Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:16:00 | Win2K-f | 173.22.166.125 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
01:09:00 | Win2K-f | 88.156.34.210 (VECTRANET.PL): VECTRA S.A, OLSZTYN, WARMINSKO-MAZURSKIE, PL. |
n/a | US:www.yahoo.com :pdsfqsas.biz :osael.com US:vycfd.org :jofppbe.net NL:fccjppgd.org :ihnmir.biz US:bkxhg.info :wlzpbjv.net :vjfodsvff.com :shdyjng.biz :lblcoewoak.net US:wczavcxz.org US:lbtfwq.info :ouffhnhdakf.net NL:xaqnerne.org US:kwznthwufzr.info :xozvhtv.com :krdlxvqb.com :ehiyllvjlcp.net :ufyhneq.com :joiegupe.biz :olyxbsie.net :hnajixpmppn.biz :wupdehjcq.biz :adpiquuw.com :sjowzi.net US:lmkxe.org US:stbywynopji.info :blpflysnmy.biz :ebxojqlj.com :bjhfzseqt.org NL:bvwekczz.org US:rvhxcevjxht.org :ylduprr.com :umysffns.biz :cfcgup.net :ndawwovn.org NL:rtgoeyoa.info :gqcqed.net US:hzljqghllq.org :qujnitnct.net US:icteyunz.org :igqacbzwvv.net :fpmhe.biz US:bawjrmyr.info US:teslrzgoe.org US:imwdrpbn.org :idlgmkn.net US:usrknemnc.org :pjaptnyk.info :nmdlmdadxk.com :upwlxme.net US:bolsfnwyty.info :ibyaauiopm.net :zjmchuy.net US:fnzmvj.org :jsdtojzr.org NL:rpcduauoswh.org :iuvopwct.com US:qovvpuvxp.org :cjxebnttqwk.com US:whnjtkm.info US:ypqgjjzst.info :xlbksrbrzhb.biz :wcgdiahzjrd.com US:tlrsktypg.org :cvxtud.biz US:mtiyvjw.org :eurjmx.net :yacisuqnhns.net US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:23:00 | Win2K-f | 114.73.159.226 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 34 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | 53bfe15e91 NEW |
1473091351 [0] | ASM:Graph |
tElock| | lines=75 embedded dns |
trace |
T:01:28:00 | WinXP | 74.81.40.134 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
02:36:00 | Win2K-f | 124.8.55.112 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org US:getmyip.co.uk DE:131.220.6.26:80 208.78.70.70:80 US:65.254.39.170:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:02:42:00 | Win2K-f | 173.22.145.237 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 56 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:04:01:00 | WinXP | 123.52.36.191 (163DATA.COM.CN): CHINANET HENAN PROVINCE NETWORK, HENAN, GUIZHOU, CN. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:04:06:00 | Win2K-f | 96.50.173.224 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 1009 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 41 | 770a04a72c NEW |
none[3] | none:none |
none|none | none | trace | |
T:04:38:00 | WinXP | 92.40.108.171 (IKBCC.COM): EU-ZZ, UK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 9c07aa6060 NEW |
none[none] | none:none |
none|none | none | none |
T:05:13:00 | WinXP | 93.102.66.12 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :www.google.com.au US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:05:52:00 | WinXP | 114.137.90.190 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:05:58:00 | WinXP | 79.162.182.92 (-): IDEA, PL. |
n/a | FR:proxim.ircgalaxy.pl RU:citi-bank.ru RU:213.219.245.212:80 FR:91.121.221.157:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:06:05:00 | Win2K-f | 69.193.74.22 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:03:00 | Win2K-f | 99.147.77.51 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:07:24:00 | WinXP | 87.55.75.85 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b26ed6eeac NEW |
97c1157bf8 [0] | none:none |
PolyEnE| | none | trace |
T:07:46:00 | WinXP | 114.58.209.177 (-): . |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | b062182bb1 NEW |
1fb7e59bf8 [0] | none:none |
PolyEnE| | none | trace |
08:00:00 | WinXP | 74.138.54.36 (INSIGHTBB.COM): INSIGHT COMMUNICATIONS COMPANY L.P, LOUISVILLE, KENTUCKY, US. |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | none:none |
PolyEnE| | none | trace |
T:08:16:00 | WinXP | 69.132.203.131 (RR.COM): ROAD RUNNER HOLDCO LLC, ROCKINGHAM, NORTH CAROLINA, US. |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:www.bbin.ru RU:www.binbank.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http 40 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:09:07:00 | WinXP | 84.224.10.87 (PGSM.HU): PANNON GSM TELECOMMUNICATIONS INC, HU. |
n/a | 445 | pcap | raw alerts ruleset |
shell 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:10:52:00 | WinXP | 200.219.92.98 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 2f6cc0e618 NEW |
f8f316af28 [0] | none:none |
PolyEnE| | none | trace |
T:11:12:00 | WinXP | 24.234.219.233 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:06:00 | WinXP | 71.148.35.37 (SBCGLOBAL.NET): KASSA KASSA, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:53:00 | WinXP | 87.250.55.144 (BVCOM.NET): AVCOM, CS. |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:13:24:00 | WinXP | 218.119.176.169 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
13:29:00 | Win2K-f | 190.227.143.149 (-): . |
n/a | CN:www.baidu.com :sembpsnsx.net :shdyjng.biz :idlgmkn.net :gmzstgd.net NL:ghvfddbnot.info :cfcgup.net US:vycfd.org US:olunvysf.org US:bawjrmyr.info US:qdqhlmnks.org :blpflysnmy.biz :lxlryl.com :swnaaamykm.net NL:mtiyvjw.org US:izbddjgf.info US:xaqnerne.org :gigyttsdm.com :jinstokzqqf.net :zfktwnva.biz US:imwdrpbn.org :lbwgffradlf.org :giielbalrz.biz US:mfqkdvx.info :yjnozchh.net :luzokdj.biz US:gtohblzh.org :sddrcq.net :lvcvjtgym.org :igqacbzwvv.net NL:gcdqzwbaic.info EE:www.starman.ee FI:194.215.38.3:80 US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:32:00 | Win2K-f | 66.50.6.72 (PRTC.NET): PRTC RAS, SAN JUAN, PUERTO RICO, PR. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 194 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:54:00 | WinXP | 77.29.132.223 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
87.118.98.185:7000 | DE:sobiesk1.myftp.org DE:87.118.98.185:7000 |
139 | pcap | raw alerts ruleset |
ftp irc 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 40 | 88ae32e138 NEW |
5abec5b133 [0] | none:none |
Armadillo| | none | trace |
T:14:08:00 | WinXP | 212.106.18.247 (POLBOX.PL): POLBOX, PL. |
87.118.98.185:7000 | DE:sobiesk1.myftp.org | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 40 | 88ae32e138 NEW |
5abec5b133 [0] | none:none |
Armadillo| | none | trace |
T:14:24:00 | WinXP | 85.138.201.95 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, QUARTEIRA, FARO, PT. |
213.219.245.212:80 | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
14:32:00 | Win2K-f | 95.28.227.66 (-): . |
n/a | US:www.getmyip.org US:getmyip.co.uk :checkip.dyndns.org US:204.152.184.139:80 208.78.70.70:80 US:75.126.138.202:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:14:50:00 | WinXP | 70.117.157.9 (RR.COM): ROAD RUNNER HOLDCO LLC, BEAUMONT, TEXAS, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:15:26:00 | WinXP | 112.110.127.139 (-): . |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | b27d73bfcb NEW |
473c6454ce [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:15:45:00 | WinXP | 113.254.115.38 (-): . |
n/a | CN:italian.swiifatecihno.com | 135 | pcap | raw alerts ruleset |
irc http 709 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 19 of 41 |
1d0f3fb06e NEW 205bf6f449 NEW |
none[none] 7f52ad5fa7[0] |
none:none none:none |
none|none StarForce| |
none none |
none trace |
T:16:04:00 | WinXP | 72.67.206.75 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. (100Mbps) |
200.49.145.197:3305 | FI:cx10man.weedns.com FI:fx010413.whyI.org JP:gynoman.weedns.com FI:g.0x20.biz JP:c010x1.co.cc JP:commgr.co.cc KR:telephone.dd.blueline.be AR:phonewire.dd.blueline.be KR:211.233.45.253:3305 JP:61.120.62.28:3305 |
135 | pcap | raw alerts ruleset |
irc 608 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | 69f8ccc92e NEW |
e9613e6868 [0] | none:none |
StarForce| | none | trace |
T:16:06:00 | Win2K-f | 173.22.145.237 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 53 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:16:09:00 | WinXP | 96.50.230.125 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:41:00 | WinXP | 63.25.227.23 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 84 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:48:00 | WinXP | 187.20.86.217 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 2f6cc0e618 NEW |
f8f316af28 [0] | none:none |
PolyEnE| | none | trace |
T:17:08:00 | Win2K-f | 67.8.56.42 (RR.COM): ROAD RUNNER HOLDCO LLC, NAPLES, FLORIDA, US. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:15:00 | WinXP | 121.84.102.233 (EONET.NE.JP): K-OPTICOM CORPORATION, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | a3c2a1a0c8 NEW |
none[none] | none:none |
none|none | none | none | |
T:18:33:00 | Win2K-f | 70.64.205.185 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, MOOSE JAW, SASKATCHEWAN, CA. (DSL) |
200.49.145.197:3305 | JP:cx10man.weedns.com KR:fx010413.whyI.org TH:gynoman.weedns.com KR:g.0x20.biz KR:telephone.dd.blueline.be AR:phonewire.dd.blueline.be KR:211.233.45.253:3305 JP:61.120.62.28:3305 |
135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 41 | c4c3a5fede NEW |
none[none] | none:none |
none|none | none | none |
T:18:48:00 | Win2K-f | 98.141.30.61 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:19:15:00 | WinXP | 124.66.254.72 (FCH.NE.JP): FUREAI CHANNEL INC, HIROSHIMA, HIROSHIMA, JP. |
n/a | :www.google.com.au US:www.yahoo.com :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 17028f1eda NEW |
none[3] | none:none |
tElock| | none | trace |
T:19:18:00 | WinXP | 71.144.71.236 (SBCGLOBAL.NET): PPPOX POOL - BRAS3 OKCYOK, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:37:00 | Win2K-f | 74.214.47.11 (METROCAST.NET): GMP CABLE TV, BERWICK, PENNSYLVANIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 | e30fb27bda NEW |
90ee26f451 [0] | ASM:Graph |
MEW| | lines=185 embedded dns |
trace | |
T:21:02:00 | Win2K-f | 114.42.21.57 (-): . |
n/a | US:s.unicat.org US:66.252.13.214:2081 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 41 | 67a66839f7 NEW |
7b1fc808a3 [0] | none:none |
none|none | none | trace |
21:11:00 | Win2K-f | 222.59.180.22 (HERBALQC.COM): CHINA RAILWAY TELECOMMUNICATIONS CENTER, BEIJING, BEIJING, CN. |
n/a | US:www.yahoo.com :pqcanchy.info :pisogxznpaz.net :qculhtw.com NL:omxoagkh.org :aswdgrtlojs.biz :yntfnutfd.biz US:tzliaermxl.info :ubtvepcdoa.com :fwaai.info NL:tbxbn.org :ajftfem.biz US:xxctt.info US:rjjmowkufi.info :llrij.biz NL:idqtgxtuvkb.info US:clrtwoebki.org :klxwcjkdbby.net :amzenm.com :ojinbtzxly.net :kymxeiilguy.biz :brndkist.net US:vjqshdkx.org :gtgyqfzlzq.biz :lrvlxuf.net US:mdkqnsifyvt.info US:rytcwecn.info :uufqn.biz US:cugfcvionpy.info :kcjcshh.net :sorbpqf.biz US:cxwpy.org US:emgnprdjv.info :rzwumggaljk.com :kakfzgdb.com :ymefcnmz.biz :wzadoaye.net US:kqcedpzvv.org :qjtkdcdbzas.net :uuwhezvidbp.org NL:ehciuxummc.info :rldqyxdm.com US:hkzody.org US:rykyiwice.info :rdiyq.biz US:mhdgkhkeem.org :pixywe.net :ieqyzyy.info :ttnmgehauik.biz :ubnjv.biz :gvpaaasgpdk.net :knvgbteyj.biz :kkvmuzir.com :eqiplrct.biz :noyvfkv.net :uqwprfbs.biz :jjfziohlmx.net US:lbawhyowpzx.info :dbzieocfsvw.com US:mhwwrwnnzhj.org :gwwpgwrowii.net :ieleh.org :eqctpl.com :qgjtuprw.biz :hbeydryod.biz :xirbqu.net :dohyznyii.net :xzxts.com US:sdtbtytm.org :auaveizoqdt.net :llsdo.net US:204.152.184.139:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
21:30:00 | Win2K-f | 189.186.153.229 (PROD-INFINITUM.COM.MX): UNINET S.A. DE C.V, MX. |
n/a | US:getmyip.co.uk :checkip.dyndns.org US:204.152.184.139:80 US:65.254.39.170:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:21:33:00 | WinXP | 125.4.12.108 (ZAQ.NE.JP): HIGASHI-OSAKA CABLE TELEVISION CO. LTD, OSAKA, OSAKA, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:22:17:00 | WinXP | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, AICHI, JP. |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |