Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

17 July 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
00:05:00 Win2K-f 117.197.243.83 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:00:08:00 Win2K-f 117.197.243.83 (-):
.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
00:11:00 WinXP 12.72.54.151 (ATT.NET):
AT&T WORLDNET SERVICES,
SALINAS, CALIFORNIA, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:00:15:00 WinXP 218.164.134.50 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
KAOHSIUNG, KAO-HSIUNG, TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
32 of 33 2b8c0ae381
NEW
none[none] none:none
none|none none none
T:00:15:00 Win2K-f 172.131.106.129 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:198.78.220.126:80
135 pcap raw alerts
ruleset
http
111 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33
29 of 33
3373948767
[Firefox: 6 hits: 07-03 to 07-11]
c73f738c30
[Firefox: 6 hits: 07-03 to 07-11]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
00:40:00 Win2K-f 4.229.15.152 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
MONROE, MICHIGAN, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:01:00:00 WinXP 66.54.122.118 (DIGICELBROADBAND.COM):
DIGICEL JAMAICA,
KINGSTON, KINGSTON, JM.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.99.126:80
US:205.128.79.124:80
US:8.12.202.125:80
135 pcap raw alerts
ruleset
other
87 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:01:09:00 WinXP 67.125.140.230 (PACBELL.NET):
AT&T INTERNET SERVICES,
FRESNO, CALIFORNIA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.99.124:80
US:205.128.66.124:80
US:205.128.79.124:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
01:17:00 WinXP 76.245.96.234 (PACBELL.NET):
AT&T INTERNET SERVICES,
US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:01:47:00 WinXP 61.221.250.18 (HINET.NET):
DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
57ce4acac2
[Firefox:60 hits: 06-17 to 07-16]
e07c29c4ae
[Firefox:102 hits: 06-19 to 07-16]
none[4]
57ce4acac2[1]
e07c29c4ae[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
FSG|
none
lines=81
lines=92
trace
trace
trace
01:48:00 WinXP 71.131.139.234 (-):
VALLEY FOOD INC,
PLANO, TEXAS, US. (100Mbps)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.15:80
US:69.28.178.10:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:02:26:00 Win2K-f 71.112.133.23 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
BOTHELL, WASHINGTON, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.54:80
US:208.111.148.69:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
02:27:00 Win2K-f 196.208.65.239 (TELKOM-IPNET.CO.ZA):
AFRINIC,
JOHANNESBURG, GAUTENG, ZA.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.54:80
US:208.111.148.69:80
135 pcap raw alerts
ruleset
other
81 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
02:37:00 WinXP 122.43.67.25 (-):
POWERCOMM,
KR.
n/a HK:proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:208.111.153.215:80
US:208.111.153.231:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
113 lines
Yeah : 1.3
profile
none summary
tarball
24 of 33
32 of 33
8a93930ea8
[Firefox: 7 hits: 07-06 to 07-14]
bc94f66052
[Firefox: 7 hits: 07-06 to 07-14]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:02:43:00 WinXP 122.30.180.141 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:160 hits: 09-28 to 07-15]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:02:43:00 WinXP 211.187.177.98 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
n/a HK:proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:208.111.153.231:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
http
87 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
0 of 33
0 of 33
168aab35a3
[Firefox:56 hits: 06-17 to 07-16]
4c3df24b32
[Firefox:92 hits: 06-17 to 07-16]
e07c29c4ae
[Firefox:102 hits: 06-19 to 07-16]
none[4]
4c3df24b32[1]
e07c29c4ae[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
FSG|
none
lines=81
lines=92
trace
trace
trace
T:03:03:00 Win2K-f 211.59.72.105 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
n/a HK:proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
http
87 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33
30 of 32
4c3df24b32
[Firefox:92 hits: 06-17 to 07-16]
8390780c27
[Firefox:19 hits: 06-18 to 07-15]
4c3df24b32 [1]
none [4]
ASM:Graph
none:none
Armadillo|
tElock|
lines=81
none
trace
trace
03:03:00 Win2K-f 64.31.234.18 (AIRMAIL.NET):
INTERNET AMERICA INC,
HOUSTON, TEXAS, US.
n/a US:microsoft.com
US:download.microsoft.com
US:4.23.60.125:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:03:04:00 WinXP 85.181.110.201 (ALICEDSL.DE):
HANSENET-ADSL,
MUNICH, BAYERN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:487 hits: 12-31 to 07-16]
048df78048 [0] ASM:Graph
none|none lines=61 trace
03:39:00 WinXP 124.86.37.179 (OCN.NE.JP):
NTT COMMUNICATIONS CORPORATION,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:03:43:00 WinXP 222.15.161.123 (DION.NE.JP):
DION (KDDI CORPORATION),
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:160 hits: 09-28 to 07-15]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:04:09:00 Win2K-f 124.84.110.87 (OCN.NE.JP):
NTT COMMUNICATIONS CORPORATION,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
5 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:04:20:00 WinXP 125.224.101.235 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:04:31:00 Win2K-f 122.52.78.8 (PLDT.NET):
IPG,
PH.
n/a US:microsoft.com
US:download.microsoft.com
HK:proxim.ircgalaxy.pl
US:208.111.153.236:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
129 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33
33 of 33
16874933ea
[Firefox:18 hits: 06-18 to 07-15]
76ee340669
[Firefox:18 hits: 06-18 to 07-15]
16874933ea [1]
none [4]
ASM:Graph
none:none
Armadillo|
PolyEnE|
lines=82
none
trace
trace
T:04:36:00 WinXP 75.14.253.81 (-):
REFAT M HIJAZ DBA,
PLANO, TEXAS, US. (100Mbps)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.236:80
US:208.111.173.16:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
04:40:00 WinXP 204.116.68.142 (INFOAVE.NET):
INFO AVENUE INTERNET SERVICES LLC,
MT. AIRY, NORTH CAROLINA, US.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 33 573d7d0455
NEW
none[none] none:none
none|none none none
T:04:40:00 WinXP 204.116.68.142 (INFOAVE.NET):
INFO AVENUE INTERNET SERVICES LLC,
MT. AIRY, NORTH CAROLINA, US.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 33 573d7d0455
NEW
none[none] none:none
none|none none none
T:04:40:00 WinXP 92.227.176.250 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a HK:proxim.ircgalaxy.pl
RU:moscow-advokat.ru
RU:194.6.222.11:6667
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
33 of 33 8178c88f5e
[Firefox: 7 hits: 07-08 to 07-16]
none[none] none:none
none|none none none
T:04:54:00 WinXP 124.86.37.179 (OCN.NE.JP):
NTT COMMUNICATIONS CORPORATION,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
05:21:00 WinXP 71.118.237.30 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LONG BEACH, CALIFORNIA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:199.93.46.125:80
US:205.128.66.126:80
US:205.128.79.125:80
135 pcap raw alerts
ruleset
other
181 lines
Yeah : 1.3
profile
none summary
tarball
24 of 33
31 of 33
5f11b319ef
[Firefox: 4 hits: 07-07 to 07-15]
a3f631e410
[Firefox: 4 hits: 07-07 to 07-15]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:05:28:00 WinXP 4.131.49.96 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
US. (DIAL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:05:48:00 WinXP 72.190.119.113 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:199.93.46.125:80
US:207.123.46.125:80
US:207.123.46.126:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
06:13:00 WinXP 220.209.202.175 (INFOWEB.NE.JP):
INFOWEB(FUJITSU LTD.),
TOKYO, TOKYO, JP. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:06:20:00 WinXP 58.89.94.123 (PLALA.OR.JP):
PLALA NETWORKS INC,
JP.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
06:26:00 Win2K-f 220.143.5.49 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a HK:proxim.ircgalaxy.pl
HK:210.245.211.11:65520
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 b5c46c6fb0
NEW
none[none] none:none
none|none none none
T:06:29:00 WinXP 212.27.7.11 (-):
MLIFENET,
RU.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 ea096a2bdf
NEW
none[none] none:none
none|none none none
06:38:00 WinXP 122.52.78.8 (PLDT.NET):
IPG,
PH.
n/a US:microsoft.com
US:download.microsoft.com
HK:proxim.ircgalaxy.pl
US:199.93.41.126:80
US:199.93.44.126:80
US:199.93.46.125:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
126 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33
33 of 33
16874933ea
[Firefox:18 hits: 06-18 to 07-15]
76ee340669
[Firefox:18 hits: 06-18 to 07-15]
16874933ea [1]
none [4]
ASM:Graph
none:none
Armadillo|
PolyEnE|
lines=82
none
trace
trace
T:06:47:00 WinXP 83.97.206.205 (CM-83-97-128-10.TELECABLE.ES):
TELECABLE,
GIJON, ASTURIAS, ES. (DSL)
n/a HK:proxim.ircgalaxy.pl
RU:moscow-advokat.ru
HK:210.245.211.11:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 965c2ca7e5
[Firefox: 2 hits: 07-10 to 07-11]
none[none] none:none
none|none none none
T:06:50:00 Win2K-f 203.118.233.183 (-):
GRAND TAINAN TECHNOLOGY CO.LTD,
TAINAN, KAO-HSIUNG, TW.
n/a   135 pcap raw alerts
ruleset
other
20 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:06:57:00 WinXP 190.18.21.191 (-):
.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:1420 hits: 12-31 to 07-16]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
06:58:00 WinXP 60.35.82.252 (PLALA.OR.JP):
PLALA NETWORKS INC,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:160 hits: 09-28 to 07-15]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:07:02:00 Win2K-f 122.130.154.248 (MESH.AD.JP):
NEC BIGLOBE LTD,
TOKYO, TOKYO, JP.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:07:04:00 WinXP 79.138.162.222 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 ea096a2bdf
NEW
none[none] none:none
none|none none none
07:13:00 Win2K-f 125.0.88.200 (INFOWEB.NE.JP):
FUJITSU LIMITED,
TOKYO, TOKYO, JP. (DIAL)
n/a HK:proxim.ircgalaxy.pl
HK:210.245.211.11:65520
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 dfcd73f7a7
[Firefox: 7 hits: 07-03 to 07-16]
none[none] none:none
none|none none none
T:07:18:00 WinXP 68.127.39.118 (PACBELL.NET):
PPPOX POOL - RBACK4.IRVNCA,
LOS ANGELES, CALIFORNIA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:198.78.220.124:80
US:207.123.44.126:80
US:207.123.47.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
07:52:00 WinXP 63.17.144.0 (UU.NET):
UUNET TECHNOLOGIES INC,
NEW YORK, NEW YORK, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.219:80
US:208.111.148.226:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:07:54:00 Win2K-f 122.120.99.85 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
08:03:00 Win2K-f 76.226.185.92 (-):
PPPOX SE4.SFLDMI,
PLANO, TEXAS, US.
n/a US:microsoft.com
US:download.microsoft.com
HK:proxim.ircgalaxy.pl
US:208.111.148.108:80
US:208.111.148.115:80
HK:210.245.211.11:65520
CZ:217.170.244.2:443
CZ:82.114.64.251:443
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:08:16:00 Win2K-f 12.76.221.118 (ATT.NET):
AT&T WORLDNET SERVICES,
WILMINGTON, NORTH CAROLINA, US. (DIAL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
08:24:00 WinXP 86.150.134.37 (BTCENTRALPLUS.COM):
BT-CENTRAL-PLUS,
LONDON, ENGLAND, UK.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3208 hits: 12-31 to 07-16]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
08:25:00 WinXP 218.162.119.83 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW. (DSL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:08:32:00 Win2K-f 222.159.233.32 (INFOWEB.NE.JP):
INFOWEB(FUJITSU LTD.),
TOKYO, TOKYO, JP. (DIAL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:08:45:00 WinXP 118.166.239.175 (-):
.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
08:45:00 WinXP 220.131.140.17 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
T'AI-CHUNG, T'AI-WAN, TW.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
08:49:00 Win2K-f 218.168.76.56 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
32 of 33 511dcda8ce
NEW
none[none] none:none
none|none none none
T:09:30:00 Win2K-f 217.201.210.172 (-):
TELECOM ITALIA MOBILE,
IT.
217.170.244.2:443  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
irc
28 lines
Yeah : 1.8
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:09:31:00 Win2K-f 61.229.53.90 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
217.170.244.2:443  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
irc
27 lines
Yeah : 1.8
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:09:54:00 WinXP 58.236.112.187 (-):
THRUNET-INFRA-INCHEON09,
SEOUL, KYONGGI-DO, KR.
69.64.51.132:6789 US:ice.novi-pazar.biz
NL:83.117.217.0:5800
NL:83.117.217.10:5800
NL:83.117.217.11:5800
NL:83.117.217.12:5800
NL:83.117.217.13:5800
NL:83.117.217.14:5800
NL:83.117.217.15:5800
NL:83.117.217.16:5800
NL:83.117.217.17:5800
NL:83.117.217.18:5800
NL:83.117.217.19:5800
NL:83.117.217.1:5800
NL:83.117.217.2:5800
NL:83.117.217.3:5800
NL:83.117.217.4:5800
NL:83.117.217.5:5800
NL:83.117.217.6:5800
NL:83.117.217.7:5800
NL:83.117.217.8:5800
NL:83.117.217.9:5800
139 pcap raw alerts
ruleset
shell
http
ftp
irc
20 lines
Yeah : 1.8
profile
none summary
tarball
25 of 32 588b7eb87d
NEW
none[none] none:none
none|none none none
T:09:55:00 Win2K-f 210.205.33.79 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
shell
http
ftp
8 lines
Yeah : 1.3
profile
none summary
tarball
24 of 33 063528c808
NEW
none[none] none:none
none|none none none
T:09:56:00 WinXP 70.45.133.235 (ONELINKPR.NET):
SAN JUAN CABLE LLC,
SAN JUAN, PUERTO RICO, PR.
194.54.90.246:80 HK:proxim.ircgalaxy.pl
UA:citi-bank.ru
HK:210.245.211.11:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 7ef46e4e16
[Firefox:13 hits: 11-28 to 05-06]
ef2e743fd2 [0] ASM:Graph
PolyEnE| lines=74 trace
09:56:00 WinXP 70.45.133.235 (ONELINKPR.NET):
SAN JUAN CABLE LLC,
SAN JUAN, PUERTO RICO, PR.
n/a HK:proxim.ircgalaxy.pl
UA:citi-bank.ru
HK:210.245.211.11:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 7ef46e4e16
[Firefox:13 hits: 11-28 to 05-06]
ef2e743fd2 [0] ASM:Graph
PolyEnE| lines=74 trace
T:09:59:00 WinXP 58.238.222.188 (-):
THRUNET-INFRA-BUSAN17,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
shell
http
ftp
6 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33 1fe9468d89
NEW
none[none] none:none
none|none none none
10:00:00 WinXP 58.238.222.188 (-):
THRUNET-INFRA-BUSAN17,
SEOUL, KYONGGI-DO, KR.
n/a   139 pcap raw alerts
ruleset
shell
http
ftp
6 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33 1fe9468d89
NEW
none[none] none:none
none|none none none
10:17:00 WinXP 66.53.81.155 (MDSG-PACWEST.COM):
PAC-WEST MANAGED MODEM NAS POOL,
PHOENIX, ARIZONA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.149:80
US:208.111.148.152:80
135 pcap raw alerts
ruleset
other
127 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
10:22:00 Win2K-f 24.87.144.100 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SURREY, BRITISH COLUMBIA, CA. (DSL)
n/a :preek.oihduhdd.net
CA:dong.nagitiriheiwu.net
CA:done.blacktiehsbdcs.com
CA:japan.youngpeyatech.info
CA:72.10.169.26:2293
CA:72.10.169.26:3938
135 pcap raw alerts
ruleset
other
578 lines
Yeah : 1.3
profile
none summary
tarball
28 of 30 2aa59ba425
[Firefox:43 hits: 06-30 to 06-19]
2aa59ba425 [1] ASM:Graph
ASPack| lines=10 trace
T:10:28:00 WinXP 66.19.187.96 (USLEC.NET):
USLEC CORP,
MIAMI, FLORIDA, US.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3208 hits: 12-31 to 07-16]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
10:29:00 WinXP 66.19.187.96 (USLEC.NET):
USLEC CORP,
MIAMI, FLORIDA, US.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3208 hits: 12-31 to 07-16]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:10:32:00 WinXP 66.53.81.155 (MDSG-PACWEST.COM):
PAC-WEST MANAGED MODEM NAS POOL,
PHOENIX, ARIZONA, US.
n/a   135 pcap raw alerts
ruleset
other
193 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 73f1082158
[Firefox:339 hits: 06-18 to 07-16]
73f1082158 [1] ASM:Graph
Armadillo| lines=81 trace
10:46:00 Win2K-f 218.168.156.230 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   445 pcap raw alerts
ruleset
shell
3 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:10:50:00 WinXP 67.212.107.205 (-):
.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 32a0d7d0e0
[Firefox:47 hits: 05-04 to 07-12]
d791762796 [0] ASM:Graph
tElock| lines=81
embedded dns
trace
T:10:56:00 WinXP 172.133.68.26 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:11:19:00 WinXP 67.11.1.181 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HOUSTON, TEXAS, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
[Firefox:46 hits: 12-14 to 07-16]
83893bd25d [0] ASM:Graph
none|none lines=65 trace
T:11:46:00 Win2K-f 75.77.50.83 (-):
.
n/a US:microsoft.com
US:download.microsoft.com
US:198.78.220.124:80
US:199.93.46.124:80
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
b5919931fe
[Firefox:131 hits: 06-20 to 07-16]
none[4]
a08f3b74a4[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
12:03:00 WinXP 77.101.110.216 (BLUEYONDER.CO.UK):
CABLEINET,
UK.
n/a HK:proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:192.221.99.126:80
US:199.93.41.126:80
HK:210.245.211.11:65520
US:4.23.60.125:80
135 pcap raw alerts
ruleset
other
116 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33
32 of 33
3e0057047b
NEW
dd11f9e8ab
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
13:21:00 Win2K-f 61.218.193.250 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:microsoft.com
US:download.microsoft.com
US:199.93.41.126:80
US:199.93.46.124:80
US:205.128.79.124:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
57ce4acac2
[Firefox:60 hits: 06-17 to 07-16]
none[4]
57ce4acac2[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:13:30:00 WinXP 80.161.53.122 (ADSL-DHCP.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
COPENHAGEN, COPENHAGEN, DK. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:25 hits: 05-12 to 07-13]
none[4] none:none
PolyEnE| none trace
13:31:00 WinXP 80.161.53.122 (ADSL-DHCP.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
COPENHAGEN, COPENHAGEN, DK. (DSL)
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 bce12aa21f
[Firefox:25 hits: 05-12 to 07-13]
none[4] none:none
PolyEnE| none trace
T:13:51:00 Win2K-f 211.21.186.122 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
67.43.236.98:10324 CA:xx.nadnadzz.info
CA:nadsam0.info
US:130.107.228.189:61726
135 pcap raw alerts
ruleset
irc
http
371 lines
Yeah : 1.8
profile
none summary
tarball
22 of 33
31 of 33
23 of 33
23 of 33
none
62848131e5
NEW
98cd9b1699
NEW
b44801de4f
NEW
ba05388a97
NEW
c5622bb285
[Firefox: 8 hits: 06-23 to 07-10]
none[none]
none [none]
none [none]
none [none]
none [4]
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
trace
14:08:00 WinXP 4.159.83.71 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
US. (DIAL)
n/a :www.google.com.au
US:www.altavista.com
:jbeegvia.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 17028f1eda
[Firefox:21 hits: 09-29 to 07-10]
none[3] none:none
tElock| none trace
T:14:21:00 WinXP 88.104.59.207 (AS9105.COM):
TISCALI UK LTD,
LIVERPOOL, ENGLAND, UK. (DSL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 277b6d3bba
NEW
none[none] none:none
none|none none none
14:27:00 WinXP 88.104.59.207 (AS9105.COM):
TISCALI UK LTD,
LIVERPOOL, ENGLAND, UK. (DSL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 277b6d3bba
NEW
none[none] none:none
none|none none none
T:14:37:00 WinXP 123.225.79.172 (OCN.NE.JP):
NTT COMMUNICATIONS CORPORATION,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:15:02:00 WinXP 66.57.180.53 (RR.COM):
ROAD RUNNER HOLDCO LLC,
COLUMBIA, SOUTH CAROLINA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.110.126:80
US:199.93.44.124:80
US:207.123.37.126:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
15:06:00 WinXP 122.146.81.26 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH. CO. LTD,
TW.
n/a   135 pcap raw alerts
ruleset
other
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:15:07:00 WinXP 92.114.188.133 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a HK:proxim.ircgalaxy.pl
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 33 366148f7b7
[Firefox: 7 hits: 07-06 to 07-16]
none[none] none:none
none|none none none
15:15:00 Win2K-f 208.5.149.94 (-):
AAFES/BARRACKS,
ELKHART, INDIANA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.149:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:15:18:00 WinXP 67.55.134.14 (WCCTA.NET):
WEBSTER CALHOUN TELEPHONE CO,
FT. DODGE, IOWA, US. (DSL)
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33 8e4e9c46a1
NEW
none[none] none:none
none|none none none
T:15:23:00 WinXP 4.225.234.175 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
4 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:15:24:00 WinXP 24.81.138.19 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
21 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
15:39:00 Win2K-f 80.104.22.205 (BUSINESS.TELECOMITALIA.IT):
TELECOM ITALIA S.P.A,
ROME, LAZIO, IT.
n/a   445 pcap raw alerts
ruleset
shell
ftp
22 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
15:45:00 WinXP 99.163.48.18 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
[Firefox:46 hits: 12-14 to 07-16]
83893bd25d [0] ASM:Graph
none|none lines=65 trace
T:15:50:00 WinXP 76.160.85.231 (CAVTEL.NET):
CAVALIER TELEPHONE,
US.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:3208 hits: 12-31 to 07-16]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:16:03:00 Win2K-f 12.72.210.236 (ATT.NET):
AT&T WORLDNET SERVICES,
PLEASANT HILL, CALIFORNIA, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
22 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:16:11:00 WinXP 207.68.254.212 (VISTA-EXPRESS.COM):
VISTA III MEDIA LLC,
OXFORD, MISSISSIPPI, US.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 8ae2cc2e80
[Firefox:62 hits: 05-06 to 07-09]
c24ca14cda [0] ASM:Graph
PolyEnE| lines=68 trace
T:16:14:00 WinXP 67.10.90.238 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HOUSTON, TEXAS, US. (100Mbps)
n/a US:microsoft.com
US:download.microsoft.com
US:199.93.41.124:80
US:206.33.45.125:80
US:207.123.47.126:80
135 pcap raw alerts
ruleset
other
87 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:16:20:00 WinXP 76.215.144.169 (SBCGLOBAL.NET):
PPPOX POOL - BRAS1.MTRYCA,
SALINAS, CALIFORNIA, US. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:16:32:00 WinXP 79.138.166.100 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 ea096a2bdf
NEW
none[none] none:none
none|none none none
T:16:49:00 WinXP 59.104.46.23 (SEED.NET.TW):
DIGITAL UNITED I,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a HK:proxim.ircgalaxy.pl
HK:210.245.211.11:65520
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33 8414083c68
NEW
none[none] none:none
none|none none none
16:53:00 Win2K-f 59.104.46.23 (SEED.NET.TW):
DIGITAL UNITED I,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a HK:proxim.ircgalaxy.pl
HK:210.245.211.11:65520
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 afbe7867fa
NEW
none[none] none:none
none|none none none
17:00:00 WinXP 217.201.68.74 (-):
TELECOM ITALIA MOBILE,
IT.
n/a HK:proxim.ircgalaxy.pl
HK:210.245.211.11:65520
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 9974f322de
NEW
none[none] none:none
none|none none none
T:17:06:00 WinXP 99.151.56.95 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
17:06:00 WinXP 99.151.56.95 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:17:21:00 WinXP 12.205.214.225 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CASPER, WYOMING, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a0139d7ad8
[Firefox:451 hits: 05-02 to 07-12]
d9e9662db1 [0] ASM:Graph
PolyEnE| lines=68 trace
17:29:00 Win2K-f 166.82.198.128 (CTC.NET):
CTC INTERNET SERVICES INC,
GREENSBORO, NORTH CAROLINA, US.
n/a   135 pcap raw alerts
ruleset
other
10 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:17:33:00 Win2K-f 71.114.92.144 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
WOODBRIDGE, VIRGINIA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.236:80
US:208.111.173.16:80
135 pcap raw alerts
ruleset
other
166 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:17:36:00 WinXP 12.74.20.195 (ATT.NET):
AT&T WORLDNET SERVICES,
SAN ANGELO, TEXAS, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:487 hits: 12-31 to 07-16]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:17:40:00 Win2K-f 68.147.207.232 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.236:80
US:208.111.173.16:80
135 pcap raw alerts
ruleset
http
111 lines
Yeah : 1.3
profile
none summary
tarball
29 of 33
31 of 33
5ba106150e
NEW
801e729de2
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
17:45:00 WinXP 76.184.131.15 (RR.COM):
ROAD RUNNER HOLDCO LLC,
DALLAS, TEXAS, US. (100Mbps)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:487 hits: 12-31 to 07-16]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:18:19:00 WinXP 61.218.192.234 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
KAOHSIUNG, KAO-HSIUNG, TW.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.215:80
US:208.111.153.231:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
57ce4acac2
[Firefox:60 hits: 06-17 to 07-16]
none[4]
57ce4acac2[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
18:20:00 WinXP 200.97.75.83 (VELOXZONE.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 c83fa9ee1f
NEW
none[none] none:none
none|none none none
T:18:29:00 WinXP 76.77.231.60 (MADISONTELCO.COM):
MADISON TELEPHONE COMPANY,
HAMEL, ILLINOIS, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
13 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:18:35:00 WinXP 200.77.197.221 (CABLERED.COM.MX):
TELECABLE DE JUAREZ SA DE CV,
TIJUANA, MEXICO, MX. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 33 fce9309509
[Firefox: 2 hits: 07-03 to 07-09]
none[none] none:none
none|none none none
T:19:10:00 WinXP 61.215.245.135 (CATVNET.NE.JP):
CATV NETWORK SERVICES(STNET INCROPORATE),
OSAKA, OSAKA, JP.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:19:15:00 WinXP 4.252.44.199 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
TAYLORS, SOUTH CAROLINA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:19:55:00 Win2K-f 61.196.38.47 (ODN.AD.JP):
OPEN DATA NETWORK(JAPAN TELECOM CO. LTD.),
HIROSHIMA, HIROSHIMA, JP. (DIAL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
19:57:00 WinXP 76.215.156.130 (SBCGLOBAL.NET):
PPPOX POOL - BRAS1.MTRYCA,
PLANO, TEXAS, US.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:703 hits: 07-11 to 07-16]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
20:13:00 Win2K-f 12.198.30.48 (-):
JOYCE MEDIA INC,
ACTON, CALIFORNIA, US. (100Mbps)
n/a US:microsoft.com
US:download.microsoft.com
US:205.128.66.124:80
US:207.123.37.126:80
US:4.23.60.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:20:15:00 Win2K-f 65.23.242.168 (PRTC.NET):
PUERTO RICO TELEPHONE COMPANY,
SAN JUAN, PUERTO RICO, PR.
n/a US:microsoft.com
US:download.microsoft.com
US:205.128.66.124:80
US:207.123.37.126:80
US:4.23.60.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
a08f3b74a4
[Firefox:225 hits: 06-18 to 07-16]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
20:42:00 Win2K-f 12.210.173.69 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
SALT LAKE CITY, UTAH, US.
n/a US:microsoft.com
US:download.microsoft.com
US:4.23.60.125:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
20:43:00 WinXP 75.63.211.99 (SBCGLOBAL.NET):
PPPOX POOL - BRAS3.HSTNTX,
DALLAS, TEXAS, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
52 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 73f1082158
[Firefox:339 hits: 06-18 to 07-16]
73f1082158 [1] ASM:Graph
Armadillo| lines=81 trace
T:21:04:00 WinXP 70.65.22.238 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RED DEER, ALBERTA, CA. (DSL)
n/a HK:proxim.ircgalaxy.pl
RU:moscow-advokat.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
33 of 33 2b402a57aa
NEW
none[none] none:none
none|none none none
T:21:25:00 WinXP 220.219.36.238 (INFOWEB.NE.JP):
INFOWEB(FUJITSU LTD.),
TOKYO, TOKYO, JP. (DIAL)
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
21:28:00 WinXP 200.177.48.152 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:160 hits: 09-28 to 07-15]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
21:29:00 Win2K-f 12.74.176.218 (ATT.NET):
AT&T WORLDNET SERVICES,
CHOCTAW, OKLAHOMA, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
21:32:00 WinXP 118.1.92.143 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:160 hits: 09-28 to 07-15]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
21:36:00 Win2K-f 64.181.117.26 (AUSTINCPAAC.COM):
FIBERNET OF WEST VIRGINIA,
CHARLESTON, WEST VIRGINIA, US. (100Mbps)
n/a US:microsoft.com
US:download.microsoft.com
US:8.12.202.125:80
135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
b7082104e4
[Firefox:49 hits: 06-18 to 07-16]
none[4]
none [4]
none:none
none:none
tElock|
tElock|
none
none
trace
trace
21:42:00 Win2K-f 118.160.185.206 (-):
.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
22:01:00 Win2K-f 117.197.244.241 (-):
.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
22:13:00 WinXP 98.134.166.30 (-):
.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
22:24:00 WinXP 12.74.54.120 (ATT.NET):
AT&T WORLDNET SERVICES,
LOUISVILLE, KENTUCKY, US. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
22:32:00 Win2K-f 24.78.91.87 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.110.125:80
US:199.93.46.125:80
US:204.160.126.126:80
135 pcap raw alerts
ruleset
other
203 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
31 of 33
99c1c370c4
[Firefox: 2 hits: 07-09 to 07-16]
ac59067d9b
[Firefox: 2 hits: 07-09 to 07-16]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:22:45:00 Win2K-f 61.193.13.115 (MESH.AD.JP):
NEC CORPORATION,
JP.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:22:46:00 Win2K-f 210.199.90.189 (FLETS-I-AS-EAST-1-10.DSN.JP):
DS NETWORKS CO,
JP.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:22:56:00 Win2K-f 70.74.65.221 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
DAWSON CREEK, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
b5919931fe
[Firefox:131 hits: 06-20 to 07-16]
none[4]
73f1082158[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
23:22:00 Win2K-f 218.165.83.38 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAINAN, KAO-HSIUNG, TW.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:23:26:00 WinXP 222.15.161.46 (DION.NE.JP):
DION (KDDI CORPORATION),
JP.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:160 hits: 09-28 to 07-15]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:23:36:00 Win2K-f 118.19.106.188 (-):
.
n/a  
CZ:217.170.244.2:443
CZ:82.114.64.251:443
445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
25 of 28 7fdfe363d5
[Firefox:2945 hits: 12-31 to 07-16]
10862ea8b8 [0] ASM:Graph
FSG| lines=1933
embedded dns
trace
T:23:37:00 WinXP 218.160.61.213 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAOYUAN, T'AI-WAN, TW.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:304 hits: 05-03 to 07-13]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
T:23:47:00 Win2K-f 218.211.147.90 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH. CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.215:80
US:208.111.153.231:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:702 hits: 06-17 to 07-16]
73f1082158
[Firefox:339 hits: 06-18 to 07-16]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace