Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
03:33:00 | Win2K-f | 173.45.70.211 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
07:49:00 | Win2K-f | 81.28.112.11 (NS2.SAMA.JO): INTERNET USERS (DSL DIALUP), JO. (DSL) |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:09:23:00 | Win2K-f | 98.116.104.183 (-): . |
n/a | :pk.ub9.net :s1.xiaopohai.com :bfkq.com US:jsactivity.com :touristdot.com US:64.56.64.63:3954 74.54.201.210:8392 74.54.41.18:80 74.55.37.210:8392 |
445 | pcap | raw alerts ruleset |
http 64 lines |
Argh : 0.3 profile |
none | summary tarball |
4 of 41 6 of 41 0 of 41 |
80b5dc1bc4 NEW a4c9fa47d4 NEW bc20e0e6b8 NEW |
none[none] 620e2191be[none] none [none] |
none:none none:none none:none |
StarForce| PEQuake| none|none |
none none none |
trace trace trace |
T:09:27:00 | Win2K-f | 81.28.112.11 (NS2.SAMA.JO): INTERNET USERS (DSL DIALUP), JO. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:64.246.48.99:666 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:09:45:00 | Win2K-f | 173.67.92.214 (-): . |
n/a | US:www.seekisp.com US:www.abcjmp.com US:findlinkslive.com US:images01.tzimg.com US:domdex.com :ad.yieldmanager.com US:ad.adtegrity.net :cdn.media6degrees.com US:map.media6degrees.com US:209.59.194.20:80 US:64.56.64.63:3954 |
135 | pcap | raw alerts ruleset |
http http http http 33 lines |
Argh : 0.3 profile |
none | summary tarball |
1 of 41 | 36807eaa84 NEW |
none[none] | none:none |
none|none | none | trace |
T:10:09:00 | WinXP | 219.238.244.4 (IAPCM.AC.CN): BEIJING TELETRON TELECOM ENGINEERING CO. LTD, BEIJING, GUANGDONG, CN. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 40 37 of 40 |
1a76ee47c1 NEW 78834f5ab6 NEW |
8ef942208b [0] 2e416b0e36[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=64 embedded dns |
trace trace |
T:10:28:00 | WinXP | 196.219.91.129 (TEDATA.NET): PPPOE-DSL, CAIRO, AL QAHIRAH, EG. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
T:10:47:00 | WinXP | 91.154.30.253 (ELISA-LAAJAKAISTA.FI): ELISA, FI. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
11:12:00 | Win2K-f | 190.55.245.128 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:11:56:00 | WinXP | 78.60.115.123 (ZEBRA.LT): LIETUVOS, LT. |
213.219.245.212:80 114.80.101.21:65520 | CN:proxim.ircgalaxy.pl RU:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 37 | 952cb75a19 NEW |
59cc2f1497 [none] | none:none |
PolyEnE| | none | trace |
T:11:58:00 | WinXP | 75.177.161.214 (RR.COM): ROAD RUNNER HOLDCO LLC, RALEIGH, NORTH CAROLINA, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 40 | c42f9f40e3 NEW |
e024741844 [none] | none:none |
FASM| | none | trace | |
T:12:12:00 | WinXP | 66.69.38.142 (RR.COM): ROAD RUNNER HOLDCO LLC, SAN ANTONIO, TEXAS, US. (100Mbps) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
12:23:00 | Win2K-f | 69.39.225.46 (GIGENET.NET): ECOMDEVEL LLC, OAK BROOK, ILLINOIS, US. |
n/a | US:www.maxmind.com US:www.getmyip.org EU:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:12:36:00 | Win2K-f | 61.221.250.18 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:54:00 | WinXP | 69.12.235.190 (BEIGECOUGAR.COM): SONIC.NET INC, TRACY, CALIFORNIA, US. |
61.120.62.28:3305 | GB:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 573 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 40 | 70ec5c4b3f NEW |
f697adabdd [0] | none:none |
StarForce| | none | trace |
T:13:14:00 | Win2K-f | 24.234.221.222 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 516 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 4e12ded53f NEW |
464265496c [none] | none:none |
ASProtect| | none | trace | |
T:13:39:00 | WinXP | 98.141.9.167 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:53:00 | Win2K-f | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:01:00 | Win2K-f | 69.39.225.46 (GIGENET.NET): ECOMDEVEL LLC, OAK BROOK, ILLINOIS, US. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:14:21:00 | WinXP | 89.111.226.226 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
15:27:00 | Win2K-f | 201.255.66.246 (COM.AR): TELEFONICA DE ARGENTINA, AR. |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:15:28:00 | Win2K-f | 4.176.69.95 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, TUCSON, ARIZONA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:40:00 | WinXP | 173.20.140.66 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:42:00 | Win2K-f | 217.219.174.81 (-): ROAD MAINTANANCE AND TRANSPORTAION ORAGANIZATION OF MAZANDARAN, IR. (100Mbps) |
n/a | US:qtas.net CZ:t32.marund.net |
445 | pcap | raw alerts ruleset |
http irc 65 lines |
Yeah : 0.8 profile |
none | summary tarball |
12 of 41 | c33cc35f15 NEW |
4e5523c2ae [none] | none:none |
MingWin32| | none | trace |
T:15:42:00 | Win2K-f | 24.231.107.8 (VDN.CA): BELL CANADA - CABLE VDN, MONTREAL, QUEBEC, CA. |
121.12.116.142:65520 | US:mx1.hotmail.com US:ftp.icq.com US:maila.microsoft.com US:mailin-04.mx.aol.com US:mailin-03.mx.aol.com CN:proxim.ircgalaxy.pl US:yutunrz.1dumb.com US:http.icq.com.edgesuite.net :xx.enterhere.biz CN:goasi.cn CN:lometr.pl CN:brenz.pl :onuka.cn CA:xx.ka3ek.com :zone2tech.info 114.80.101.21:65520 US:65.54.244.8:25 US:67.19.219.74:80 US:74.53.96.138:80 95.129.144.178:80 |
135 | pcap | raw alerts ruleset |
http irc 852 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 39 39 of 41 7 of 40 24 of 40 19 of 40 |
367ce61cff NEW 889c9de162 NEW abf828b2d5 NEW f1bb8174e3 NEW f37b5a8f0c NEW |
48128671a8 [0] 5218b453e9[none] 230036ecf3[0] ff7d442dd1[0] dce19a471e[0] |
ASM:Graph none:none ASM:Graph none:none none:none |
StarForce| FSG| none|none none|none none|none |
lines=52 none lines=6 none none |
trace trace trace trace trace |
T:16:26:00 | WinXP | 4.178.189.17 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, VANCOUVER, WASHINGTON, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
16:31:00 | Win2K-f | 190.90.108.166 (EQUITEL.COM.CO): INTERNEXA S.A. E.S.P, CO. |
n/a | US:www.maxmind.com US:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
16:49:00 | Win2K-f | 196.41.109.5 (SAOL-NET.COM): AFRINIC, ZA. (DSL) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:50:00 | WinXP | 208.101.202.185 (BENTONCOUNTYCABLE.NET): AURORA CABLETV DBA BENTON COUNTY CABLEVISION, CAMDEN, TENNESSEE, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
17:08:00 | Win2K-f | 208.126.81.43 (NETINS.NET): NETINS INC, US. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:09:00 | WinXP | 114.48.156.241 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
17:14:00 | Win2K-f | 94.74.131.171 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:22:00 | Win2K-f | 94.74.131.171 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:64.246.48.99:666 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
17:26:00 | Win2K-f | 216.108.20.6 (INTERNORTH.COM): INUVIALUIT DEVELOPMENT CORP, INUVIK, NORTHWEST TERRITORIES, CA. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:17:34:00 | Win2K-f | 216.108.20.6 (INTERNORTH.COM): INUVIALUIT DEVELOPMENT CORP, INUVIK, NORTHWEST TERRITORIES, CA. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org US:64.246.48.99:666 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:18:04:00 | Win2K-f | 24.67.48.16 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, LETHBRIDGE, ALBERTA, CA. (DSL) |
n/a | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 602 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5e8c8e6c7f NEW |
5e4407efc5 [none] | none:none |
StarForce| | none | trace |
18:22:00 | Win2K-f | 173.45.77.245 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org :getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
139 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:18:24:00 | WinXP | 98.14.35.231 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 492957db81 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=69 embedded dns |
trace |
T:18:43:00 | Win2K-f | 63.17.221.94 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:47:00 | WinXP | 4.154.33.73 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NORTH CAROLINA, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad |
445 | pcap | raw alerts ruleset |
http http http 21 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
18:53:00 | Win2K-f | 216.22.81.99 (KMM-WEB.COM.BR): INTERNATIONAL BUSINESS LINK, RIVERVIEW, FLORIDA, US. |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:19:07:00 | WinXP | 96.8.197.107 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
20:11:00 | Win2K-f | 79.51.9.150 (SRC.ORG): TELECOM ITALIA NET, ROME, LAZIO, IT. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:20:18:00 | WinXP | 4.178.171.31 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PORTLAND, OREGON, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:21:00 | Win2K-f | 70.184.102.222 (COX.NET): COX COMMUNICATIONS, CHANDLER, ARIZONA, US. |
121.12.116.142:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:goasi.cn |
135 | pcap | raw alerts ruleset |
irc http 130 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 36 35 of 36 |
bea8cb1865 NEW fac78fde16 NEW |
154de51a66 [none] 882896ab05[none] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
20:30:00 | WinXP | 72.21.131.178 (-): ACETECH USA INC, LIBERTY LAKE, WASHINGTON, US. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 042774a2b7 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=71 embedded dns |
trace |
20:48:00 | Win2K-f | 114.44.232.185 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org 208.78.69.70:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:48:00 | Win2K-f | 218.172.226.242 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:microsoft.com US:208.109.234.200:80 CN:222.186.13.27:80 94.75.207.146:80 |
445 | pcap | raw alerts ruleset |
irc 26 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:03:00 | Win2K-f | 219.121.44.35 (ASAHI-NET.OR.JP): ASAHI-NET-CIDR-BLK, OSAKA, OSAKA, JP. (DIAL) |
n/a | US:microsoft.com US:208.109.234.200:80 CN:221.12.89.137:80 CN:222.186.13.27:80 CN:61.158.167.77:80 US:67.19.219.74:80 US:74.53.96.138:80 94.75.207.146:80 95.129.144.178:80 |
135 | pcap | raw alerts ruleset |
irc 17 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:25:00 | Win2K-f | 118.232.36.46 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:48:00 | Win2K-f | 118.174.177.59 (-): . |
n/a | US:qtas.net CZ:t32.marund.net |
445 | pcap | raw alerts ruleset |
http irc 50 lines |
Yeah : 0.8 profile |
none | summary tarball |
12 of 41 | c33cc35f15 NEW |
4e5523c2ae [none] | none:none |
MingWin32| | none | trace |
T:21:56:00 | WinXP | 76.83.61.14 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0ada72d805 NEW |
none[0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:23:24:00 | Win2K-f | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:23:36:00 | WinXP | 99.145.98.115 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace |