Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

24 June 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:02:17:00 Win2K-f 124.241.138.142 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, AICHI, JP.
61.120.62.28:3305 TH:cx10man.weedns.com 135 pcap raw alerts
ruleset
irc
573 lines
Yeah : 1.8
profile
none summary
tarball
39 of 40 70ec5c4b3f
NEW
f697adabdd [0] none:none
StarForce| none trace
03:13:00 WinXP 196.20.165.247 (-):
MAURITIUS TELECOM,
MU.
n/a :proxim.ircgalaxy.pl
RU:citi-bank.ru
114.80.101.21:65520
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 5a5b76f39a
NEW
61cacea663 [0] none:none
PolyEnE| none trace
T:03:57:00 WinXP 211.128.47.138 (SO-NET.NE.JP):
SO-NET ENTERTAINMENT CORPORATION,
TOKYO, TOKYO, JP.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:04:12:00 Win2K-f 64.75.158.5 (TURQUOISE.NET):
HAWAII ONLINE,
US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
121 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:04:16:00 WinXP 217.203.140.178 (-):
TELECOM ITALIA MOBILE,
IT.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:04:45:00 Win2K-f 207.5.236.176 (SUSCOM-MAINE.NET):
GREAT WORKS INTERNET,
BRUNSWICK, MAINE, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
04:50:00 Win2K-f 94.76.147.221 (-):
.
n/a US:www.maxmind.com
US:checkip.dyndns.org
US:www.getmyip.org
:getmyip.co.uk
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 917c085aca
NEW
none[3] none:none
Armadillo| none trace
T:05:31:00 WinXP 122.120.97.75 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
35 of 41 9ebf734e41
NEW
none[4] none:none
none|none none trace
T:05:37:00 WinXP 114.121.16.233 (-):
.
114.80.101.21:65520 :proxim.ircgalaxy.pl
CN:goasi.cn
DE:dl2.guarddog2009.com
:www.google.com
:upr15may.com
CN:lometr.pl
CN:brenz.pl
GB:zz-dns.com
114.80.101.21:65520
EU:91.207.61.180:80
445 pcap raw alerts
ruleset
http
irc
http
http
45 lines
Yeah : 1.3
profile
none summary
tarball
38 of 40
18 of 41
21 of 41
19 of 40
0658d04f28
NEW
effe8947b3
NEW
f31caaa1c8
NEW
f37b5a8f0c
NEW
07f788a60e [0]
3425ff1392[0]
e76df652d5[0]
dce19a471e[0]
none:none
none:none
none:none
none:none
PolyEnE|
none|none
StarForce|
none|none
none
none
none
none
trace
trace
trace
trace
T:06:00:00 Win2K-f 71.113.143.38 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
BLOOMINGTON, ILLINOIS, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
144 lines
Yeah : 1.3
profile
none summary
tarball
39 of 40 10980f4df2
NEW
1fd3385a95 [0] ASM:Graph
none|none lines=556 trace
07:02:00 Win2K-f 114.218.153.66 (-):
.
n/a US:www.maxmind.com
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:07:32:00 Win2K-f 24.78.229.176 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
SQUAMISH, BRITISH COLUMBIA, CA. (DSL)
n/a :fuck.urpal43sourpalhuh.com
:teek.ihshsd8.com
:japan.youngpeyatech.info
135 pcap raw alerts
ruleset
other
524 lines
Yeah : 1.3
profile
none summary
tarball
38 of 40 fcab6c9d17
NEW
none[4] none:none
Xtreme-Pr| none trace
T:07:45:00 Win2K-f 210.181.111.219 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
114.80.101.21:65520 :proxim.ircgalaxy.pl
US:microsoft.com
CN:goasi.cn
CN:lometr.pl
CN:brenz.pl
EU:91.207.61.180:80
135 pcap raw alerts
ruleset
irc
http
135 lines
Yeah : 1.8
profile
none summary
tarball
29 of 32
28 of 32
19 of 40
8a75955033
NEW
9276c8b36b
NEW
f37b5a8f0c
NEW
2bf3e548b9 [0]
none [0]
dce19a471e[0]
ASM:Graph
ASM:Graph
none:none
tElock|
Armadillo|
none|none
lines=126
embedded dns
lines=81
none
trace
trace
trace
T:07:47:00 WinXP 66.65.197.34 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CLIFTON PARK, NEW YORK, US.
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
:wpad
GB:new.egg.com
445 pcap raw alerts
ruleset
http
http
http
http
36 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 df17a625ee
NEW
none[0] none:none
ASPack| lines=298
embedded dns
trace
T:07:55:00 WinXP 123.225.51.241 (OCN.NE.JP):
NTT COMMUNICATIONS CORPORATION,
TOKYO, TOKYO, JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:08:11:00 WinXP 118.216.158.125 (-):
.
121.12.116.142:65520 :proxim.ircgalaxy.pl
US:microsoft.com
CN:goasi.cn
CN:lometr.pl
CN:brenz.pl
EU:91.207.61.180:80
135 pcap raw alerts
ruleset
irc
http
143 lines
Yeah : 1.8
profile
none summary
tarball
30 of 33
28 of 33
19 of 40
533d15b5ce
NEW
58c343a8d8
NEW
f37b5a8f0c
NEW
c67adf46e2 [0]
none [0]
dce19a471e[0]
ASM:Graph
none:none
none:none
tElock|
Armadillo|
none|none
lines=126
embedded dns
lines=91
none
trace
trace
trace
T:08:59:00 Win2K-f 208.103.154.72 (CORETEL.NET):
CORETEL AMERICA INC,
ANNAPOLIS, MARYLAND, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
151 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:09:11:00 Win2K-f 116.126.246.203 (-):
HANARO TELECOM,
SEOUL, KYONGGI-DO, KR.
121.12.116.142:65520 US:microsoft.com
CN:proxima.ircgalaxy.pl
CN:goasi.cn
CN:lometr.pl
CN:brenz.pl
EU:91.207.61.180:80
135 pcap raw alerts
ruleset
irc
http
110 lines
Yeah : 1.8
profile
none summary
tarball
31 of 33
0 of 33
19 of 40
168aab35a3
NEW
4c3df24b32
NEW
f37b5a8f0c
NEW
60b730b97e [0]
none [0]
dce19a471e[0]
ASM:Graph
ASM:Graph
none:none
tElock|
Armadillo|
none|none
lines=120
embedded dns
lines=81
none
trace
trace
trace
T:09:31:00 Win2K-f 92.98.73.105 (APEXCOVANTAGE.COM):
EU-ZZ,
UK.
121.12.116.142:65520 CN:proxima.ircgalaxy.pl
CN:goasi.cn
CN:lometr.pl
CN:brenz.pl
EU:91.207.61.180:80
445 pcap raw alerts
ruleset
irc
http
20 lines
Yeah : 0.8
profile
none summary
tarball
19 of 40 f37b5a8f0c
NEW
dce19a471e [0] none:none
none|none none trace
T:10:40:00 WinXP 99.33.235.161 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
T:11:57:00 WinXP 61.98.187.22 (HAEDONGTEK.CO.KR):
THRUNET CO. LTD,
SEOUL, KYONGGI-DO, KR.
114.80.101.21:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
CN:goasi.cn
CN:lometr.pl
CN:brenz.pl
135 pcap raw alerts
ruleset
irc
http
134 lines
Yeah : 1.8
profile
none summary
tarball
29 of 32
28 of 32
19 of 40
8a75955033
NEW
9276c8b36b
NEW
f37b5a8f0c
NEW
2bf3e548b9 [0]
none [0]
dce19a471e[0]
ASM:Graph
ASM:Graph
none:none
tElock|
Armadillo|
none|none
lines=126
embedded dns
lines=81
none
trace
trace
trace
T:12:59:00 Win2K-f 173.25.43.11 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
12:59:00 Win2K-f 115.83.84.229 (-):
.
n/a US:www.maxmind.com
EU:checkip.dyndns.org
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
2 of 37 fcb4920986
NEW
none[3] none:none
UPX| none trace
T:13:09:00 Win2K-f 115.83.84.229 (-):
.
n/a US:www.maxmind.com
:getmyip.co.uk
:checkip.dyndns.org
US:64.246.48.99:666
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
2 of 37 fcb4920986
NEW
none[3] none:none
UPX| none trace
13:49:00 Win2K-f 200.71.99.202 (TELESAT.COM.CO):
COLDECON,
CALI, VALLE DEL CAUCA, CO.
n/a US:www.maxmind.com
:checkip.dyndns.org
US:67.15.94.80:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:13:58:00 Win2K-f 200.71.99.202 (TELESAT.COM.CO):
COLDECON,
CALI, VALLE DEL CAUCA, CO.
n/a US:www.maxmind.com
US:checkip.dyndns.org
US:64.246.48.99:666
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
14:22:00 WinXP 87.103.19.111 (REV.VODAFONE.PT):
GPRS POOLS,
ERICEIRA, LISBOA, PT.
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:15:02:00 WinXP 72.215.32.113 (COX.NET):
COX COMMUNICATIONS,
NICEVILLE, FLORIDA, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
15:19:00 WinXP 77.54.183.58 (REV.VODAFONE.PT):
VODAFONE TELECEL COMUNICACOES PESSOAIS SA,
PT.
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 3ae357d17b
NEW
none[0] ASM:Graph
PolyEnE| lines=73 trace
T:16:21:00 WinXP 204.183.123.121 (-):
AA/TWA RESERVATIONS,
TULSA, OKLAHOMA, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 41
4d4b7efca2
NEW
539d61fc06
NEW
ec83dac222 [0]
c3af874c93[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
16:24:00 Win2K-f 211.20.204.168 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:www.maxmind.com
US:www.getmyip.org
:getmyip.co.uk
EU:checkip.dyndns.org
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:16:33:00 Win2K-f 211.20.204.168 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:www.maxmind.com
:getmyip.co.uk
:checkip.dyndns.org
US:www.getmyip.org
208.78.69.70:80
US:64.246.48.99:666
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:17:09:00 Win2K-f 4.182.161.56 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
GRESHAM, OREGON, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
37 of 41
b56f7d6da7
NEW
f0662a1a03
NEW
ec31659c2f [0]
ac285ae4a1[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
17:16:00 Win2K-f 201.20.64.40 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a US:www.maxmind.com
:getmyip.co.uk
US:www.getmyip.org
:checkip.dyndns.org
208.78.68.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:17:24:00 WinXP 63.25.165.175 (UU.NET):
UUNET TECHNOLOGIES INC,
NEWARK, NEW JERSEY, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
104 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:17:25:00 Win2K-f 201.20.64.40 (STERLINGSTUDENTS.NET):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a US:www.maxmind.com
US:www.getmyip.org
:getmyip.co.uk
US:checkip.dyndns.org
US:64.246.48.99:666
445 pcap raw alerts
ruleset
http
6 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
17:48:00 WinXP 75.86.240.223 (RR.COM):
ROAD RUNNER HOLDCO LLC,
MILWAUKEE, WISCONSIN, US.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 3ae357d17b
NEW
none[0] ASM:Graph
PolyEnE| lines=73 trace
18:03:00 Win2K-f 200.23.134.33 (CORREO.CHAPINGO.MX):
UNIVERSIDAD AUTONOMA CHAPINGO,
MX.
n/a US:www.maxmind.com
US:www.getmyip.org
EU:checkip.dyndns.org
:getmyip.co.uk
208.78.69.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
2 of 37 409ef22885
NEW
none[3] none:none
UPX| none trace
T:18:12:00 Win2K-f 200.23.134.33 (CORREO.CHAPINGO.MX):
UNIVERSIDAD AUTONOMA CHAPINGO,
MX.
n/a US:www.maxmind.com
:checkip.dyndns.org
US:64.246.48.99:666
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
2 of 37 409ef22885
NEW
none[3] none:none
UPX| none trace
19:21:00 Win2K-f 222.85.27.207 (163DATA.COM.CN):
CHINANET HENAN PROVINCE NETWORK,
BEIJING, BEIJING, CN.
n/a US:www.maxmind.com
:getmyip.co.uk
:checkip.dyndns.org
US:www.getmyip.org
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
2 of 37 409ef22885
NEW
none[3] none:none
UPX| none trace
19:26:00 Win2K-f 114.47.126.86 (-):
.
n/a US:www.maxmind.com
US:checkip.dyndns.org
:getmyip.co.uk
US:www.getmyip.org
208.78.69.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:20:09:00 Win2K-f 114.47.126.86 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
EU:checkip.dyndns.org
US:64.246.48.99:666
445 pcap raw alerts
ruleset
http
6 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:20:22:00 WinXP 4.228.213.235 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
LAS VEGAS, NEVADA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
20:57:00 Win2K-f 82.66.244.145 (PROXAD.NET):
PROXAD / FREE SAS,
PARIS, ILE-DE-FRANCE, FR. (DSL)
n/a   445 pcap raw alerts
ruleset
http
6 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:21:19:00 WinXP 113.255.113.62 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
78 lines
Yeah : 1.3
profile
none summary
tarball
32 of 40
33 of 33
27b17a2724
NEW
53bfe15e91
NEW
a1d5ac965b [0]
1473091351[0]
none:none
ASM:Graph
tElock|
tElock|
none
lines=75
embedded dns
trace
trace
T:21:25:00 WinXP 63.246.125.200 (SPEAKEASY.NET):
US.
n/a   135 pcap raw alerts
ruleset
other
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
21:30:00 Win2K-f 212.174.151.223 (-):
KUMTEL DAYANIKLI TUKETIM MALLARI PLASTIK SANAYI TIC. A.S,
ANKARA, ANKARA, TR. (100Mbps)
n/a US:www.maxmind.com
:checkip.dyndns.org
US:www.getmyip.org
:getmyip.co.uk
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
7 of 37 7587773eea
NEW
none[3] none:none
StarForce| none trace
T:22:59:00 Win2K-f 117.241.168.147 (-):
.
n/a US:qtas.net
CZ:t32.marund.net
445 pcap raw alerts
ruleset
http
irc
53 lines
Yeah : 0.8
profile
none summary
tarball
5 of 41 b6a68cb0e8
NEW
2c7dbb8c1c [0] none:none
MingWin32| none trace
23:44:00 Win2K-f 94.76.216.211 (-):
.
n/a US:www.maxmind.com
:getmyip.co.uk
US:www.getmyip.org
:checkip.dyndns.org
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
23:46:00 Win2K-f 209.62.119.50 (EV1SERVERS.NET):
EVERYONES INTERNET,
US.
n/a US:www.maxmind.com
:getmyip.co.uk
US:www.getmyip.org
US:checkip.dyndns.org
208.78.69.70:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
7 of 37 3862324588
NEW
none[3] none:none
UPX| none trace
T:23:53:00 Win2K-f 94.76.216.211 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
:getmyip.co.uk
EU:checkip.dyndns.org
208.78.68.70:80
US:64.246.48.99:666
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace