Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:37:00 | WinXP | 98.141.160.56 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:46:00 | Win2K-f | 172.163.142.167 (AOL.COM): AMERICA ONLINE, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 146 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:01:53:00 | Win2K-f | 41.206.136.154 (-): VODAFONE EGYPT, EG. |
n/a | CZ:qtas.net CZ:82.114.87.50:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
10 of 41 | e4b069ac64 NEW |
5d97cec8e6 [0] | none:none |
FSG| | none | trace |
T:03:33:00 | WinXP | 96.50.140.81 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 426 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 46414f5b59 NEW |
93d8800aec [0] | none:none |
ASPack| | none | trace | |
T:05:11:00 | WinXP | 189.58.134.10 (BRASILTELECOM.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spt.information.com US:spi.domainsponsor.com :wpad DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 16 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 41 | 21aeb3c922 NEW |
93e24e62a9 [0] | none:none |
ASPack| | none | trace |
05:31:00 | WinXP | 209.42.184.147 (WISPNET.NET): WISPNET LLC, KENTUCKY, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
36 of 38 | 5865b09945 NEW |
4d99f4784a [0] | none:none |
PolyEnE| | none | trace |
T:06:05:00 | WinXP | 114.137.77.35 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:06:26:00 | WinXP | 86.155.23.249 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SWANSEA, WALES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:07:04:00 | WinXP | 213.120.3.16 (BT.NET): BT PUBLIC INTERNET SERVICE, LONDON, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:07:08:00 | WinXP | 113.27.152.144 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 4e94a1a314 NEW |
b34f7d40bd [0] | none:none |
PolyEnE| | none | trace |
T:07:20:00 | WinXP | 219.254.243.228 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 41 | b693a4d00a NEW |
b693a4d00a [1] | ASM:Graph |
Armadillo| | lines=82 | trace | |
T:07:50:00 | Win2K-f | 4.178.233.132 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 36 of 40 |
47d3548e36 NEW d8722af110 NEW |
ab13346633 [0] ab30a55931[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:07:53:00 | Win2K-f | 72.66.8.36 (VERIZON.NET): GAIP INC, VIENNA, VIRGINIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:58:00 | WinXP | 121.121.168.243 (MAXIS.NET.MY): MAXIS COMMUNICATIONS BHD, MY. |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:08:35:00 | Win2K-f | 68.146.170.26 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com :irc.zief.pl |
135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 40 0 of 32 |
36e5a0310e NEW 73f1082158 NEW |
4eda72bd91 [0] none [0] |
none:none none:none |
StarForce| Armadillo| |
none lines=90 |
trace trace |
T:09:14:00 | WinXP | 217.203.206.235 (-): TELECOM ITALIA MOBILE, IT. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 74b3d149e8 NEW |
cef0fa2981 [0] | none:none |
PolyEnE| | none | trace |
T:09:44:00 | WinXP | 94.196.214.123 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:29:00 | WinXP | 70.67.182.78 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, DUNCAN, BRITISH COLUMBIA, CA. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:35:00 | WinXP | 117.20.176.81 (KMTCSIN.COM.SG): STARHUB INTERNET PTE LTD, SG. |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | c3be1629e5 NEW |
5b893564fb [0] | none:none |
PolyEnE| | none | trace |
T:11:47:00 | WinXP | 70.235.69.110 (SBCGLOBAL.NET): PPPOX POOL - BRAS12 MRDNCT, SEYMOUR, CONNECTICUT, US. (DSL) |
n/a | :www.google.com.au US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | bb7681eca8 NEW |
none[3] | none:none |
tElock| | none | trace |
T:11:53:00 | Win2K-f | 4.172.111.1 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BRONX, NEW YORK, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
12:21:00 | Win2K-f | 219.83.69.22 (-): HOST TATELY NV, JAKARTA, JAKARTA RAYA (DJAKARTA RAYA), ID. (100Mbps) |
n/a | US:www.maxmind.com :checkip.dyndns.org |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:12:54:00 | Win2K-f | 98.141.9.205 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:12:00 | WinXP | 114.48.148.119 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 39 | 53dfd10e91 NEW |
48915ad1fe [0] | none:none |
PolyEnE| | none | trace |
T:13:18:00 | WinXP | 118.87.18.132 (-): . |
n/a | CA:xx.ka3ek.com :nadsamcabran12.com |
135 | pcap | raw alerts ruleset |
irc http 343 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 41 32 of 38 38 of 41 |
47d76e8dce NEW 524bc0f75c NEW 820b27d4c6 NEW |
457779e597 [0] d3e9510bb3[0] 1102de0215[0] |
none:none none:none none:none |
Neolite| PENinja S| Armadillo| |
none none none |
trace trace trace |
T:14:45:00 | WinXP | 208.113.27.206 (NTDAPPAREL.COM): ACCELERATED CONNECTIONS, ONTARIO, CA. |
n/a | :gg.arrancar.org | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 154e28f846 NEW |
4d85da80b1 [0] | none:none |
none|none | none | trace |
T:14:59:00 | Win2K-f | 173.22.166.144 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:15:13:00 | WinXP | 4.184.56.86 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 174 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:15:00 | WinXP | 130.13.48.198 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b062182bb1 NEW |
1fb7e59bf8 [0] | none:none |
PolyEnE| | none | trace |
T:15:16:00 | Win2K-f | 196.208.94.194 (TELKOM-IPNET.CO.ZA): AFRINIC, CAPE TOWN, WESTERN CAPE, ZA. |
n/a | 135 | pcap | raw alerts ruleset |
other 711 lines |
Yeah : 1.3 profile |
none | summary tarball |
27 of 41 | de2a8e3f8e NEW |
032d753367 [0] | none:none |
PENinja S| | none | trace | |
T:15:52:00 | Win2K-f | 4.191.66.185 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SALEM, OREGON, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
5c39773b13 NEW a1acc403a2 NEW |
c64405f2e9 [0] 54ef26c2f9[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
15:56:00 | Win2K-f | 59.37.165.79 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. |
n/a | US:www.maxmind.com US:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org 208.78.70.70:80 US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:12:00 | WinXP | 200.226.50.55 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 943521a3dd NEW |
ae2b3cc87e [0] | none:none |
PolyEnE| | none | trace |
16:23:00 | Win2K-f | 190.51.138.249 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. |
n/a | US:www.maxmind.com US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org 208.78.70.70:80 US:65.254.39.170:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
7 of 37 | 7587773eea NEW |
none[3] | none:none |
StarForce| | none | trace |
T:16:23:00 | Win2K-f | 64.75.154.21 (ALOHA.NET): HAWAII ONLINE, LIHUE, HAWAII, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:17:06:00 | WinXP | 219.165.145.238 (PLALA.OR.JP): PLALA NETWORKS INC, KASHIWA, CHIBA, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:17:19:00 | WinXP | 68.203.231.145 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, TEXAS, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:17:34:00 | WinXP | 66.74.93.1 (RR.COM): ROAD RUNNER HOLDCO LLC, CANYON COUNTRY, CALIFORNIA, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | db7ddb4fff NEW |
dec3399fbb [0] | none:none |
PENinja S| | none | trace | |
17:40:00 | WinXP | 68.203.231.145 (RR.COM): ROAD RUNNER HOLDCO LLC, ORANGE, TEXAS, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | none:none |
PolyEnE| | none | trace |
T:17:48:00 | WinXP | 76.200.153.236 (SBCGLOBAL.NET): BRAS44.PLTNCA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b NEW |
none[0] | none:none |
none|none | lines=64 | trace | |
T:18:12:00 | WinXP | 204.120.197.191 (WBSNET.NET): WHEATLAND ELECTRIC COOP, SCOTT CITY, KANSAS, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 40 | 824d6a706e NEW |
a66fd13bcb [0] | none:none |
PolyEnE| | none | trace |
T:18:55:00 | WinXP | 89.111.226.239 (TEOL.NET): TELEKOMSRPSKE, BA. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | f54691063f NEW |
6039c698cd [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:19:01:00 | WinXP | 222.233.229.102 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 101 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 32 18 of 41 |
9276c8b36b NEW a837b5c1fd NEW |
none[0] none [3] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
|
T:19:22:00 | WinXP | 121.121.96.100 (MAXIS.NET.MY): MAXIS COMMUNICATIONS BHD, MY. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 40 | cdbb312d0a NEW |
8050e5ba3e [0] | none:none |
PolyEnE| | none | trace |
T:19:27:00 | WinXP | 114.145.211.217 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | 10318ada62 NEW |
a5b9f355da [0] | none:none |
none|none | none | trace | |
T:20:24:00 | WinXP | 70.244.120.175 (SWBELL.NET): PPPOX POOL - RBACK7 AUSTTX, AUSTIN, TEXAS, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:20:27:00 | Win2K-f | 68.150.38.31 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (DSL) |
72.10.172.211:8080 67.43.236.67:10324 | CA:xx.ka3ek.com CA:xx.nadnadzz.info :nadsamcabran12.com |
135 | pcap | raw alerts ruleset |
irc http 337 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 41 32 of 38 41 of 41 |
47d76e8dce NEW 524bc0f75c NEW 730bad1b41 NEW |
457779e597 [0] d3e9510bb3[0] 0986ba3540[0] |
none:none none:none none:none |
Neolite| PENinja S| FSG| |
none none none |
trace trace trace |
T:20:29:00 | WinXP | 211.206.92.30 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
218.93.205.23:65520 216.245.213.194:80 | CN:proxim.ircgalaxy.pl CN:dretis.cn CN:kritq.cn :onuka.cn :mxs.mail.ru US:alt4.gmail-smtp-in.l.google.com US:in1.smtp.messagingengine.com US:mail7.digitalwaves.co.nz 115.86.88.182:3128 119.0.235.3:3128 119.204.12.58:3128 KR:121.1.116.106:3128 KR:121.178.225.40:3128 CN:124.73.15.120:3128 IN:202.141.141.148:3128 KR:202.167.218.90:3128 GB:217.112.42.7:25 TH:58.9.248.133:3128 HK:61.239.140.92:3128 |
139 | pcap | raw alerts ruleset |
irc http 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
7 of 41 37 of 41 33 of 41 19 of 41 |
5354e986cd NEW 5e35242196 NEW 6d3f17a608 NEW f1b692ebfc NEW |
55eb7e6494 [0] be5536a4a0[0] 8cfa5407d6[0] 9883e831ff[0] |
none:none none:none none:none none:none |
PENinja| none|none ASPack| Obsidium| |
none none none none |
trace trace trace trace |
T:20:35:00 | Win2K-f | 4.227.194.169 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ELBERT, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 94 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
21:04:00 | Win2K-f | 59.125.210.63 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:www.maxmind.com :checkip.dyndns.org US:getmyip.co.uk US:www.getmyip.org 208.78.70.70:80 US:65.254.39.170:80 US:67.15.94.80:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
21:11:00 | WinXP | 121.121.96.100 (MAXIS.NET.MY): MAXIS COMMUNICATIONS BHD, MY. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 40 | cdbb312d0a NEW |
8050e5ba3e [0] | none:none |
PolyEnE| | none | trace |
T:21:22:00 | Win2K-f | 96.8.242.42 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:30:00 | Win2K-f | 58.236.167.90 (-): THRUNET-INFRA-INCHEON10, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:22:32:00 | WinXP | 130.13.180.145 (QWEST.NET): QWEST BROADBAND SERVICES INC, PHOENIX, ARIZONA, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | none:none |
PolyEnE| | none | trace |
T:23:15:00 | WinXP | 79.132.204.82 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 14302579d2 NEW |
2d61d0464e [0] | none:none |
PolyEnE| | none | trace |
T:23:45:00 | WinXP | 77.20.60.25 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
66.252.13.214:9890 | US:f.unicat.org US:66.252.13.214:9890 |
445 | pcap | raw alerts ruleset |
ftp irc 40 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 NEW |
none[0] | none:none |
ASProtect| | lines=585 embedded dns |
trace |
T:23:51:00 | Win2K-f | 203.90.73.165 (ITC.CO.IN): HCL INFINET LIMITED, BHOPAL, MADHYA PRADESH, IN. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:52:00 | WinXP | 173.88.137.235 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |