Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

15 June 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
00:05:00 WinXP 212.233.218.203 (-):
NTL,
FR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:00:06:00 Win2K-f 122.52.29.92 (PLDT.NET):
IPG,
PH.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:00:06:00 Win2K-f 89.136.63.48 (UPCNET.RO):
ASTRAL UPC PLOIESTI,
PLOIESTI, PRAHOVA, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:00:12:00 Win2K-f 218.220.116.230 (ZAQ.NE.JP):
J-COM KANSAI CO. LTD,
OSAKA, OSAKA, JP.
n/a   139 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:00:14:00 Win2K-f 116.123.57.165 (-):
HANARO TELECOM,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
00:21:00 Win2K-f 61.227.11.186 (HINET.NET):
DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:00:24:00 WinXP 123.50.68.101 (-):
MANA INTERNET SERVICE PROVIDER,
PAPEETE, FRENCH POLYNESIA, PF.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:31 hits: 09-28 to 06-12]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
00:25:00 WinXP 211.212.204.222 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
00:26:00 Win2K-f 89.28.18.162 (89-28-0-10.STARNET.MD):
STARNET,
CHISINAU, CHISINAU, MD.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:00:30:00 Win2K-f 78.96.184.153 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:00:30:00 WinXP 85.186.122.186 (-):
ASTRAL BUZAU CPE,
BUZAU, BUZAU, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
00:31:00 WinXP 78.96.84.245 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:00:33:00 Win2K-f 218.168.71.147 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
00:49:00 Win2K-f 92.114.163.84 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
00:51:00 Win2K-f 92.80.104.202 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
00:52:00 WinXP 85.217.136.112 (VT.EVO.BG):
EVO IP ADDRESS SPACE,
SOFIA, SOFIYA, BG.
n/a   139 pcap raw alerts
ruleset
ftp
11 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
00:58:00 Win2K-f 220.136.247.246 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
01:05:00 WinXP 92.49.211.236 (IKBCC.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 3c80772ad2
NEW
none[3] none:none
none|none none trace
T:01:08:00 Win2K-f 58.124.53.155 (HANANET.NET):
HANARO TELECOM INC,
KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:01:12:00 WinXP 81.243.157.173 (ISP.BELGACOM.BE):
BELGACOM-ADSL,
NAMUR, NAMUR, BE. (DSL)
n/a :adware.rxmods.net 139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
17 of 32 8ed2e75017
[Firefox:12 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
01:14:00 WinXP 81.243.157.173 (ISP.BELGACOM.BE):
BELGACOM-ADSL,
NAMUR, NAMUR, BE. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
17 of 32 8ed2e75017
[Firefox:12 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:01:15:00 WinXP 85.66.75.78 (BACS-NET.HU):
FIBERNET COMMUNICATION CO,
DEBRECEN, HAJDU-BIHAR, HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
01:18:00 WinXP 92.84.119.230 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:01:18:00 Win2K-f 87.205.178.196 (INETIA.PL):
INTERNETIA,
KATOWICE, SLASKIE, PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
01:22:00 WinXP 85.67.111.210 (-):
FIBERNET,
HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:01:22:00 Win2K-f 78.84.4.201 (MICROLINK.LV):
TELEKOM,
RIGA, RIGA, LV.
n/a   139 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:01:23:00 WinXP 85.66.67.168 (BACS-NET.HU):
FIBERNET COMMUNICATION CO,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
01:25:00 Win2K-f 83.196.179.7 (ABO.WANADOO.FR):
IP2000-ADSL-BAS,
REIMS, CHAMPAGNE-ARDENNE, FR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
01:27:00 Win2K-f 87.228.94.55 (-):
INFOLINE ZAO,
RU.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:01:41:00 Win2K-f 81.56.254.84 (PROXAD.NET):
PROXAD / FREE SAS,
PARIS, ILE-DE-FRANCE, FR. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:01:44:00 Win2K-f 218.52.191.225 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:01:52:00 WinXP 92.40.182.162 (IKBCC.COM):
EU-ZZ,
UK.
n/a :proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
30 of 32 a0e6bec09f
NEW
none[4] none:none
PolyEnE| none trace
01:58:00 Win2K-f 218.168.71.147 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
217.170.244.2:443   445 pcap raw alerts
ruleset
shell
ftp
irc
61 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2643 hits: 12-31 to 06-14]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:02:03:00 WinXP 60.50.223.210 (TM.NET.MY):
TELEKOM MALAYSIA BERHAD,
MUAR, JOHOR, MY.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:02:07:00 Win2K-f 78.96.84.245 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
02:07:00 WinXP 78.96.179.177 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:02:10:00 Win2K-f 92.81.154.68 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
02:11:00 Win2K-f 211.245.63.221 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:02:14:00 Win2K-f 78.92.150.45 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
02:14:00 WinXP 211.245.66.5 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
02:14:00 Win2K-f 83.103.132.208 (ASTRAL.RO):
ASTRAL-CJ-DOCSIS,
CLUJ-NAPOCA, CLUJ, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
02:15:00 WinXP 78.96.245.69 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
02:17:00 Win2K-f 92.247.244.15 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:02:22:00 Win2K-f 218.191.129.69 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
02:31:00 WinXP 78.92.171.215 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
02:41:00 Win2K-f 89.28.114.10 (89-28-0-10.STARNET.MD):
STARNET,
CHISINAU, CHISINAU, MD.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:02:42:00 WinXP 221.141.18.104 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
02:46:00 Win2K-f 219.255.8.203 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:02:55:00 WinXP 83.31.90.78 (TPNET.PL):
NEOSTRADA PLUS,
WARSAW, MAZOWIECKIE, PL. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:01:00 Win2K-f 78.96.99.249 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
03:06:00 WinXP 77.253.170.119 (COM.PL):
NETIA,
PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
03:07:00 WinXP 88.161.111.235 (PROXAD.NET):
PROXAD / FREE SAS,
FR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:08:00 WinXP 116.121.68.242 (-):
HANARO TELECOM,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:03:10:00 WinXP 125.232.150.88 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
217.170.244.2:443  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
irc
29 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2643 hits: 12-31 to 06-14]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
03:13:00 Win2K-f 118.165.4.163 (-):
.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:14:00 WinXP 88.243.253.105 (TTNET.NET.TR):
TT ADSL-ALCATEL DYNAMIC_ACI,
ISTANBUL, ISTANBUL, TR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:17:00 WinXP 218.190.197.217 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
03:26:00 WinXP 58.124.147.168 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:03:32:00 Win2K-f 89.28.80.141 (89-28-0-10.STARNET.MD):
STARNET,
CHISINAU, CHISINAU, MD.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
03:35:00 WinXP 78.96.99.249 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
14 of 32 fd5d1b2787
NEW
none[3] none:none
none|none none trace
T:03:37:00 Win2K-f 219.249.155.132 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
03:43:00 Win2K-f 78.92.142.26 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:03:45:00 Win2K-f 85.102.106.160 (TTNET.NET.TR):
TURK TELEKOM ADSL-DYNAMIC,
ISTANBUL, ISTANBUL, TR. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:47:00 WinXP 78.96.222.240 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:49:00 WinXP 78.92.142.26 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
03:49:00 Win2K-f 85.67.65.61 (-):
FIBERNET,
HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:51:00 Win2K-f 78.97.16.248 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:03:58:00 Win2K-f 122.2.39.138 (PLDT.NET):
JNEC7300I03_CONSUMER,
CEBU, CEBU CITY, PH.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:03:00 WinXP 78.97.209.124 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:04:11:00 Win2K-f 62.201.110.71 (T-ONLINE.HU):
HUNGARIAN TELECOM MATAV,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:11:00 Win2K-f 222.235.147.37 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a  
FI:194.215.38.3:80
EE:62.65.192.24:80
135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
04:14:00 WinXP 83.1.71.196 (-):
PROTONET ADRIAN LUDYGA,
PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:15:00 WinXP 92.46.135.161 (IKBCC.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:23:00 Win2K-f 124.111.141.170 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:04:26:00 WinXP 88.177.188.166 (PROXAD.NET):
PROXAD / FREE SAS,
FR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
17 of 32 8ed2e75017
[Firefox:12 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:04:30:00 WinXP 87.67.199.47 (ISP.BELGACOM.BE):
BELGACOM-ADSL,
BE. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:34:00 Win2K-f 89.137.141.79 (ASTRAL.RO):
ASTRAL IASI DOCSIS NETWORK,
IASI, IASI, RO.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:35:00 WinXP 78.96.222.240 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
04:41:00 WinXP 66.26.89.222 (RR.COM):
ROAD RUNNER HOLDCO LLC,
RALEIGH, NORTH CAROLINA, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:411 hits: 12-31 to 06-12]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:04:42:00 WinXP 194.9.52.203 (NET.PL):
EKOTRANSTECH EWELINA LIBERA,
KATOWICE, SLASKIE, PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:04:45:00 Win2K-f 78.97.209.124 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:04:46:00 WinXP 88.251.235.214 (TTNET.NET.TR):
TT ADSL-ALCATEL DYNAMIC_ACI,
MANISA, MANISA, TR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:04:47:00 Win2K-f 211.72.110.153 (EPA.COM.TW):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:04:51:00 Win2K-f 88.161.46.126 (PROXAD.NET):
PROXAD / FREE SAS,
FR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
04:54:00 Win2K-f 80.96.151.37 (NEXTRA.RO):
SC-NEXTRA TELECOM SRL,
TIMISOARA, TIMIS, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:04:58:00 WinXP 80.96.151.37 (NEXTRA.RO):
SC-NEXTRA TELECOM SRL,
TIMISOARA, TIMIS, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:05:06:00 Win2K-f 211.202.18.137 (HANANET.NET):
HANARO TELECOM INC,
KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:05:07:00 Win2K-f 62.201.111.95 (T-ONLINE.HU):
HUNGARIAN TELECOM MATAV,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
05:09:00 WinXP 118.161.215.16 (-):
.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
05:09:00 Win2K-f 211.213.0.89 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
05:17:00 WinXP 92.80.31.24 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
05:23:00 Win2K-f 85.67.101.239 (-):
FIBERNET,
HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:05:25:00 Win2K-f 92.83.79.130 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:05:29:00 WinXP 85.222.81.1 (-):
ASTER CITY CABLE LTD,
PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
05:32:00 Win2K-f 87.116.204.37 (TNP.PL):
NETWORK OF INTERNET SERVICE PROVIDER,
PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:05:35:00 Win2K-f 76.90.103.146 (-):
.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
05:37:00 WinXP 92.83.70.145 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:05:37:00 Win2K-f 85.186.56.94 (-):
ASTRAL-DEVA-CPE,
SIMERIA, HUNEDOARA, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
05:41:00 Win2K-f 78.96.110.161 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
05:43:00 Win2K-f 130.67.16.43 (ONLINE.NO):
NORTELE-H,
LILLEHAMMER, OPPLAND, NO. (DIAL)
72.10.172.218:3938 CA:wiger.blacktiehsbdcs.com
US:msn.com
BR:www.terra.com.br
GB:msn.de
KR:daum.net
US:google.ae
AU:ninemsn.com.au
135 pcap raw alerts
ruleset
irc
10 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 7b85d88f4b
NEW
none[4] none:none
none|none none trace
05:58:00 Win2K-f 213.164.224.107 (ASTRAL.RO):
CABLENETWORK-BUCHAREST,
BUCHAREST, BUCURESTI, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
05:59:00 WinXP 121.125.168.54 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:06:08:00 Win2K-f 59.112.187.103 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
06:10:00 WinXP 122.2.201.39 (PLDT.NET):
IPG,
PH.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
06:11:00 WinXP 218.169.70.174 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:06:18:00 Win2K-f 219.255.8.203 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
06:26:00 Win2K-f 92.249.124.107 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:06:27:00 WinXP 218.167.139.131 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   139 pcap raw alerts
ruleset
ftp
11 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
06:27:00 WinXP 69.134.245.169 (RR.COM):
ROAD RUNNER HOLDCO LLC,
RALEIGH, NORTH CAROLINA, US.
n/a UA:citi-bank.ru
EU:kidos-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3051 hits: 12-31 to 06-14]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:06:29:00 WinXP 78.96.153.172 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:06:38:00 Win2K-f 85.67.2.20 (BACS-NET.HU):
FIBERNET COMMUNICATION CO,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
06:38:00 Win2K-f 125.181.214.12 (-):
POWC-214,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:06:41:00 Win2K-f 78.96.179.177 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
06:41:00 WinXP 122.2.221.210 (PLDT.NET):
IPG,
PH.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
06:52:00 WinXP 213.238.105.16 (INETIA.PL):
NETIA SA ADSL NETWORK,
POZNAN, WIELKOPOLSKIE, PL. (DSL)
n/a :adware.rxmods.net 139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
17 of 32 8ed2e75017
[Firefox:12 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:06:53:00 WinXP 122.52.31.210 (PLDT.NET):
IPG,
PH.
n/a   139 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
06:56:00 Win2K-f 211.117.48.233 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
27 of 32 b65a426bee
[Firefox:25 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
06:57:00 Win2K-f 87.205.191.164 (INETIA.PL):
INTERNETIA,
PL. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
17 of 32 8ed2e75017
[Firefox:12 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
T:07:01:00 Win2K-f 81.198.138.234 (-):
ADDRESS POOL FOR LTC-HOME CUSTOMERS,
RIGA, RIGA, LV.
n/a   139 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:07:03:00 WinXP 85.66.48.150 (BACS-NET.HU):
FIBERNET COMMUNICATION CO,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:07:05:00 Win2K-f 58.235.49.236 (-):
THRUNET-INFRA-BUSAN15,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
07:09:00 Win2K-f 122.52.31.210 (PLDT.NET):
IPG,
PH.
n/a   139 pcap raw alerts
ruleset
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
07:16:00 Win2K-f 89.136.43.135 (UPCNET.RO):
ASTRAL UPC TIMISOARA,
TIMISOARA, TIMIS, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:07:22:00 Win2K-f 92.84.69.83 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
07:23:00 WinXP 85.67.30.116 (-):
FIBERNET,
HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
07:27:00 WinXP 87.18.80.204 (RETAIL.TELECOMITALIA.IT):
TELECOM ITALIA S.P.A. TIN EASY LITE,
IT.
n/a   139 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
07:30:00 WinXP 83.141.139.148 (EVC.NET):
DHCP POOL EVC,
BASEL, BASEL-STADT, CH.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:07:34:00 Win2K-f 92.84.92.177 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:07:36:00 Win2K-f 118.169.25.229 (-):
.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
07:38:00 Win2K-f 87.205.255.140 (INETIA.PL):
NETIA,
VIENNA, WIEN, AT. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
07:39:00 WinXP 76.168.73.62 (RR.COM):
ROAD RUNNER HOLDCO LLC,
VENICE, CALIFORNIA, US. (100Mbps)
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:411 hits: 12-31 to 06-12]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:07:42:00 Win2K-f 87.205.255.140 (INETIA.PL):
NETIA,
VIENNA, WIEN, AT. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:07:44:00 Win2K-f 78.92.79.54 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:07:48:00 WinXP 220.228.69.192 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:07:53:00 Win2K-f 85.66.102.79 (BACS-NET.HU):
FIBERNET COMMUNICATION CO,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:08:03:00 Win2K-f 87.228.94.55 (-):
INFOLINE ZAO,
RU.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
08:09:00 WinXP 92.46.143.18 (IKBCC.COM):
EU-ZZ,
UK.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
08:10:00 Win2K-f 89.123.227.32 (PLATINUMGROUP.RO):
ARTELECOM,
RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
08:12:00 WinXP 77.254.135.132 (COM.PL):
NETIA,
PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
08:16:00 Win2K-f 61.229.87.121 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:08:24:00 WinXP 213.138.231.120 (NETMADEIRA.COM):
CABO TV MADEIRENSE S.A,
FUNCHAL, MADEIRA, PT.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:08:29:00 Win2K-f 81.245.69.50 (ISP.BELGACOM.BE):
BELGACOM-ADSL,
EUPEN, LIEGE, BE. (DSL)
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:08:30:00 WinXP 71.113.77.184 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LYNNWOOD, WASHINGTON, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
113 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
08:34:00 Win2K-f 70.69.46.165 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
MAPLE RIDGE, BRITISH COLUMBIA, CA.
n/a   135 pcap raw alerts
ruleset
other
838 lines
Yeah : 0.8
profile
none summary
tarball
29 of 32 d74613e216
NEW
d74613e216 [1] ASM:Graph
ASProtect| lines=45 trace
T:08:34:00 Win2K-f 89.137.118.140 (-):
ASTRAL CLUJ-NAPOCA DOCSIS NETWORK,
CLUJ-NAPOCA, CLUJ, RO.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:08:37:00 Win2K-f 77.253.164.86 (COM.PL):
NETIA,
PL.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
08:42:00 WinXP 211.209.84.232 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
08:45:00 WinXP 84.3.247.125 (T-ONLINE.HU):
HUNGARIAN TELECOM,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:08:56:00 Win2K-f 172.130.197.244 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:08:58:00 WinXP 61.230.145.165 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
17 of 32 8ed2e75017
[Firefox:12 hits: 06-14 to 06-14]
none[3] none:none
ASPack| none trace
09:02:00 WinXP 82.224.119.221 (PROXAD.NET):
PROXAD / FREE SAS,
LILLE, NORD-PAS-DE-CALAIS, FR.
n/a   139 pcap raw alerts
ruleset
ftp
11 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
09:04:00 WinXP 87.202.21.60 (OTENET.GR):
MULTIPROTOCOL SERVICE PROVIDER TO OTHER ISP'S AND END USERS,
ATHENS, ATTIKI, GR. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:638 hits: 07-11 to 06-14]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
09:06:00 Win2K-f 78.59.188.74 (ZEBRA.LT):
LIETUVOS,
LT.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
09:08:00 Win2K-f 78.57.6.172 (ZEBRA.LT):
LIETUVOS,
KAUNAS, KAUNO APSKRITIS, LT.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
21 of 32 f7f466aa6f
[Firefox:32 hits: 06-14 to 06-14]
none[3] none:none
TXT2COM| none trace
T:09:14:00 Win2K-f 82.224.119.221 (PROXAD.NET):
PROXAD / FREE SAS,
LILLE, NORD-PAS-DE-CALAIS, FR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:09:29:00 Win2K-f 61.229.146.55 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:09:32:00 WinXP 83.132.164.54 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
LISBON, LISBOA, PT. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 f2668b51f1
[Firefox: 7 hits: 08-10 to 06-14]
none[4] none:none
PolyEnE| none trace
T:09:42:00 Win2K-f 201.252.122.145 (NET.AR):
APOLO -GOLD-TELECOM-PER,
AR.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:09:44:00 WinXP 172.132.10.251 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
102 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:10:04:00 Win2K-f 87.67.81.195 (ISP.BELGACOM.BE):
BELGACOM-ADSL,
BE.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:10:31:00 WinXP 70.247.163.53 (SWBELL.NET):
PPPOX POOL - BRAS17 RCSNTX,
FT. WORTH, TEXAS, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:411 hits: 12-31 to 06-12]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:10:48:00 Win2K-f 85.67.30.116 (-):
FIBERNET,
HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:10:52:00 WinXP 85.66.33.52 (BACS-NET.HU):
FIBERNET COMMUNICATION CO,
BUDAPEST, BUDAPEST, HU.
n/a   139 pcap raw alerts
ruleset
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
23 of 32 0f143d3856
[Firefox:86 hits: 06-14 to 06-14]
none[3] none:none
none|none none trace
T:11:09:00 WinXP 89.246.223.149 (VERSANETONLINE.DE):
VERSATEL NORD-DEUTSCHLAND GMBH,
DE.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:31 hits: 09-28 to 06-12]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:13:06:00 Win2K-f 4.232.24.165 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
LOS ANGELES, CALIFORNIA, US. (DIAL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 0.8
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2643 hits: 12-31 to 06-14]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:13:29:00 Win2K-f 4.90.19.64 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
US. (DIAL)
217.170.244.2:443  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
irc
26 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2643 hits: 12-31 to 06-14]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:13:40:00 WinXP 122.109.230.136 (-):
.
n/a   135 pcap raw alerts
ruleset
other
568 lines
Yeah : 0.8
profile
none summary
tarball
26 of 32 24a72b5a84
NEW
none[4] none:none
ASPack| none trace
T:13:56:00 WinXP 85.179.15.136 (ALICEDSL.DE):
HANSENET-ADSL,
BERLIN, BERLIN, DE. (DSL)
n/a :proxim.ircgalaxy.pl
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 0.8
profile
none summary
tarball
30 of 32 d34bd9bf09
NEW
none[4] none:none
FSG| none trace
T:15:54:00 WinXP 201.69.123.246 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a EU:siliconfireware.ru
US:searchportal.information.com
GB:new.egg.com
:wpad
US:208.73.212.12:80
DE:217.11.54.126:80
GB:217.145.225.22:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
http
http
http
27 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:1049 hits: 05-01 to 06-14]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
T:16:39:00 WinXP 70.119.53.244 (RR.COM):
ROAD RUNNER HOLDCO LLC,
ORLANDO, FLORIDA, US.
n/a   445 pcap raw alerts
ruleset
http
1 line
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:16:59:00 WinXP 65.191.29.23 (RR.COM):
ROAD RUNNER HOLDCO LLC,
FAYETTEVILLE, NORTH CAROLINA, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 d42c1cc7c0
[Firefox:289 hits: 05-01 to 06-12]
af9ca5bed1 [0] ASM:Graph
PolyEnE| lines=54 trace
T:18:32:00 Win2K-f 68.144.24.181 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA.
n/a :proxim.ircgalaxy.pl 135 pcap raw alerts
ruleset
other
276 lines
Yeah : 0.8
profile
none summary
tarball
30 of 33 d2a2fe7841
NEW
none[4] none:none
PolyEnE| none trace
T:18:40:00 WinXP 98.140.228.155 (-):
.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:19:50:00 Win2K-f 68.151.24.77 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SHERWOOD PARK, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:39:00 WinXP 64.109.228.143 (AMERITECH.NET):
DIAL POOL - TNT,
DOLTON, ILLINOIS, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:411 hits: 12-31 to 06-12]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:20:46:00 Win2K-f 222.234.97.168 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
112 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:20:54:00 WinXP 24.83.204.143 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
111 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:21:15:00 Win2K-f 116.40.56.56 (-):
LG POWERCOMM,
SEOUL, KYONGGI-DO, KR.
n/a   135 pcap raw alerts
ruleset
other
10 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none