Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

03 July 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
00:11:00 Win2K-f 173.45.91.151 (-):
.
n/a US:www.maxmind.com 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:00:23:00 WinXP 114.48.23.100 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:00:43:00 Win2K-f 4.226.225.189 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
BANDERA, TEXAS, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
01:19:00 Win2K-f 114.41.166.115 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
EU:checkip.dyndns.org
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:02:16:00 WinXP 118.6.244.206 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41 10318ada62
NEW
a5b9f355da [0] none:none
none|none none trace
T:02:36:00 Win2K-f 71.148.35.37 (SBCGLOBAL.NET):
KASSA KASSA,
PLANO, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:02:46:00 Win2K-f 60.250.29.223 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a   135 pcap raw alerts
ruleset
other
186 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41 02eb808a61
NEW
3e26f13f19 [0] none:none
none|none none trace
T:03:09:00 WinXP 89.247.147.205 (VERSANET.DE):
VERSATEL NORD-DEUTSCHLAND GMBH,
DE.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:04:10:00 WinXP 173.20.140.66 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:04:36:00 Win2K-f 99.190.152.127 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:04:40:00 Win2K-f 70.184.13.201 (COX.NET):
COX COMMUNICATIONS,
NEWPORT, RHODE ISLAND, US.
218.93.205.24:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
CN:brenz.pl
CN:lometr.pl
CN:dailybucks.vipinstall.cn
CN:218.93.205.24:65520
135 pcap raw alerts
ruleset
irc
http
136 lines
Yeah : 1.8
profile
none summary
tarball
18 of 41
8 of 41
32 of 36
35 of 36
1772d47c4c
NEW
5448de5424
NEW
bea8cb1865
NEW
fac78fde16
NEW
8bd43a2dce [0]
909699af1a[0]
154de51a66[0]
882896ab05[0]
none:none
none:none
ASM:Graph
none:none
Stranik|
tElock|
Armadillo|
tElock|
none
none
lines=91
none
trace
trace
trace
trace
04:46:00 Win2K-f 61.56.212.75 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH CO. LTD,
TAIPEI, T'AI-PEI, TW.
n/a US:www.maxmind.com
:checkip.dyndns.org
US:www.getmyip.org
US:getmyip.co.uk
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:04:51:00 Win2K-f 113.254.73.235 (-):
.
n/a :japan.youngpeyatech.info
:fuck.urpal43sourpalhuh.com
:teek.ihshsd8.com
135 pcap raw alerts
ruleset
other
545 lines
Yeah : 1.3
profile
none summary
tarball
38 of 40 fcab6c9d17
NEW
none[4] none:none
Xtreme-Pr| none trace
T:04:55:00 Win2K-f 61.56.212.75 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH CO. LTD,
TAIPEI, T'AI-PEI, TW.
221.5.74.39:65520 CN:proxim.ircgalaxy.pl
US:www.maxmind.com
US:www.getmyip.org
:checkip.dyndns.org
US:microsoft.com
CN:221.5.74.39:65520
445 pcap raw alerts
ruleset
http
irc
29 lines
Yeah : 1.3
profile
none summary
tarball
18 of 41
8 of 41
3 of 37
1772d47c4c
NEW
5448de5424
NEW
d9cb288f31
NEW
8bd43a2dce [0]
909699af1a[0]
45603a001c[0]
none:none
none:none
ASM:Graph
Stranik|
tElock|
UPX|
none
none
lines=174
embedded dns
trace
trace
trace
T:05:12:00 Win2K-f 59.97.137.143 (10/24.BSNL.IN):
NIB (NATIONAL INTERNET BACKBONE),
DELHI, DELHI, IN.
n/a CZ:qtas.net
CZ:t32.marund.net
445 pcap raw alerts
ruleset
http
irc
47 lines
Yeah : 0.8
profile
none summary
tarball
11 of 40 ea23d4c1f9
NEW
8f4c3a8da3 [0] none:none
MingWin32| none trace
T:05:51:00 Win2K-f 173.27.28.121 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:06:16:00 Win2K-f 123.212.105.6 (-):
HANARO TELECOM,
SEOUL, KYONGGI-DO, KR.
218.93.205.24:65520 US:microsoft.com
CN:proxim.ircgalaxy.pl
CN:put.ghura.pl
CN:brenz.pl
CN:lometr.pl
:onuka.cn
US:alt1.gmail-smtp-in.l.google.com
:alt4.gmail-smtp-in.l.google.com
US:alt2.gmail-smtp-in.l.google.com
US:alt3.gmail-smtp-in.l.google.com
208.115.108.122:3954
GB:212.117.177.212:4831
135 pcap raw alerts
ruleset
irc
http
331 lines
Yeah : 1.8
profile
none summary
tarball
18 of 41
15 of 41
30 of 33
28 of 33
31 of 41
24 of 40
1772d47c4c
NEW
298243013a
NEW
533d15b5ce
NEW
58c343a8d8
NEW
8228665f19
NEW
f1bb8174e3
NEW
8bd43a2dce [0]
b8c969e769[0]
c67adf46e2[0]
none [0]
9e7dff694f[0]
ff7d442dd1[0]
none:none
none:none
ASM:Graph
none:none
none:none
none:none
Stranik|
PEQuake|
tElock|
Armadillo|
none|none
none|none
none
none
lines=126
embedded dns
lines=91
none
none
trace
trace
trace
trace
trace
trace
T:06:34:00 Win2K-f 59.96.164.172 (10/24.BSNL.IN):
NIB (NATIONAL INTERNET BACKBONE),
GURGAON, HARYANA, IN.
n/a  
208.115.108.122:3954
US:209.85.212.77:25
GB:212.117.177.136:3954
GB:212.117.177.212:4831
445 pcap raw alerts
ruleset
irc
24 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:06:47:00 Win2K-f 79.70.226.31 (AS9105.COM):
TELINCO,
UK.
n/a US:alt2.gmail-smtp-in.l.google.com
:alt4.gmail-smtp-in.l.google.com
US:alt3.gmail-smtp-in.l.google.com
US:mail.global.frontbridge.com
US:server41.appriver.com
US:server42.appriver.com
US:mbay5.mx.proofpoint.com
US:mbay1.mx.proofpoint.com
US:mbay6.mx.proofpoint.com
FR:mx.libertysurf.net
US:server90.appriver.com
US:server91.appriver.com
US:publicms2.mail2world.com
US:publicms.mail2world.com
US:mbay3.mx.proofpoint.com
GB:mx1.uk.tiscali.com
GB:mx3.uk.tiscali.com
GB:mx4.uk.tiscali.com
GB:mx5.uk.tiscali.com
DE:mx0.gmx.net
DE:mx1.gmx.net
US:publicms1.mail2world.com
GB:mx2.uk.tiscali.com
GB:mx6.uk.tiscali.com
:mailinator.com
GB:212.117.177.212:4831
CN:218.93.205.24:65520
139 pcap raw alerts
ruleset
other
595 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:07:42:00 WinXP 218.235.90.106 (HANANET.NET):
HANARO TELECOM INC,
SEOUL, KYONGGI-DO, KR.
218.93.205.24:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
CN:brenz.pl
CN:lometr.pl
:onuka.cn
GB:212.117.177.136:3954
US:64.191.104.197:3954
135 pcap raw alerts
ruleset
irc
http
137 lines
Yeah : 1.8
profile
none summary
tarball
18 of 41
29 of 32
28 of 32
30 of 40
24 of 40
1772d47c4c
NEW
8a75955033
NEW
9276c8b36b
NEW
cb513b1bf5
NEW
f1bb8174e3
NEW
8bd43a2dce [0]
2bf3e548b9[0]
none [0]
9e7dff694f[0]
ff7d442dd1[0]
none:none
ASM:Graph
ASM:Graph
none:none
none:none
Stranik|
tElock|
Armadillo|
none|none
none|none
none
lines=126
embedded dns
lines=81
none
none
trace
trace
trace
trace
trace
T:08:45:00 WinXP 71.114.62.227 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
WOODBRIDGE, VIRGINIA, US. (DSL)
n/a :gg.arrancar.org 135 pcap raw alerts
ruleset
other
186 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41 df5957180f
NEW
a6e09a125b [0] none:none
none|none none trace
T:09:51:00 WinXP 77.64.140.33 (PRIMACOM.NET):
PRIMACOM-HEADENDS,
LEIPZIG, SACHSEN, DE.
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
none c05290bb06
NEW
dddfe6a7fe [0] none:none
PolyEnE| none trace
T:09:51:00 Win2K-f 24.85.37.2 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RICHMOND, BRITISH COLUMBIA, CA.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
116 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40
38 of 40
2721d2b151
NEW
b044168966
NEW
fde14d4abe [0]
b02ac1f831[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:10:46:00 Win2K-f 122.146.80.107 (SPARQNET.NET):
NEW CENTURY INFOCOMM TECH. CO. LTD,
TW.
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
12:37:00 Win2K-f 189.109.26.140 (-):
.
n/a US:www.maxmind.com
US:www.getmyip.org
US:getmyip.co.uk
US:checkip.dyndns.org
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 917c085aca
NEW
none[3] none:none
Armadillo| none trace
T:12:37:00 Win2K-f 114.202.209.212 (-):
.
218.93.205.24:65520 US:microsoft.com
CN:proxim.ircgalaxy.pl
CN:put.ghura.pl
CN:brenz.pl
CN:lometr.pl
135 pcap raw alerts
ruleset
irc
http
163 lines
Yeah : 1.8
profile
none summary
tarball
18 of 41
4 of 41
15 of 41
38 of 40
38 of 40
1772d47c4c
NEW
1e07abae19
NEW
298243013a
NEW
66863cfb13
NEW
e8dfca0741
NEW
8bd43a2dce [0]
1136f27263[0]
b8c969e769[0]
fca240f318[0]
20dfd2147c[0]
none:none
none:none
none:none
none:none
none:none
Stranik|
StarForce|
PEQuake|
Armadillo|
tElock|
none
none
none
none
none
trace
trace
trace
trace
trace
12:50:00 Win2K-f 190.50.98.207 (COM.AR):
TELEFONICA DE ARGENTINA,
AR.
n/a US:www.maxmind.com
EU:checkip.dyndns.org
US:getmyip.co.uk
US:www.getmyip.org
208.78.69.70:80
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
2 of 37 216ec67841
NEW
none[3] none:none
StarForce| none trace
T:12:59:00 Win2K-f 190.50.98.207 (COM.AR):
TELEFONICA DE ARGENTINA,
AR.
n/a US:www.maxmind.com
:checkip.dyndns.org
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
2 of 37 216ec67841
NEW
none[3] none:none
StarForce| none trace
T:13:04:00 WinXP 4.184.217.245 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
WASHINGTON, DISTRICT OF COLUMBIA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
112 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:13:37:00 WinXP 61.218.192.234 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
KAOHSIUNG, KAO-HSIUNG, TW.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
57ce4acac2
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:13:40:00 WinXP 4.168.0.74 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
FULLERTON, CALIFORNIA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
154 lines
Yeah : 1.3
profile
none summary
tarball
35 of 41
38 of 41
c17655e7f6
NEW
fd8dc4a8c9
NEW
1b9278cf1b [0]
83013248a6[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:13:55:00 WinXP 60.249.37.247 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TW.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
34 of 38
35 of 38
38ed850a0e
NEW
b9297745a1
NEW
46990f37cd [0]
4294884d84[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
14:44:00 WinXP 24.105.219.43 (MHCABLE.COM):
MID-HUDSON CABLEVISION INC. (CATSKILL),
HUDSON, NEW YORK, US. (DSL)
221.5.74.39:65520 CN:proxim.ircgalaxy.pl
CN:brenz.pl
CN:lometr.pl
:onuka.cn
CN:211.95.79.6:80
GB:212.117.177.136:3954
GB:212.117.177.212:4831
US:66.197.252.149:3954
445 pcap raw alerts
ruleset
http
irc
35 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36
18 of 41
30 of 39
24 of 40
04ed4d2967
NEW
1772d47c4c
NEW
6583d08abf
NEW
f1bb8174e3
NEW
e8aa304d1c [0]
8bd43a2dce[0]
9e7dff694f[0]
ff7d442dd1[0]
none:none
none:none
none:none
none:none
PolyEnE|
Stranik|
none|none
none|none
none
none
none
none
trace
trace
trace
trace
T:15:04:00 WinXP 88.130.223.72 (VERSANETONLINE.DE):
VERSATEL NORD-DEUTSCHLAND GMBH,
DORTMUND, NORDRHEIN-WESTFALEN, DE.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:15:26:00 WinXP 4.137.72.108 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
CHARLOTTE, NORTH CAROLINA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
65 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33 a08f3b74a4
NEW
none[0] none:none
Armadillo| lines=90 trace
T:15:50:00 WinXP 173.29.130.232 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 40
067917e07b
NEW
d764c1dcb2
NEW
dae35b319c [0]
3d2bc60c5d[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:16:21:00 Win2K-f 71.130.22.21 (PACBELL.NET):
WILLIAM MARTINEZ DBA,
PLANO, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
17:36:00 Win2K-f 195.22.21.71 (CLARA.NET):
VIA NET.WORKS PORTUGAL - TECNOLOGIAS DE INFORMA CAO SA,
PT.
n/a US:www.maxmind.com
US:getmyip.co.uk
US:www.getmyip.org
:checkip.dyndns.org
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:17:41:00 WinXP 122.26.205.211 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP.
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
NEW
none[0] ASM:Graph
none|none lines=61 trace
T:17:45:00 Win2K-f 195.22.21.71 (CLARA.NET):
VIA NET.WORKS PORTUGAL - TECNOLOGIAS DE INFORMA CAO SA,
PT.
n/a US:www.maxmind.com
US:checkip.dyndns.org
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:18:15:00 Win2K-f 24.80.110.208 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
BURNABY, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
123 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 41
34cbe7a593
NEW
3e83a2d4d7
NEW
d38cb78003 [0]
b97fd63d29[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:18:32:00 Win2K-f 174.6.59.189 (-):
.
n/a   135 pcap raw alerts
ruleset
other
186 lines
Yeah : 1.3
profile
none summary
tarball
34 of 39 ce28648035
NEW
126d2f4655 [0] ASM:Graph
none|none lines=546 trace
19:16:00 Win2K-f 202.53.84.155 (NETTLINX.COM):
NETTLINX LIMITED,
HYDERABAD, ANDHRA PRADESH, IN.
n/a US:www.maxmind.com 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 0.8
profile
none summary
tarball
7 of 37 7587773eea
NEW
none[3] none:none
StarForce| none trace
T:19:25:00 WinXP 91.63.83.230 (T-IPCONNECT.DE):
DEUTSCHE TELEKOM AG,
DE.
n/a RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
37 of 39 b8e39f84c2
NEW
51276fb869 [0] ASM:Graph
PolyEnE| lines=68 trace
T:19:34:00 WinXP 173.19.124.204 (-):
.
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
21:51:00 Win2K-f 190.48.240.15 (COM.AR):
TELEFONICA DE ARGENTINA,
BUENOS AIRES, BUENOS AIRES, AR.
n/a US:www.maxmind.com
US:getmyip.co.uk
US:www.getmyip.org
EU:checkip.dyndns.org
US:65.254.39.170:80
US:67.15.94.80:80
US:75.126.138.202:80
EU:91.198.22.70:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:22:56:00 WinXP 122.49.244.147 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32
33 of 33
07fabc79ef
NEW
53bfe15e91
NEW
none[0]
1473091351[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=81
lines=75
embedded dns
trace
trace
T:23:07:00 Win2K-f 118.221.10.210 (-):
.
218.93.205.24:65520 US:microsoft.com
CN:proxim.ircgalaxy.pl
CN:put.ghura.pl
CN:brenz.pl
CN:lometr.pl
:onuka.cn
US:ns2.msft.net
US:alt2.gmail-smtp-in.l.google.com
US:alt3.gmail-smtp-in.l.google.com
US:alt1.gmail-smtp-in.l.google.com
:alt4.gmail-smtp-in.l.google.com
CN:218.93.205.24:65520
CN:221.5.74.39:65520
US:64.191.104.197:3954
72.167.37.74:80
135 pcap raw alerts
ruleset
irc
http
316 lines
Yeah : 1.8
profile
none summary
tarball
18 of 41
15 of 41
4 of 41
31 of 41
29 of 32
24 of 40
1772d47c4c
NEW
298243013a
NEW
372b880eb1
NEW
50fea6b517
NEW
8a75955033
NEW
f1bb8174e3
NEW
8bd43a2dce [0]
b8c969e769[0]
164314a8cc[0]
9e7dff694f[0]
2bf3e548b9[0]
ff7d442dd1[0]
none:none
none:none
none:none
none:none
ASM:Graph
none:none
Stranik|
PEQuake|
Armadillo|
none|none
tElock|
none|none
none
none
none
none
lines=126
embedded dns
none
trace
trace
trace
trace
trace
trace
T:23:13:00 WinXP 208.125.40.153 (RR.COM):
ROAD RUNNER HOLDCO LLC,
BINGHAMTON, NEW YORK, US.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace