Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:22:00 | Win2K-f | 24.80.114.200 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:00:43:00 | Win2K-f | 118.174.11.51 (-): . |
n/a | US:qtas.net CZ:t32.marund.net CZ:82.114.87.44:2345 |
445 | pcap | raw alerts ruleset |
http 38 lines |
Yeah : 0.8 profile |
none | summary tarball |
5 of 41 | b6a68cb0e8 NEW |
2c7dbb8c1c [0] | none:none |
MingWin32| | none | trace |
T:01:41:00 | WinXP | 114.48.209.58 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
02:32:00 | Win2K-f | 210.212.88.60 (-): ESSEL SHYAM COMMUNICATION LTD, NOIDA, ASSAM, IN. |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
10 of 38 | 9aaa5d9b81 NEW |
none[3] | none:none |
UPX| | none | trace |
T:02:34:00 | WinXP | 87.122.181.137 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, COLOGNE, NORDRHEIN-WESTFALEN, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:02:35:00 | Win2K-f | 61.89.230.204 (SENSYU.NE.JP): SNS, KISHIWADA, MIYAGI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
02:43:00 | Win2K-f | 200.71.107.182 (TELESAT.COM.CO): COLDECON, CALI, VALLE DEL CAUCA, CO. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:50:00 | Win2K-f | 203.73.84.184 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:22:00 | WinXP | 119.228.208.31 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 7b313206a2 NEW |
0c866c8cce [0] | none:none |
none|none | none | trace | |
T:03:31:00 | Win2K-f | 4.225.210.8 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LOVELAND, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 83 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:42:00 | Win2K-f | 71.111.37.222 (VERIZON.NET): VERIZON INTERNET SERVICES INC, GRESHAM, OREGON, US. (DSL) |
61.120.62.28:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 59c104b04a NEW |
9c0c7f9efa [0] | none:none |
StarForce| | none | trace |
T:04:13:00 | WinXP | 95.56.251.10 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
04:33:00 | Win2K-f | 173.45.103.205 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:51:00 | Win2K-f | 173.45.103.205 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:64.246.48.99:666 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
05:55:00 | Win2K-f | 110.49.83.239 (-): . |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
06:19:00 | Win2K-f | 61.67.135.11 (KBTELECOM.NET.TW): KOOS BROADBAND TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:www.maxmind.com :getmyip.co.uk US:checkip.dyndns.org US:67.15.94.80:80 |
139 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:38:00 | WinXP | 98.134.162.189 (-): . |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com |
445 | pcap | raw alerts ruleset |
http http 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:07:08:00 | Win2K-f | 86.217.214.55 (ABO.WANADOO.FR): IP2000-ADSL-BAS, PARIS, ILE-DE-FRANCE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9087d184e3 NEW |
631ae2f910 [0] | none:none |
ASPack| | none | trace | |
T:07:09:00 | WinXP | 82.238.210.201 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. (DSL) |
n/a | US:atmacasoft.com :ad.yieldmanager.com :www.google-analytics.com :adserving.cpxinteractive.com US:content.yieldmanager.edgesuite.net RU:m.DRD3H.COM US:www.worldbank.org US:siteresources.worldbank.org :wbglobalext.112.2o7.net |
139 | pcap | raw alerts ruleset |
ftp http irc http 84 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 9121eddc1a NEW |
0958827bdb [0] | none:none |
ASPack| | none | trace |
T:07:09:00 | Win2K-f | 59.104.2.87 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | d7265c89b6 NEW |
4fadf3fb74 [0] | none:none |
ASPack| | none | trace |
T:07:09:00 | WinXP | 62.165.253.159 (TVNETWORK.HU): TVNETWORK-EXPAND, AMSTERDAM, NOORD-HOLLAND, NL. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:07:10:00 | WinXP | 70.72.136.225 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 50cdd5c6cf NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:07:22:00 | Win2K-f | 82.233.226.51 (PROXAD.NET): PROXAD / FREE SAS, NOISY-LE-GRAND, ILE-DE-FRANCE, FR. |
n/a | RU:m.drd3h.com RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
33 of 41 | ccdfac7dab NEW |
1e4ad6cdb1 [0] | none:none |
ASPack| | none | trace |
T:07:24:00 | Win2K-f | 221.169.192.154 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:07:30:00 | WinXP | 114.58.210.1 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
07:31:00 | Win2K-f | 207.26.149.2 (GETCOACTIVE.COM): OPTIMUM GROUP, CINCINNATI, OHIO, US. |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:31:00 | Win2K-f | 218.160.232.99 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 41 | f75c895158 NEW |
afaf06d6cd [0] | none:none |
pex| | none | trace | |
07:43:00 | Win2K-f | 121.241.213.153 (VSNL.NET.IN): VIDESH SANCHAR NIGAM LTD - INDIA, IN. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:07:51:00 | Win2K-f | 78.131.123.113 (-): EMKTV DOROG DOCSIS, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8128405d8c NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:07:59:00 | Win2K-f | 221.124.241.205 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:08:00:00 | WinXP | 88.174.205.27 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 40 | 3490e2ea15 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:08:00:00 | WinXP | 61.229.82.92 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 1b3d8e9fe7 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:08:08:00 | WinXP | 24.80.173.47 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | RU:m.drd3h.com RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 83f00dca51 NEW |
ffa5d1870c [0] | none:none |
ASPack| | none | trace |
T:08:28:00 | WinXP | 90.130.243.205 (SWIP.NET): SWIPNET, SE. |
114.80.101.21:65520 | CN:proxim.ircgalaxy.pl CN:goasi.cn CN:lometr.pl CN:brenz.pl :onuka.cn US:66.197.252.149:3954 67.215.233.58:2085 |
445 | pcap | raw alerts ruleset |
http irc 35 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:30:00 | Win2K-f | 85.67.33.66 (-): FIBERNET, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8128405d8c NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:08:33:00 | WinXP | 93.114.172.163 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 41 | 1f6e430d3b NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:08:33:00 | WinXP | 85.139.106.135 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, OEIRAS, LISBOA, PT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:35:00 | WinXP | 80.219.25.29 (HISPEED.CH): CABLECOMMAIN-NET, ZURICH, ZURICH, CH. (DSL) |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl CN:goasi.cn CN:211.95.79.6:80 |
139 | pcap | raw alerts ruleset |
ftp irc 43 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 005b382e66 NEW |
e6ae9a9b91 [0] | none:none |
PolyEnE| | none | trace |
T:08:44:00 | Win2K-f | 82.233.226.63 (PROXAD.NET): PROXAD / FREE SAS, NOISY-LE-GRAND, ILE-DE-FRANCE, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 41 | f75c895158 NEW |
afaf06d6cd [0] | none:none |
pex| | none | trace | |
T:08:45:00 | Win2K-f | 94.74.78.86 (-): . |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | d8e60db98a NEW |
6991257f56 [0] | none:none |
pex| | none | trace |
T:08:47:00 | WinXP | 84.46.203.61 (ERDVES.LT): POINT TO POINT CLIENT NETWORKS, NERINGA, KLAIPEDOS APSKRITIS, LT. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 1b3d8e9fe7 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:08:53:00 | WinXP | 61.229.167.227 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 013a5ba10e NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:08:59:00 | Win2K-f | 88.185.136.41 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | 954a98c971 NEW |
cdd769f7a4 [0] | none:none |
FSG| | none | trace | |
09:00:00 | Win2K-f | 190.0.67.115 (ASTER.COM.DO): ASTER, SANTO DOMINGO, DISTRITO NACIONAL, DO. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org US:64.246.48.99:666 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
09:16:00 | Win2K-f | 190.97.132.134 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk 208.78.69.70:80 US:64.246.48.99:666 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:09:19:00 | WinXP | 174.6.6.6 (-): . |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8128405d8c NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:09:22:00 | Win2K-f | 85.95.210.184 (CALIXO.NET): VIALIS - REGIE MUNICIPALE DE COLMAR, FR. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 61a9127875 NEW |
61a9127875 [1] | ASM:Graph |
pex| | lines=19 | trace |
T:09:24:00 | WinXP | 78.61.12.118 (ZEBRA.LT): LIETUVOS-TELEKOMAS, LT. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 3a1bb83dcd NEW |
d316b1a994 [0] | none:none |
ASPack| | none | trace |
T:09:25:00 | Win2K-f | 190.97.132.134 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.68.70:80 US:64.246.48.99:666 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
4 of 37 | 8ce32ded17 NEW |
none[3] | none:none |
Armadillo| | none | trace |
T:09:30:00 | Win2K-f | 89.247.53.143 (VERSANETONLINE.DE): VERSATEL NORD-DEUTSCHLAND GMBH, DE. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 733bfa6caf NEW |
ea191a79f8 [0] | none:none |
ASPack| | none | trace | |
T:09:38:00 | Win2K-f | 81.198.1.13 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 10 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:43:00 | WinXP | 83.215.17.56 (SALZBURG-ONLINE.AT): SALZBURG AG PROVIDES INTERNET-SERVICES, SALZBURG, SALZBURG, AT. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:09:48:00 | WinXP | 61.231.229.166 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 013a5ba10e NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:09:54:00 | WinXP | 79.70.172.180 (AS9105.COM): TELINCO, UK. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 4dd4197eb4 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:09:55:00 | Win2K-f | 85.67.117.37 (-): FIBERNET, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8128405d8c NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:10:08:00 | WinXP | 211.173.184.31 (-): CJ CABLENET PUKINCHEON BROADCASTING CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 1b3d8e9fe7 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:10:14:00 | Win2K-f | 89.152.162.145 (-): TVCABO PORTUGAL S.A, PT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 7b9a48dc79 NEW |
d76340a7cd [0] | none:none |
ASPack| | none | trace | |
T:10:19:00 | Win2K-f | 70.103.153.90 (FRONTIERNET.NET): ELECTRIC LIGHTWAVE INC, US. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 379a6daa0d NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:10:29:00 | WinXP | 94.197.130.192 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | 824d6a706e NEW |
a66fd13bcb [0] | none:none |
PolyEnE| | none | trace |
T:10:33:00 | WinXP | 24.172.183.77 (RR.COM): ROAD RUNNER HOLDCO LLC, LIVONIA, MICHIGAN, US. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | b47e522889 NEW |
9399e2ac48 [0] | none:none |
ASPack| | none | trace |
T:10:36:00 | Win2K-f | 80.218.141.227 (HISPEED.CH): CABLECOMMAIN-NET, ZURICH, ZURICH, CH. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 41 | 82614b1bbc NEW |
e5a12e2022 [0] | none:none |
ASPack| | none | trace | |
T:10:40:00 | Win2K-f | 78.131.99.222 (-): EMKTV DEBRECEN DOCSIS, BUCHAREST, BUCURESTI, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 1b3d8e9fe7 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:10:41:00 | WinXP | 41.249.118.197 (IAM.NET.MA): AFRINIC, MA. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 40 | 3490e2ea15 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:10:41:00 | Win2K-f | 78.58.60.84 (ZEBRA.LT): LIETUVOS, LT. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 013a5ba10e NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:11:08:00 | Win2K-f | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, KAO-HSIUNG, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:13:00 | Win2K-f | 81.56.222.221 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | e3faefa56a NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
11:15:00 | Win2K-f | 190.188.229.5 (NET.AR): PRIMA S.A, AR. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:11:25:00 | Win2K-f | 190.188.229.5 (NET.AR): PRIMA S.A, AR. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org 208.78.69.70:80 US:64.246.48.99:666 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:11:32:00 | WinXP | 114.38.138.146 (-): . |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 8887d42f5c NEW |
afaf06d6cd [0] | none:none |
pex| | none | trace |
T:11:41:00 | Win2K-f | 114.37.195.78 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8128405d8c NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:11:46:00 | Win2K-f | 77.254.89.187 (COM.PL): NETIA, PL. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | e3faefa56a NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:11:55:00 | WinXP | 89.167.16.136 (-): PRONET NETWORK - RESERVED FOR VOICE OVER IP SERVICES, PL. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8128405d8c NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:11:59:00 | Win2K-f | 83.60.154.198 (RIMA-TDE.NET): TELEFONICA DE ESPANA(NCC#2005070725), MADRID, MADRID, ES. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 013a5ba10e NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:12:01:00 | Win2K-f | 122.47.116.115 (-): POWERCOMM, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 3ca0933333 NEW |
1ff5b69ba2 [0] | none:none |
ASPack| | none | trace | |
T:12:05:00 | Win2K-f | 88.132.1.200 (-): PRTELECOM, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 41 | e7f3e11cf0 NEW |
d316b1a994 [0] | none:none |
ASPack| | none | trace | |
T:12:27:00 | WinXP | 81.84.193.172 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, PORTO, PORTO, PT. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
36 of 41 | a15f571a55 NEW |
2c8fba56d0 [0] | none:none |
PolyEnE| | none | trace |
T:12:42:00 | Win2K-f | 203.76.66.181 (KCT.AD.JP): KURASHIKI CABLE TV CORPORATION, KURASHIKI, OKAYAMA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
0fbd3620c4 NEW 9659e9e487 NEW |
0d031aab2f [0] d19073741a[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:12:47:00 | WinXP | 195.0.201.49 (BLUECOM.NO): CATCH COMMUNCIATIONS ASA, OSLO, OSLO, NO. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 25 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | f14fd68756 NEW |
f14fd68756 [1] | ASM:Graph |
pex| | lines=19 | trace |
T:12:53:00 | Win2K-f | 118.166.78.222 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 41 | f75c895158 NEW |
afaf06d6cd [0] | none:none |
pex| | none | trace | |
T:12:58:00 | Win2K-f | 212.107.225.139 (SKYCOM.SE): STOCKHOLM SWEDEN, STOCKHOLM, STOCKHOLM, SE. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:05:00 | WinXP | 213.22.8.27 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, QUELUZ, LISBOA, PT. |
n/a | :moscow-advokat.ru :brussels.be.eu.undernet.org SE:viking.dal.net :lia.zanet.net :caen.fr.eu.undernet.org FI:london.uk.eu.undernet.org :washington.dc.us.undernet.org SE:coins.dal.net SE:ozbytes.dal.net SE:qis.md.us.dal.net :gaspode.zanet.org.za SE:broadway.ny.us.dal.net AT:graz.at.eu.undernet.org SE:vancouver.dal.net SE:ced.dal.net :los-angeles.ca.us.undernet.org NL:diemen.nl.eu.undernet.org :flanders.be.eu.undernet.org :lulea.se.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | e49bd14db6 NEW |
cd910f4cfa [0] | none:none |
PolyEnE| | none | trace |
T:13:12:00 | Win2K-f | 208.103.154.27 (CORETEL.NET): CORETEL AMERICA INC, ANNAPOLIS, MARYLAND, US. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:38:00 | Win2K-f | 213.99.251.84 (-): TELEFONICA MOVILES ESPANA (NCC#2006042768), ES. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:13:43:00 | Win2K-f | 220.142.30.13 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, KAOHSIUNG, KAO-HSIUNG, TW. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 28 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 013a5ba10e NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:14:01:00 | WinXP | 78.84.162.141 (MICROLINK.LV): TELEKOM, RIGA, RIGA, LV. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 41 | f75c895158 NEW |
afaf06d6cd [0] | none:none |
pex| | none | trace |
T:14:05:00 | Win2K-f | 71.41.227.36 (RR.COM): ROAD RUNNER HOLDCO LLC, ALTAMONTE SPRINGS, FLORIDA, US. |
n/a | RU:m.drd3h.com | 139 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 450ad1b683 NEW |
1e4ad6cdb1 [0] | none:none |
ASPack| | none | trace |
T:14:16:00 | WinXP | 204.212.15.188 (-): AAFES/BARRACKS, HERNDON, VIRGINIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:19:00 | WinXP | 85.122.58.60 (RNC.RO): RNC, RO. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 41 | fb4b1960f6 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
14:26:00 | Win2K-f | 190.220.65.132 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk US:checkip.dyndns.org US:64.246.48.99:666 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 37 | 2bb18aceee NEW |
none[3] | none:none |
UPX| | none | trace |
14:32:00 | Win2K-f | 96.51.148.199 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
14:37:00 | Win2K-f | 190.220.68.37 (-): . |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org :getmyip.co.uk 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:14:39:00 | WinXP | 72.51.243.154 (NEWWAVECOMM.NET): NEW WAVE COMMUNICATIONS, SPARTA, ILLINOIS, US. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ae7a5cd8b1 NEW |
18ff3687ad [0] | none:none |
ASPack| | none | trace |
T:14:41:00 | Win2K-f | 96.51.148.199 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org US:64.246.48.99:666 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:03:00 | Win2K-f | 220.136.28.112 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 40 | 3490e2ea15 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:15:03:00 | WinXP | 78.61.5.237 (ZEBRA.LT): LIETUVOS-TELEKOMAS, KAUNAS, KAUNO APSKRITIS, LT. |
114.80.101.21:65520 | CN:proxim.ircgalaxy.pl CN:goasi.cn CN:lometr.pl CN:brenz.pl :onuka.cn US:mx4.hotmail.com US:ns2.msft.net US:ns1.msft.net DE:mx-ha02.web.de DE:mx-ha01.web.de :alt1.gmail-smtp-in.l.google.com US:alt2.gmail-smtp-in.l.google.com US:alt3.gmail-smtp-in.l.google.com US:alt4.gmail-smtp-in.l.google.com US:mailin-04.mx.aol.com US:mailin-01.mx.aol.com US:mailin-03.mx.aol.com 67.215.233.58:2085 67.215.233.58:2086 |
139 | pcap | raw alerts ruleset |
ftp irc http 259 lines |
Yeah : 1.3 profile |
none | summary tarball |
24 of 40 | f1bb8174e3 NEW |
ff7d442dd1 [0] | none:none |
none|none | none | trace |
T:15:06:00 | WinXP | 24.105.195.94 (MHCABLE.COM): MID-HUDSON CABLEVISION INC. CATSKILL, HUDSON, NEW YORK, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:15:12:00 | WinXP | 88.186.177.55 (PROXAD.NET): PROXAD / FREE SAS, FR. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 24bd7b91ab NEW |
5577c9ffd9 [0] | none:none |
ASPack| | none | trace |
T:15:16:00 | WinXP | 64.46.22.144 (NOVUSCOM.NET): NOVUS ENTERTAINMENT INC, VANCOUVER, BRITISH COLUMBIA, CA. |
n/a | RU:m.DRD3H.COM RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 65a0de1f09 NEW |
850cbe49c7 [0] | none:none |
ASPack| | none | trace |
T:15:19:00 | Win2K-f | 119.94.98.151 (-): . |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | c13a6c3da5 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:15:26:00 | WinXP | 218.173.225.31 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
66.252.13.214:2081 | US:s.unicat.org US:66.252.13.214:2081 |
445 | pcap | raw alerts ruleset |
ftp irc 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 67a66839f7 NEW |
7b1fc808a3 [0] | none:none |
none|none | none | trace |
15:45:00 | Win2K-f | 189.23.122.6 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
139 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:45:00 | WinXP | 189.0.250.151 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:03:00 | WinXP | 114.46.61.38 (-): . |
n/a | RU:m.drd3h.com | 139 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 9b2c7d1c22 NEW |
1e4ad6cdb1 [0] | none:none |
ASPack| | none | trace |
T:16:04:00 | Win2K-f | 4.159.86.120 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CLEVELAND, OHIO, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 781 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 41 | 537e7076da NEW |
none[3] | none:none |
StarForce| | none | trace | |
T:16:06:00 | Win2K-f | 78.62.40.241 (ZEBRA.LT): LIETUVOS, LT. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:15:00 | Win2K-f | 190.246.194.28 (-): . |
n/a | US:www.maxmind.com EU:checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:16:24:00 | Win2K-f | 190.246.194.28 (-): . |
n/a | US:www.maxmind.com :checkip.dyndns.org US:64.246.48.99:666 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:16:38:00 | WinXP | 83.60.154.198 (RIMA-TDE.NET): TELEFONICA DE ESPANA(NCC#2005070725), MADRID, MADRID, ES. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 013a5ba10e NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:16:40:00 | Win2K-f | 4.182.135.182 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, VISALIA, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 189 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 40 38 of 41 |
29b1147e8c NEW 45d0b04679 NEW |
cb0cdc25cb [0] d2d218b6e3[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:16:55:00 | WinXP | 65.191.30.208 (RR.COM): ROAD RUNNER HOLDCO LLC, FAYETTEVILLE, NORTH CAROLINA, US. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
T:16:59:00 | WinXP | 96.13.244.83 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 41 26 of 28 |
7d89e4dffc NEW 7d99b0e910 NEW |
a9315eb14c [0] none [0] |
none:none none:none |
FASM| PolyEnE| |
none lines=68 |
trace trace |
T:17:07:00 | Win2K-f | 113.253.12.148 (-): . |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 80563974df NEW |
afaf06d6cd [0] | none:none |
pex| | none | trace | |
T:17:24:00 | WinXP | 119.228.118.74 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:17:28:00 | WinXP | 208.103.191.205 (CORETEL.NET): CORETEL AMERICA INC, ANNAPOLIS, MARYLAND, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 141 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 0ce6381a33 NEW |
2670133512 [0] | none:none |
Armadillo| | none | trace | |
T:17:36:00 | WinXP | 68.93.134.119 (SWBELL.NET): PPPOX POOL - RBACK7 AUSTTX, AUSTIN, TEXAS, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:17:40:00 | Win2K-f | 211.236.137.4 (-): CJ CABLENET PUKINCHEON BROADCASTING CO. LTD, KR. |
n/a | RU:m.drd3h.com RU:89.221.18.86:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 9b2c7d1c22 NEW |
1e4ad6cdb1 [0] | none:none |
ASPack| | none | trace |
T:17:56:00 | Win2K-f | 70.166.101.182 (COX.NET): COX COMMUNICATIONS, PHOENIX, ARIZONA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:03:00 | WinXP | 122.120.130.10 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 36 | e96823d223 NEW |
none[3] | none:none |
none|none | none | trace | |
T:18:10:00 | Win2K-f | 114.206.46.242 (-): . |
114.80.101.21:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:goasi.cn CN:lometr.pl CN:brenz.pl :onuka.cn DE:mx-ha02.web.de DE:mx-ha01.web.de US:mx4.hotmail.com GB:ns3.msft.net US:b.mx.mail.yahoo.com US:c.mx.mail.yahoo.com US:d.mx.mail.yahoo.com US:e.mx.mail.yahoo.com :f.mx.mail.yahoo.com US:g.mx.mail.yahoo.com :a.mx.mail.yahoo.com US:ns1.msft.net :alt1.gmail-smtp-in.l.google.com US:alt2.gmail-smtp-in.l.google.com US:alt3.gmail-smtp-in.l.google.com US:alt4.gmail-smtp-in.l.google.com US:mailin-04.mx.aol.com US:mailin-01.mx.aol.com US:mailin-03.mx.aol.com 114.80.101.21:65520 208.115.112.138:3954 CN:222.186.13.27:80 US:67.19.219.74:80 US:74.53.96.138:80 |
135 | pcap | raw alerts ruleset |
irc http 327 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 30 of 33 28 of 33 0 of 41 24 of 40 19 of 40 |
4efa213b79 NEW 533d15b5ce NEW 58c343a8d8 NEW a518b3db58 NEW f1bb8174e3 NEW f37b5a8f0c NEW |
9e7dff694f [0] c67adf46e2[0] none [0] none [4] ff7d442dd1[0] dce19a471e[0] |
none:none ASM:Graph none:none none:none none:none none:none |
none|none tElock| Armadillo| none|none none|none none|none |
none lines=126 embedded dns lines=91 none none none |
trace trace trace trace trace trace |
T:18:15:00 | WinXP | 4.235.105.62 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, FLORIDA, US. (DIAL) |
121.12.116.142:65520 | CN:proxim.ircgalaxy.pl CN:goasi.cn CN:lometr.pl CN:brenz.pl :onuka.cn US:mx4.hotmail.com US:ns2.msft.net DE:mx-ha02.web.de US:alt4.gmail-smtp-in.l.google.com US:alt3.gmail-smtp-in.l.google.com US:alt2.gmail-smtp-in.l.google.com US:mailin-03.mx.aol.com US:mailin-04.mx.aol.com US:g.mx.mail.yahoo.com US:c.mx.mail.yahoo.com US:d.mx.mail.yahoo.com US:e.mx.mail.yahoo.com :f.mx.mail.yahoo.com US:b.mx.mail.yahoo.com CN:121.12.116.142:65520 US:64.85.163.90:3954 67.215.233.58:2086 |
445 | pcap | raw alerts ruleset |
http irc 264 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 41 37 of 39 24 of 40 19 of 40 |
4efa213b79 NEW dab4da4e21 NEW f1bb8174e3 NEW f37b5a8f0c NEW |
9e7dff694f [0] e63b813015[0] ff7d442dd1[0] dce19a471e[0] |
none:none ASM:Graph none:none none:none |
none|none PolyEnE| none|none none|none |
none lines=134 none none |
trace trace trace trace |
T:18:17:00 | Win2K-f | 70.60.10.186 (RR.COM): ROAD RUNNER HOLDCO LLC, NASHPORT, OHIO, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
18:19:00 | WinXP | 173.28.193.89 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 4d4b114a18 NEW |
2414a15ebd [0] | none:none |
PolyEnE| | none | trace |
T:18:43:00 | Win2K-f | 79.103.170.164 (G-M-I.NET): EU-ZZ, UK. |
121.12.116.142:65520 | CN:211.95.79.6:80 US:66.197.252.149:3954 |
139 | pcap | raw alerts ruleset |
irc 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:18:49:00 | Win2K-f | 67.11.81.84 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
194.109.11.65:6556 | NL:0x80.online-software.org NL:0x80.martiansong.com :0xff.memzero.info :0x80.my-secure.name NL:0x80.goingformars.com NL:0x80.my1x1.com NL:194.109.11.65:1023 NL:194.109.11.65:6556 |
135 | pcap | raw alerts ruleset |
other 188 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 32 | 15d4d85dc0 NEW |
4c95ae4b3d [0] | ASM:Graph |
StarForce| | lines=212 embedded dns |
trace |
T:19:39:00 | Win2K-f | 4.244.72.58 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:54:00 | WinXP | 122.126.142.226 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | RU:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:20:22:00 | Win2K-f | 99.25.151.39 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
20:38:00 | Win2K-f | 222.255.3.40 (LOCALHOST): VIETNAM DATA COMMUNICATION COMPANY, VN. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
5 of 37 | 741c93f3c1 NEW |
none[3] | none:none |
UPX| | none | trace |
T:20:47:00 | Win2K-f | 222.255.3.40 (LOCALHOST): VIETNAM DATA COMMUNICATION COMPANY, VN. |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org US:64.246.48.99:666 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
5 of 37 | 741c93f3c1 NEW |
none[3] | none:none |
UPX| | none | trace |
20:48:00 | Win2K-f | 189.30.9.171 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | US:www.maxmind.com :getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org 208.78.68.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
21:28:00 | Win2K-f | 61.67.135.11 (KBTELECOM.NET.TW): KOOS BROADBAND TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org :getmyip.co.uk EU:checkip.dyndns.org TW:61.67.135.11:5203 US:67.15.94.80:80 US:75.126.138.202:80 |
139 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
21:43:00 | Win2K-f | 66.90.103.23 (ON-DEMAND-TECH.COM): FDC SERVERS.NET LLC, CHICAGO, ILLINOIS, US. |
n/a | US:www.maxmind.com :checkip.dyndns.org :getmyip.co.uk US:www.getmyip.org US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:52:00 | Win2K-f | 66.90.103.23 (ON-DEMAND-TECH.COM): FDC SERVERS.NET LLC, CHICAGO, ILLINOIS, US. |
n/a | US:www.maxmind.com :getmyip.co.uk :checkip.dyndns.org US:64.246.48.99:666 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:46:00 | Win2K-f | 221.124.98.223 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 39 | 1a6c7da535 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:22:47:00 | WinXP | 114.121.71.187 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 06f29527f1 NEW |
01b1457ad7 [0] | none:none |
PolyEnE| | none | trace |
23:04:00 | Win2K-f | 222.51.124.197 (HERBALQC.COM): CHINA RAILWAY TELECOMMUNICATIONS CENTER, BEIJING, BEIJING, CN. |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:14:00 | WinXP | 60.36.193.245 (PLALA.OR.JP): PLALA NETWORKS INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | acc2931977 NEW |
5c47a9cff5 [0] | none:none |
none|none | none | trace | |
T:23:26:00 | Win2K-f | 60.249.37.247 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
23:32:00 | Win2K-f | 190.26.209.14 (-): . |
n/a | US:www.maxmind.com :getmyip.co.uk US:www.getmyip.org EU:checkip.dyndns.org 208.78.69.70:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:23:41:00 | Win2K-f | 190.26.209.14 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:64.246.48.99:666 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |