Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:05:00 | Win2K-f | 117.197.243.83 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:00:08:00 | Win2K-f | 117.197.243.83 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
00:11:00 | WinXP | 12.72.54.151 (ATT.NET): AT&T WORLDNET SERVICES, SALINAS, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:00:15:00 | WinXP | 218.164.134.50 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, KAOHSIUNG, KAO-HSIUNG, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 33 | 2b8c0ae381 NEW |
none[none] | none:none |
none|none | none | none | |
T:00:15:00 | Win2K-f | 172.131.106.129 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.126:80 |
135 | pcap | raw alerts ruleset |
http 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 29 of 33 |
3373948767 [Firefox: 6 hits: 07-03 to 07-11] c73f738c30 [Firefox: 6 hits: 07-03 to 07-11] |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
00:40:00 | Win2K-f | 4.229.15.152 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MONROE, MICHIGAN, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:00:00 | WinXP | 66.54.122.118 (DIGICELBROADBAND.COM): DIGICEL JAMAICA, KINGSTON, KINGSTON, JM. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 US:205.128.79.124:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:01:09:00 | WinXP | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.124:80 US:205.128.66.124:80 US:205.128.79.124:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
01:17:00 | WinXP | 76.245.96.234 (PACBELL.NET): AT&T INTERNET SERVICES, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:01:47:00 | WinXP | 61.221.250.18 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 57ce4acac2 [Firefox:60 hits: 06-17 to 07-16] e07c29c4ae [Firefox:102 hits: 06-19 to 07-16] |
none[4] 57ce4acac2[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| FSG| |
none lines=81 lines=92 |
trace trace trace |
01:48:00 | WinXP | 71.131.139.234 (-): VALLEY FOOD INC, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.15:80 US:69.28.178.10:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:02:26:00 | Win2K-f | 71.112.133.23 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BOTHELL, WASHINGTON, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.54:80 US:208.111.148.69:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
02:27:00 | Win2K-f | 196.208.65.239 (TELKOM-IPNET.CO.ZA): AFRINIC, JOHANNESBURG, GAUTENG, ZA. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.54:80 US:208.111.148.69:80 |
135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
02:37:00 | WinXP | 122.43.67.25 (-): POWERCOMM, KR. |
n/a | HK:proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:208.111.153.215:80 US:208.111.153.231:80 HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
24 of 33 32 of 33 |
8a93930ea8 [Firefox: 7 hits: 07-06 to 07-14] bc94f66052 [Firefox: 7 hits: 07-06 to 07-14] |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:02:43:00 | WinXP | 122.30.180.141 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:160 hits: 09-28 to 07-15] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:02:43:00 | WinXP | 211.187.177.98 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | HK:proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:208.111.153.231:80 HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
http 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 0 of 33 0 of 33 |
168aab35a3 [Firefox:56 hits: 06-17 to 07-16] 4c3df24b32 [Firefox:92 hits: 06-17 to 07-16] e07c29c4ae [Firefox:102 hits: 06-19 to 07-16] |
none[4] 4c3df24b32[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| FSG| |
none lines=81 lines=92 |
trace trace trace |
T:03:03:00 | Win2K-f | 211.59.72.105 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | HK:proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
http 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 30 of 32 |
4c3df24b32 [Firefox:92 hits: 06-17 to 07-16] 8390780c27 [Firefox:19 hits: 06-18 to 07-15] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
03:03:00 | Win2K-f | 64.31.234.18 (AIRMAIL.NET): INTERNET AMERICA INC, HOUSTON, TEXAS, US. |
