Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:49:00 | Win2K-f | 124.195.156.74 (-): . |
218.93.205.24:65520 85.114.137.60:80 | US:microsoft.com CN:proxim.ircgalaxy.pl CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com |
135 | pcap | raw alerts ruleset |
irc http 150 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 11 of 41 38 of 41 36 of 41 |
1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW 6c887ab06d NEW c3c69766b2 NEW |
8bd43a2dce [0] none [4] 209464113c[0] a0d5f064f8[0] acdd4c83bd[0] |
none:none none:none none:none none:none none:none |
Stranik| Xtreme-Pr| none|none tElock| Armadillo| |
none none none none none |
trace trace trace trace trace |
T:01:35:00 | WinXP | 63.28.113.122 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:38:00 | WinXP | 41.202.176.42 (-): . |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 0505ea7e51 NEW |
6fde8a0b6c [0] | none:none |
PolyEnE| | none | trace |
T:01:47:00 | WinXP | 173.21.231.50 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
03:16:00 | Win2K-f | 88.39.99.105 (BUSINESS.TELECOMITALIA.IT): S.G.B. GEVI SPA, NAPOLI, CAMPANIA, IT. (100Mbps) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org US:getmyip.co.uk US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:03:25:00 | Win2K-f | 88.39.99.105 (BUSINESS.TELECOMITALIA.IT): S.G.B. GEVI SPA, NAPOLI, CAMPANIA, IT. (100Mbps) |
n/a | US:www.maxmind.com | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:23:00 | Win2K-f | 58.235.121.27 (-): THRUNET-INFRA-BUSAN15, SEOUL, KYONGGI-DO, KR. |
221.5.74.39:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:brenz.pl CN:lometr.pl DE:www.exerevenue.com CN:221.5.74.39:65520 |
135 | pcap | raw alerts ruleset |
irc http 131 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 30 of 33 28 of 33 11 of 41 21 of 41 |
1772d47c4c NEW 244f946118 NEW 533d15b5ce NEW 58c343a8d8 NEW 5df8069b2c NEW 91a724a238 NEW |
8bd43a2dce [0] none [4] c67adf46e2[0] none [0] 209464113c[0] 504c125f39[0] |
none:none none:none ASM:Graph none:none none:none none:none |
Stranik| Xtreme-Pr| tElock| Armadillo| none|none StarForce| |
none none lines=126 embedded dns lines=91 none none |
trace trace trace trace trace trace |
T:04:24:00 | WinXP | 77.64.140.39 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c05290bb06 NEW |
dddfe6a7fe [0] | none:none |
PolyEnE| | none | trace |
T:04:40:00 | WinXP | 78.250.221.151 (PRESTONAUTO.COM): PROXAD INTERNET SERVICE PROVIDER IN FRANCE, PARIS, ILE-DE-FRANCE, FR. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 32989f917c NEW |
8772fbc6f6 [0] | none:none |
PolyEnE| | none | trace |
T:04:55:00 | WinXP | 87.54.193.89 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
210.166.223.51:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 753 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 4a8c393d7e NEW |
678c362a37 [0] | none:none |
StarForce| | none | trace |
T:05:01:00 | Win2K-f | 88.172.25.50 (PROXAD.NET): PROXAD / FREE SAS, FR. |
190.12.5.5:6669 | :X5.l1qu1d.net EC:190.12.5.5:6669 |
135 | pcap | raw alerts ruleset |
irc 450 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 41 | 29fffb4de5 NEW |
b6fbac850b [0] | none:none |
StarForce| | none | trace |
05:19:00 | Win2K-f | 81.40.14.37 (RIMA-TDE.NET): TELEFONICA DE ESPANA SAU, MADRID, MADRID, ES. |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:51:00 | WinXP | 114.162.22.44 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:05:52:00 | WinXP | 4.131.16.164 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BEDFORD, OHIO, US. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:turing.oversee.net US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 30 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee NEW |
none[0] | none:none |
ASPack| | lines=298 embedded dns |
trace |
T:08:19:00 | WinXP | 75.43.214.122 (SBCGLOBAL.NET): PPPOX POOL - BRAS2.LSAN, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 34 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:08:44:00 | WinXP | 219.255.25.241 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
218.93.205.24:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com |
135 | pcap | raw alerts ruleset |
irc http 168 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 11 of 41 30 of 33 31 of 33 |
1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW 87bd0a062f NEW c7d6018f97 NEW |
8bd43a2dce [0] none [4] 209464113c[0] dc70d9623a[0] 5c1d8bbd5b[0] |
none:none none:none none:none none:none none:none |
Stranik| Xtreme-Pr| none|none Armadillo| tElock| |
none none none none none |
trace trace trace trace trace |
T:08:51:00 | WinXP | 70.77.232.86 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
221.5.74.39:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com |
445 | pcap | raw alerts ruleset |
http irc 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 18 of 41 10 of 41 11 of 41 |
0658d04f28 NEW 1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW |
07f788a60e [0] 8bd43a2dce[0] none [4] 209464113c[0] |
none:none none:none none:none none:none |
PolyEnE| Stranik| Xtreme-Pr| none|none |
none none none none |
trace trace trace trace |
T:09:07:00 | WinXP | 76.15.117.175 (-): . |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad GB:welcome3.smile.co.uk GB:195.92.84.198:80 |
445 | pcap | raw alerts ruleset |
http http http 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
0 of 41 29 of 29 |
8fadd74f25 NEW df17a625ee NEW |
none[4] none [0] |
none:none none:none |
none|none ASPack| |
none lines=298 embedded dns |
trace trace |
T:09:33:00 | WinXP | 94.251.185.142 (-): . |
221.5.74.39:65520 | CN:proxim.ircgalaxy.pl RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:10:10:00 | Win2K-f | 64.144.35.70 (LADDFINANCIAL.COM): DSL.NET INC, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:25:00 | WinXP | 76.167.188.23 (RR.COM): ROAD RUNNER HOLDCO LLC, CHINO HILLS, CALIFORNIA, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad |
445 | pcap | raw alerts ruleset |
http http http 29 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0ada72d805 NEW |
none[0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
T:10:46:00 | Win2K-f | 211.49.192.112 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, PYEONGTAEK, KYONGGI-DO, KR. |
218.93.205.24:65520 85.114.137.60:80 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com CN:218.93.205.24:65520 |
135 | pcap | raw alerts ruleset |
irc http 141 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 10 of 41 11 of 41 29 of 32 28 of 32 |
1772d47c4c NEW 244f946118 NEW 5df8069b2c NEW 8a75955033 NEW 9276c8b36b NEW |
8bd43a2dce [0] none [4] 209464113c[0] 2bf3e548b9[0] none [0] |
none:none none:none none:none ASM:Graph ASM:Graph |
Stranik| Xtreme-Pr| none|none tElock| Armadillo| |
none none none lines=126 embedded dns lines=81 |
trace trace trace trace trace |
T:11:13:00 | WinXP | 114.32.140.186 (-): . |
221.5.74.39:65520 85.114.137.60:80 218.93.205.24:65520 | CN:proxim.ircgalaxy.pl CN:brenz.pl CN:lometr.pl CN:put.ghura.pl DE:www.exerevenue.com CN:www.webalfa.cn |
445 | pcap | raw alerts ruleset |
shell ftp irc http 59 lines |
Yeah : 1.8 profile |
none | summary tarball |
18 of 41 15 of 41 19 of 41 11 of 41 38 of 40 19 of 41 |
1772d47c4c NEW 298243013a NEW 2fd99ca961 NEW 5df8069b2c NEW 7bc8d57d8c NEW ba587fa75c NEW |
8bd43a2dce [0] b8c969e769[0] 1ad221dc34[0] 209464113c[0] be025ab204[0] ba587fa75c[1] |
none:none none:none none:none none:none none:none ASM:Graph |
Stranik| PEQuake| StarForce| none|none none|none Stranik| |
none none none none none lines=0 |
trace trace trace trace trace trace |
T:11:15:00 | WinXP | 93.108.112.232 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:11:32:00 | WinXP | 86.142.179.74 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
218.93.205.24:65520 | CN:put.ghura.pl :www.google.com CN:trisem.com BE:upload.octopus-multimedia.be CN:brenz.pl CN:proxim.ircgalaxy.pl CN:www.webalfa.cn CN:211.95.79.6:80 |
445 | pcap | raw alerts ruleset |
irc http http http http http 60 lines |
Yeah : 0.8 profile |
none | summary tarball |
15 of 41 27 of 41 21 of 41 |
298243013a NEW 7601d29070 NEW 91a724a238 NEW |
b8c969e769 [0] 34a67bb407[0] 504c125f39[0] |
none:none none:none none:none |
PEQuake| tElock| StarForce| |
none none none |
trace trace trace |
T:11:56:00 | WinXP | 70.182.172.62 (COX.NET): COX COMMUNICATIONS, ATLANTA, GEORGIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:19:00 | Win2K-f | 173.19.215.26 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:27:00 | WinXP | 76.244.155.139 (PACBELL.NET): AT&T INTERNET SERVICES, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:14:00 | WinXP | 187.22.201.108 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | c4466f7a54 NEW |
cb6c5c5ff0 [0] | none:none |
PolyEnE| | none | trace |
T:13:33:00 | WinXP | 72.67.206.75 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. (100Mbps) |
61.120.62.28:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | 69f8ccc92e NEW |
e9613e6868 [0] | none:none |
StarForce| | none | trace |
T:14:16:00 | WinXP | 95.74.187.47 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:20:00 | Win2K-f | 190.51.132.61 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | US:www.maxmind.com US:checkip.dyndns.org US:getmyip.co.uk US:www.getmyip.org US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:15:21:00 | WinXP | 99.163.48.62 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:15:22:00 | WinXP | 68.146.213.189 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1004 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 | 177beeaf73 NEW |
none[3] | none:none |
StarForce| | none | trace | |
T:15:57:00 | WinXP | 4.229.198.63 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:03:00 | WinXP | 122.55.151.165 (PLDT.NET): IPG, PH. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 | 6529257178 NEW |
71e290f942 [0] | none:none |
none|none | none | trace | |
T:16:46:00 | Win2K-f | 173.19.83.178 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:51:00 | WinXP | 72.21.142.114 (-): ACETECH USA INC, LIBERTY LAKE, WASHINGTON, US. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :wpad |
445 | pcap | raw alerts ruleset |
http http http 29 lines |
Yeah : 0.8 profile |
none | summary tarball |
0 of 41 29 of 29 |
50f473a5fe NEW df17a625ee NEW |
none[4] none [0] |
none:none none:none |
none|none ASPack| |
none lines=298 embedded dns |
trace trace |
T:19:36:00 | Win2K-f | 74.75.26.41 (RR.COM): ROAD RUNNER HOLDCO LLC, PITTSFIELD, MASSACHUSETTS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:20:18:00 | Win2K-f | 70.182.78.44 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 89 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 38 of 41 |
53bfe15e91 NEW e1b108bd6d NEW |
1473091351 [0] fc828d3918[0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns none |
trace trace |
20:19:00 | Win2K-f | 116.6.14.242 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk EU:checkip.dyndns.org US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:20:37:00 | WinXP | 98.149.112.99 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 60 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:21:36:00 | Win2K-f | 74.211.53.122 (BEYONDBB.COM): ORANGE BROADBAND, CHARLOTTE, NORTH CAROLINA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
4 of 41 | a8c1c0e956 NEW |
df796d44f5 [0] | none:none |
StarForce| | none | trace | |
T:22:02:00 | WinXP | 79.132.200.107 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 173232485c NEW |
65a8f41baa [0] | none:none |
PolyEnE| | none | trace |
T:22:03:00 | Win2K-f | 117.242.80.18 (-): . |
n/a | CZ:qtas.net CZ:82.114.87.44:80 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:54:00 | Win2K-f | 222.239.170.94 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:brenz.pl CN:211.95.79.6:80 |
135 | pcap | raw alerts ruleset |
irc 134 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 |
533d15b5ce NEW 58c343a8d8 NEW |
c67adf46e2 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=126 embedded dns lines=91 |
trace trace |
23:03:00 | WinXP | 67.150.140.202 (MDSG-PACWEST.COM): PAC-WEST MANAGED MODEM NAS POOL, SACRAMENTO, CALIFORNIA, US. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |