Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:09:00 | WinXP | 79.163.169.118 (-): IDEA, PL. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:10:00 | Win2K-f | 70.68.159.248 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, COQUITLAM, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 504 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 none |
d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] e8c32090ab NEW |
none[3] none [none] |
ASM:Graph none:none |
none|none none|none |
lines=0 none |
trace none |
|
00:24:00 | Win2K-f | 218.211.83.56 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
00:34:00 | Win2K-f | 64.83.242.10 (CLEARWAVE.COM): CLEARWAVE COMMUNICATIONS, HARRISBURG, ILLINOIS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 195 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace | |
T:00:34:00 | WinXP | 222.237.114.222 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com 115.126.2.121:65520 US:208.111.148.54:80 US:208.111.148.69:80 |
135 | pcap | raw alerts ruleset |
other 106 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:01:04:00 | WinXP | 68.126.242.240 (PACBELL.NET): AT&T INTERNET SERVICES, LOS ANGELES, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.104.126:80 US:206.33.45.125:80 |
135 | pcap | raw alerts ruleset |
http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 0 of 32 |
a08f3b74a4 [Firefox:1161 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
a08f3b74a4 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
T:01:18:00 | WinXP | 94.191.158.77 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:26:00 | WinXP | 41.214.174.34 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:27:00 | WinXP | 41.214.174.34 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:31:00 | Win2K-f | 216.211.244.51 (NORWOODLIGHT.COM): NORWOOD LIGHT BROADBAND, NORWOOD, MASSACHUSETTS, US. |
n/a | US:microsoft.com US:download.microsoft.com US:206.33.45.125:80 US:207.123.37.123:80 US:207.123.42.126:80 |
135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
018b7b7e27 [Firefox: 7 hits: 10-16 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
01:33:00 | Win2K-f | 172.129.100.6 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:44:00 | WinXP | 81.39.180.68 (RIMA-TDE.NET): TELEFONICA DE ESPANA, ALICANTE, VALENCIA, ES. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:58:00 | WinXP | 87.103.63.4 (REV.VODAFONE.PT): VODAFONE PORTUGAL, PT. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:58:00 | WinXP | 87.103.63.4 (REV.VODAFONE.PT): VODAFONE PORTUGAL, PT. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:01:00 | Win2K-f | 72.64.30.16 (VERIZON.NET): VERIZON INTERNET SERVICES INC, CHARLESTON, WEST VIRGINIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.96.126:80 US:199.93.41.124:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
02:03:00 | WinXP | 89.51.145.254 (PPPOOL.DE): FREENET CITYLINE GMBH, DE. (DIAL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:14:00 | Win2K-f | 116.123.134.229 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com 115.126.2.121:65520 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
http 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
61709fc4d6 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
02:14:00 | WinXP | 122.120.96.163 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
02:44:00 | WinXP | 91.144.96.205 (MEGATHERM.HU): ANTENNA TAVKOZLESI, BUDAPEST, BUDAPEST, HU. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:02:00 | WinXP | 118.109.135.35 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:04:00 | Win2K-f | 24.78.173.52 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, NORTH VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.44.124:80 US:207.123.37.125:80 US:207.123.42.126:80 |
135 | pcap | raw alerts ruleset |
other 131 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:03:06:00 | WinXP | 78.175.24.6 (SMYTHECRAMER.COM): TELEKOM, TR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
03:24:00 | WinXP | 60.234.105.116 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:03:44:00 | WinXP | 86.141.191.47 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:03:53:00 | Win2K-f | 24.65.53.63 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 620 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 none |
d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] fe538b44e4 NEW |
none[3] none [none] |
ASM:Graph none:none |
none|none none|none |
lines=0 none |
trace none |
|
03:57:00 | WinXP | 124.87.147.182 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
other 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:03:00 | WinXP | 87.58.9.95 (ADSL-DHCP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:23:00 | WinXP | 41.214.176.5 (-): . |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:35:00 | Win2K-f | 122.147.97.195 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
018b7b7e27 [Firefox: 7 hits: 10-16 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
04:36:00 | WinXP | 91.65.213.60 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | US:www.altavista.com :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:36:00 | WinXP | 91.65.213.60 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | US:www.altavista.com :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:46:00 | WinXP | 189.49.193.214 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:00:00 | WinXP | 117.96.76.19 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:01:00 | WinXP | 78.157.26.115 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:02:00 | WinXP | 79.163.180.163 (-): IDEA, PL. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:06:00 | WinXP | 78.114.55.213 (CEGETEL.NET): INTERNET RESIDENTIEL CEGETEL FRANCE, FR. |
n/a | UA:citi-bank.ru :makemegood24.com :4408f.makemegood24.com :aaakemegood24.com :perfectchoice1.com :44274.perfectchoice1.com :bparfectchoice1.com DE:cash-ddt.net DE:49557.cash-ddt.net :ccaah-ddt.net :ddr-cash.net :5339a.ddr-cash.net :dddracash.net :trn-cash.net :58fc4.trn-cash.net :etrn-aash.net :money-frn.net :5a2a0.money-frn.net :fmoneyafrn.net :clr-cash.net :5ff37.clr-cash.net :galr-cash.net :xxxl-cash.net :65a57.xxxl-cash.net :hxaxl-cash.net :www.kjwre77638dfqwieuoi.info UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:11:00 | Win2K-f | 122.53.169.237 (PLDT.NET): IPG, PH. |
n/a | 135 | pcap | raw alerts ruleset |
other 444 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
cc56e2f971 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
|
T:05:25:00 | WinXP | 89.231.197.97 (MM.PL): SZEL-SAT, PL. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:26:00 | WinXP | 85.176.120.67 (ALICEDSL.DE): HANSENET-ADSL, HAMBURG, HAMBURG, DE. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:26:00 | Win2K-f | 116.123.42.88 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com :proxima.ircgalaxy.pl US:download.microsoft.com 115.126.2.121:65520 |
135 | pcap | raw alerts ruleset |
http 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 0 of 32 |
4c3df24b32 [Firefox:221 hits: 06-17 to 10-15] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
4c3df24b32 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
05:34:00 | Win2K-f | 99.128.59.193 (-): . |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
8 of 33 0 of 32 |
b7082104e4 [Firefox:212 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[4] none [3] |
none:none ASM:Graph |
tElock| none|none |
none lines=0 |
trace trace |
T:05:39:00 | WinXP | 117.99.33.118 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
05:41:00 | WinXP | 117.99.33.118 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:45:00 | WinXP | 192.160.7.142 (ALCATEL.COM): ALCATEL NETWORK SERVICES, PLANO, TEXAS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
05:57:00 | WinXP | 82.208.134.229 (ASTRAL.RO): ASTRAL-CJ-DOCSIS, CLUJ-NAPOCA, CLUJ, RO. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:03:00 | WinXP | 79.138.195.196 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:07:00 | WinXP | 117.195.6.58 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:22:00 | WinXP | 118.237.96.1 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:26:00 | WinXP | 89.46.114.19 (JUMP.RO): SC AZURE SOFTWARE SRL, RO. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:31:00 | WinXP | 220.219.254.229 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:35:00 | WinXP | 201.94.161.184 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:44:00 | WinXP | 88.167.56.151 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:44:00 | WinXP | 88.170.218.136 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:46:00 | WinXP | 200.175.121.12 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com DE:ebookfinaltrash.ru :wpad US:208.73.210.32:80 |
445 | pcap | raw alerts ruleset |
http http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:06:48:00 | WinXP | 116.59.141.214 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:49:00 | WinXP | 116.59.141.214 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
06:54:00 | WinXP | 77.222.112.108 (-): INTERSVYAZ, RU. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
07:04:00 | WinXP | 93.172.213.74 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:14:00 | WinXP | 80.223.88.208 (INET.FI): BROADBAND ACCESS POOL, VARKAUS, ITA-SUOMEN LAANI, FI. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:16:00 | WinXP | 217.201.172.63 (-): TELECOM ITALIA MOBILE, IT. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
07:16:00 | WinXP | 217.201.172.63 (-): TELECOM ITALIA MOBILE, IT. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:26:00 | Win2K-f | 69.198.129.61 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.108:80 US:208.111.148.115:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
018b7b7e27 [Firefox: 7 hits: 10-16 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
07:26:00 | WinXP | 60.169.41.161 (AH163.NET): CHINANET ANHUI PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:28:00 | WinXP | 64.184.89.6 (SWAYZEE.COM): SWAYZEE TELEPHONE CO, SWAYZEE, INDIANA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:48:00 | WinXP | 24.100.4.206 (-): . |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 256 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
2f48a8e2b2 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:07:56:00 | WinXP | 220.219.254.229 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
08:00:00 | WinXP | 76.211.87.127 (SBCGLOBAL.NET): PPPOX POOL - BRAS6.STLSMO, SOUTH FORK, MISSOURI, US. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:03:00 | WinXP | 218.166.82.58 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:05:00 | WinXP | 75.34.107.250 (SBCGLOBAL.NET): MOHSEN KHAZIRI DBA, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 61 lines |
Yeah : 1.3 profile |
none | summary tarball |
8 of 33 0 of 32 |
b7082104e4 [Firefox:212 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[4] none [3] |
none:none ASM:Graph |
tElock| none|none |
none lines=0 |
trace trace |
08:13:00 | Win2K-f | 123.214.205.189 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com :proxima.ircgalaxy.pl US:download.microsoft.com 115.126.2.121:65520 |
135 | pcap | raw alerts ruleset |
http 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
b58fa3d317 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
08:14:00 | WinXP | 94.191.169.1 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
08:20:00 | WinXP | 79.163.174.93 (-): IDEA, PL. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:34:00 | WinXP | 220.102.27.63 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:38:00 | WinXP | 70.60.102.142 (RR.COM): ROAD RUNNER HOLDCO LLC, CHARLOTTE, NORTH CAROLINA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.73.126:80 US:207.123.37.123:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
08:47:00 | Win2K-f | 97.86.83.76 (CHARTER.COM): CHARTER COMMUNICATIONS, ST. LOUIS, MISSOURI, US. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
9a0c580209 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:08:57:00 | WinXP | 74.75.234.169 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:00:00 | WinXP | 117.96.90.17 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:03:00 | Win2K-f | 196.208.89.218 (TELKOM-IPNET.CO.ZA): AFRINIC, ZA. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.174:80 US:208.111.148.219:80 |
135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
09:07:00 | WinXP | 222.239.195.216 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.174:80 US:208.111.148.219:80 |
135 | pcap | raw alerts ruleset |
other 87 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:09:09:00 | WinXP | 79.138.212.74 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:29:00 | WinXP | 204.193.217.158 (QWEST.NET): QWEST BROADBAND SERVICES INC, DENVER, COLORADO, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:51:00 | WinXP | 89.204.231.178 (O2.IE): O2 IRELAND MOBILE PHONE OPERATOR, IE. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:54:00 | WinXP | 63.246.52.104 (GEUSNET.NET): GEUS, GREENVILLE, TEXAS, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:03:00 | WinXP | 117.99.55.31 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:80 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:24:00 | WinXP | 4.228.6.44 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, AURORA, COLORADO, US. (DIAL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:33:00 | WinXP | 70.15.70.173 (PTD.NET): PENTELEDATA INC. - CABLE, SELINSGROVE, PENNSYLVANIA, US. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:37:00 | WinXP | 190.138.223.140 (NET.AR): TELECOM ARGENTINA S.A, AR. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:38:00 | WinXP | 69.150.167.227 (-): WACOTX ADSL RBACK1 PPPOX, TEMPLE, TEXAS, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:38:00 | WinXP | 81.191.192.76 (BLUECOM.NO): CATCH COMMUNCIATIONS ASA, OSLO, OSLO, NO. |
n/a | DE:siliconfireware.ru US:searchportal.information.com :wpad US:208.73.210.32:80 DE:212.227.111.29:80 DE:217.11.54.126:80 |
445 | pcap | raw alerts ruleset |
http http http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:10:44:00 | WinXP | 77.56.68.148 (HISPEED.CH): CABLECOM, ZURICH, ZURICH, CH. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
10:44:00 | WinXP | 77.56.68.148 (HISPEED.CH): CABLECOM, ZURICH, ZURICH, CH. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:00:00 | WinXP | 193.250.13.84 (STATIC-IP.OLEANE.FR): TELECOM, MONTPELLIER, LANGUEDOC-ROUSSILLON, FR. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
11:02:00 | Win2K-f | 211.119.110.132 (BORA.NET): BORANET-NET, KR. |
n/a | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com 115.126.2.121:65520 |
135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
6bc2b65a8d NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:11:03:00 | WinXP | 118.221.57.173 (-): . |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com 115.126.2.121:65520 US:208.111.148.23:80 |
135 | pcap | raw alerts ruleset |
http 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
0d080d76c6 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
11:15:00 | WinXP | 94.79.66.134 (-): . |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:80 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:17:00 | Win2K-f | 93.80.65.25 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
115.126.2.121:65520 | :fleshkatera.cn :proxim.ircgalaxy.pl 115.126.2.110:80 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
irc 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:31:00 | WinXP | 89.32.216.161 (-): SC MONDO-BYTE SRL, IASI, IASI, RO. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
11:52:00 | WinXP | 190.5.193.76 (UNICAUCA.EDU.CO): EMTEL S.A. E.S.P, POPAYAN, CAUCA, CO. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:01:00 | WinXP | 68.149.229.221 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:01:00 | WinXP | 190.159.81.210 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:02:00 | WinXP | 79.163.202.89 (-): IDEA, PL. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:11:00 | WinXP | 87.50.126.237 (ADSL-DHCP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, SILKEBORG, ARHUS, DK. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:12:00 | WinXP | 92.96.73.181 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:13:00 | WinXP | 76.178.234.145 (RR.COM): ROAD RUNNER HOLDCO LLC, NORTH WOODSTOCK, NEW HAMPSHIRE, US. |
n/a | RU:moscow-advokat.ru :washington.dc.us.undernet.org NL:london.uk.eu.undernet.org RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:13:00 | WinXP | 41.210.206.163 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:15:00 | WinXP | 65.190.167.117 (RR.COM): ROAD RUNNER HOLDCO LLC, RALEIGH, NORTH CAROLINA, US. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:16:00 | WinXP | 65.190.167.117 (RR.COM): ROAD RUNNER HOLDCO LLC, RALEIGH, NORTH CAROLINA, US. |
n/a | UA:citi-bank.ru DE:kidos-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:18:00 | WinXP | 190.159.27.16 (-): . |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru :parex-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
12:22:00 | Win2K-f | 4.158.255.119 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, RACINE, WISCONSIN, US. (DIAL) |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.201.126:80 US:204.160.126.126:80 US:205.128.66.126:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
12:33:00 | WinXP | 70.184.216.118 (COX.NET): COX COMMUNICATIONS, OMAHA, NEBRASKA, US. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
T:12:35:00 | WinXP | 87.68.169.103 (012.NET.IL): GOLDENLINES-CABLE, EILAT, HADAROM (SOUTHERN), IL. (DSL) |
n/a | :proxima.ircgalaxy.pl RU:moscow-advokat.ru 115.126.2.121:65520 RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:40:00 | WinXP | 70.15.65.146 (PTD.NET): PENTELEDATA INC. - CABLE, SELINSGROVE, PENNSYLVANIA, US. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:01:00 | WinXP | 82.247.35.211 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:02:00 | WinXP | 82.247.35.211 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:17:00 | WinXP | 63.23.4.159 (UU.NET): UUNET TECHNOLOGIES INC, SAN FRANCISCO, CALIFORNIA, US. |
n/a | :www.google.com.au US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:33:00 | Win2K-f | 24.76.172.201 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 124 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 none |
d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] ea271eef76 NEW |
none[3] none [none] |
ASM:Graph none:none |
none|none none|none |
lines=0 none |
trace none |
T:13:47:00 | WinXP | 92.96.116.24 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:54:00 | WinXP | 193.250.107.95 (ABO.WANADOO.FR): WANADOO FRANCE, PARIS, ILE-DE-FRANCE, FR. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:59:00 | Win2K-f | 122.53.100.220 (PLDT.NET): IPG, PH. |
67.43.236.66:8080 | :xx.nadnadzz.info CA:xx.ka3ek.com CA:nadsam0.info CA:zonetech.info CA:ns.ircstyle.net :lb.lebanonbot.com CA:ns.enterhere.biz US:130.107.187.62:32472 |
135 | pcap | raw alerts ruleset |
irc http 353 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 0 of 32 |
9a78716c5b NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
14:07:00 | WinXP | 89.24.97.250 (4GINTERNET.CZ): RADIOMOBIL, CZ. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:07:00 | WinXP | 89.24.97.250 (4GINTERNET.CZ): RADIOMOBIL, CZ. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:10:00 | Win2K-f | 207.5.222.219 (METROCAST.NET): GREAT WORKS INTERNET, ROCHESTER, NEW HAMPSHIRE, US. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.137:80 US:208.111.148.152:80 |
135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
018b7b7e27 [Firefox: 7 hits: 10-16 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
14:16:00 | WinXP | 81.56.44.139 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | :proxim.ircgalaxy.pl RU:moscow-advokat.ru 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:51:00 | WinXP | 4.188.12.101 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SYLVA, NORTH CAROLINA, US. (DIAL) |
n/a | :proxim.ircgalaxy.pl EU:siliconfireware.ru US:searchportal.information.com DE:ebookfinaltrash.ru :wpad US:spi.domainsponsor.com 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http http http http 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:23:00 | WinXP | 24.59.6.118 (RR.COM): ROAD RUNNER HOLDCO LLC, ROME, NEW YORK, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:24:00 | WinXP | 201.82.233.15 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:31:00 | WinXP | 119.95.85.132 (-): . |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:39:00 | WinXP | 4.159.77.69 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CLEVELAND, OHIO, US. (DIAL) |
n/a | US:www.altavista.com :jbeegvia.ru SE:www.kavkazcenter.com US:www.worldbank.org :yoiayoi.ru :wcqahzhzn.ru :iirpryry.ru :rihafvu.ru :wpad :ryryodokm.ru :uvjiis.ru :gwvwka.ru :jqsbnyzkp.ru :pvygdo.ru :fxkyagpnw.ru :knclvdz.ru :trsqeigw.ru :odokeqy.ru :kelmpsjp.ru :edjiesp.ru :vllcdvv.ru :nuksdln.ru :tmmeno.ru :zoxdgqx.ru :pwvbfz.ru :nuzbcp.ru :bqpuqt.ru :okskyyn.ru DE:kavkaz.co.uk :pnlkria.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:39:00 | WinXP | 190.18.211.61 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:11:00 | Win2K-f | 98.141.160.17 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:14:00 | WinXP | 76.188.47.104 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW PHILADELPHIA, OHIO, US. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.254:80 US:208.111.153.215:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
16:17:00 | WinXP | 4.248.231.4 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:27:00 | WinXP | 211.11.31.227 (OCN.NE.JP): OPEN COMPUTER NETWORK, OSAKA, OSAKA, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:27:00 | Win2K-f | 209.127.192.127 (-): TELSCAPE COMMUNICATIONS INC, TORONTO, OHIO, US. |
n/a | :proxim.ircgalaxy.pl 115.126.2.121:65520 |
135 | pcap | raw alerts ruleset |
other 307 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
16:31:00 | WinXP | 68.200.24.153 (RR.COM): ROAD RUNNER HOLDCO LLC, LAKELAND, FLORIDA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:31:00 | WinXP | 68.200.24.153 (RR.COM): ROAD RUNNER HOLDCO LLC, LAKELAND, FLORIDA, US. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:43:00 | WinXP | 203.153.243.178 (AMNET.NET.AU): AMNET IT SERVICES PTY LTD, PERTH, WESTERN AUSTRALIA, AU. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.44.124:80 US:199.93.53.125:80 US:207.123.47.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
16:43:00 | WinXP | 67.11.54.40 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:43:00 | Win2K-f | 151.118.198.79 (QWEST.NET): QWEST BROADBAND, LITTLETON, COLORADO, US. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com 115.126.2.121:65520 |
135 | pcap | raw alerts ruleset |
http 125 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
1dfe3cd5e5 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:16:59:00 | WinXP | 66.217.142.125 (USLEC.NET): USLEC CORP, CHARLOTTE, NORTH CAROLINA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.137:80 US:208.111.148.152:80 |
135 | pcap | raw alerts ruleset |
other 140 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:17:08:00 | Win2K-f | 121.254.81.193 (TCOL.COM.TW): MONAD DIGITNAMIC CORP, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.148.108:80 US:208.111.148.69:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:17:10:00 | WinXP | 75.138.119.230 (CHARTER.COM): CHARTER COMMUNICATIONS, GREENVILLE, SOUTH CAROLINA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:11:00 | WinXP | 82.232.109.154 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
17:26:00 | Win2K-f | 124.241.168.49 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 68 lines |
Yeah : 1.3 profile |
none | summary tarball |
8 of 33 0 of 32 |
b7082104e4 [Firefox:212 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[4] none [3] |
none:none ASM:Graph |
tElock| none|none |
none lines=0 |
trace trace |
17:26:00 | WinXP | 189.126.20.16 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:35:00 | WinXP | 87.78.193.111 (NETCOLOGNE.DE): NETCOLOGNE GMBH, COLOGNE, NORDRHEIN-WESTFALEN, DE. (DSL) |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:39:00 | WinXP | 66.8.203.154 (RR.COM): ROAD RUNNER HOLDCO LLC, HONOLULU, HAWAII, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:02:00 | WinXP | 220.219.13.200 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:04:00 | WinXP | 204.193.218.99 (QWEST.NET): QWEST BROADBAND SERVICES INC, DENVER, COLORADO, US. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:28:00 | WinXP | 99.163.51.15 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:30:00 | WinXP | 118.174.111.72 (-): . |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:40:00 | WinXP | 79.138.206.130 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:42:00 | WinXP | 99.137.214.176 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
18:45:00 | WinXP | 96.15.8.177 (-): . |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:59:00 | Win2K-f | 125.58.120.191 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:206.33.45.125:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
19:21:00 | WinXP | 24.67.175.100 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, KELOWNA, BRITISH COLUMBIA, CA. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
19:30:00 | Win2K-f | 70.72.25.141 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:206.33.45.125:80 US:207.123.37.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
19:31:00 | Win2K-f | 207.5.188.178 (GWI.NET): GREAT WORKS INTERNET, SHAPLEIGH, MAINE, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:206.33.45.125:80 US:207.123.37.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[3] | ASM:Graph |
none|none | lines=0 | trace |
T:19:41:00 | WinXP | 71.136.17.66 (-): MILANO DESIGN, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
48a07a035e NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
19:47:00 | WinXP | 24.82.187.59 (SHELLCOMPUTERS.COM): SHAW COMMUNICATIONS INC, COQUITLAM, BRITISH COLUMBIA, CA. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:01:00 | WinXP | 75.138.119.84 (CHARTER.COM): CHARTER COMMUNICATIONS, GREENVILLE, SOUTH CAROLINA, US. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:11:00 | Win2K-f | 172.132.202.40 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 83 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 0 of 32 |
a08f3b74a4 [Firefox:1161 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
a08f3b74a4 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
20:11:00 | WinXP | 94.191.162.250 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:20:00 | WinXP | 24.76.233.129 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:23:00 | WinXP | 4.155.33.36 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, OWINGS MILLS, MARYLAND, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
20:32:00 | WinXP | 24.174.13.12 (CARRERACOMMUNICATIONS.NET): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. |
n/a | DE:siliconfireware.ru :wpad US:searchportal.information.com US:208.73.210.32:80 |
445 | pcap | raw alerts ruleset |
http http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:33:00 | WinXP | 72.174.70.48 (BRESNAN.NET): BRESNAN COMMUNICATIONS LLC, PURCHASE, NEW YORK, US. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:80 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:20:34:00 | WinXP | 207.5.222.219 (METROCAST.NET): GREAT WORKS INTERNET, ROCHESTER, NEW HAMPSHIRE, US. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
20:35:00 | WinXP | 125.4.11.100 (ZAQ.NE.JP): HIGASHI-OSAKA CABLE TELEVISION CO. LTD, OSAKA, OSAKA, JP. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
07fabc79ef [Firefox:22 hits: 06-19 to 10-14] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
07fabc79ef [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
T:20:42:00 | WinXP | 123.2.108.16 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. |
n/a | :proxim.ircgalaxy.pl RU:moscow-advokat.ru 115.126.2.121:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
20:56:00 | WinXP | 116.59.184.237 (-): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http irc 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:07:00 | Win2K-f | 116.120.98.201 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com 115.126.2.121:65520 US:208.111.148.226:80 US:208.111.148.247:80 |
135 | pcap | raw alerts ruleset |
other 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 0 of 32 |
043bfed045 NEW d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
none[none] none [3] |
none:none ASM:Graph |
none|none none|none |
none lines=0 |
none trace |
T:21:12:00 | WinXP | 65.173.138.42 (MAYSVILLEKY.NET): LIME STONE CABLE, MAYSVILLE, KENTUCKY, US. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:29:00 | WinXP | 220.105.166.212 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:21:32:00 | Win2K-f | 123.225.66.245 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | US:microsoft.com :proxima.ircgalaxy.pl US:download.microsoft.com 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:42:00 | Win2K-f | 68.150.127.216 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LEDUC, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
21:57:00 | WinXP | 130.13.71.65 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
22:06:00 | Win2K-f | 24.166.51.15 (RR.COM): ROAD RUNNER HOLDCO LLC, CUYAHOGA FALLS, OHIO, US. |
n/a | US:microsoft.com US:download.microsoft.com US:206.33.45.125:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 0 of 32 |
a08f3b74a4 [Firefox:1161 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
a08f3b74a4 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
22:30:00 | Win2K-f | 218.236.199.92 (-): HANANET-LLINE-MJCATV, KR. |
115.126.2.121:65520 | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:208.111.173.46:80 |
135 | pcap | raw alerts ruleset |
irc 135 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 32 none |
d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] fb37b86d36 NEW |
none[3] none [none] |
ASM:Graph none:none |
none|none none|none |
lines=0 none |
trace none |
22:35:00 | WinXP | 67.150.253.48 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, SAN JOSE, CALIFORNIA, US. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:35:00 | WinXP | 117.99.22.60 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
22:56:00 | Win2K-f | 99.170.21.97 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.201.126:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
23:02:00 | WinXP | 24.85.10.213 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:08:00 | WinXP | 204.214.131.156 (-): AAFES/BARRACKS, ELMWOOD, NEBRASKA, US. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 0 of 32 |
73f1082158 [Firefox:1594 hits: 06-18 to 10-17] d41d8cd98f [Firefox:136 hits: 12-31 to 10-17] |
73f1082158 [1] none [3] |
ASM:Graph ASM:Graph |
Armadillo| none|none |
lines=81 lines=0 |
trace trace |
23:22:00 | Win2K-f | 70.184.4.247 (COX.NET): COX COMMUNICATIONS, MACON, GEORGIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 164 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 860c4e8781 NEW |
none[none] | none:none |
none|none | none | none | |
T:23:56:00 | WinXP | 74.218.252.66 (-): . |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru 115.126.2.121:65520 UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |