Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:35:00 | Win2K-f | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:00:44:00 | WinXP | 203.73.84.199 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:01:00 | Win2K-f | 173.28.209.165 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 415 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | a52f10d936 NEW |
8252b99ecb [0] | none:none |
PENinja S| | none | trace | |
T:01:14:00 | WinXP | 96.49.135.75 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:24:00 | WinXP | 114.48.208.184 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
02:38:00 | Win2K-f | 186.18.49.46 (-): . |
n/a | US:www.maxmind.com US:getmyip.co.uk EU:checkip.dyndns.org 186.18.49.46:4024 US:65.254.39.170:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:03:37:00 | WinXP | 114.121.2.60 (-): . |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
05:59:00 | Win2K-f | 92.48.68.9 (IKBCC.COM): EU-ZZ, UK. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org US:getmyip.co.uk US:65.254.39.170:80 US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:08:00 | Win2K-f | 92.48.68.9 (IKBCC.COM): EU-ZZ, UK. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:35:00 | WinXP | 112.110.46.47 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 824d6a706e NEW |
a66fd13bcb [0] | none:none |
PolyEnE| | none | trace | |
T:06:36:00 | Win2K-f | 110.11.82.208 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 100 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
372580ac1d NEW fc493d3732 NEW |
4d82137ab0 [0] 16e365df5b[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:07:36:00 | WinXP | 211.74.91.124 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | bd81d71c06 NEW |
1993ba73cd [0] | none:none |
PolyEnE| | none | trace |
T:07:40:00 | WinXP | 86.99.94.85 (NET.AE): EMIRATES TELECOMMUNICATIONS CORPORATION, DUBAI, DUBAI, AE. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 453 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 47c7e9af76 NEW |
22bcd9c8fe [0] | none:none |
StarForce| | none | trace |
T:07:41:00 | Win2K-f | 89.174.119.156 (GTSENERGIS.PL): GTS POLSKA SP. Z O.O, PL. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 387 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | d0e7723e9b NEW |
6c9f33ae69 [0] | none:none |
StarForce| | none | trace |
T:07:44:00 | WinXP | 82.64.114.168 (PROXAD.NET): PROXAD / FREE SAS, FR. (DSL) |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 462 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 88b3b7a353 NEW |
e8769ee902 [0] | none:none |
StarForce| | none | trace |
T:07:44:00 | Win2K-f | 190.231.142.246 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 455 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:07:49:00 | WinXP | 92.96.220.44 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 408 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 1b3feab839 NEW |
6c9f33ae69 [0] | none:none |
StarForce| | none | trace |
07:50:00 | WinXP | 87.123.81.78 (VERSANET.DE): VERSATEL DEUTSCHLAND DYNAMIC POOL, BERLIN, BERLIN, DE. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 434 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | e6666eeeda NEW |
067414a093 [0] | none:none |
StarForce| | none | trace |
T:07:54:00 | Win2K-f | 77.47.108.97 (CABLESURF.DE): KABELFERNSEHEN MUENCHEN SERVICENTER GMBH & CO.KG, MUNICH, BAYERN, DE. (DSL) |
61.120.62.28:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 1007 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:07:58:00 | WinXP | 89.254.144.138 (-): OSTKOM, LV. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 475 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
08:05:00 | WinXP | 211.74.91.124 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | bd81d71c06 NEW |
1993ba73cd [0] | none:none |
PolyEnE| | none | trace |
T:08:08:00 | WinXP | 201.204.242.162 (ICE.CO.CR): INSTITUTO COSTARRICENSE DE ELECTRICIDAD Y TELECOM, CR. |
89.138.22.15:6669 | IL:X5.l1qu1d.net :dc143.4shared.com |
135 | pcap | raw alerts ruleset |
irc 492 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:08:15:00 | Win2K-f | 186.81.153.51 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net :dc143.4shared.com |
135 | pcap | raw alerts ruleset |
irc 412 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 041b82a1ae NEW |
041b82a1ae [1] | ASM:Graph |
StarForce| | lines=88 | trace |
T:08:17:00 | Win2K-f | 190.209.76.45 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net :dc143.4shared.com IL:89.138.22.15:6669 |
135 | pcap | raw alerts ruleset |
irc 456 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:08:22:00 | WinXP | 190.255.50.234 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net IL:89.138.22.15:6669 |
135 | pcap | raw alerts ruleset |
irc 451 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:08:23:00 | WinXP | 190.55.211.197 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 458 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
08:39:00 | Win2K-f | 115.81.135.131 (-): . |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org US:getmyip.co.uk US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:08:46:00 | Win2K-f | 190.66.10.189 (TELECOM.COM.CO): COLOMBIA TELECOMUNICACIONES S.A. ESP, CO. |
67.43.236.66:10324 72.10.172.211:8080 | CA:xx.nadnadzz.info CA:xx.ka3ek.com :nadsamcabran12.com 67.215.1.206:80 CA:67.43.236.66:10324 |
135 | pcap | raw alerts ruleset |
irc 126 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 | a4dde6f9e4 NEW |
none[4] | none:none |
none|none | none | trace |
T:09:06:00 | WinXP | 68.210.231.104 (BELLSOUTH.NET): BELLSOUTH.NET INC, AIKEN, SOUTH CAROLINA, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:www.bbin.ru RU:www.binbank.ru :wpad US:204.13.161.51:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http http http 31 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:09:11:00 | WinXP | 190.255.72.190 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 702 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:09:29:00 | WinXP | 91.152.122.74 (ELISA-LAAJAKAISTA.FI): ELISA-ADSL, ESPOO, ETELA-SUOMEN LAANI, FI. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 434 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:09:29:00 | Win2K-f | 186.81.60.39 (-): . |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 411 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | b625cc283c NEW |
cd3e986e95 [0] | none:none |
StarForce| | none | trace |
T:09:35:00 | Win2K-f | 217.114.5.253 (SKY.RU): SKYNET-CLNT-NPOA, EKATERINBURG, SVERDLOVSKAYA OBLAST', RU. (100Mbps) |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 426 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:09:49:00 | WinXP | 190.55.246.67 (-): . |
n/a | IL:X5.l1qu1d.net IL:89.138.22.15:6669 |
135 | pcap | raw alerts ruleset |
irc 433 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | d4c829bd4b NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:09:53:00 | Win2K-f | 89.41.92.183 (HOST-89-41-64-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. |
n/a | IL:X5.l1qu1d.net IL:89.138.22.15:6669 |
135 | pcap | raw alerts ruleset |
irc 427 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:10:00:00 | WinXP | 201.234.254.106 (COM.AR): VER TV S.A, BUENOS AIRES, BUENOS AIRES, AR. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 379 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 1b3feab839 NEW |
6c9f33ae69 [0] | none:none |
StarForce| | none | trace |
T:10:04:00 | WinXP | 86.10.147.100 (NTL.COM): NTLI, UK. |
89.138.22.15:6669 | IL:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 396 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 526615a393 NEW |
63943ff544 [0] | none:none |
StarForce| | none | trace |
T:10:18:00 | WinXP | 211.202.194.35 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:lometr.pl US:www.microsoft.com :zaikod.cn |
135 | pcap | raw alerts ruleset |
irc http lanman 273 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 15 of 41 none none 31 of 41 38 of 41 |
1772d47c4c NEW 298243013a NEW 4faab4a9f5 NEW 898e8c400b NEW c61078e573 NEW d80521c9d9 NEW |
8bd43a2dce [0] b8c969e769[0] 4faab4a9f5[1] b2ed41db60[0] 670955f966[0] 6d39f1a62e[0] |
none:none none:none ASM:Graph none:none none:none none:none |
Stranik| PEQuake| Armadillo| Armadillo| Armadillo| tElock| |
none none lines=608 none none none |
trace trace trace trace trace trace |
T:10:28:00 | Win2K-f | 91.66.9.18 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | db4b4d507c NEW |
1f2fc1a994 [0] | none:none |
none|none | none | trace |
T:10:35:00 | WinXP | 67.52.237.117 (RR.COM): ROAD RUNNER HOLDCO LLC, KANSAS CITY, MISSOURI, US. |
n/a | :moscow-advokat.ru AT:graz.at.eu.undernet.org |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 6b796d4152 NEW |
4ceb4e4e5a [0] | none:none |
pex| | none | trace |
T:11:14:00 | Win2K-f | 82.10.198.21 (NTL.COM): NTL INFRASTRUCTURE - WALTHAM PARK, UK. (DSL) |
66.252.13.214:2081 | US:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 67a66839f7 NEW |
7b1fc808a3 [0] | none:none |
none|none | none | trace |
T:11:41:00 | WinXP | 216.19.43.153 (COMMSPEED.NET): COMMSPEED ARIZONA LLC, COTTONWOOD, ARIZONA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:54:00 | WinXP | 63.28.70.186 (UU.NET): UUNET TECHNOLOGIES INC, HONOLULU, HAWAII, US. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
28 of 35 | 452313e1c7 NEW |
a6402924ba [0] | none:none |
ASPack| | none | trace |
T:12:06:00 | Win2K-f | 67.10.66.79 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
12:42:00 | Win2K-f | 200.35.216.52 (SUPERCABLE.NET.VE): SUPERCABLE, CARACAS, DISTRITO FEDERAL, VE. (DSL) |
n/a | US:www.maxmind.com US:getmyip.co.uk EU:checkip.dyndns.org US:www.getmyip.org US:65.254.39.170:80 US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 3862324588 NEW |
none[3] | none:none |
UPX| | none | trace |
T:13:47:00 | Win2K-f | 172.131.207.114 (AOL.COM): AMERICA ONLINE, RESTON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 106 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:25:00 | WinXP | 4.226.9.223 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MIDLOTHIAN, TEXAS, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 29 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:15:52:00 | WinXP | 89.111.226.247 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:16:11:00 | WinXP | 207.5.155.42 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:16:39:00 | WinXP | 70.166.105.37 (COX.NET): COX COMMUNICATIONS, SURPRISE, ARIZONA, US. |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 356 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 1e4f8f9259 NEW |
e73db583fd [0] | none:none |
none|none | none | trace |
T:16:41:00 | WinXP | 173.22.151.254 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:16:44:00 | Win2K-f | 209.102.247.224 (LEXCOMINC.NET): LEXCOM TELEPHONE, LANCASTER, SOUTH CAROLINA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1074 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 2a09bf2f60 NEW |
none[3] | none:none |
none|none | none | trace | |
16:48:00 | Win2K-f | 190.208.70.162 (-): . |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | d60e538e72 NEW |
none[3] | none:none |
UPX| | none | trace |
T:17:30:00 | Win2K-f | 114.37.69.156 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:40:00 | WinXP | 121.115.133.144 (PLALA.OR.JP): PLALA NETWORKS INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:18:06:00 | WinXP | 172.165.37.248 (AOL.COM): AMERICA ONLINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:25:00 | Win2K-f | 24.27.121.254 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:08:00 | WinXP | 93.102.71.144 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:www.altavista.com US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:19:15:00 | WinXP | 93.102.68.69 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:19:19:00 | WinXP | 99.20.195.252 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:19:51:00 | WinXP | 173.51.175.122 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 2f6afffda4 NEW |
ede9ae4e6d [0] | none:none |
PolyEnE| | none | trace |
T:20:17:00 | WinXP | 70.247.154.13 (SWBELL.NET): PPPOX POOL - BRAS3.OKCYOK, OKLAHOMA CITY, OKLAHOMA, US. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:24:00 | WinXP | 207.5.155.42 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:20:35:00 | WinXP | 71.112.12.131 (VERIZON.NET): VERIZON INTERNET SERVICES INC, BOTHELL, WASHINGTON, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 2d16d63f91 NEW |
27cb26ee14 [0] | none:none |
PolyEnE| | none | trace |
T:20:43:00 | WinXP | 211.110.32.140 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:lometr.pl NL:teenagersporn.net |
135 | pcap | raw alerts ruleset |
irc http 167 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 18 of 41 15 of 41 30 of 33 none |
176fe26a6e NEW 1772d47c4c NEW 298243013a NEW 2ef9098242 NEW 863428a979 NEW |
none[4] 8bd43a2dce[0] b8c969e769[0] de91d8b5d0[0] a6fe83396d[0] |
none:none none:none none:none none:none none:none |
PolyEnE| Stranik| PEQuake| Armadillo| none|none |
none none none none none |
trace trace trace trace trace |
T:21:13:00 | Win2K-f | 71.111.208.232 (VERIZON.NET): VERIZON INTERNET SERVICES INC, DURHAM, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:34:00 | WinXP | 71.116.212.170 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:07:00 | Win2K-f | 24.234.205.141 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 460 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | f19387f40e NEW |
ab37c11b34 [0] | none:none |
ASProtect| | none | trace | |
22:21:00 | Win2K-f | 59.104.254.118 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org DE:131.220.6.26:80 US:65.254.39.170:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:22:30:00 | Win2K-f | 59.104.254.118 (SEED.NET.TW): DIGITAL UNITED I, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org US:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
6 of 37 | 13e15a653e NEW |
none[3] | none:none |
UPX| | none | trace |
T:23:27:00 | Win2K-f | 122.49.244.241 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:23:37:00 | Win2K-f | 203.118.238.245 (-): GRAND TAINAN TECHNOLOGY CO.LTD, TAINAN, KAO-HSIUNG, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |