Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:51:00 | Win2K-f | 114.203.72.50 (-): . |
218.93.205.24:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com CN:www.zief.pl CN:dretis.cn CN:kritq.cn :onuka.cn US:client155.faster-hosting.com 116.75.103.108:3128 119.204.13.54:3128 119.63.138.160:3128 PH:122.2.120.48:3128 PH:122.54.26.244:3128 123.237.99.93:3128 124.153.224.40:3128 CN:124.95.103.37:3128 KR:210.116.189.162:3128 KR:211.246.215.29:3128 KR:221.160.223.56:3128 |
135 | pcap | raw alerts ruleset |
irc http 302 lines |
Yeah : 1.8 profile |
none | summary tarball |
7 of 41 26 of 41 17 of 41 7 of 41 34 of 36 29 of 32 16 of 41 |
18dfbbc85b NEW 2e4a7c4e94 NEW 36b2aae01e NEW 5354e986cd NEW 99b248336f NEW 9d677c3f70 NEW cfcdd90ac1 NEW |
4f6fcecea3 [0] 9c3a214ff5[0] a4b7eefc40[0] 55eb7e6494[0] c64bd1a776[0] 77e75ff10f[0] 2f95782b9b[0] |
none:none none:none none:none none:none none:none none:none none:none |
UPX| ASPack| StarForce| PENinja| Armadillo| tElock| StarForce| |
none none none none none none none |
trace trace trace trace trace trace trace |
T:01:14:00 | Win2K-f | 84.75.62.118 (HISPEED.CH): CABLECOMMAIN-NET, ZURICH, ZURICH, CH. (DSL) |
n/a | :groups.yahoo.com NL:us.js2.yimg.com :l.yimg.com NL:us.i1.yimg.com NL:ads.yimg.com NL:us.bcast1.yimg.com :ad.yieldmanager.com US:us.bc.yahoo.com :ads.bluelithium.com 112.200.93.104:6667 124.153.235.31:6667 CN:124.165.110.229:6667 CN:125.62.48.47:6667 CN:211.142.178.34:6667 KR:211.223.33.26:6667 MY:60.54.123.252:6667 US:66.94.242.24:80 |
445 | pcap | raw alerts ruleset |
irc http http 73 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:45:00 | WinXP | 114.204.70.102 (-): . |
218.93.205.24:65520 216.245.213.194:80 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:dretis.cn CN:kritq.cn :onuka.cn 112.201.114.101:3128 116.75.103.108:3128 123.237.215.162:3128 KR:165.194.83.189:3128 187.44.31.42:3128 BR:189.23.153.33:3128 189.79.213.149:3128 KR:210.108.183.12:3128 KR:211.107.56.136:3128 CN:211.142.178.34:3128 KR:211.192.165.158:3128 RO:86.124.109.166:3128 PL:89.228.47.21:3128 |
135 | pcap | raw alerts ruleset |
irc http http http 125 lines |
Yeah : 1.8 profile |
none | summary tarball |
16 of 41 30 of 33 7 of 41 28 of 33 26 of 41 |
325cdc4edb NEW 533d15b5ce NEW 5354e986cd NEW 58c343a8d8 NEW cf0dff3130 NEW |
8650c0e241 [0] c67adf46e2[0] 55eb7e6494[0] none [0] 9c3a214ff5[0] |
none:none ASM:Graph none:none none:none none:none |
StarForce| tElock| PENinja| Armadillo| ASPack| |
none lines=126 embedded dns none lines=91 none |
trace trace trace trace trace |
T:02:24:00 | Win2K-f | 210.79.177.153 (MEDIATTI.NET): MEDIATTI COMMUNICATIONS INC, OKINAWA, OKINAWA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 92 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
3ed16ae12d NEW 79c01ec060 NEW |
none[0] 1bfd34056c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=64 embedded dns |
trace trace |
T:02:51:00 | WinXP | 86.155.23.8 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SWANSEA, WALES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:03:10:00 | Win2K-f | 118.221.182.152 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 41 39 of 40 |
eaa0c6f82c NEW fc493d3732 NEW |
61fd82b754 [0] 16e365df5b[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:03:29:00 | WinXP | 24.103.196.250 (-): . |
67.43.236.66:8080 72.10.172.211:8080 | :xx.enterhere.biz CA:xx.ka3ek.com :nadsamcabran12.com CA:67.43.226.242:8080 CA:67.43.236.66:8080 |
135 | pcap | raw alerts ruleset |
irc http 350 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 38 37 of 40 |
524bc0f75c NEW a0a15f5ebf NEW |
d3e9510bb3 [0] c506c7cc86[0] |
none:none none:none |
PENinja
S| Mew| |
none none |
trace trace |
T:03:46:00 | WinXP | 114.48.143.108 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:04:20:00 | Win2K-f | 96.10.73.83 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:39:00 | Win2K-f | 76.168.31.169 (RR.COM): ROAD RUNNER HOLDCO LLC, PACIFIC PALISADES, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:59:00 | WinXP | 71.15.238.14 (CHARTER.COM): CHARTER COMMUNICATIONS, SUFFOLK, VIRGINIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:00:00 | Win2K-f | 125.4.241.87 (ZAQ.NE.JP): KITAKAWACHI CABLE NET CO LTD, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
2e45ae247e NEW 53bfe15e91 NEW |
36aa8cd03d [0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
none lines=75 embedded dns |
trace trace |
T:06:25:00 | Win2K-f | 12.204.1.6 (ATT.NET): AT&T WORLDNET SERVICES, BOULDER, COLORADO, US. |
n/a | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl IL:xt67ur.wwlax.com CN:dretis.cn IL:bugreport.waverevenue.com IL:tidwhmep.s4upd.com CN:kritq.cn IL:rec.bestrevenue.net US:b152.bundlext.com IL:62.90.134.24:80 |
135 | pcap | raw alerts ruleset |
irc http 475 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 7 of 41 37 of 41 28 of 41 38 of 41 13 of 41 19 of 41 1 of 41 |
18dfbbc85b NEW 5354e986cd NEW 574fe82ce3 NEW 6648e7022b NEW 95d0f82a9b NEW 9857a367e2 NEW cd88b89d5e NEW d28f46aa2b NEW |
4f6fcecea3 [0] 55eb7e6494[0] 99a500f47b[0] 0ad0f97bcc[0] 4ff81f1a63[0] 8d4e5ce4de[0] 150e365b1e[0] 47edcab014[0] |
none:none none:none none:none none:none none:none none:none none:none none:none |
UPX| PENinja| PolyEnE| UPX| Armadillo| ASProtect| UPX| StarForce| |
none none none none none none none none |
trace trace trace trace trace trace trace trace |
T:06:42:00 | Win2K-f | 124.165.48.68 (-): CNCGROUP SHAN1XI PROVINCE NETWORK, CN. |
n/a | CN:proxim.ircgalaxy.pl CN:dretis.cn CN:kritq.cn |
445 | pcap | raw alerts ruleset |
irc http 97 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 41 1 of 41 |
5354e986cd NEW d28f46aa2b NEW |
55eb7e6494 [0] 47edcab014[0] |
none:none none:none |
PENinja| StarForce| |
none none |
trace trace |
T:07:26:00 | WinXP | 61.222.5.21 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:30:00 | WinXP | 98.141.161.39 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:21:00 | WinXP | 189.6.52.42 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:08:23:00 | WinXP | 63.246.121.100 (SPEAKEASY.NET): US. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
10:06:00 | Win2K-f | 190.51.68.120 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | US:www.maxmind.com US:checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:10:35:00 | WinXP | 93.102.4.64 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:www.altavista.com :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:11:30:00 | WinXP | 67.94.180.90 (ALGX.NET): XO COMMUNICATIONS, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | a92e3f8fc8 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:35:00 | WinXP | 71.127.246.100 (VERIZON.NET): VERIZON INTERNET SERVICES INC, ITHACA, NEW YORK, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
13:41:00 | Win2K-f | 189.97.240.87 (-): . |
n/a | US:www.msn.com :gljmlh.biz US:wkuqvqsr.info :qocgqfnc.net :nwkgoqd.biz :fwjox.biz :nabkporu.net :qrxmliiu.net :sncncxslco.net :lozzxssde.com US:lgaivs.info :dygkpeb.biz :ylkfhs.biz NL:ibjbmngt.org :lmjexkiwti.com :imusgtip.com :ukvzmg.com US:cgbjywrhlm.info US:uttvuhuyfr.org :phjipa.biz :syerynatbw.com US:zmauwbqlvgz.org NL:rjuey.org US:zzidwn.org US:dcirwujn.org :tmpgd.net :yuftirka.biz :avdvsolozo.net :eqckpzqj.com :xsnyiuaabdn.org :glszmvgnjs.net US:204.152.184.92:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:17:00 | Win2K-f | 70.61.157.34 (RR.COM): ROAD RUNNER HOLDCO LLC, CINCINNATI, OHIO, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:42:00 | WinXP | 211.206.133.90 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:02:00 | WinXP | 123.3.178.124 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d5921904f9 NEW |
8526f07834 [0] | none:none |
PolyEnE| | none | trace |
16:46:00 | Win2K-f | 61.59.172.111 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.w3.org US:iwtbyhxjrpk.org :wbejqis.com :zwyoyxcofnq.net US:zdaoazka.info :rkhmvgvwkyg.net US:dzngun.info :zvpsuds.info NL:jsnis.org US:twxsfy.info US:kkcbw.info DE:helli.com :ebddqphca.net US:pyclgeqch.org :rtyozmsub.com US:jkshpmls.info :eibkfjompis.com :ueggvcahavw.biz :jbmzdzzg.biz :phvlaivnakv.net US:jtetcijz.info :bdttybejz.biz :btkvtkzq.biz :mwsczdjsu.biz :sdwzcx.com US:vjtihs.info US:zzidwn.org :wcuolwn.net US:hlaibjaeh.info :lmjexkiwti.com :eccfwkcajo.com US:204.152.184.92:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:16:52:00 | WinXP | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:23:00 | WinXP | 70.169.226.73 (COX.NET): COX COMMUNICATIONS, LAGUNA NIGUEL, CALIFORNIA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:52:00 | WinXP | 24.83.118.197 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, COQUITLAM, BRITISH COLUMBIA, CA. (DSL) |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 2a3036afb7 NEW |
79a17e6e18 [0] | none:none |
none|none | none | trace |
T:18:30:00 | WinXP | 125.4.4.190 (ZAQ.NE.JP): HIGASHI-OSAKA CABLE TELEVISION CO. LTD, OSAKA, OSAKA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:18:55:00 | WinXP | 99.163.51.172 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:18:59:00 | WinXP | 67.242.23.153 (-): . |
n/a | :moscow-advokat.ru SE:vancouver.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:19:39:00 | WinXP | 66.74.166.103 (RR.COM): ROAD RUNNER HOLDCO LLC, HUNTINGTON BEACH, CALIFORNIA, US. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
19:51:00 | Win2K-f | 189.100.73.12 (-): . |
n/a | :www.google.com :xjwdeyu.net :lkfrxwsvqu.biz US:lbptv.info :dsbyb.com :nfocpdlwv.com US:ihyccxzquw.info US:wjohpxqsj.info US:wtxgjhbxn.info :pkfufjzavu.biz :uanzaimh.biz :cbzimesgazp.biz US:qdqgeizh.info US:quclms.info :ewqcpj.com :bbrrjnvj.info :avabq.net US:zjrmqvbuynm.info :ddssoetg.biz :zzdnighk.com :fhsqkifxahv.com US:znpfxamu.org :cufwb.biz :vkdaqjsj.biz :dkfwhsyxkba.net :eksdhcuzjp.biz :phdemuvr.com :ekwluyyyj.com :mmqjsyb.biz :dakjaf.biz :ggofyawj.com US:204.152.184.92:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:57:00 | WinXP | 211.211.74.109 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
218.93.205.24:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:put.ghura.pl CN:dretis.cn CN:kritq.cn :onuka.cn 112.66.33.148:3128 115.126.196.117:3128 116.41.234.219:3128 KR:122.38.120.237:3128 IN:124.125.243.179:3128 124.153.218.176:3128 189.106.96.64:3128 BR:189.15.44.149:3128 ID:202.159.52.59:3128 KR:210.116.189.162:3128 HK:61.239.140.92:3128 EU:77.239.4.170:3128 |
135 | pcap | raw alerts ruleset |
irc http http 131 lines |
Yeah : 1.8 profile |
none | summary tarball |
7 of 41 20 of 41 26 of 41 30 of 33 7 of 41 28 of 33 |
18dfbbc85b NEW 1ead23128e NEW 4d07ee2598 NEW 533d15b5ce NEW 5354e986cd NEW 58c343a8d8 NEW |
4f6fcecea3 [0] db9082e878[0] 9c3a214ff5[0] c67adf46e2[0] 55eb7e6494[0] none [0] |
none:none none:none none:none ASM:Graph none:none none:none |
UPX| tElock| Armadillo| tElock| PENinja| Armadillo| |
none none none lines=126 embedded dns none lines=91 |
trace trace trace trace trace trace |
T:20:44:00 | WinXP | 173.22.150.5 (-): . |
61.120.62.28:3305 | GB:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:21:56:00 | Win2K-f | 114.202.46.143 (-): . |
221.5.74.39:65520 | US:microsoft.com CN:proxima.ircgalaxy.pl CN:dretis.cn CN:kritq.cn :onuka.cn US:client155.faster-hosting.com 112.200.121.97:3128 115.86.64.11:3128 117.102.113.3:3128 117.68.8.79:3128 CN:124.115.37.201:3128 KR:124.49.62.227:3128 ES:155.54.19.250:3128 BR:200.133.48.28:3128 ID:202.159.52.59:3128 KR:210.108.183.12:3128 KR:211.246.215.29:3128 ES:84.124.241.148:3128 |
135 | pcap | raw alerts ruleset |
irc http http http 299 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 17 of 41 7 of 41 31 of 33 20 of 41 25 of 40 |
168aab35a3 NEW 36b2aae01e NEW 5354e986cd NEW 667f0c59f3 NEW 78282818c8 NEW 97fed26b5c NEW |
60b730b97e [0] a4b7eefc40[0] 55eb7e6494[0] 8fe2be2095[0] 8ca8103f06[0] 9c3a214ff5[0] |
ASM:Graph none:none none:none ASM:Graph none:none none:none |
tElock| StarForce| PENinja| Armadillo| tElock| Armadillo| |
lines=120 embedded dns none none lines=91 none none |
trace trace trace trace trace trace |
T:22:33:00 | Win2K-f | 78.138.170.65 (84.IN-ADDR.ARPA): TATTELECOM, KAZAN, TATARSTAN, RU. |
218.93.205.24:65520 | :edit.yahoo.com CN:proxima.ircgalaxy.pl 116.73.23.232:6667 KR:121.138.93.12:6667 KR:124.56.201.202:6667 CN:124.95.103.37:6667 KR:218.158.67.21:6667 IN:220.227.7.106:6667 US:72.36.194.10:80 |
445 | pcap | raw alerts ruleset |
irc http 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:40:00 | WinXP | 219.110.198.57 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace |