaatshariat.com US:www.counterdata.com DE:m1.webstats.motigo.com FI:imgs2.kavkazcenter.com GB:www.chechenpress.co.uk :www.google.com FI:static.kavkazchat.com DK:193.201.35.247:80 US:208.73.212.12:80 GB:217.194.210.198:80 US:67.15.211.9:80 |
445 | pcap | raw alerts ruleset |
http http 133 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | ab5e47bf8d [Firefox:47 hits: 05-10 to 06-02] |
none[3] | none:none |
ASPack| | none | trace |
T:05:38:00 | Win2K-f | 79.65.199.30 (AS9105.COM): TELINCO, UK. |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2639 hits: 12-31 to 06-07] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace | |
T:05:43:00 | Win2K-f | 218.210.137.61 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:54:00 | WinXP | 122.42.20.32 (-): POWERCOMM, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:20:00 | WinXP | 211.245.94.28 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:06:22:00 | Win2K-f | 219.249.155.132 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:06:37:00 | Win2K-f | 77.253.178.119 (COM.PL): NETIA, PL. |
n/a | 139 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:43:00 | WinXP | 92.84.81.7 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:06:48:00 | Win2K-f | 194.105.102.41 (CABLESURF.DE): KABELFERNSEHEN-MUENCHEN-NET, DE. |
n/a | 139 | pcap | raw alerts ruleset |
other 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:05:00 | WinXP | 87.64.97.68 (ISP.BELGACOM.BE): BELGACOM-ADSL, GENT, OOST-VLAANDEREN, BE. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:07:14:00 | WinXP | 87.205.148.83 (INETIA.PL): NETIA, PL. (DSL) |
66.252.13.234:1728 | :adware.rxmods.net US:ak.anaa.mobi |
139 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace |
T:07:18:00 | Win2K-f | 122.2.207.208 (PLDT.NET): IPG, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:07:22:00 | Win2K-f | 85.120.37.230 (-): SC ARY CAB SAN SRL, ARAD, ARAD, RO. |
n/a | 139 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:30:00 | WinXP | 83.103.199.24 (ASTRAL.RO): ASTRAL-GL-CABLE, GALATI, GALATI, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:07:35:00 | WinXP | 189.43.183.130 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:07:37:00 | Win2K-f | 81.56.110.134 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:07:44:00 | WinXP | 221.141.75.174 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:07:48:00 | Win2K-f | 62.87.214.89 (NET.PL): DYNAMIC BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:07:51:00 | Win2K-f | 88.231.25.180 (-): TT ADSL-NEC DYNAMIC_ULUS, TR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:07:57:00 | Win2K-f | 85.67.111.210 (-): FIBERNET, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:05:00 | WinXP | 83.132.106.233 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, LISBON, LISBOA, PT. |
n/a | UA:citi-bank.ru :parex-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | f2668b51f1 [Firefox: 6 hits: 08-10 to 06-09] |
none[4] | none:none |
PolyEnE| | none | trace |
T:08:11:00 | WinXP | 85.67.93.80 (-): FIBERNET, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:19:00 | Win2K-f | 79.143.166.83 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:25:00 | WinXP | 89.28.82.50 (89-28-0-10.STARNET.MD): STARNET, CHISINAU, CHISINAU, MD. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:29:00 | WinXP | 58.236.173.178 (-): THRUNET-INFRA-INCHEON10, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:08:30:00 | WinXP | 89.123.47.102 (PLATINUMGROUP.RO): ARTELECOM, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:08:31:00 | Win2K-f | 78.59.171.215 (ZEBRA.LT): LIETUVOS, LT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:40:00 | WinXP | 78.96.240.56 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:46:00 | Win2K-f | 84.3.77.178 (T-ONLINE.HU): HUNGARIAN TELECOM, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:08:57:00 | Win2K-f | 87.246.196.136 (LUBLIN.PL): UNIWERSYTET MARII CURIE SKLODOWSKIEJ, LUBLIN, LUBELSKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:09:06:00 | WinXP | 222.234.154.124 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:09:10:00 | WinXP | 92.83.210.188 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:09:11:00 | Win2K-f | 92.130.52.127 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:09:14:00 | WinXP | 219.39.220.70 (BBTEC.NET): SOFTBANK BB CORP, TOKYO, TOKYO, JP. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:22:00 | Win2K-f | 122.135.160.57 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:09:47:00 | Win2K-f | 84.51.84.90 (IPAPER.COM): BLOCK FOR PI ASSIGNMENTS, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:09:48:00 | WinXP | 211.109.218.233 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:09:49:00 | WinXP | 211.109.50.221 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:09:51:00 | Win2K-f | 212.106.20.203 (POLBOX.PL): POLBOX, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:09:52:00 | WinXP | 89.137.254.199 (ASTRAL.RO): ASTRAL TELECOM SA, CLUJ-NAPOCA, CLUJ, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:10:00:00 | Win2K-f | 78.96.95.44 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:10:10:00 | Win2K-f | 124.241.148.178 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:14:00 | WinXP | 194.9.8.214 (-): SC PROACTIV NETWORK SRL, BUCHAREST, BUCURESTI, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:10:18:00 | Win2K-f | 83.115.86.134 (ABO.WANADOO.FR): IP2000-ADSL-BAS, CAEN, BASSE-NORMANDIE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:10:22:00 | WinXP | 211.108.237.226 (KRLINE.NET): KRNIC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:10:38:00 | Win2K-f | 81.168.246.208 (NET.PL): STATIC BROADBAND SERVICES, GLOGOW, DOLNOSLASKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:49:00 | Win2K-f | 85.243.223.248 (DSL.TELEPAC.PT): PT.COM - COMUNICACOES INTERACTIVAS S.A, PT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:10:52:00 | WinXP | 212.106.25.86 (POLBOX.PL): POLBOX, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:10:55:00 | Win2K-f | 92.46.154.146 (IKBCC.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:05:00 | Win2K-f | 92.80.202.83 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:11:07:00 | WinXP | 189.28.210.241 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:15:00 | WinXP | 81.168.245.67 (NET.PL): STATIC BROADBAND SERVICES, GLOGOW, DOLNOSLASKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:17:00 | WinXP | 88.165.108.123 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:20:00 | Win2K-f | 4.236.255.116 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:25:00 | Win2K-f | 92.114.163.84 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:36:00 | WinXP | 88.167.149.70 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:47:00 | Win2K-f | 24.161.208.184 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:50:00 | Win2K-f | 88.254.61.174 (TTNET.NET.TR): TT ADSL-ALCATEL DYNAMIC_ULUS, ISTANBUL, ISTANBUL, TR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:51:00 | Win2K-f | 83.115.3.153 (ABO.WANADOO.FR): IP2000-ADSL-BAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:54:00 | Win2K-f | 87.18.80.62 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, IT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:11:55:00 | WinXP | 89.136.19.62 (-): ASTRAL BUZAU DOCSIS NETWORK, BUZAU, BUZAU, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:11:56:00 | WinXP | 88.177.228.68 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | :adware.rxmods.net US:ak.anaa.mobi US:66.252.13.234:1728 |
139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace |
T:12:06:00 | WinXP | 211.213.0.89 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:12:08:00 | Win2K-f | 86.106.98.247 (SMANET.RO): JUMP NETWORK SERVICES S.R.L, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:13:00 | Win2K-f | 78.59.87.33 (ZEBRA.LT): LIETUVOS, LT. |
n/a | 139 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:20:00 | Win2K-f | 88.173.61.229 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:29:00 | WinXP | 78.8.65.205 (NET.PL): DIALOG, WROCLAW, DOLNOSLASKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:32:00 | Win2K-f | 89.231.200.242 (MM.PL): SZEL-SAT, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:41:00 | WinXP | 92.249.235.122 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :adware.rxmods.net | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace |
T:12:46:00 | WinXP | 78.96.101.49 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:51:00 | Win2K-f | 85.66.68.145 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:12:52:00 | Win2K-f | 85.67.67.60 (-): FIBERNET, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:13:00:00 | WinXP | 12.72.34.203 (ATT.NET): AT&T WORLDNET SERVICES, MORRISTOWN, NEW JERSEY, US. (DIAL) |
82.114.64.251:443 | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2639 hits: 12-31 to 06-07] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:13:06:00 | Win2K-f | 78.96.110.161 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:13:10:00 | Win2K-f | 87.67.91.45 (ISP.BELGACOM.BE): BELGACOM-ADSL, BE. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:13:12:00 | Win2K-f | 88.109.141.90 (AS9105.COM): TISCALI UK LTD, UK. (DSL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2639 hits: 12-31 to 06-07] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:13:21:00 | WinXP | 82.51.79.1 (POOL8251.INTERBUSINESS.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, IT. |
82.114.64.251:443 | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
13:24:00 | WinXP | 201.14.66.131 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:40:00 | Win2K-f | 82.227.158.65 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
13:43:00 | WinXP | 83.238.225.60 (INETIA.PL): INTERNETIA, KATOWICE, SLASKIE, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
13:49:00 | WinXP | 86.152.245.84 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | cce9566ceb NEW |
none[4] | none:none |
PolyEnE| | none | trace | |
T:13:54:00 | WinXP | 78.96.236.123 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
13:57:00 | WinXP | 85.66.153.166 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
14:05:00 | Win2K-f | 82.229.69.203 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:07:00 | Win2K-f | 88.171.221.180 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
14:12:00 | Win2K-f | 88.132.1.137 (-): PRTELECOM, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
14:13:00 | Win2K-f | 78.96.177.159 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:16:00 | WinXP | 89.231.206.182 (MM.PL): SZEL-SAT, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:14:31:00 | Win2K-f | 82.229.82.17 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
14:36:00 | WinXP | 78.92.178.191 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:14:52:00 | WinXP | 24.109.237.50 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SCHENECTADY, NEW YORK, US. (DSL) |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 2c7cd6b344 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
14:53:00 | WinXP | 24.109.237.50 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SCHENECTADY, NEW YORK, US. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 | 2c7cd6b344 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
14:53:00 | WinXP | 85.66.67.168 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:54:00 | WinXP | 201.253.163.33 (NET.AR): APOLO -GOLD-TELECOM-PER, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
14:56:00 | Win2K-f | 218.39.252.169 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:14:59:00 | Win2K-f | 78.96.177.159 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:15:00:00 | WinXP | 85.222.0.61 (WAW.PL): OTN GOCAWII IP ASSIGNMENT, WARSAW, MAZOWIECKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
15:02:00 | WinXP | 212.30.188.73 (MTU.RU): ZAO MTU-INTEL, MOSCOW, MOSKVA, RU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:15:04:00 | Win2K-f | 78.92.178.191 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
15:05:00 | Win2K-f | 88.173.61.229 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
15:17:00 | WinXP | 222.147.166.223 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:635 hits: 07-11 to 06-12] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:15:19:00 | Win2K-f | 211.202.44.28 (HANANET.NET): HANARO TELECOM INC, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
15:23:00 | Win2K-f | 77.254.142.149 (COM.PL): NETIA, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
15:30:00 | WinXP | 211.213.96.92 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:15:34:00 | WinXP | 122.2.22.200 (PLDT.NET): JNEC7300I02_CONSUMER, CEBU, CEBU CITY, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:15:48:00 | Win2K-f | 77.254.142.149 (COM.PL): NETIA, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:15:50:00 | Win2K-f | 189.55.48.36 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
15:51:00 | Win2K-f | 81.56.177.253 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
15:52:00 | WinXP | 58.224.56.111 (HANANET.NET): HANARO TELECOM INC, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 109 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:52:00 | Win2K-f | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, KAO-HSIUNG, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:58:00 | Win2K-f | 89.123.224.164 (PLATINUMGROUP.RO): ARTELECOM, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:16:04:00 | Win2K-f | 77.253.250.159 (COM.PL): NETIA, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:16:06:00 | WinXP | 85.67.2.124 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. |
n/a | 139 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:07:00 | Win2K-f | 122.120.37.109 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
16:17:00 | WinXP | 89.136.252.46 (-): ASTRAL TURDA DOCSIS NETWORK, CLUJ-NAPOCA, CLUJ, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
16:22:00 | WinXP | 75.138.61.8 (CHARTER.COM): CHARTER COMMUNICATIONS, HICKORY, NORTH CAROLINA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:25:00 | Win2K-f | 122.52.29.92 (PLDT.NET): IPG, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:16:25:00 | Win2K-f | 222.234.111.158 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
16:31:00 | Win2K-f | 93.180.76.194 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 32 | 51986b6834 NEW |
none[3] | none:none |
none|none | none | trace | |
16:38:00 | Win2K-f | 190.128.175.4 (TELESURF.COM.PY): TELECEL S.A, ASUNCION, ASUNCION, PY. |
n/a | FI:194.215.38.3:80 EE:62.65.192.24:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:38:00 | Win2K-f | 85.66.186.122 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
16:40:00 | WinXP | 211.243.243.115 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, POHANG, CHEJU-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:16:41:00 | WinXP | 85.110.51.36 (TTNET.NET.TR): TT ADSL-ALCATEL DYNAMIC_ULUS, TR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:16:50:00 | Win2K-f | 201.47.109.27 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :adware.rxmods.net US:ak.anaa.mobi US:66.252.13.234:1728 |
139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace |
T:16:53:00 | Win2K-f | 118.160.106.55 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
16:59:00 | Win2K-f | 219.255.31.167 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
16:59:00 | WinXP | 68.148.201.241 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:02:00 | WinXP | 211.52.129.53 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
17:10:00 | WinXP | 84.0.28.97 (T-ONLINE.HU): DSL DYNAMIC POOL T-ONLINE HUNGARY, HU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:17:18:00 | Win2K-f | 88.161.135.175 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
17:22:00 | Win2K-f | 88.240.116.131 (TTNET.NET.TR): TT ADSL-ALCATEL_ACI, ISTANBUL, ISTANBUL, TR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:17:24:00 | Win2K-f | 84.0.28.97 (T-ONLINE.HU): DSL DYNAMIC POOL T-ONLINE HUNGARY, HU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
17:36:00 | WinXP | 220.141.8.35 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
17:37:00 | WinXP | 64.139.104.242 (RCABLETV.COM): NCI DATA.COM INC, REPUBLIC, WASHINGTON, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
17:48:00 | WinXP | 218.39.52.197 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:17:53:00 | Win2K-f | 125.224.133.153 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:17:57:00 | Win2K-f | 219.255.38.3 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
17:58:00 | Win2K-f | 77.254.148.82 (COM.PL): NETIA, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:18:06:00 | Win2K-f | 219.241.37.108 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
18:07:00 | WinXP | 58.235.88.88 (-): THRUNET-INFRA-BUSAN15, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:18:09:00 | WinXP | 218.39.252.169 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
18:13:00 | Win2K-f | 24.109.251.145 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, THUNDER BAY, ONTARIO, CA. |
n/a | :proxim.ircgalaxy.pl | 135 | pcap | raw alerts ruleset |
other 266 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | 0a6b1672a1 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:18:25:00 | Win2K-f | 211.209.100.35 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
18:26:00 | WinXP | 218.210.84.15 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:27:00 | WinXP | 125.233.14.184 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:18:30:00 | Win2K-f | 4.245.119.23 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SPARKS, NEVADA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
18:31:00 | Win2K-f | 211.49.57.25 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
18:43:00 | WinXP | 219.250.57.52 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:18:43:00 | Win2K-f | 220.141.6.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
18:53:00 | Win2K-f | 211.202.168.175 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
19:12:00 | Win2K-f | 81.56.105.241 (PROXAD.NET): PROXAD / FREE SAS, STRASBOURG, ALSACE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:19:14:00 | Win2K-f | 219.241.225.158 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:18:00 | WinXP | 211.110.186.115 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
19:19:00 | WinXP | 211.209.218.54 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:19:23:00 | Win2K-f | 116.127.17.11 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
19:32:00 | WinXP | 58.228.64.49 (DIEHLAUTO.COM): HANARO TELECOM INC, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:19:50:00 | Win2K-f | 211.211.93.64 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
19:52:00 | WinXP | 12.218.243.169 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MOBILE, ALABAMA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1332 hits: 12-31 to 06-13] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
19:57:00 | WinXP | 211.109.212.91 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
20:00:00 | WinXP | 211.109.172.9 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:20:00:00 | WinXP | 219.250.217.164 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:20:11:00 | WinXP | 218.232.215.132 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
20:16:00 | Win2K-f | 221.143.113.48 (GUTZWILLER.CH): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 57 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
20:20:00 | WinXP | 67.9.251.215 (RR.COM): ROAD RUNNER HOLDCO LLC, SHREVEPORT, LOUISIANA, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad GB:welcome3.smile.co.uk |
445 | pcap | raw alerts ruleset |
http http http http 36 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1048 hits: 05-01 to 06-12] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
20:24:00 | Win2K-f | 211.109.218.233 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | FI:194.215.38.3:80 EE:62.65.192.24:80 |
139 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:26:00 | Win2K-f | 80.103.0.242 (DYNAMIC.ORANGE.ES): UNI2 IP DATA NETWORK, ES. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
11 of 32 | dff8ae3caa NEW |
none[3] | none:none |
none|none | none | trace | |
T:20:31:00 | WinXP | 219.251.165.43 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:35:00 | Win2K-f | 4.245.112.71 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SPARKS, NEVADA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
20:36:00 | Win2K-f | 218.160.64.153 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAOYUAN, T'AI-WAN, TW. |
n/a | FI:194.215.38.3:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:46:00 | Win2K-f | 64.75.158.18 (TURQUOISE.NET): HAWAII ONLINE, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:55:00 | Win2K-f | 125.224.140.56 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:21:01:00 | Win2K-f | 219.254.3.157 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
21:01:00 | Win2K-f | 211.204.209.208 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
21:03:00 | Win2K-f | 92.49.211.41 (IKBCC.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:21:04:00 | WinXP | 59.114.13.98 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 33 | 23d19b4035 NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
21:09:00 | WinXP | 4.131.80.239 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DALLAS, TEXAS, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:13:00 | Win2K-f | 211.186.206.103 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
21:25:00 | Win2K-f | 89.41.98.144 (HOST-89-41-64-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:21:25:00 | Win2K-f | 211.212.33.79 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
21:28:00 | Win2K-f | 85.66.95.231 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:29:00 | WinXP | 58.235.88.88 (-): THRUNET-INFRA-BUSAN15, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
21:30:00 | WinXP | 190.76.12.13 (MOVILNET.COM.VE): CANTV SERVICIOS VENEZUELA, VE. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:36:00 | Win2K-f | 219.251.165.43 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:21:44:00 | Win2K-f | 201.47.132.17 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :adware.rxmods.net US:ak.anaa.mobi US:66.252.13.234:1728 |
139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 NEW |
none[3] | none:none |
ASPack| | none | trace |
T:21:46:00 | Win2K-f | 118.171.206.107 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
21:47:00 | Win2K-f | 80.241.22.189 (CATV-KABELMEDIEN.AT): CATV KABELMEDIEN REG. GENOSSENSCHAFT M.B.H, AT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
21:51:00 | WinXP | 122.2.27.145 (PLDT.NET): JNEC7300I02_CONSUMER, CEBU, CEBU CITY, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:22:01:00 | WinXP | 124.115.15.45 (163DATA.COM.CN): CHINANET SHANXI(SN) PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:10:00 | Win2K-f | 61.35.11.242 (BORA.NET): DACOM CORP, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:19:00 | Win2K-f | 61.227.14.147 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:22:24:00 | Win2K-f | 211.44.74.94 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:22:32:00 | WinXP | 212.220.141.250 (-): JSC GERKON, EKATERINBURG, SVERDLOVSKAYA OBLAST', RU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:35:00 | WinXP | 86.106.34.210 (UPCNET.RO): SC UPC ROMANIA SA, TIMISOARA, TIMIS, RO. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
22:40:00 | Win2K-f | 70.183.161.219 (COX.NET): COX COMMUNICATIONS, WOONSOCKET, RHODE ISLAND, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:41:00 | Win2K-f | 122.2.105.52 (PLDT.NET): IPG, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:22:44:00 | Win2K-f | 78.96.255.178 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
22:58:00 | Win2K-f | 85.187.5.112 (EVRO.NET): LAN-NET.BG OOD, BG. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:23:03:00 | Win2K-f | 81.56.177.253 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:23:04:00 | Win2K-f | 211.59.72.105 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:06:00 | WinXP | 122.2.39.138 (PLDT.NET): JNEC7300I03_CONSUMER, CEBU, CEBU CITY, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:23:08:00 | Win2K-f | 78.97.13.238 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:23:10:00 | WinXP | 80.241.22.189 (CATV-KABELMEDIEN.AT): CATV KABELMEDIEN REG. GENOSSENSCHAFT M.B.H, AT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:23:12:00 | WinXP | 92.81.192.250 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
23:13:00 | Win2K-f | 24.79.213.242 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
23:19:00 | WinXP | 122.52.23.79 (PLDT.NET): IPG, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
23:22:00 | WinXP | 211.209.47.179 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
23:23:00 | Win2K-f | 92.49.206.53 (IKBCC.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:23:28:00 | Win2K-f | 83.9.231.204 (TPNET.PL): NEOSTRADA PLUS, BIALYSTOK, PODLASKIE, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:23:30:00 | Win2K-f | 80.96.206.116 (AIRBOY.RO): SC IZA-NET SRL, BUCHAREST, BUCURESTI, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:23:39:00 | Win2K-f | 85.187.5.112 (EVRO.NET): LAN-NET.BG OOD, BG. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
23:41:00 | WinXP | 82.208.140.50 (ASTRAL.RO): ASTRAL TELECOM IASI, IASI, IASI, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 60cd45803c NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
23:42:00 | Win2K-f | 119.95.74.237 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 NEW |
none[3] | none:none |
none|none | none | trace | |
T:23:44:00 | WinXP | 61.101.129.83 (KRLINE.NET): KRNIC, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:46:00 | WinXP | 220.139.166.30 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2639 hits: 12-31 to 06-07] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
23:46:00 | WinXP | 221.141.18.104 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f NEW |
none[3] | none:none |
TXT2COM| | none | trace | |
T:23:50:00 | WinXP | 222.147.240.234 (OCN.NE.JP): OPEN COMPUTER NETWORK, OSAKA, OSAKA, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:635 hits: 07-11 to 06-12] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
23:59:00 | Win2K-f | 189.55.48.36 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |