Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

20 September 2008
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:09:00 Win2K-f 61.34.136.38 (BORA.NET):
DACOM CORP,
SEOUL, KYONGGI-DO, KR.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
73f1082158[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
00:21:00 Win2K-f 64.90.218.95 (AIRADVANTAGE.NET):
AIR ADVANTAGE,
SEBEWAING, MICHIGAN, US.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.108.126:80
US:204.160.104.126:80
US:207.123.37.124:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
57ce4acac2
[Firefox:189 hits: 06-17 to 09-19]
none[4]
57ce4acac2[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:00:32:00 Win2K-f 98.175.153.16 (-):
.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.108.126:80
US:207.123.42.126:80
US:209.84.20.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
00:39:00 WinXP 71.113.77.184 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LYNNWOOD, WASHINGTON, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.43:80
US:208.111.148.54:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:00:51:00 WinXP 221.171.49.149 (MESH.AD.JP):
BIGLOBE-CIDR-BLK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
33 of 36 1f653ddb7f
NEW
none[none] none:none
none|none none none
01:00:00 WinXP 82.7.58.218 (NTL.COM):
NTL INFRASTRUCTURE - WALTHAM PARK,
UK. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
36 of 36 b7a2b9be2a
NEW
none[none] none:none
none|none none none
T:01:15:00 Win2K-f 118.83.151.130 (-):
.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
111 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
29 of 33
627731ae2b
[Firefox: 2 hits: 07-02 to 08-09]
9db7aea9c0
[Firefox: 2 hits: 07-02 to 08-09]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
01:24:00 WinXP 114.121.114.141 (-):
.
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
01:27:00 Win2K-f 24.234.205.170 (COX.NET):
COX COMMUNICATIONS INC,
LAS VEGAS, NEVADA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:207.123.42.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:01:33:00 Win2K-f 68.150.135.235 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
LEDUC, ALBERTA, CA. (DSL)
n/a :proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:199.93.44.126:80
US:205.128.73.126:80
US:207.123.46.125:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
113 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36
32 of 36
5339bd7cdf
NEW
f89b0fbb86
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
01:35:00 Win2K-f 71.101.205.90 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
PALMETTO, FLORIDA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:205.128.73.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:01:37:00 WinXP 88.162.163.32 (PROXAD.NET):
PROXAD / FREE SAS,
FR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:01:47:00 WinXP 76.174.68.4 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CHINO HILLS, CALIFORNIA, US.
n/a   445 pcap raw alerts
ruleset
shell
shell
shell
ftp
20 lines
Yeah : 0.8
profile
none summary
tarball
35 of 36 278f5bd23c
NEW
none[none] none:none
none|none none none
02:09:00 Win2K-f 60.249.242.178 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
US:204.160.104.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
57ce4acac2
[Firefox:189 hits: 06-17 to 09-19]
none[4]
57ce4acac2[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
02:11:00 WinXP 218.211.222.69 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH CO. LTD,
KAOHSIUNG, KAO-HSIUNG, TW.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.99.124:80
US:204.160.104.126:80
US:207.123.42.126:80
135 pcap raw alerts
ruleset
other
87 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:02:28:00 WinXP 190.246.50.48 (-):
.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:02:46:00 WinXP 117.99.58.94 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:02:50:00 WinXP 121.254.118.51 (TCOL.COM.TW):
MONAD DIGITNAMIC CORP,
TW.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:03:49:00 WinXP 60.249.198.98 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.108.126:80
US:204.160.104.126:80
US:207.123.42.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
57ce4acac2
[Firefox:189 hits: 06-17 to 09-19]
none[4]
57ce4acac2[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
04:16:00 WinXP 117.99.2.39 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 a9cfbd1b0c
[Firefox: 5 hits: 09-12 to 09-15]
none[none] none:none
none|none none none
T:04:27:00 WinXP 78.34.16.112 (NETCOLOGNE.DE):
NETCOLOGNE GMBH,
KOELN, NORDRHEIN-WESTFALEN, DE.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 f353d4eed9
[Firefox: 3 hits: 09-17 to 09-18]
none[none] none:none
none|none none none
04:44:00 WinXP 58.188.134.173 (EONET.NE.JP):
K-OPTICOM CORPORATION,
OSAKA, OSAKA, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
[Firefox:547 hits: 01-01 to 09-19]
eb7546c600 [0] ASM:Graph
none|none lines=61 trace
T:04:54:00 WinXP 117.99.47.49 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 33 7f6ea12654
[Firefox:21 hits: 07-13 to 08-30]
none[none] none:none
none|none none none
05:27:00 Win2K-f 219.250.172.79 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a US:microsoft.com
:proxim.ircgalaxy.pl
US:download.microsoft.com
US:204.160.126.124:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
http
114 lines
Yeah : 1.3
profile
none summary
tarball
29 of 32
28 of 32
8a75955033
[Firefox:32 hits: 06-20 to 09-18]
9276c8b36b
[Firefox:32 hits: 06-20 to 09-18]
none[4]
9276c8b36b[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
05:35:00 WinXP 220.215.239.211 (CATV02.ITSCOM.JP):
ITS COMMUNICATIONS INC,
JP.
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:375 hits: 01-05 to 09-19]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:05:43:00 WinXP 92.40.120.215 (IKBCC.COM):
EU-ZZ,
UK.
n/a :proxim.ircgalaxy.pl
DE:siliconfireware.ru
DE:ebookfinaltrash.ru
DE:212.227.111.29:80
DE:217.11.54.126:80
EU:78.47.200.154:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 b4438fd66a
NEW
none[none] none:none
none|none none none
T:05:47:00 Win2K-f 124.195.205.161 (-):
.
n/a US:microsoft.com
US:download.microsoft.com
US:205.128.73.126:80
US:8.12.222.126:80
135 pcap raw alerts
ruleset
http
77 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
a08f3b74a4[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
05:50:00 Win2K-f 116.127.164.194 (-):
HANARO TELECOM,
SEOUL, KYONGGI-DO, KR.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
100 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
31 of 33
0 of 32
776985f561
[Firefox:13 hits: 06-24 to 09-19]
8ec6129efe
[Firefox:13 hits: 06-24 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
776985f561 [1]
none [4]
b5919931fe[1]
ASM:Graph
none:none
ASM:Graph
Armadillo|
tElock|
ASProtect|
lines=82
none
lines=90
trace
trace
trace
T:06:06:00 WinXP 92.41.0.150 (IKBCC.COM):
EU-ZZ,
UK.
n/a :proxim.ircgalaxy.pl 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
30 of 32 a0e6bec09f
NEW
none[4] none:none
PolyEnE| none trace
06:15:00 Win2K-f 74.214.47.11 (METROCAST.NET):
GMP CABLE TV,
BERWICK, PENNSYLVANIA, US.
n/a   135 pcap raw alerts
ruleset
other
98 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33 e30fb27bda
[Firefox: 8 hits: 07-07 to 09-16]
none[none] none:none
none|none none none
06:15:00 WinXP 84.74.89.111 (HISPEED.CH):
CABLECOMMAIN-NET,
ZURICH, ZURICH, CH. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 b872c76081
[Firefox:10 hits: 09-13 to 09-19]
none[none] none:none
none|none none none
T:06:21:00 WinXP 78.34.14.246 (NETCOLOGNE.DE):
NETCOLOGNE GMBH,
KOELN, NORDRHEIN-WESTFALEN, DE.
n/a RU:moscow-advokat.ru
SE:qis.md.us.dal.net
SE:ozbytes.dal.net
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:07:00:00 WinXP 83.41.251.151 (RIMA-TDE.NET):
TELEFONICA DE ESPANA,
ALICANTE, VALENCIA, ES.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:77 hits: 01-14 to 09-18]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
T:07:16:00 WinXP 12.73.102.90 (ATT.NET):
AT&T WORLDNET SERVICES,
TACOMA, WASHINGTON, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 f502585714
[Firefox:41 hits: 01-02 to 09-14]
ae590430c5 [0] ASM:Graph
PolyEnE| lines=63 trace
07:18:00 Win2K-f 70.73.107.59 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
77 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
73f1082158[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
T:07:22:00 WinXP 118.218.141.101 (-):
.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
99 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
31 of 33
0 of 33
168aab35a3
[Firefox:131 hits: 06-17 to 09-18]
667f0c59f3
[Firefox:23 hits: 07-04 to 09-17]
e07c29c4ae
[Firefox:474 hits: 06-19 to 09-19]
none[4]
none [none]
e07c29c4ae[1]
none:none
none:none
ASM:Graph
tElock|
none|none
FSG|
none
none
lines=92
trace
none
trace
T:07:34:00 WinXP 68.145.14.215 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 ba6f48b79a
[Firefox: 5 hits: 09-15 to 09-16]
none[none] none:none
none|none none none
07:34:00 WinXP 4.229.165.121 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
CANTON, OHIO, US. (DIAL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.173.41:80
US:208.111.173.42:80
135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
07:49:00 Win2K-f 24.44.234.137 (OPTONLINE.NET):
OPTIMUM ONLINE (CABLEVISION SYSTEMS),
NORWALK, CONNECTICUT, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.247:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
07:49:00 Win2K-f 60.249.198.98 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
57ce4acac2
[Firefox:189 hits: 06-17 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
57ce4acac2[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
07:59:00 WinXP 121.73.137.80 (TELSTRACLEAR.NET):
TELECOMMUNICATIONS COMPANY,
NZ.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
349 lines
Yeah : 1.3
profile
none summary
tarball
32 of 36
34 of 36
0 of 33
7f89b38665
[Firefox:14 hits: 08-02 to 09-19]
a51a50404e
[Firefox:14 hits: 08-02 to 09-19]
e07c29c4ae
[Firefox:474 hits: 06-19 to 09-19]
none[none]
none [none]
e07c29c4ae[1]
none:none
none:none
ASM:Graph
none|none
none|none
FSG|
none
none
lines=92
none
none
trace
08:06:00 Win2K-f 203.91.179.148 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, AICHI, JP.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
222 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36
33 of 36
389cf0c860
[Firefox: 2 hits: 08-26 to 08-29]
ed7d5d9ce7
[Firefox: 3 hits: 08-26 to 09-14]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
08:25:00 WinXP 81.84.239.41 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
LISBON, LISBOA, PT.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
34 of 36 11079645a6
NEW
none[none] none:none
none|none none none
T:08:25:00 WinXP 81.84.239.41 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
LISBON, LISBOA, PT.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 11079645a6
NEW
none[none] none:none
none|none none none
08:27:00 WinXP 217.202.120.179 (-):
TELECOM ITALIA MOBILE,
IT.
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
08:35:00 Win2K-f 4.224.237.250 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
FAIRBORN, OHIO, US. (DIAL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
114 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
a08f3b74a4[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
T:08:37:00 Win2K-f 65.34.30.26 (RR.COM):
ROAD RUNNER HOLDCO LLC,
ORLANDO, FLORIDA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.174:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:08:48:00 WinXP 134.129.43.6 (NODAK.EDU):
NORTH DAKOTA STATE UNIVERSITY COMPUTER CENTER,
FARGO, NORTH DAKOTA, US.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 e1a16d858c
NEW
none[none] none:none
none|none none none
08:48:00 WinXP 92.41.72.37 (IKBCC.COM):
EU-ZZ,
UK.
n/a :proxim.ircgalaxy.pl
HK:210.245.211.11:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 31 85597d85c0
[Firefox: 2 hits: 04-29 to 07-22]
f00f427b94 [0] ASM:Graph
PolyEnE| lines=265
embedded dns
trace
T:09:06:00 Win2K-f 140.239.40.37 (XO.NET):
XO COMMUNICATIONS,
CHELMSFORD, MASSACHUSETTS, US.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
09:16:00 WinXP 155.239.94.198 (TELKOM-IPNET.CO.ZA):
AFRINIC,
ZA.
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:403 hits: 12-31 to 09-19]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:09:25:00 Win2K-f 68.146.99.214 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
:proxim.ircgalaxy.pl
US:208.111.148.43:80
US:208.111.148.54:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
123 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36
32 of 36
2204fd4d17
[Firefox: 4 hits: 09-15 to 09-18]
eb0857e1b1
[Firefox: 4 hits: 09-15 to 09-18]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
09:26:00 WinXP 4.228.225.127 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
LAS VEGAS, NEVADA, US. (DIAL)
n/a UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a0139d7ad8
[Firefox:103 hits: 01-03 to 09-19]
d9e9662db1 [0] ASM:Graph
PolyEnE| lines=68 trace
09:43:00 WinXP 221.251.49.172 (UCOM.NE.JP):
TK,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:375 hits: 01-05 to 09-19]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
10:09:00 Win2K-f 64.139.104.175 (RCABLETV.COM):
NCI DATA.COM INC,
REPUBLIC, WASHINGTON, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
4 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
10:12:00 WinXP 88.168.176.200 (PROXAD.NET):
PROXAD / FREE SAS,
FR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 c707b3f22a
[Firefox: 3 hits: 08-06 to 08-19]
none[none] none:none
none|none none none
T:10:21:00 WinXP 41.214.163.63 (-):
.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 41065f98ee
[Firefox: 6 hits: 08-04 to 09-16]
none[none] none:none
none|none none none
10:40:00 WinXP 199.224.91.193 (EPIX.NET):
FRONTIER COMMUNICATIONS OF AMERICA INC,
BLOOMSBURG, PENNSYLVANIA, US. (DIAL)
n/a :proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:207.123.46.125:80
HK:210.245.211.11:65520
US:4.23.60.125:80
135 pcap raw alerts
ruleset
http
120 lines
Yeah : 1.3
profile
none summary
tarball
28 of 33
31 of 33
0 of 33
ba4637f8f0
[Firefox:11 hits: 07-01 to 09-18]
d02ae67164
[Firefox:11 hits: 07-01 to 09-18]
e07c29c4ae
[Firefox:474 hits: 06-19 to 09-19]
none[none]
none [none]
e07c29c4ae[1]
none:none
none:none
ASM:Graph
none|none
none|none
FSG|
none
none
lines=92
none
none
trace
T:10:48:00 WinXP 190.225.239.193 (-):
.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
11:04:00 WinXP 77.253.147.217 (COM.PL):
NETIA,
PL.
194.54.90.246:80 :proxim.ircgalaxy.pl
UA:citi-bank.ru
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 d7d1a04bbe
NEW
none[none] none:none
none|none none none
T:11:21:00 Win2K-f 96.15.68.199 (-):
.
n/a US:microsoft.com
:proxim.ircgalaxy.pl
US:download.microsoft.com
US:192.221.108.126:80
US:204.160.104.126:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
http
114 lines
Yeah : 1.3
profile
none summary
tarball
28 of 33
31 of 33
0 of 32
6d86a1ff5a
[Firefox:34 hits: 06-25 to 08-20]
7f6e032fc0
[Firefox:34 hits: 06-25 to 08-20]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[none]
none [none]
b5919931fe[1]
none:none
none:none
ASM:Graph
none|none
none|none
ASProtect|
none
none
lines=90
none
none
trace
11:21:00 Win2K-f 96.15.68.199 (-):
.
n/a :proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:192.221.108.126:80
US:204.160.104.126:80
US:207.123.46.125:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
113 lines
Yeah : 1.3
profile
none summary
tarball
28 of 33
31 of 33
6d86a1ff5a
[Firefox:34 hits: 06-25 to 08-20]
7f6e032fc0
[Firefox:34 hits: 06-25 to 08-20]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
11:27:00 WinXP 200.165.197.63 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
35 of 36 571e381ed4
[Firefox: 9 hits: 09-14 to 09-19]
none[none] none:none
none|none none none
T:11:38:00 Win2K-f 71.49.223.248 (EMBARQHSD.NET):
EMBARQ CORPORATION,
LAS VEGAS, NEVADA, US.
n/a :proxim.ircgalaxy.pl
US:microsoft.com
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
5 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
11:42:00 WinXP 64.184.89.50 (SWAYZEE.COM):
SWAYZEE TELEPHONE CO,
SWAYZEE, INDIANA, US.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36 49d6cdaab4
[Firefox: 2 hits: 09-13 to 09-15]
none[none] none:none
none|none none none
T:11:46:00 Win2K-f 99.164.57.43 (-):
.
n/a US:microsoft.com
US:download.microsoft.com
US:192.221.108.126:80
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:12:09:00 WinXP 88.157.220.81 (REV-82-102-32-10.TVTEL.PT):
TVTEL - GRANDE PORTO COMUNICACOES SA,
PORTO, PORTO, PT. (DSL)
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 42cd06418e
NEW
none[none] none:none
none|none none none
T:12:12:00 Win2K-f 78.106.224.138 (CORBINA.NET):
INVESTELEKTROSVIAZ LTD,
RU.
n/a :proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:12:14:00 WinXP 87.54.179.169 (IP.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
DK.
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
:washington.dc.us.undernet.org
US:lia.zanet.net
:gaspode.zanet.org.za
:los-angeles.ca.us.undernet.org
SE:coins.dal.net
:flanders.be.eu.undernet.org
AT:graz.at.eu.undernet.org
NL:london.uk.eu.undernet.org
SE:vancouver.dal.net
HK:210.245.211.11:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 a398065ae3
NEW
none[none] none:none
none|none none none
T:12:36:00 WinXP 24.87.145.11 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SURREY, BRITISH COLUMBIA, CA. (DSL)
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
12:38:00 WinXP 82.0.57.142 (NTL.COM):
NTL INFRASTRUCTURE - MIDDLESBROUGH,
MIDDLESBROUGH, ENGLAND, UK. (DSL)
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
12:52:00 WinXP 84.75.140.67 (HISPEED.CH):
CABLECOMMAIN-NET,
ZURICH, ZURICH, CH. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
36 of 36 b872c76081
[Firefox:10 hits: 09-13 to 09-19]
none[none] none:none
none|none none none
T:13:00:00 WinXP 190.137.115.79 (NET.AR):
TELECOM ARGENTINA S.A,
AR.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
35 of 36 516f7aaac5
[Firefox: 2 hits: 09-19 to 09-19]
none[none] none:none
none|none none none
13:05:00 Win2K-f 70.184.102.222 (COX.NET):
COX COMMUNICATIONS,
CHANDLER, ARIZONA, US.
210.245.211.11:65520 US:microsoft.com
:proxim.ircgalaxy.pl
US:download.microsoft.com
DE:dl2.teenpassage.com
US:4.23.60.125:80
DE:85.114.141.207:80
135 pcap raw alerts
ruleset
irc
137 lines
Yeah : 1.8
profile
none summary
tarball
32 of 36
35 of 36
bea8cb1865
[Firefox:11 hits: 08-11 to 09-17]
fac78fde16
[Firefox: 2 hits: 09-13 to 09-17]
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
13:10:00 WinXP 68.144.106.195 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 e1a16d858c
NEW
none[none] none:none
none|none none none
T:13:10:00 WinXP 68.144.106.195 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
194.54.90.246:80 :proxim.ircgalaxy.pl
UA:citi-bank.ru
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 e1a16d858c
NEW
none[none] none:none
none|none none none
13:24:00 Win2K-f 68.145.161.5 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.215:80
US:208.111.153.231:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:13:28:00 Win2K-f 24.77.71.211 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
MAPLE RIDGE, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
113 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32
2 of 32
607b60ad51
[Firefox:35 hits: 06-20 to 09-18]
e5c7bce70e
[Firefox:34 hits: 06-20 to 09-18]
none[4]
e5c7bce70e[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
13:30:00 WinXP 217.201.166.44 (-):
TELECOM ITALIA MOBILE,
FIRENZE, TOSCANA, IT.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:13:31:00 WinXP 217.201.166.44 (-):
TELECOM ITALIA MOBILE,
FIRENZE, TOSCANA, IT.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
13:32:00 WinXP 211.74.112.179 (SEED.NET.TW):
DIGITAL UNITED INC,
TAIPEI, T'AI-PEI, TW. (DSL)
210.245.211.11:65520 :proxim.ircgalaxy.pl
DE:dl2.teenpassage.com
DE:85.114.141.207:80
445 pcap raw alerts
ruleset
http
irc
4 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36 43c48370d1
NEW
none[none] none:none
none|none none none
T:13:32:00 WinXP 81.84.110.16 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
PT.
n/a :proxim.ircgalaxy.pl
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 2334b1bb4c
NEW
none[none] none:none
none|none none none
13:32:00 WinXP 81.84.110.16 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
PT.
210.245.211.11:65520 :proxim.ircgalaxy.pl
DE:dl2.teenpassage.com
DE:85.114.141.207:80
445 pcap raw alerts
ruleset
http
irc
10 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 2334b1bb4c
NEW
none[none] none:none
none|none none none
T:13:43:00 Win2K-f 76.87.210.98 (G-M-I.NET):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.173.16:80
US:208.111.173.41:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:13:55:00 WinXP 217.201.215.171 (-):
TELECOM ITALIA MOBILE,
IT.
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
RU:194.6.222.11:6667
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 ae024849a2
NEW
none[none] none:none
none|none none none
14:00:00 Win2K-f 144.138.215.93 (TMNS.NET.AU):
TELSTRAINTERNET31,
CANBERRA, AUSTRALIAN CAPITAL TERRITORY, AU.
n/a US:microsoft.com
US:download.microsoft.com
US:204.160.104.126:80
US:205.128.73.126:80
US:8.12.222.126:80
135 pcap raw alerts
ruleset
other
61 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
b7082104e4
[Firefox:138 hits: 06-18 to 09-19]
none[4]
none [4]
none:none
none:none
tElock|
tElock|
none
none
trace
trace
14:03:00 Win2K-f 24.86.254.153 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
EDMONTON, ALBERTA, CA.
n/a US:microsoft.com
US:download.microsoft.com
US:205.128.73.126:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:14:13:00 Win2K-f 24.80.101.171 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
BURNABY, BRITISH COLUMBIA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
14:23:00 WinXP 60.251.30.251 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
111 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36
32 of 36
4c1a8e5092
NEW
8c5987537c
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:14:32:00 WinXP 87.205.229.88 (INETIA.PL):
INTERNETIA,
PL. (DSL)
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 26e3526604
NEW
none[none] none:none
none|none none none
14:40:00 WinXP 75.176.37.63 (RR.COM):
ROAD RUNNER HOLDCO LLC,
GASTONIA, NORTH CAROLINA, US.
n/a DE:siliconfireware.ru
US:searchportal.information.com
:www.proxy-socks.net
:wpad
US:208.73.210.32:80
445 pcap raw alerts
ruleset
http
http
http
3 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
[Firefox:242 hits: 01-01 to 09-19]
9bbdd086c5 [0] ASM:Graph
ASPack| lines=186
embedded dns
trace
T:14:42:00 WinXP 68.113.43.42 (CHARTER.COM):
CHARTER COMMUNICATIONS,
BROOKINGS, OREGON, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 a0139d7ad8
[Firefox:103 hits: 01-03 to 09-19]
d9e9662db1 [0] ASM:Graph
PolyEnE| lines=68 trace
T:14:52:00 WinXP 41.214.181.114 (-):
.
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 2570434ea6
NEW
none[none] none:none
none|none none none
14:55:00 WinXP 78.96.68.93 (ASTRAL.RO):
ASTRAL TELECOM SA,
RO.
n/a   445 pcap raw alerts
ruleset
other
0 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:14:55:00 WinXP 65.248.183.229 (HARTCOM.NET):
HART TELECOM,
HARTWELL, GEORGIA, US.
n/a EU:siliconfireware.ru
US:searchportal.information.com
:www.proxy-socks.net
:wpad
US:208.73.210.32:80
445 pcap raw alerts
ruleset
http
http
http
3 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
[Firefox:525 hits: 01-01 to 09-18]
40f7f463c4 [0] ASM:Graph
ASPack| lines=281
embedded dns
trace
14:58:00 WinXP 121.93.207.141 (INFOWEB.NE.JP):
INFOWEB(FUJITSU LTD.),
TOKYO, TOKYO, JP. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:375 hits: 01-05 to 09-19]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
T:15:06:00 Win2K-f 72.139.83.40 (ROGERS.COM):
ROGERS CABLE INC. FLFRD,
TORONTO, ONTARIO, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.173.53:80
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
73f1082158[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
T:15:10:00 Win2K-f 172.129.148.253 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
119 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
73f1082158 [1] ASM:Graph
Armadillo| lines=81 trace
T:15:16:00 WinXP 209.216.178.39 (GORGE.NET):
GORGE NETWORKS INC,
HOOD RIVER, OREGON, US. (DIAL)
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 da5b172485
NEW
none[none] none:none
none|none none none
15:19:00 Win2K-f 172.129.19.53 (AOL.COM):
AMERICA ONLINE,
RESTON, VIRGINIA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:8.12.202.125:80
135 pcap raw alerts
ruleset
http
111 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33
0 of 32
29 of 33
3373948767
[Firefox:24 hits: 07-03 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
c73f738c30
[Firefox:24 hits: 07-03 to 09-19]
none[none]
b5919931fe[1]
none [none]
none:none
ASM:Graph
none:none
none|none
ASProtect|
none|none
none
lines=90
none
none
trace
none
T:15:31:00 WinXP 201.231.109.103 (SRC.ORG):
CABLEVISION S.A,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 1b7ec6ce60
[Firefox: 4 hits: 09-16 to 09-18]
none[none] none:none
none|none none none
15:47:00 WinXP 24.32.95.154 (CEBRIDGE.NET):
CEBRIDGE CONNECTIONS,
CABOT, ARKANSAS, US.
n/a US:microsoft.com
US:download.microsoft.com
US:204.160.104.126:80
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
e07c29c4ae
[Firefox:474 hits: 06-19 to 09-19]
none[4]
73f1082158[1]
e07c29c4ae[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
FSG|
none
lines=81
lines=92
trace
trace
trace
15:49:00 Win2K-f 98.141.161.7 (-):
.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:15:51:00 WinXP 99.163.51.62 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
[Firefox:129 hits: 01-08 to 09-19]
83893bd25d [0] ASM:Graph
none|none lines=65 trace
15:54:00 WinXP 98.132.165.126 (-):
ALLTEL SIP CUSTOMERS - CHARLOTTE,
MATTHEWS, NORTH CAROLINA, US.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 a84ffdf670
[Firefox: 3 hits: 09-14 to 09-18]
none[none] none:none
none|none none none
T:15:58:00 WinXP 72.0.248.90 (SPEAKEASY.NET):
US.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 cdf8cd94a9
[Firefox: 7 hits: 09-14 to 09-19]
none[none] none:none
none|none none none
T:16:05:00 WinXP 68.147.199.146 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
135 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32 73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
73f1082158 [1] ASM:Graph
Armadillo| lines=81 trace
T:16:13:00 WinXP 68.204.164.21 (RR.COM):
ROAD RUNNER HOLDCO LLC,
ORLANDO, FLORIDA, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
16:14:00 WinXP 96.15.173.175 (-):
.
194.54.90.246:80 :proxim.ircgalaxy.pl
UA:citi-bank.ru
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 cdf8cd94a9
[Firefox: 7 hits: 09-14 to 09-19]
none[none] none:none
none|none none none
16:25:00 WinXP 76.90.152.205 (-):
.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
33 of 33 f0b49cdcfc
[Firefox:15 hits: 07-04 to 09-15]
none[none] none:none
none|none none none
T:16:25:00 WinXP 170.51.112.159 (COM.AR):
CTI COMPANIA DE TELEFONAS DEL INTERIOR S.A,
AR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 eca9a5fa95
[Firefox:14 hits: 08-09 to 09-17]
none[none] none:none
none|none none none
T:16:41:00 WinXP 189.49.207.80 (BRASILTELECOM.NET.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR.
210.245.211.11:65520 :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 1.3
profile
none summary
tarball
34 of 36 bfdd984464
NEW
none[none] none:none
none|none none none
T:16:41:00 WinXP 92.113.202.54 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
36 of 36 71b183b0c8
[Firefox: 2 hits: 09-17 to 09-19]
none[none] none:none
none|none none none
16:51:00 WinXP 190.137.167.239 (NET.AR):
TELECOM ARGENTINA S.A,
AR.
194.54.90.246:80 :proxim.ircgalaxy.pl
UA:citi-bank.ru
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 516f7aaac5
[Firefox: 2 hits: 09-19 to 09-19]
none[none] none:none
none|none none none
T:16:51:00 WinXP 190.137.167.239 (NET.AR):
TELECOM ARGENTINA S.A,
AR.
210.245.211.11:65520 :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 516f7aaac5
[Firefox: 2 hits: 09-19 to 09-19]
none[none] none:none
none|none none none
16:57:00 WinXP 24.144.24.235 (CONWAYCORP.NET):
CONWAY CORPORATION,
CONWAY, ARKANSAS, US. (DSL)
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 ae024849a2
NEW
none[none] none:none
none|none none none
T:17:11:00 Win2K-f 70.127.93.106 (RR.COM):
ROAD RUNNER HOLDCO LLC,
PALM HARBOR, FLORIDA, US.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
a08f3b74a4[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
T:17:15:00 WinXP 98.133.184.62 (-):
ALLTEL SIP CUSTOMERS - ATLANTA,
ATLANTA, GEORGIA, US.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 0.8
profile
none summary
tarball
36 of 36 a84ffdf670
[Firefox: 3 hits: 09-14 to 09-18]
none[none] none:none
none|none none none
17:27:00 Win2K-f 72.230.139.136 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US.
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
17:32:00 WinXP 78.34.26.153 (NETCOLOGNE.DE):
NETCOLOGNE GMBH,
KOELN, NORDRHEIN-WESTFALEN, DE.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 f353d4eed9
[Firefox: 3 hits: 09-17 to 09-18]
none[none] none:none
none|none none none
T:17:32:00 WinXP 78.34.26.153 (NETCOLOGNE.DE):
NETCOLOGNE GMBH,
KOELN, NORDRHEIN-WESTFALEN, DE.
210.245.211.11:65520 :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36 f353d4eed9
[Firefox: 3 hits: 09-17 to 09-18]
none[none] none:none
none|none none none
T:17:54:00 WinXP 190.31.92.21 (NET.AR):
APOLO -GOLD-TELECOM-PER,
AR.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 36 bd8d0a8f7b
NEW
none[none] none:none
none|none none none
17:55:00 WinXP 24.85.112.106 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SURREY, BRITISH COLUMBIA, CA.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.231:80
US:208.111.153.236:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
18:10:00 WinXP 202.169.240.71 (BLUELINE.CO.ID):
PT. RABIK BANGUN PERTIWI PMA,
DENPASAR, BALI, ID.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.153.231:80
US:208.111.153.236:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:18:31:00 WinXP 70.65.99.157 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RED DEER, ALBERTA, CA. (DSL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 1fcc146d70
[Firefox:43 hits: 01-02 to 09-19]
258fafe892 [0] ASM:Graph
PolyEnE| lines=68 trace
18:31:00 WinXP 70.65.99.157 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RED DEER, ALBERTA, CA. (DSL)
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1fcc146d70
[Firefox:43 hits: 01-02 to 09-19]
258fafe892 [0] ASM:Graph
PolyEnE| lines=68 trace
18:33:00 Win2K-f 24.80.178.213 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.173.46:80
US:208.111.173.47:80
135 pcap raw alerts
ruleset
other
95 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32
2 of 32
607b60ad51
[Firefox:35 hits: 06-20 to 09-18]
e5c7bce70e
[Firefox:34 hits: 06-20 to 09-18]
none[4]
e5c7bce70e[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:18:33:00 WinXP 4.155.255.145 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
MARYLAND, US. (DIAL)
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 986b59708d
[Firefox:77 hits: 01-14 to 09-18]
8a00217866 [0] ASM:Graph
PolyEnE| lines=57 trace
T:18:34:00 Win2K-f 64.150.148.220 (SCCOAST.NET):
HTC COMMUNICATIONS LLC,
CONWAY, SOUTH CAROLINA, US.
n/a   135 pcap raw alerts
ruleset
other
402 lines
Yeah : 1.3
profile
none summary
tarball
11 of 36 c4c5a56ffe
[Firefox: 7 hits: 08-15 to 08-24]
none[none] none:none
none|none none none
T:18:37:00 WinXP 211.52.164.70 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:208.111.173.46:80
US:208.111.173.47:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
99 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
34 of 36
168aab35a3
[Firefox:131 hits: 06-17 to 09-18]
58828b2adc
NEW
none[4]
none [none]
none:none
none:none
tElock|
none|none
none
none
trace
none
18:38:00 Win2K-f 64.150.148.220 (SCCOAST.NET):
HTC COMMUNICATIONS LLC,
CONWAY, SOUTH CAROLINA, US.
n/a   135 pcap raw alerts
ruleset
other
402 lines
Yeah : 1.3
profile
none summary
tarball
11 of 36 c4c5a56ffe
[Firefox: 7 hits: 08-15 to 08-24]
none[none] none:none
none|none none none
18:39:00 WinXP 61.220.116.19 (HINET.NET):
DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.173.46:80
US:208.111.173.47:80
135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
57ce4acac2
[Firefox:189 hits: 06-17 to 09-19]
none[4]
57ce4acac2[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
T:18:49:00 WinXP 67.11.55.117 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 36 eca9a5fa95
[Firefox:14 hits: 08-09 to 09-17]
none[none] none:none
none|none none none
T:19:10:00 WinXP 123.204.83.137 (SEED.NET.TW):
DIGITAL UNITED INC,
TAIPEI, T'AI-PEI, TW. (DSL)
123.204.83.137:80   445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
19:28:00 Win2K-f 124.111.206.234 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a US:microsoft.com
:proxim.ircgalaxy.pl
US:download.microsoft.com
US:208.111.148.219:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
118 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33
28 of 33
533d15b5ce
[Firefox:25 hits: 06-21 to 09-16]
58c343a8d8
[Firefox:28 hits: 06-21 to 09-16]
none[4]
58c343a8d8[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=82
trace
trace
19:31:00 WinXP 213.22.168.166 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
LISBON, LISBOA, PT.
n/a :proxim.ircgalaxy.pl
UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
36 of 36 e4ed963a77
[Firefox: 2 hits: 09-18 to 09-19]
none[none] none:none
none|none none none
19:41:00 Win2K-f 64.183.209.202 (RR.COM):
ROAD RUNNER HOLDCO LLC,
DALLAS, TEXAS, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.15:80
135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
b7082104e4
[Firefox:138 hits: 06-18 to 09-19]
none[4]
none [4]
none:none
none:none
tElock|
tElock|
none
none
trace
trace
19:48:00 WinXP 117.99.27.218 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
19:50:00 WinXP 68.118.64.20 (CHARTER.COM):
CHARTER COMMUNICATIONS,
CRESCENT CITY, CALIFORNIA, US.
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
EU:gaz-prom.ru
:irc.kar.net
:washington.dc.us.undernet.org
AT:graz.at.eu.undernet.org
:gaspode.zanet.org.za
:caen.fr.eu.undernet.org
RU:irc.tsk.ru
:brussels.be.eu.undernet.org
NL:london.uk.eu.undernet.org
:los-angeles.ca.us.undernet.org
:flanders.be.eu.undernet.org
RU:194.6.222.11:6667
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
other
0 lines
Yeah : 1.3
profile
none summary
tarball
33 of 36 842b9045e1
NEW
none[none] none:none
none|none none none
T:20:07:00 WinXP 82.224.191.245 (PROXAD.NET):
PROXAD / FREE SAS,
PARIS, ILE-DE-FRANCE, FR.
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 142c0d8e6f
NEW
none[none] none:none
none|none none none
20:15:00 Win2K-f 211.213.155.250 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:208.111.148.69:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
http
87 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33
34 of 36
0 of 32
4c3df24b32
[Firefox:186 hits: 06-17 to 09-18]
99745b0c1d
NEW
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
4c3df24b32 [1]
none [none]
b5919931fe[1]
ASM:Graph
none:none
ASM:Graph
Armadillo|
none|none
ASProtect|
lines=81
none
lines=90
trace
none
trace
T:20:21:00 Win2K-f 64.22.193.13 (NETEXPRESS.NET):
LIGHTEDGE SOLUTIONS,
DAVENPORT, IOWA, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.108:80
US:208.111.148.69:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
20:30:00 Win2K-f 72.70.198.164 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
HAZLETON, PENNSYLVANIA, US.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:208.111.148.69:80
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
20:45:00 WinXP 220.215.239.205 (CATV02.ITSCOM.JP):
ITS COMMUNICATIONS INC,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:375 hits: 01-05 to 09-19]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
21:05:00 Win2K-f 63.22.104.102 (UU.NET):
UUNET TECHNOLOGIES INC,
BOSTON, MASSACHUSETTS, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.174:80
135 pcap raw alerts
ruleset
http
98 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
none[4]
a08f3b74a4[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
21:21:00 WinXP 66.50.120.31 (PRTC.NET):
PUERTO RICO TELEPHONE COMPANY,
SAN JUAN, PUERTO RICO, PR.
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:21:30:00 WinXP 60.236.80.162 (MESH.AD.JP):
NEC CORPORATION,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:375 hits: 01-05 to 09-19]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
21:55:00 WinXP 60.186.172.222 (163DATA.COM.CN):
CHINANET-ZJ HANGZHOU NODE NETWORK,
HANGZHOU, ZHEJIANG, CN.
n/a :proxim.ircgalaxy.pl
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 d6be94e7ab
NEW
none[none] none:none
none|none none none
21:55:00 WinXP 117.99.57.166 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
T:21:56:00 WinXP 117.99.57.166 (XLRI.AC.IN):
BHARTI AIRTEL LTD,
DELHI, DELHI, IN.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
22:02:00 WinXP 99.163.48.34 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
[Firefox:129 hits: 01-08 to 09-19]
83893bd25d [0] ASM:Graph
none|none lines=65 trace
22:08:00 WinXP 75.63.155.216 (SBCGLOBAL.NET):
PPPOX ADSL - BRAS1.SNANTX,
DALLAS, TEXAS, US. (DSL)
194.54.90.246:80 UA:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
22:09:00 Win2K-f 24.68.116.44 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
VANCOUVER, BRITISH COLUMBIA, CA.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.173.16:80
US:208.111.173.41:80
135 pcap raw alerts
ruleset
other
114 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32
23 of 33
bca9e0fb5f
[Firefox:26 hits: 06-18 to 08-30]
e53a9ea82e
[Firefox:26 hits: 06-18 to 08-30]
none[4]
e53a9ea82e[1]
none:none
ASM:Graph
PolyEnE|
Armadillo|
none
lines=81
trace
trace
22:15:00 WinXP 98.25.121.246 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
17 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
[Firefox:403 hits: 12-31 to 09-19]
048df78048 [0] ASM:Graph
none|none lines=61 trace
T:22:27:00 Win2K-f 71.111.239.253 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
DURHAM, NORTH CAROLINA, US. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.115:80
135 pcap raw alerts
ruleset
http
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
a08f3b74a4
[Firefox:787 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
a08f3b74a4[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
22:38:00 WinXP 222.233.182.167 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
US:208.111.173.46:80
US:208.111.173.47:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
98 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
30 of 32
1509c8d024
[Firefox:23 hits: 06-17 to 09-15]
f23b040440
[Firefox:14 hits: 06-22 to 09-15]
none[4]
f23b040440[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=82
trace
trace
22:40:00 Win2K-f 218.39.26.61 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a US:microsoft.com
:proxim.ircgalaxy.pl
US:download.microsoft.com
US:208.111.173.46:80
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
other
124 lines
Yeah : 1.3
profile
none summary
tarball
27 of 33
31 of 33
1951eee0cd
[Firefox: 6 hits: 06-18 to 09-18]
e5e0dbde57
[Firefox: 6 hits: 06-18 to 09-18]
1951eee0cd [1]
none [4]
ASM:Graph
none:none
Armadillo|
tElock|
lines=82
none
trace
trace
22:42:00 WinXP 4.238.167.189 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
WAYNESBORO, PENNSYLVANIA, US. (DIAL)
n/a RU:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:22:43:00 WinXP 4.238.167.189 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
WAYNESBORO, PENNSYLVANIA, US. (DIAL)
n/a RU:moscow-advokat.ru
RU:194.6.222.11:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
[Firefox:585 hits: 12-31 to 09-19]
1aad8e4632 [0] ASM:Graph
PolyEnE| lines=93
embedded dns
trace
T:22:44:00 WinXP 222.233.182.167 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
n/a :proxima.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
HK:210.245.211.11:65520
135 pcap raw alerts
ruleset
http
101 lines
Yeah : 1.3
profile
none summary
tarball
31 of 33
30 of 32
1509c8d024
[Firefox:23 hits: 06-17 to 09-15]
f23b040440
[Firefox:14 hits: 06-22 to 09-15]
none[4]
f23b040440[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=82
trace
trace
22:46:00 WinXP 24.82.163.30 (SHELLCOMPUTERS.COM):
SHAW COMMUNICATIONS INC,
COQUITLAM, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
96 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32
2 of 32
607b60ad51
[Firefox:35 hits: 06-20 to 09-18]
e5c7bce70e
[Firefox:34 hits: 06-20 to 09-18]
none[4]
e5c7bce70e[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace
22:50:00 WinXP 70.72.209.63 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
260 lines
Yeah : 1.3
profile
none summary
tarball
30 of 33 18f75b34a5
[Firefox: 2 hits: 06-18 to 06-20]
none[4] none:none
PolyEnE| none trace
23:02:00 Win2K-f 116.4.232.90 (163DATA.COM.CN):
CHINANET GUANGDONG PROVINCE NETWORK,
BEIJING, BEIJING, CN.
n/a :proxim.ircgalaxy.pl
US:microsoft.com
US:download.microsoft.com
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:23:02:00 WinXP 24.68.225.255 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
CALGARY, ALBERTA, CA. (DSL)
n/a US:microsoft.com
US:download.microsoft.com
135 pcap raw alerts
ruleset
http
114 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32
23 of 33
bca9e0fb5f
[Firefox:26 hits: 06-18 to 08-30]
e53a9ea82e
[Firefox:26 hits: 06-18 to 08-30]
none[4]
e53a9ea82e[1]
none:none
ASM:Graph
PolyEnE|
Armadillo|
none
lines=81
trace
trace
T:23:13:00 Win2K-f 122.147.97.231 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH. CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:microsoft.com
US:download.microsoft.com
US:204.160.126.126:80
135 pcap raw alerts
ruleset
http
141 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
b5919931fe
[Firefox:609 hits: 06-20 to 09-19]
none[4]
73f1082158[1]
b5919931fe[1]
none:none
ASM:Graph
ASM:Graph
tElock|
Armadillo|
ASProtect|
none
lines=81
lines=90
trace
trace
trace
T:23:22:00 WinXP 221.169.121.121 (SEED.NET.TW):
DIGITAL UNITED I,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a :proxim.ircgalaxy.pl
RU:moscow-advokat.ru
RU:194.6.222.11:6667
HK:210.245.211.11:65520
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 d99da8735e
[Firefox: 3 hits: 09-18 to 09-19]
none[none] none:none
none|none none none
T:23:23:00 WinXP 166.230.131.235 (MYVZW.COM):
SERVICE PROVIDER CORPORATION,
BEDMINSTER, NEW JERSEY, US.
n/a UA:citi-bank.ru
UA:194.54.90.246:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
[Firefox:1118 hits: 12-31 to 09-19]
7a70e1b592 [0] ASM:Graph
PolyEnE| lines=68 trace
23:31:00 WinXP 189.48.77.213 (BRASILTELECOM.NET.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR.
n/a US:www.yahoo.com
US:www.altavista.com
:jbeegvia.ru
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
31 of 32 17028f1eda
[Firefox:33 hits: 04-18 to 09-15]
none[3] none:none
tElock| none trace
23:40:00 Win2K-f 140.239.40.163 (XO.NET):
XO COMMUNICATIONS,
CHELMSFORD, MASSACHUSETTS, US.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
23:41:00 WinXP 61.115.94.209 (WAKWAK.NE.JP):
XEPHION(NTT-ME CORPORATION),
JP. (DIAL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
[Firefox:375 hits: 01-05 to 09-19]
e0197e8a64 [0] ASM:Graph
none|none lines=62 trace
23:42:00 Win2K-f 211.22.210.69 (EAI.COM.TW):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.152:80
US:208.111.148.174:80
135 pcap raw alerts
ruleset
other
572 lines
Yeah : 1.3
profile
none summary
tarball
33 of 36
34 of 36
55d816f3e9
NEW
84a24d85f7
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
23:46:00 Win2K-f 70.117.151.52 (RR.COM):
ROAD RUNNER HOLDCO LLC,
BEAUMONT, TEXAS, US.
n/a US:microsoft.com
US:download.microsoft.com
US:208.111.148.174:80
135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
[Firefox:2283 hits: 06-17 to 09-19]
73f1082158
[Firefox:1138 hits: 06-18 to 09-19]
none[4]
73f1082158[1]
none:none
ASM:Graph
tElock|
Armadillo|
none
lines=81
trace
trace