n/a | US:microsoft.com US:download.microsoft.com US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:03:04:00 | WinXP | 85.181.110.201 (ALICEDSL.DE): HANSENET-ADSL, MUNICH, BAYERN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:487 hits: 12-31 to 07-16] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
03:39:00 | WinXP | 124.86.37.179 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:03:43:00 | WinXP | 222.15.161.123 (DION.NE.JP): DION (KDDI CORPORATION), JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:160 hits: 09-28 to 07-15] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:04:09:00 | Win2K-f | 124.84.110.87 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell 5 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:20:00 | WinXP | 125.224.101.235 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:04:31:00 | Win2K-f | 122.52.78.8 (PLDT.NET): IPG, PH. |
n/a | US:microsoft.com US:download.microsoft.com HK:proxim.ircgalaxy.pl US:208.111.153.236:80 HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
other 129 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 33 of 33 |
16874933ea [Firefox:18 hits: 06-18 to 07-15] 76ee340669 [Firefox:18 hits: 06-18 to 07-15] |
16874933ea [1] none [4] |
ASM:Graph none:none |
Armadillo| PolyEnE| |
lines=82 none |
trace trace |
T:04:36:00 | WinXP | 75.14.253.81 (-): REFAT M HIJAZ DBA, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.153.236:80 US:208.111.173.16:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
04:40:00 | WinXP | 204.116.68.142 (INFOAVE.NET): INFO AVENUE INTERNET SERVICES LLC, MT. AIRY, NORTH CAROLINA, US. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 33 | 573d7d0455 NEW |
none[none] | none:none |
none|none | none | none |
T:04:40:00 | WinXP | 204.116.68.142 (INFOAVE.NET): INFO AVENUE INTERNET SERVICES LLC, MT. AIRY, NORTH CAROLINA, US. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 33 | 573d7d0455 NEW |
none[none] | none:none |
none|none | none | none |
T:04:40:00 | WinXP | 92.227.176.250 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | HK:proxim.ircgalaxy.pl RU:moscow-advokat.ru RU:194.6.222.11:6667 HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 33 | 8178c88f5e [Firefox: 7 hits: 07-08 to 07-16] |
none[none] | none:none |
none|none | none | none |
T:04:54:00 | WinXP | 124.86.37.179 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
05:21:00 | WinXP | 71.118.237.30 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LONG BEACH, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.46.125:80 US:205.128.66.126:80 US:205.128.79.125:80 |
135 | pcap | raw alerts ruleset |
other 181 lines |
Yeah : 1.3 profile |
none | summary tarball |
24 of 33 31 of 33 |
5f11b319ef [Firefox: 4 hits: 07-07 to 07-15] a3f631e410 [Firefox: 4 hits: 07-07 to 07-15] |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:05:28:00 | WinXP | 4.131.49.96 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:05:48:00 | WinXP | 72.190.119.113 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.46.125:80 US:207.123.46.125:80 US:207.123.46.126:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
06:13:00 | WinXP | 220.209.202.175 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:20:00 | WinXP | 58.89.94.123 (PLALA.OR.JP): PLALA NETWORKS INC, JP. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
06:26:00 | Win2K-f | 220.143.5.49 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | b5c46c6fb0 NEW |
none[none] | none:none |
none|none | none | none |
T:06:29:00 | WinXP | 212.27.7.11 (-): MLIFENET, RU. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | ea096a2bdf NEW |
none[none] | none:none |
none|none | none | none |
06:38:00 | WinXP | 122.52.78.8 (PLDT.NET): IPG, PH. |
n/a | US:microsoft.com US:download.microsoft.com HK:proxim.ircgalaxy.pl US:199.93.41.126:80 US:199.93.44.126:80 US:199.93.46.125:80 HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
other 126 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 33 of 33 |
16874933ea [Firefox:18 hits: 06-18 to 07-15] 76ee340669 [Firefox:18 hits: 06-18 to 07-15] |
16874933ea [1] none [4] |
ASM:Graph none:none |
Armadillo| PolyEnE| |
lines=82 none |
trace trace |
T:06:47:00 | WinXP | 83.97.206.205 (CM-83-97-128-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | HK:proxim.ircgalaxy.pl RU:moscow-advokat.ru HK:210.245.211.11:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | 965c2ca7e5 [Firefox: 2 hits: 07-10 to 07-11] |
none[none] | none:none |
none|none | none | none |
T:06:50:00 | Win2K-f | 203.118.233.183 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, KAO-HSIUNG, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:57:00 | WinXP | 190.18.21.191 (-): . |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1420 hits: 12-31 to 07-16] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
06:58:00 | WinXP | 60.35.82.252 (PLALA.OR.JP): PLALA NETWORKS INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:160 hits: 09-28 to 07-15] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:07:02:00 | Win2K-f | 122.130.154.248 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:07:04:00 | WinXP | 79.138.162.222 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | ea096a2bdf NEW |
none[none] | none:none |
none|none | none | none | |
07:13:00 | Win2K-f | 125.0.88.200 (INFOWEB.NE.JP): FUJITSU LIMITED, TOKYO, TOKYO, JP. (DIAL) |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | dfcd73f7a7 [Firefox: 7 hits: 07-03 to 07-16] |
none[none] | none:none |
none|none | none | none |
T:07:18:00 | WinXP | 68.127.39.118 (PACBELL.NET): PPPOX POOL - RBACK4.IRVNCA, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.124:80 US:207.123.44.126:80 US:207.123.47.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
07:52:00 | WinXP | 63.17.144.0 (UU.NET): UUNET TECHNOLOGIES INC, NEW YORK, NEW YORK, US. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.219:80 US:208.111.148.226:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:07:54:00 | Win2K-f | 122.120.99.85 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
08:03:00 | Win2K-f | 76.226.185.92 (-): PPPOX SE4.SFLDMI, PLANO, TEXAS, US. |
n/a | US:microsoft.com US:download.microsoft.com HK:proxim.ircgalaxy.pl US:208.111.148.108:80 US:208.111.148.115:80 HK:210.245.211.11:65520 CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:08:16:00 | Win2K-f | 12.76.221.118 (ATT.NET): AT&T WORLDNET SERVICES, WILMINGTON, NORTH CAROLINA, US. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
08:24:00 | WinXP | 86.150.134.37 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3208 hits: 12-31 to 07-16] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
08:25:00 | WinXP | 218.162.119.83 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. (DSL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:08:32:00 | Win2K-f | 222.159.233.32 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:08:45:00 | WinXP | 118.166.239.175 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
08:45:00 | WinXP | 220.131.140.17 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, T'AI-CHUNG, T'AI-WAN, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
08:49:00 | Win2K-f | 218.168.76.56 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 | 511dcda8ce NEW |
none[none] | none:none |
none|none | none | none |
T:09:30:00 | Win2K-f | 217.201.210.172 (-): TELECOM ITALIA MOBILE, IT. |
217.170.244.2:443 | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:09:31:00 | Win2K-f | 61.229.53.90 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
217.170.244.2:443 | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:09:54:00 | WinXP | 58.236.112.187 (-): THRUNET-INFRA-INCHEON09, SEOUL, KYONGGI-DO, KR. |
69.64.51.132:6789 | US:ice.novi-pazar.biz NL:83.117.217.0:5800 NL:83.117.217.10:5800 NL:83.117.217.11:5800 NL:83.117.217.12:5800 NL:83.117.217.13:5800 NL:83.117.217.14:5800 NL:83.117.217.15:5800 NL:83.117.217.16:5800 NL:83.117.217.17:5800 NL:83.117.217.18:5800 NL:83.117.217.19:5800 NL:83.117.217.1:5800 NL:83.117.217.2:5800 NL:83.117.217.3:5800 NL:83.117.217.4:5800 NL:83.117.217.5:5800 NL:83.117.217.6:5800 NL:83.117.217.7:5800 NL:83.117.217.8:5800 NL:83.117.217.9:5800 |
139 | pcap | raw alerts ruleset |
shell http ftp irc 20 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 32 | 588b7eb87d NEW |
none[none] | none:none |
none|none | none | none |
T:09:55:00 | Win2K-f | 210.205.33.79 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
shell http ftp 8 lines |
Yeah : 1.3 profile |
none | summary tarball |
24 of 33 | 063528c808 NEW |
none[none] | none:none |
none|none | none | none | |
T:09:56:00 | WinXP | 70.45.133.235 (ONELINKPR.NET): SAN JUAN CABLE LLC, SAN JUAN, PUERTO RICO, PR. |
194.54.90.246:80 | HK:proxim.ircgalaxy.pl UA:citi-bank.ru HK:210.245.211.11:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 7ef46e4e16 [Firefox:13 hits: 11-28 to 05-06] |
ef2e743fd2 [0] | ASM:Graph |
PolyEnE| | lines=74 | trace |
09:56:00 | WinXP | 70.45.133.235 (ONELINKPR.NET): SAN JUAN CABLE LLC, SAN JUAN, PUERTO RICO, PR. |
n/a | HK:proxim.ircgalaxy.pl UA:citi-bank.ru HK:210.245.211.11:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 7ef46e4e16 [Firefox:13 hits: 11-28 to 05-06] |
ef2e743fd2 [0] | ASM:Graph |
PolyEnE| | lines=74 | trace |
T:09:59:00 | WinXP | 58.238.222.188 (-): THRUNET-INFRA-BUSAN17, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
shell http ftp 6 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | 1fe9468d89 NEW |
none[none] | none:none |
none|none | none | none | |
10:00:00 | WinXP | 58.238.222.188 (-): THRUNET-INFRA-BUSAN17, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
shell http ftp 6 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | 1fe9468d89 NEW |
none[none] | none:none |
none|none | none | none | |
10:17:00 | WinXP | 66.53.81.155 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, PHOENIX, ARIZONA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.149:80 US:208.111.148.152:80 |
135 | pcap | raw alerts ruleset |
other 127 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
10:22:00 | Win2K-f | 24.87.144.100 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | :preek.oihduhdd.net CA:dong.nagitiriheiwu.net CA:done.blacktiehsbdcs.com CA:japan.youngpeyatech.info CA:72.10.169.26:2293 CA:72.10.169.26:3938 |
135 | pcap | raw alerts ruleset |
other 578 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 30 | 2aa59ba425 [Firefox:43 hits: 06-30 to 06-19] |
2aa59ba425 [1] | ASM:Graph |
ASPack| | lines=10 | trace |
T:10:28:00 | WinXP | 66.19.187.96 (USLEC.NET): USLEC CORP, MIAMI, FLORIDA, US. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3208 hits: 12-31 to 07-16] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
10:29:00 | WinXP | 66.19.187.96 (USLEC.NET): USLEC CORP, MIAMI, FLORIDA, US. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3208 hits: 12-31 to 07-16] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:10:32:00 | WinXP | 66.53.81.155 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, PHOENIX, ARIZONA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 193 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
73f1082158 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
10:46:00 | Win2K-f | 218.168.156.230 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:50:00 | WinXP | 67.212.107.205 (-): . |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 32a0d7d0e0 [Firefox:47 hits: 05-04 to 07-12] |
d791762796 [0] | ASM:Graph |
tElock| | lines=81 embedded dns |
trace |
T:10:56:00 | WinXP | 172.133.68.26 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:19:00 | WinXP | 67.11.1.181 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b [Firefox:46 hits: 12-14 to 07-16] |
83893bd25d [0] | ASM:Graph |
none|none | lines=65 | trace | |
T:11:46:00 | Win2K-f | 75.77.50.83 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.124:80 US:199.93.46.124:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] b5919931fe [Firefox:131 hits: 06-20 to 07-16] |
none[4] a08f3b74a4[1] b5919931fe[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| ASProtect| |
none lines=81 lines=90 |
trace trace trace |
12:03:00 | WinXP | 77.101.110.216 (BLUEYONDER.CO.UK): CABLEINET, UK. |
n/a | HK:proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 US:199.93.41.126:80 HK:210.245.211.11:65520 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 32 of 33 |
3e0057047b NEW dd11f9e8ab NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
13:21:00 | Win2K-f | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.126:80 US:199.93.46.124:80 US:205.128.79.124:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 57ce4acac2 [Firefox:60 hits: 06-17 to 07-16] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:13:30:00 | WinXP | 80.161.53.122 (ADSL-DHCP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, COPENHAGEN, COPENHAGEN, DK. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:25 hits: 05-12 to 07-13] |
none[4] | none:none |
PolyEnE| | none | trace |
13:31:00 | WinXP | 80.161.53.122 (ADSL-DHCP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, COPENHAGEN, COPENHAGEN, DK. (DSL) |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:25 hits: 05-12 to 07-13] |
none[4] | none:none |
PolyEnE| | none | trace |
T:13:51:00 | Win2K-f | 211.21.186.122 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
67.43.236.98:10324 | CA:xx.nadnadzz.info CA:nadsam0.info US:130.107.228.189:61726 |
135 | pcap | raw alerts ruleset |
irc http 371 lines |
Yeah : 1.8 profile |
none | summary tarball |
22 of 33 31 of 33 23 of 33 23 of 33 none |
62848131e5 NEW 98cd9b1699 NEW b44801de4f NEW ba05388a97 NEW c5622bb285 [Firefox: 8 hits: 06-23 to 07-10] |
none[none] none [none] none [none] none [none] none [4] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none trace |
14:08:00 | WinXP | 4.159.83.71 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | :www.google.com.au US:www.altavista.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda [Firefox:21 hits: 09-29 to 07-10] |
none[3] | none:none |
tElock| | none | trace |
T:14:21:00 | WinXP | 88.104.59.207 (AS9105.COM): TISCALI UK LTD, LIVERPOOL, ENGLAND, UK. (DSL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 277b6d3bba NEW |
none[none] | none:none |
none|none | none | none |
14:27:00 | WinXP | 88.104.59.207 (AS9105.COM): TISCALI UK LTD, LIVERPOOL, ENGLAND, UK. (DSL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 277b6d3bba NEW |
none[none] | none:none |
none|none | none | none |
T:14:37:00 | WinXP | 123.225.79.172 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:15:02:00 | WinXP | 66.57.180.53 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBIA, SOUTH CAROLINA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:199.93.44.124:80 US:207.123.37.126:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
15:06:00 | WinXP | 122.146.81.26 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:07:00 | WinXP | 92.114.188.133 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | 366148f7b7 [Firefox: 7 hits: 07-06 to 07-16] |
none[none] | none:none |
none|none | none | none |
15:15:00 | Win2K-f | 208.5.149.94 (-): AAFES/BARRACKS, ELKHART, INDIANA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.149:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:15:18:00 | WinXP | 67.55.134.14 (WCCTA.NET): WEBSTER CALHOUN TELEPHONE CO, FT. DODGE, IOWA, US. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | 8e4e9c46a1 NEW |
none[none] | none:none |
none|none | none | none |
T:15:23:00 | WinXP | 4.225.234.175 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:24:00 | WinXP | 24.81.138.19 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:39:00 | Win2K-f | 80.104.22.205 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA S.P.A, ROME, LAZIO, IT. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
15:45:00 | WinXP | 99.163.48.18 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b [Firefox:46 hits: 12-14 to 07-16] |
83893bd25d [0] | ASM:Graph |
none|none | lines=65 | trace | |
T:15:50:00 | WinXP | 76.160.85.231 (CAVTEL.NET): CAVALIER TELEPHONE, US. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3208 hits: 12-31 to 07-16] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:03:00 | Win2K-f | 12.72.210.236 (ATT.NET): AT&T WORLDNET SERVICES, PLEASANT HILL, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:11:00 | WinXP | 207.68.254.212 (VISTA-EXPRESS.COM): VISTA III MEDIA LLC, OXFORD, MISSISSIPPI, US. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 8ae2cc2e80 [Firefox:62 hits: 05-06 to 07-09] |
c24ca14cda [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:14:00 | WinXP | 67.10.90.238 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:206.33.45.125:80 US:207.123.47.126:80 |
135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:16:20:00 | WinXP | 76.215.144.169 (SBCGLOBAL.NET): PPPOX POOL - BRAS1.MTRYCA, SALINAS, CALIFORNIA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:16:32:00 | WinXP | 79.138.166.100 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | ea096a2bdf NEW |
none[none] | none:none |
none|none | none | none |
T:16:49:00 | WinXP | 59.104.46.23 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | 8414083c68 NEW |
none[none] | none:none |
none|none | none | none |
16:53:00 | Win2K-f | 59.104.46.23 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | afbe7867fa NEW |
none[none] | none:none |
none|none | none | none |
17:00:00 | WinXP | 217.201.68.74 (-): TELECOM ITALIA MOBILE, IT. |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 9974f322de NEW |
none[none] | none:none |
none|none | none | none |
T:17:06:00 | WinXP | 99.151.56.95 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
17:06:00 | WinXP | 99.151.56.95 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:17:21:00 | WinXP | 12.205.214.225 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CASPER, WYOMING, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 [Firefox:451 hits: 05-02 to 07-12] |
d9e9662db1 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
17:29:00 | Win2K-f | 166.82.198.128 (CTC.NET): CTC INTERNET SERVICES INC, GREENSBORO, NORTH CAROLINA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:33:00 | Win2K-f | 71.114.92.144 (VERIZON.NET): VERIZON INTERNET SERVICES INC, WOODBRIDGE, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.153.236:80 US:208.111.173.16:80 |
135 | pcap | raw alerts ruleset |
other 166 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:17:36:00 | WinXP | 12.74.20.195 (ATT.NET): AT&T WORLDNET SERVICES, SAN ANGELO, TEXAS, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:487 hits: 12-31 to 07-16] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:17:40:00 | Win2K-f | 68.147.207.232 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.153.236:80 US:208.111.173.16:80 |
135 | pcap | raw alerts ruleset |
http 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 31 of 33 |
5ba106150e NEW 801e729de2 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
17:45:00 | WinXP | 76.184.131.15 (RR.COM): ROAD RUNNER HOLDCO LLC, DALLAS, TEXAS, US. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:487 hits: 12-31 to 07-16] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:18:19:00 | WinXP | 61.218.192.234 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, KAOHSIUNG, KAO-HSIUNG, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.153.215:80 US:208.111.153.231:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 57ce4acac2 [Firefox:60 hits: 06-17 to 07-16] |
none[4] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
18:20:00 | WinXP | 200.97.75.83 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | c83fa9ee1f NEW |
none[none] | none:none |
none|none | none | none |
T:18:29:00 | WinXP | 76.77.231.60 (MADISONTELCO.COM): MADISON TELEPHONE COMPANY, HAMEL, ILLINOIS, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
T:18:35:00 | WinXP | 200.77.197.221 (CABLERED.COM.MX): TELECABLE DE JUAREZ SA DE CV, TIJUANA, MEXICO, MX. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
30 of 33 | fce9309509 [Firefox: 2 hits: 07-03 to 07-09] |
none[none] | none:none |
none|none | none | none |
T:19:10:00 | WinXP | 61.215.245.135 (CATVNET.NE.JP): CATV NETWORK SERVICES(STNET INCROPORATE), OSAKA, OSAKA, JP. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:15:00 | WinXP | 4.252.44.199 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, TAYLORS, SOUTH CAROLINA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:55:00 | Win2K-f | 61.196.38.47 (ODN.AD.JP): OPEN DATA NETWORK(JAPAN TELECOM CO. LTD.), HIROSHIMA, HIROSHIMA, JP. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
19:57:00 | WinXP | 76.215.156.130 (SBCGLOBAL.NET): PPPOX POOL - BRAS1.MTRYCA, PLANO, TEXAS, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:703 hits: 07-11 to 07-16] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
20:13:00 | Win2K-f | 12.198.30.48 (-): JOYCE MEDIA INC, ACTON, CALIFORNIA, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.66.124:80 US:207.123.37.126:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:20:15:00 | Win2K-f | 65.23.242.168 (PRTC.NET): PUERTO RICO TELEPHONE COMPANY, SAN JUAN, PUERTO RICO, PR. |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.66.124:80 US:207.123.37.126:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] a08f3b74a4 [Firefox:225 hits: 06-18 to 07-16] |
none[4] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
20:42:00 | Win2K-f | 12.210.173.69 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SALT LAKE CITY, UTAH, US. |
n/a | US:microsoft.com US:download.microsoft.com US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
20:43:00 | WinXP | 75.63.211.99 (SBCGLOBAL.NET): PPPOX POOL - BRAS3.HSTNTX, DALLAS, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 52 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
73f1082158 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
T:21:04:00 | WinXP | 70.65.22.238 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, RED DEER, ALBERTA, CA. (DSL) |
n/a | HK:proxim.ircgalaxy.pl RU:moscow-advokat.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
33 of 33 | 2b402a57aa NEW |
none[none] | none:none |
none|none | none | none |
T:21:25:00 | WinXP | 220.219.36.238 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
21:28:00 | WinXP | 200.177.48.152 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:160 hits: 09-28 to 07-15] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
21:29:00 | Win2K-f | 12.74.176.218 (ATT.NET): AT&T WORLDNET SERVICES, CHOCTAW, OKLAHOMA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:32:00 | WinXP | 118.1.92.143 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:160 hits: 09-28 to 07-15] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
21:36:00 | Win2K-f | 64.181.117.26 (AUSTINCPAAC.COM): FIBERNET OF WEST VIRGINIA, CHARLESTON, WEST VIRGINIA, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] b7082104e4 [Firefox:49 hits: 06-18 to 07-16] |
none[4] none [4] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
21:42:00 | Win2K-f | 118.160.185.206 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
22:01:00 | Win2K-f | 117.197.244.241 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
22:13:00 | WinXP | 98.134.166.30 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
22:24:00 | WinXP | 12.74.54.120 (ATT.NET): AT&T WORLDNET SERVICES, LOUISVILLE, KENTUCKY, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:32:00 | Win2K-f | 24.78.91.87 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.125:80 US:199.93.46.125:80 US:204.160.126.126:80 |
135 | pcap | raw alerts ruleset |
other 203 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 31 of 33 |
99c1c370c4 [Firefox: 2 hits: 07-09 to 07-16] ac59067d9b [Firefox: 2 hits: 07-09 to 07-16] |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:45:00 | Win2K-f | 61.193.13.115 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:22:46:00 | Win2K-f | 210.199.90.189 (FLETS-I-AS-EAST-1-10.DSN.JP): DS NETWORKS CO, JP. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
T:22:56:00 | Win2K-f | 70.74.65.221 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, DAWSON CREEK, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] b5919931fe [Firefox:131 hits: 06-20 to 07-16] |
none[4] 73f1082158[1] b5919931fe[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| ASProtect| |
none lines=81 lines=90 |
trace trace trace |
23:22:00 | Win2K-f | 218.165.83.38 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAINAN, KAO-HSIUNG, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:23:26:00 | WinXP | 222.15.161.46 (DION.NE.JP): DION (KDDI CORPORATION), JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:160 hits: 09-28 to 07-15] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
T:23:36:00 | Win2K-f | 118.19.106.188 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2945 hits: 12-31 to 07-16] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
T:23:37:00 | WinXP | 218.160.61.213 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAOYUAN, T'AI-WAN, TW. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d [Firefox:304 hits: 05-03 to 07-13] |
8a00217866 [0] | ASM:Graph |
PolyEnE| | lines=57 | trace |
T:23:47:00 | Win2K-f | 218.211.147.90 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.153.215:80 US:208.111.153.231:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:702 hits: 06-17 to 07-16] 73f1082158 [Firefox:339 hits: 06-18 to 07-16] |
none[4] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |