Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:08:00 | Win2K-f | 117.242.80.21 (-): . |
n/a | CZ:qtas.net CZ:t32.marund.net CZ:82.114.87.44:2345 CZ:82.114.87.44:80 |
445 | pcap | raw alerts ruleset |
http irc 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 41 | 73e6ee933b NEW |
711b1f9e71 [0] | none:none |
MingWin32| | none | trace |
T:01:24:00 | Win2K-f | 4.182.160.216 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:14:00 | WinXP | 207.5.209.117 (GWI.NET): GREAT WORKS INTERNET, ROCHESTER, NEW HAMPSHIRE, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:56:00 | WinXP | 74.75.26.41 (RR.COM): ROAD RUNNER HOLDCO LLC, PITTSFIELD, MASSACHUSETTS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:03:52:00 | WinXP | 64.75.158.16 (TURQUOISE.NET): HAWAII ONLINE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:12:00 | WinXP | 4.131.18.99 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BEDFORD, OHIO, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 25 lines |
Yeah : 0.8 profile |
none | summary tarball |
0 of 40 29 of 29 |
905fce8225 NEW df17a625ee NEW |
none[4] none [0] |
none:none none:none |
none|none ASPack| |
none lines=298 embedded dns |
trace trace |
T:04:38:00 | Win2K-f | 4.137.196.188 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CHARLOTTE, NORTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 146 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:57:00 | Win2K-f | 63.28.57.113 (UU.NET): UUNET TECHNOLOGIES INC, CHICAGO, ILLINOIS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 72 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 41 | fc30b25c46 NEW |
fc30b25c46 [1] | ASM:Graph |
FASM| | lines=40 | trace | |
T:05:06:00 | WinXP | 79.163.96.110 (-): IDEA, PL. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 06a5e31b47 NEW |
25e6e52787 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:15:00 | Win2K-f | 63.246.125.232 (SPEAKEASY.NET): US. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:44:00 | WinXP | 72.66.8.36 (VERIZON.NET): GAIP INC, VIENNA, VIRGINIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:27:00 | Win2K-f | 66.66.254.71 (RR.COM): ROAD RUNNER HOLDCO LLC, SCHENECTADY, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:08:50:00 | WinXP | 123.111.125.199 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
218.93.205.24:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com |
135 | pcap | raw alerts ruleset |
irc http 165 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 11 of 41 38 of 40 38 of 40 |
1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW 66863cfb13 NEW e8dfca0741 NEW |
8bd43a2dce [0] none [4] 209464113c[0] fca240f318[0] 20dfd2147c[0] |
none:none none:none none:none none:none none:none |
Stranik| Xtreme-Pr| none|none Armadillo| tElock| |
none none none none none |
trace trace trace trace trace |
T:09:38:00 | WinXP | 74.170.98.228 (BELLSOUTH.NET): BELLSOUTH.NET INC, JACKSONVILLE, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:08:00 | Win2K-f | 118.216.188.45 (-): . |
221.5.74.39:65520 85.114.137.60:80 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com CN:www.upononjob.cn :horobl.cn |
135 | pcap | raw alerts ruleset |
irc http 181 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 11 of 41 40 of 41 39 of 40 |
1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW a50c054e50 NEW f28964bd2f NEW |
8bd43a2dce [0] none [4] 209464113c[0] d5f51c70ad[0] a85e4a26c3[0] |
none:none none:none none:none none:none none:none |
Stranik| Xtreme-Pr| none|none tElock| Armadillo| |
none none none none none |
trace trace trace trace trace |
T:10:39:00 | WinXP | 4.225.18.190 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KOKOMO, INDIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:24:00 | WinXP | 116.125.27.76 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com |
135 | pcap | raw alerts ruleset |
irc http 133 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 11 of 41 29 of 32 28 of 32 |
1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW 8a75955033 NEW 9276c8b36b NEW |
8bd43a2dce [0] none [4] 209464113c[0] 2bf3e548b9[0] none [0] |
none:none none:none none:none ASM:Graph ASM:Graph |
Stranik| Xtreme-Pr| none|none tElock| Armadillo| |
none none none lines=126 embedded dns lines=81 |
trace trace trace trace trace |
T:11:26:00 | WinXP | 200.100.67.20 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:15:00 | WinXP | 92.40.87.200 (IKBCC.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:12:26:00 | WinXP | 4.131.20.228 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BEDFORD, OHIO, US. (DIAL) |
82.98.86.170:80 | DE:siliconfireware.ru DE:ebookfinaltrash.ru :wpad US:searchportal.information.com US:spi.domainsponsor.com DE:212.227.111.29:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http http http 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 29 | 3ce8dd4359 NEW |
cb80a979e8 [0] | ASM:Graph |
ASPack| | lines=2 | trace |
T:12:34:00 | WinXP | 61.99.41.146 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl :www.google.com CN:trisem.com BE:upload.octopus-multimedia.be CN:brenz.pl CN:lometr.pl GB:zz-dns.com |
135 | pcap | raw alerts ruleset |
irc http http http 189 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 15 of 41 31 of 33 24 of 33 21 of 41 26 of 41 |
1772d47c4c NEW 244f946118 NEW 298243013a NEW 6e2eaa0359 NEW 740e3bffe0 NEW 91a724a238 NEW c7781579ae NEW |
8bd43a2dce [0] none [4] b8c969e769[0] none [4] 421938c984[0] 504c125f39[0] 34a67bb407[0] |
none:none none:none none:none none:none none:none none:none none:none |
Stranik| Xtreme-Pr| PEQuake| PolyEnE| Armadillo| StarForce| tElock| |
none none none none none none none |
trace trace trace trace trace trace trace |
T:13:03:00 | Win2K-f | 208.103.154.99 (CORETEL.NET): CORETEL AMERICA INC, ANNAPOLIS, MARYLAND, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 169 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
13:39:00 | Win2K-f | 130.13.15.171 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:40:00 | WinXP | 24.231.107.8 (VDN.CA): BELL CANADA - CABLE VDN, MONTREAL, QUEBEC, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 38 of 41 |
3a7b76a7cb NEW a249d609b4 NEW |
e6e0573464 [0] b92719554f[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:14:15:00 | WinXP | 200.225.164.4 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 39 | b8e39f84c2 NEW |
51276fb869 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:14:36:00 | WinXP | 70.77.232.6 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
218.93.205.24:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl CN:put.ghura.pl :www.google.com CN:trisem.com BE:upload.octopus-multimedia.be CN:brenz.pl CN:lometr.pl DE:www.exerevenue.com GB:zz-dns.com CN:221.5.74.39:65520 |
445 | pcap | raw alerts ruleset |
http irc http http 37 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 18 of 41 10 of 41 11 of 41 26 of 41 21 of 41 |
0658d04f28 NEW 1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW 624ac030e2 NEW 91a724a238 NEW |
07f788a60e [0] 8bd43a2dce[0] none [4] 209464113c[0] 34a67bb407[0] 504c125f39[0] |
none:none none:none none:none none:none none:none none:none |
PolyEnE| Stranik| Xtreme-Pr| none|none tElock| StarForce| |
none none none none none none |
trace trace trace trace trace trace |
15:34:00 | Win2K-f | 162.42.208.14 (CYBERTRAILS.COM): CYBERTRAILS, SHOW LOW, ARIZONA, US. |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:43:00 | Win2K-f | 162.42.208.14 (CYBERTRAILS.COM): CYBERTRAILS, SHOW LOW, ARIZONA, US. |
n/a | US:www.maxmind.com US:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org DE:131.220.6.26:80 208.78.69.70:80 US:65.254.39.170:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
16:04:00 | Win2K-f | 202.104.188.123 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. |
n/a | US:www.maxmind.com US:www.getmyip.org US:checkip.dyndns.org US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:37:00 | WinXP | 76.173.107.51 (RR.COM): ROAD RUNNER HOLDCO LLC, SEAL BEACH, CALIFORNIA, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com SE:kavkazcenter.com SE:kavkazcenter.net FI:kavkazchat.com US:chechenpress.info GB:chechenpress.co.uk :shaheeds.org :daymohk.info :chripress.org :marsho.dk FI:imgs2.kavkazcenter.com :www.google.com FI:static.kavkazchat.com GB:www.chechenpress.co.uk US:72.29.65.216:80 |
445 | pcap | raw alerts ruleset |
http http 119 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | ab5e47bf8d NEW |
67fb5eff61 [0] | none:none |
ASPack| | none | trace |
T:16:46:00 | WinXP | 76.247.46.87 (PACBELL.NET): AT&T INTERNET SERVICES, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:17:20:00 | WinXP | 74.75.189.179 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | :www.google.com.au US:www.altavista.com :jbeegvia.ru |
135 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:17:45:00 | WinXP | 118.7.18.99 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:18:00:00 | WinXP | 200.31.8.159 (IMPSAT.NET.EC): IMPSAT ECUADOR-INTERNET DIALUP, QUITO, PICHINCHA, EC. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 96d089e522 NEW |
b9dd25bdfb [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
T:18:31:00 | WinXP | 76.241.135.4 (-): SE4.BCVLOH PPPOX, RICHARDSON, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
18:43:00 | Win2K-f | 162.42.208.14 (CYBERTRAILS.COM): CYBERTRAILS, SHOW LOW, ARIZONA, US. |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org EU:checkip.dyndns.org US:162.42.208.14:5884 US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:18:45:00 | WinXP | 124.241.189.71 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:14:00 | Win2K-f | 122.49.245.168 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:19:43:00 | WinXP | 119.56.69.21 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 40 | 4ab228985c NEW |
4ef788e7d5 [0] | none:none |
PolyEnE| | none | trace | |
20:59:00 | Win2K-f | 121.63.161.2 (163DATA.COM.CN): CHINANET HUBEI PROVINCE NETWORK, WUHAN, HUBEI, CN. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org US:getmyip.co.uk US:65.254.39.170:80 US:67.15.94.80:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 3862324588 NEW |
none[3] | none:none |
UPX| | none | trace |
T:21:33:00 | Win2K-f | 190.12.130.215 (SUPERCABLETV.NET.CO): SUPERCABLE TELECOMUNICACIONES, CO. |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 394 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 41 | 1b3feab839 NEW |
6c9f33ae69 [0] | none:none |
StarForce| | none | trace |
T:21:35:00 | WinXP | 217.114.236.87 (AHA.RU): PROVIDER LOCAL INTERNET REGISTRY, RU. |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 435 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 41 | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:21:36:00 | Win2K-f | 201.221.118.129 (-): . |
n/a | :mysql.unibaq.com | 135 | pcap | raw alerts ruleset |
irc 114 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 40 | bac17fb3bc NEW |
fc2c78c658 [0] | none:none |
PENinja S| | none | trace |
T:21:51:00 | WinXP | 188.17.80.140 (DAVITA.COM): VARIOUS REGISTRIES, UK. |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 404 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 | b625cc283c NEW |
cd3e986e95 [0] | none:none |
StarForce| | none | trace |
T:21:52:00 | WinXP | 190.209.121.251 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 454 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 41 | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:21:59:00 | WinXP | 95.37.137.13 (-): . |
200.204.157.111:5555 | BR:fix.drshells.com | 135 | pcap | raw alerts ruleset |
irc 518 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:04:00 | WinXP | 95.104.44.68 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 407 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 41 | b18e98061e NEW |
cd3e986e95 [0] | none:none |
StarForce| | none | trace |
T:22:07:00 | Win2K-f | 190.108.6.108 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 416 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 41 | b146ebb992 NEW |
cd3e986e95 [0] | none:none |
StarForce| | none | trace |
T:22:08:00 | Win2K-f | 89.214.115.128 (-): TMN - TELECOMUNICACOES MOVEIS NACIONAIS SA, PT. |
61.120.62.28:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 885 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:22:09:00 | WinXP | 190.31.163.216 (NET.AR): APOLO -GOLD-TELECOM-PER, AR. |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 500 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:22:00 | Win2K-f | 186.100.160.110 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 443 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 41 | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
22:25:00 | Win2K-f | 200.49.20.85 (BSR1000.PAPNET.CL): PLUG AND PLAY NET S.A, CL. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:getmyip.co.uk US:www.getmyip.org US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:22:26:00 | WinXP | 190.0.79.105 (ASTER.COM.DO): ASTER, SANTO DOMINGO, DISTRITO NACIONAL, DO. |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 475 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 41 | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:22:31:00 | WinXP | 190.209.120.47 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 423 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 | 041b82a1ae NEW |
041b82a1ae [1] | ASM:Graph |
StarForce| | lines=88 | trace |
T:22:34:00 | Win2K-f | 200.49.20.85 (BSR1000.PAPNET.CL): PLUG AND PLAY NET S.A, CL. |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk US:checkip.dyndns.org 208.78.69.70:80 US:65.254.39.170:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:22:46:00 | WinXP | 190.209.15.80 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 440 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 41 | c0f08def5e NEW |
c64727de72 [0] | none:none |
StarForce| | none | trace |
T:22:54:00 | Win2K-f | 186.100.201.11 (-): . |
190.12.5.5:6669 | MD:X5.l1qu1d.net | 135 | pcap | raw alerts ruleset |
irc 418 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 40 | 25377c183b NEW |
86f99a7a67 [0] | none:none |
StarForce| | none | trace |
T:23:34:00 | Win2K-f | 76.173.110.134 (RR.COM): ROAD RUNNER HOLDCO LLC, SEAL BEACH, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 41 |
53bfe15e91 NEW 78db854b5b NEW |
1473091351 [0] 209f80de5b[0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns none |
trace trace |
T:23:40:00 | WinXP | 75.60.208.95 (SBCGLOBAL.NET): PPPOX POOL - SE1.WOTNOH, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |