Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:05:00 | WinXP | 12.214.237.156 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHENOA, ILLINOIS, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:44 hits: 09-28 to 06-20] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:00:06:00 | WinXP | 70.74.202.183 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. |
72.10.172.218:7382 | CA:italian.swiifatecihno.com CA:done.blacktiehsbdcs.com CA:fuck.urpal43sourpalhuh.com CA:72.10.169.26:3938 CA:72.10.172.218:7382 CA:72.10.172.218:7763 |
135 | pcap | raw alerts ruleset |
other 589 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 30 | 2aa59ba425 [Firefox:43 hits: 06-30 to 06-19] |
2aa59ba425 [1] | ASM:Graph |
ASPack| | lines=10 | trace |
T:00:20:00 | WinXP | 86.11.100.247 (NTL.COM): NTL INFRASTRUCTURE - BROMLEY, LONDON, ENGLAND, UK. (DSL) |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | f41d65b459 [Firefox:78 hits: 08-28 to 06-19] |
none[3] | none:none |
PolyEnE| | none | trace |
00:21:00 | WinXP | 86.11.100.247 (NTL.COM): NTL INFRASTRUCTURE - BROMLEY, LONDON, ENGLAND, UK. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | f41d65b459 [Firefox:78 hits: 08-28 to 06-19] |
none[3] | none:none |
PolyEnE| | none | trace |
00:38:00 | Win2K-f | 222.239.30.74 (-): INCHON CABLE TV NAMDONG BROADCAST, INCHON, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.126:80 US:199.93.41.126:80 US:205.128.66.124:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 [Firefox:10 hits: 06-17 to 06-20] 53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
T:00:53:00 | WinXP | 87.61.169.4 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | c05385e600 [Firefox:19 hits: 06-24 to 06-19] |
6a383b021d [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:00:54:00 | WinXP | 58.52.129.190 (163DATA.COM.CN): CHINANET HUBEI PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:00:55:00 | Win2K-f | 70.62.67.113 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBIA, SOUTH CAROLINA, US. |
n/a | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com US:204.2.160.90:80 US:204.2.160.91:80 |
135 | pcap | raw alerts ruleset |
other 188 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
2110c8100f NEW 89366f61bb NEW |
none[4] 89366f61bb[1] |
none:none ASM:Graph |
PolyEnE| Armadillo| |
none lines=81 |
trace trace |
00:58:00 | WinXP | 122.148.40.194 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.160.90:80 US:204.2.160.91:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:00:59:00 | WinXP | 41.214.180.203 (-): . |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | a3f358bd55 [Firefox: 6 hits: 08-25 to 06-19] |
none[4] | none:none |
PolyEnE| | none | trace |
01:05:00 | WinXP | 99.164.38.227 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.160.90:80 US:204.2.160.91:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:01:23:00 | WinXP | 218.169.57.37 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell shell ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:02:01:00 | WinXP | 218.52.172.96 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.124:80 US:205.128.66.124:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 [Firefox:10 hits: 06-17 to 06-20] 53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
02:18:00 | Win2K-f | 12.74.162.108 (ATT.NET): AT&T WORLDNET SERVICES, ALABAMA, US. (DIAL) |
12.74.162.108:21 | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | c8f6429e83 NEW |
none[4] | none:none |
FSG| | none | trace | |
T:04:12:00 | Win2K-f | 118.231.76.116 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:04:12:00 | WinXP | 41.214.135.124 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
04:13:00 | WinXP | 64.134.122.161 (WAYPORT.NET): WAYPORT INC, AUSTIN, TEXAS, US. |
n/a | US:microsoft.com US:download.microsoft.com CA:64.86.142.18:80 CA:64.86.142.27:80 |
135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 33 of 33 |
3ed16ae12d NEW 79c01ec060 [Firefox: 2 hits: 06-18 to 06-19] |
3ed16ae12d [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
T:04:27:00 | WinXP | 86.155.8.231 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:651 hits: 07-11 to 06-20] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
04:30:00 | Win2K-f | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.44.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
04:39:00 | WinXP | 121.254.95.217 (TCOL.COM.TW): MONAD DIGITNAMIC CORP, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:205.128.66.126:80 US:206.33.45.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
04:42:00 | WinXP | 86.140.230.154 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:429 hits: 12-31 to 06-20] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
04:49:00 | WinXP | 219.122.149.217 (EONET.NE.JP): K-OPTICOM CORPORATION, JP. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | fca1ec9a98 NEW |
none[4] | none:none |
PolyEnE| | none | trace |
T:05:01:00 | Win2K-f | 220.130.194.247 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:16:00 | Win2K-f | 64.230.86.45 (BELL.CA): SYMPATICO HSE, OTTAWA, ONTARIO, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:207.123.44.126:80 |
135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
e592406be2 [Firefox: 2 hits: 06-19 to 06-19] f1218dd4e7 [Firefox: 2 hits: 06-19 to 06-19] |
e592406be2 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=82 none |
trace trace |
05:37:00 | Win2K-f | 68.144.36.184 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:12.190.48.65:80 US:12.190.48.97:80 |
135 | pcap | raw alerts ruleset |
other 171 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
2b41be5e59 NEW d1599ce1f5 NEW |
none[4] d1599ce1f5[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
05:41:00 | WinXP | 24.76.71.117 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:12.190.48.65:80 US:12.190.48.97:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
12df83cb4f NEW 2e7dc3f066 NEW |
12df83cb4f [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=82 none |
trace trace |
05:48:00 | WinXP | 66.220.226.26 (VERMONTEL.NET): VERMONT TELEPHONE COMPANY INC, CHESTER, VERMONT, US. |
n/a | US:www.altavista.com US:www.yahoo.com :jbeegvia.ru NL:www.viruslist.com US:www.worldbank.org :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :wpad :rihafvu.ru :ryryodokm.ru :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru SE:kavkaz.tv :pwvbfz.ru :nuzbcp.ru RU:alfabank.ru :bqpuqt.ru :okskyyn.ru :pnlkria.ru :kargai.ru GB:www.candidateverifier.com :kfwfceki.ru US:crime-research.ru :nhuwxyuw.ru :udluzuq.ru :fiazpvnne.ru US:prodexteam.net :ppxuub.ru RU:www.cbr.ru :lvwgdhwlj.ru :raxeqajrf.ru :dhagunb.ru :zpwmktjv.ru RU:www.mmbank.ru :aadqca.ru :ygnrqi.ru :ycgnbe.ru :yeqsuem.ru :aiizkak.ru RU:www.sbrf.ru :dupeloz.ru DE:kavkaz.co.uk :dodgscv.ru :lodrzze.ru :nkuoonxuz.ru US:bill.ccbill.com :tmamzn.ru :jxdodqm.ru :jgoueta.ru :zokwirdm.ru :jfbved.ru IN:www.bankofindia.com :zurrnzssl.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda [Firefox:10 hits: 09-29 to 06-20] |
none[3] | none:none |
tElock| | none | trace |
T:05:57:00 | WinXP | 222.149.145.127 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:44 hits: 09-28 to 06-20] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:06:15:00 | WinXP | 125.58.82.13 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:16:00 | WinXP | 67.241.149.253 (-): . |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3071 hits: 12-31 to 06-20] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:30:00 | WinXP | 65.173.139.164 (MAYSVILLEKY.NET): LIME STONE CABLE, MAYSVILLE, KENTUCKY, US. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3071 hits: 12-31 to 06-20] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
06:32:00 | Win2K-f | 4.162.15.228 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DALLAS, TEXAS, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:32:00 | Win2K-f | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:192.221.99.126:80 US:205.128.79.124:80 |
135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
06:33:00 | WinXP | 12.210.158.160 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, JASPER, INDIANA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:192.221.99.126:80 US:205.128.79.124:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:06:48:00 | WinXP | 80.102.244.236 (DYNAMIC.ORANGE.ES): UNI2 IP DATA NETWORK, BARCELONA, CATALUñA, ES. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:429 hits: 12-31 to 06-20] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
06:57:00 | Win2K-f | 24.84.232.228 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KAMLOOPS, BRITISH COLUMBIA, CA. |
n/a | US:microsoft.com US:download.microsoft.com US:207.123.44.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:07:02:00 | WinXP | 119.94.163.228 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:206.33.45.125:80 US:207.123.37.125:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 127 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
a4eb225807 NEW f85f8eb994 NEW |
none[4] f85f8eb994[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
07:18:00 | Win2K-f | 72.251.11.235 (1DIAL.COM): AD-BASE SYSTEMS INC. (DBA GLOBALPOPS), PITTSBURGH, PENNSYLVANIA, US. (DIAL) |
n/a | :proxim.ircgalaxy.pl CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 5c7aead574 NEW |
none[4] | none:none |
FSG| | none | trace |
07:33:00 | WinXP | 124.241.161.173 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
67.43.236.66:8080 72.10.172.211:8080 | CA:xx.nadnadzz.info CA:xx.enterhere.biz CA:xx.ka3ek.com CA:67.43.226.242:8080 CA:67.43.236.66:8080 CA:67.43.236.98:10324 CA:67.43.236.98:1863 CA:67.43.236.99:10324 CA:67.43.236.99:1863 CA:72.10.172.211:8080 |
135 | pcap | raw alerts ruleset |
other 227 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | 2595d6e010 NEW |
none[4] | none:none |
none|none | none | trace |
07:34:00 | WinXP | 77.253.162.209 (COM.PL): NETIA, PL. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 31 | 4ab5b0788c [Firefox: 9 hits: 04-21 to 06-19] |
272da55ef8 [0] | ASM:Graph |
PolyEnE| | lines=114 | trace |
07:41:00 | WinXP | 125.101.54.39 (UCOM.NE.JP): G-MG0001N, JP. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 3e209ce796 NEW |
none[4] | none:none |
none|none | none | trace | |
T:07:45:00 | Win2K-f | 24.24.234.55 (RR.COM): ROAD RUNNER HOLDCO LLC, WESTMINSTER, CALIFORNIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.124:80 US:205.128.79.125:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
07:56:00 | WinXP | 86.143.28.102 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SHEFFIELD, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | cce9566ceb [Firefox: 6 hits: 06-12 to 06-19] |
none[4] | none:none |
PolyEnE| | none | trace | |
08:02:00 | WinXP | 123.99.103.54 (-): TBROAD NAKDONG BROADCASTING CO LTD, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:205.128.79.124:80 US:207.123.37.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
04538c6f42 NEW d280e1c3a0 NEW |
04538c6f42 [1] none [4] |
ASM:Graph none:none |
FASM| tElock| |
lines=81 none |
trace trace |
T:08:04:00 | Win2K-f | 24.86.67.191 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.79.124:80 US:207.123.37.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:08:06:00 | WinXP | 216.126.169.184 (USLEC.NET): USLEC CORP, SUMNER, WASHINGTON, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1340 hits: 12-31 to 06-19] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
08:25:00 | WinXP | 86.49.104.19 (UPC.CZ): UPC CESKA REPUBLIKA A.S, CZ. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | cce9566ceb [Firefox: 6 hits: 06-12 to 06-19] |
none[4] | none:none |
PolyEnE| | none | trace | |
T:08:45:00 | Win2K-f | 122.53.123.185 (PLDT.NET): IPG, PH. |
n/a | US:microsoft.com US:download.microsoft.com :proxim.ircgalaxy.pl US:72.247.30.81:80 US:72.247.30.83:80 |
135 | pcap | raw alerts ruleset |
other 126 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 33 of 33 |
16874933ea [Firefox: 4 hits: 06-18 to 06-20] 76ee340669 [Firefox: 4 hits: 06-18 to 06-20] |
16874933ea [1] none [4] |
ASM:Graph none:none |
Armadillo| PolyEnE| |
lines=82 none |
trace trace |
T:08:47:00 | WinXP | 216.10.170.251 (WISPNET.NET): WISPNET LLC, WILSON, NORTH CAROLINA, US. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
08:48:00 | WinXP | 122.105.11.152 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, SYDNEY, NEW SOUTH WALES, AU. |
n/a | 135 | pcap | raw alerts ruleset |
other 538 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 07d98cfb7c NEW |
none[4] | none:none |
PolyEnE| | none | trace | |
T:08:57:00 | WinXP | 198.68.23.5 (SPRINTLINK.NET): SPRINT, CORVALLIS, OREGON, US. |
n/a | DE:siliconfireware.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
22 of 32 | 4f8fc4407f [Firefox: 2 hits: 08-13 to 06-19] |
none[4] | none:none |
ASPack| | none | trace |
09:32:00 | WinXP | 155.239.183.182 (TELKOM-IPNET.CO.ZA): AFRINIC, ZA. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 03f912899b [Firefox:16 hits: 12-14 to 06-20] |
83893bd25d [0] | ASM:Graph |
none|none | lines=65 | trace | |
T:09:36:00 | WinXP | 97.89.22.172 (-): . |
n/a | :proxim.ircgalaxy.pl | 135 | pcap | raw alerts ruleset |
other 277 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 398530ed93 [Firefox: 2 hits: 06-19 to 06-20] |
none[4] | none:none |
PolyEnE| | none | trace |
09:52:00 | WinXP | 80.199.42.114 (ADSL-FIXED.TELE.DK): TDC-INTERNET-STATIC-ASSIGNED-IP, COPENHAGEN, COPENHAGEN, DK. (DSL) |
n/a | EU:siliconfireware.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:469 hits: 05-04 to 06-19] |
9bbdd086c5 [0] | ASM:Graph |
ASPack| | lines=186 embedded dns |
trace |
09:59:00 | WinXP | 68.26.46.171 (SPCSDNS.NET): SPRINT PCS, HUNTINGTON BEACH, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.66.126:80 US:207.123.37.126:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
10:05:00 | Win2K-f | 219.26.206.10 (BBTEC.NET): SOFTBANK BB CORP, TOKYO, TOKYO, JP. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:207.123.44.125:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 33 of 33 |
07fabc79ef NEW 53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] |
07fabc79ef [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
T:10:14:00 | WinXP | 4.253.2.37 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, YOAKUM, TEXAS, US. (DIAL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1340 hits: 12-31 to 06-19] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:21:00 | WinXP | 125.175.143.46 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 21e5edb96d [Firefox: 2 hits: 06-19 to 06-20] |
none[4] | none:none |
none|none | none | trace | |
T:10:30:00 | WinXP | 204.95.50.112 (NEP.NET): THE NORTH-EASTERN PENNSYLVANIA TELEPHONE COMPANY, FOREST CITY, PENNSYLVANIA, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell 5 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:41:00 | WinXP | 99.163.49.149 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b [Firefox:16 hits: 12-14 to 06-20] |
83893bd25d [0] | ASM:Graph |
none|none | lines=65 | trace | |
11:02:00 | Win2K-f | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 204 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | fe22b8315f NEW |
none[4] | none:none |
StarForce| | none | trace | |
T:11:09:00 | WinXP | 193.33.163.209 (-): IACCES-NET, RO. |
n/a | :proxim.ircgalaxy.pl RU:moscow-advokat.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | d23978004f [Firefox: 3 hits: 06-12 to 06-19] |
none[4] | none:none |
PolyEnE| | none | trace |
11:10:00 | WinXP | 193.33.163.209 (-): IACCES-NET, RO. |
n/a | :proxim.ircgalaxy.pl RU:moscow-advokat.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 32 | d23978004f [Firefox: 3 hits: 06-12 to 06-19] |
none[4] | none:none |
PolyEnE| | none | trace |
11:10:00 | WinXP | 81.198.244.204 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:429 hits: 12-31 to 06-20] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
11:26:00 | WinXP | 71.98.138.214 (VERIZON.NET): VERIZON INTERNET SERVICES INC, NEW PORT RICHEY, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:32:00 | Win2K-f | 24.79.81.161 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:39:00 | WinXP | 96.51.18.181 (-): . |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:298 hits: 05-01 to 06-20] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
11:40:00 | WinXP | 64.230.86.45 (BELL.CA): SYMPATICO HSE, OTTAWA, ONTARIO, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 US:207.123.47.126:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
e592406be2 [Firefox: 2 hits: 06-19 to 06-19] f1218dd4e7 [Firefox: 2 hits: 06-19 to 06-19] |
e592406be2 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=82 none |
trace trace |
T:11:43:00 | WinXP | 12.72.150.185 (ATT.NET): AT&T WORLDNET SERVICES, SACRAMENTO, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:48:00 | Win2K-f | 85.69.36.44 (MTZ.MODULONET.FR): METZ CABLE MODEM USERS, VERSAILLES, ILE-DE-FRANCE, FR. |
n/a | :proxim.ircgalaxy.pl CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 6ae020a074 NEW |
none[4] | none:none |
FSG| | none | trace |
12:00:00 | WinXP | 206.169.217.103 (NETPTC.NET): PONDEROSA CABLEVISION, HANFORD, CALIFORNIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:199.93.46.125:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
other 84 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:12:21:00 | WinXP | 190.18.24.78 (-): . |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1340 hits: 12-31 to 06-19] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:12:28:00 | WinXP | 70.183.164.199 (COX.NET): COX COMMUNICATIONS, WARWICK, RHODE ISLAND, US. |
n/a | US:microsoft.com US:download.microsoft.com US:72.247.30.81:80 US:72.247.30.83:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
12:29:00 | WinXP | 161.184.20.221 (TELUS.NET): EDMONTON TELEPHONES CORPORATION, RED DEER, ALBERTA, CA. (DIAL) |
n/a | DE:siliconfireware.ru DE:ebookfinaltrash.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1061 hits: 05-01 to 06-20] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:12:39:00 | WinXP | 79.138.218.216 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru DE:kidos-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:298 hits: 05-01 to 06-20] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
T:13:01:00 | WinXP | 155.239.112.238 (TELKOM-IPNET.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. |
n/a | US:microsoft.com US:download.microsoft.com US:12.190.48.114:80 US:12.190.48.83:80 US:12.190.48.91:80 US:12.190.48.97:80 US:12.190.48.99:80 |
135 | pcap | raw alerts ruleset |
other 181 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
13:01:00 | Win2K-f | 155.239.112.238 (TELKOM-IPNET.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. |
n/a | 135 | pcap | raw alerts ruleset |
other 133 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
73f1082158 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
T:13:15:00 | Win2K-f | 98.133.149.9 (-): ALLTEL SIP CUSTOMERS - CLEVELAND, CLEVELAND, OHIO, US. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
13:47:00 | WinXP | 71.105.24.141 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LONG BEACH, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:72.247.30.81:80 US:72.247.30.83:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
13:55:00 | Win2K-f | 66.217.229.66 (USLEC.NET): USLEC CORP, CHARLOTTE, NORTH CAROLINA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 169 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
73f1082158 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
14:08:00 | WinXP | 64.109.228.82 (AMERITECH.NET): DIAL POOL - TNT, DOLTON, ILLINOIS, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:429 hits: 12-31 to 06-20] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
14:23:00 | WinXP | 71.103.203.182 (VERIZON.NET): VERIZON INTERNET SERVICES INC, REDLANDS, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:207.123.37.125:80 US:207.123.37.126:80 |
135 | pcap | raw alerts ruleset |
other 252 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
00fbad48e5 NEW 6ab3a543a7 NEW |
none[4] 6ab3a543a7[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=83 |
trace trace |
T:14:24:00 | Win2K-f | 24.70.238.104 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KELOWNA, BRITISH COLUMBIA, CA. (DSL) |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:207.123.37.125:80 US:207.123.37.126:80 |
135 | pcap | raw alerts ruleset |
other 95 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
48f8b1a711 NEW aecf2a5fc9 NEW |
none[4] aecf2a5fc9[1] |
none:none ASM:Graph |
PolyEnE| Armadillo| |
none lines=81 |
trace trace |
14:33:00 | Win2K-f | 216.198.164.46 (INTELLEQCOM.NET): INTELLEQ COMMUNICATIONS CORPORATION, OKLAHOMA CITY, OKLAHOMA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.126:80 US:207.123.46.125:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 none |
3cd7958258 [Firefox: 2 hits: 06-17 to 06-19] 41efedf70f NEW |
none[4] 41efedf70f[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
T:14:45:00 | WinXP | 65.149.253.121 (QWEST.NET): QWEST COMMUNICATIONS CORPORATION, ARDARA, PENNSYLVANIA, US. |
n/a | DE:siliconfireware.ru EU:ebookfinaltrash.ru :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1061 hits: 05-01 to 06-20] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:14:49:00 | WinXP | 70.182.2.254 (COX.NET): COX COMMUNICATIONS INC, CROWLEY, LOUISIANA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.126.124:80 US:205.128.79.124:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:14:52:00 | Win2K-f | 24.234.98.190 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.126.124:80 US:205.128.79.124:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
14:52:00 | WinXP | 4.224.117.76 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOUISVILLE, KENTUCKY, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:54:00 | Win2K-f | 207.5.248.224 (GWI.NET): GREAT WORKS INTERNET, LACONIA, NEW HAMPSHIRE, US. |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.126.124:80 US:205.128.79.124:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
14:56:00 | Win2K-f | 116.126.200.26 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com :proxima.ircgalaxy.pl US:download.microsoft.com US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
f10855e3e1 NEW f7f799f818 NEW |
f10855e3e1 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=82 none |
trace trace |
15:17:00 | WinXP | 68.126.115.67 (PACBELL.NET): PPPOX POOL RBACK3.IRVNCA, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:72.247.30.81:80 US:72.247.30.83:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
15:34:00 | Win2K-f | 61.218.193.242 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.126:80 US:204.160.126.124:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:15:45:00 | WinXP | 220.139.161.225 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:15:48:00 | WinXP | 200.100.91.174 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:52:00 | Win2K-f | 67.76.247.16 (EMBARQHSD.NET): EMBARQ CORPORATION, US. |
n/a | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com US:207.123.46.125:80 US:207.123.47.126:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 117 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
ae43bb721a NEW b5a9a8f575 NEW |
ae43bb721a [1] none [4] |
ASM:Graph none:none |
Armadillo| StarForce| |
lines=81 none |
trace trace |
15:58:00 | Win2K-f | 210.3.135.36 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:207.123.46.125:80 US:207.123.47.126:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
79a515c871 NEW b71c74380c NEW |
none[4] none [4] |
none:none none:none |
PolyEnE| PolyEnE| |
none none |
trace trace |
T:16:01:00 | Win2K-f | 71.112.115.75 (VERIZON.NET): VERIZON INTERNET SERVICES INC, SNOHOMISH, WASHINGTON, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:16:15:00 | WinXP | 24.108.14.127 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | SE:viking.dal.net :gaspode.zanet.org.za SE:qis.md.us.dal.net SE:coins.dal.net RU:moscow-advokat.ru |
135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:25:00 | WinXP | 24.87.54.168 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, RICHMOND, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:35:00 | WinXP | 221.191.141.248 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:44 hits: 09-28 to 06-20] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:16:52:00 | Win2K-f | 63.27.178.234 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:54:00 | Win2K-f | 61.218.193.218 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:72.247.30.81:80 |
135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
17:30:00 | Win2K-f | 208.126.94.129 (NETINS.NET): NETINS INC, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:207.123.46.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
17:34:00 | Win2K-f | 69.107.174.37 (PACBELL.NET): 3CIM INC, SAN JOSE, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com :proxim.ircgalaxy.pl US:205.128.66.124:80 |
135 | pcap | raw alerts ruleset |
other 94 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 none |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] dc92683d9a [Firefox: 2 hits: 06-19 to 06-20] |
none[4] dc92683d9a[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
18:04:00 | WinXP | 64.139.104.242 (RCABLETV.COM): NCI DATA.COM INC, REPUBLIC, WASHINGTON, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.125:80 US:205.128.66.126:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
18:07:00 | WinXP | 4.153.2.12 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:429 hits: 12-31 to 06-20] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
18:24:00 | WinXP | 66.220.226.31 (VERMONTEL.NET): VERMONT TELEPHONE COMPANY INC, CHESTER, VERMONT, US. |
n/a | US:www.altavista.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | f2ccea3f12 NEW |
none[3] | none:none |
tElock| | none | trace |
18:29:00 | WinXP | 76.83.26.196 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 [Firefox:87 hits: 05-03 to 06-19] |
ae590430c5 [0] | ASM:Graph |
PolyEnE| | lines=63 | trace |
18:44:00 | Win2K-f | 96.247.59.250 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:72.247.30.81:80 US:72.247.30.83:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
18:56:00 | WinXP | 4.158.201.129 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, GREEN BAY, WISCONSIN, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
19:36:00 | WinXP | 4.231.243.206 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NEW YORK, NEW YORK, US. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:20:37:00 | WinXP | 222.239.195.229 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 none |
4c3df24b32 [Firefox:10 hits: 06-17 to 06-20] 53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] e07c29c4ae [Firefox:12 hits: 06-19 to 06-20] |
4c3df24b32 [1] none [4] e07c29c4ae[1] |
ASM:Graph none:none ASM:Graph |
Armadillo| tElock| FSG| |
lines=81 none lines=92 |
trace trace trace |
20:45:00 | WinXP | 96.14.32.92 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:20:50:00 | WinXP | 24.234.98.190 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 none |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] e07c29c4ae [Firefox:12 hits: 06-19 to 06-20] |
none[4] a08f3b74a4[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| FSG| |
none lines=81 lines=92 |
trace trace trace |
21:24:00 | WinXP | 12.74.162.168 (ATT.NET): AT&T WORLDNET SERVICES, ALABAMA, US. (DIAL) |
12.74.162.168:21 | :irc.drxclusives.info DE:msdirect.servicemail24.de US:lebanon-online.com.lb DE:msdirectservices.com :mx.lebanon-online.com.lb :mx.msdirectservices.com :mail.msdirectservices.com :smtp.msdirectservices.com :mx1.msdirectservices.com :mxs.msdirectservices.com :mail1.msdirectservices.com :relay.msdirectservices.com :ns.msdirectservices.com :gate.msdirectservices.com DE:mail.LF.net US:mx.develooper.com :smtp.lebanon-online.com.lb :mx1.lebanon-online.com.lb :mxs.lebanon-online.com.lb DE:fb-mx.LF.net US:mrin4-b.corp.re1.yahoo.com US:perl.org :mail1.lebanon-online.com.lb US:mrin1.yahoo.com :ispsoft.de :mx.perl.org :relay.lebanon-online.com.lb US:mrin2.yahoo.com :mx.ispsoft.de :ns.lebanon-online.com.lb :mail.perl.org US:mrin3.yahoo.com :mail.ispsoft.de :gate.lebanon-online.com.lb :smtp.perl.org US:mrin4.corp.yahoo.com :smtp.ispsoft.de :mx1.perl.org US:mrin1-b.corp.re1.yahoo.com :mx1.ispsoft.de :mxs.perl.org US:mrin2-b.corp.re1.yahoo.com :mxs.ispsoft.de :mail1.perl.org US:mrin3-b.corp.re1.yahoo.com :mail1.ispsoft.de US:yahoo-inc.com :relay.perl.org :relay.ispsoft.de US:mx.yahoo-inc.com :ns.perl.org :ns.ispsoft.de US:mail.yahoo-inc.com :gate.perl.org :gate.ispsoft.de US:smtp.yahoo-inc.com US:mx1.yahoo-inc.com DE:convex.com US:mxs.yahoo-inc.com :mx.convex.com US:mail1.yahoo-inc.com :mail.convex.com US:relay.yahoo-inc.com :cam.a.uk US:ns.yahoo-inc.com :smtp.convex.com US:gate.yahoo-inc.com :mx.cam.a.uk :mx1.convex.com :mail.cam.a.uk :mxs.convex.com :smtp.cam.a.uk :mail1.convex.com :relay.convex.com :mx1.cam.a.uk :ns.convex.com :mxs.cam.a.uk :gate.convex.com :mail1.cam.a.uk :relay.cam.a.uk US:penvision.com :ns.cam.a.uk :mx.penvision.com US:mail.penvision.com :gate.cam.a.uk :smtp.penvision.com :mx1.penvision.com :mxs.penvision.com :mail1.penvision.com :relay.penvision.com :ns.penvision.com :gate.penvision.com :msg.com.mx US:wamnet.com :mx.msg.com.mx :mx.wamnet.com :mail.msg.com.mx :mail.wamnet.com DE:193.189.224.91:25 DE:212.9.160.2:25 US:63.251.223.176:25 US:64.26.62.254:25 DE:84.17.190.209:25 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | 098258b3a9 NEW |
none[4] | none:none |
FSG| | none | trace |
22:02:00 | WinXP | 211.44.228.108 (KRLINE.NET): KRNIC, KR. |
n/a | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:72.247.30.144:80 US:72.247.30.211:80 |
135 | pcap | raw alerts ruleset |
other 103 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 none |
168aab35a3 [Firefox: 5 hits: 06-17 to 06-20] acd2a6266d NEW |
none[4] acd2a6266d[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
22:44:00 | Win2K-f | 220.139.222.113 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
23:18:00 | WinXP | 69.144.24.35 (BRESNAN.NET): BRESNAN COMMUNICATIONS LLC, LARAMIE, WYOMING, US. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:208.50.79.43:80 US:208.50.79.66:80 |
135 | pcap | raw alerts ruleset |
other 511 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
1b0477aedf NEW a10eda3c29 NEW |
1b0477aedf [1] none [4] |
ASM:Graph none:none |
Armadillo| PolyEnE| |
lines=81 none |
trace trace |