Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

13 November 2009
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:01:00:00 WinXP 202.147.210.232 (KCN-TV.NE.JP):
KUMAMOTO CABLE NETWORK CORPORATION,
KUMAMOTO, KUMAMOTO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:01:08:00 WinXP 95.88.215.226 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
BERLIN, BERLIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 3633185e02
NEW
55d194738a [0] none:none
Armadillo| none trace
T:01:11:00 Win2K-f 78.9.84.36 (NET.PL):
DIALOG,
WROCLAW, DOLNOSLASKIE, PL. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 40 55667c4a85
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:01:26:00 WinXP 95.84.45.223 (SAN.RU):
NETWORK OF SARATOV BRANCH OF OJSC VOLGATELECOM,
MOSCOW, MOSCOW CITY, RU. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 ca8da15194
NEW
b6fc2a1593 [0] none:none
Armadillo| none trace
T:01:27:00 Win2K-f 61.94.9.129 (TELKOM.NET.ID):
PT TELKOM INDONESIA,
JAKARTA, JAKARTA RAYA, ID. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
10 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:01:29:00 Win2K-f 95.58.3.186 (DIAL.ONLINE.KZ):
JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE,
ALMATY, ALMATY CITY, KZ. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 ec8ab501b3
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:01:43:00 Win2K-f 88.134.180.78 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
BERLIN, BERLIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 7793daa779
NEW
5dac538fbc [0] none:none
Armadillo| none trace
T:01:44:00 WinXP 114.42.207.190 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
33 of 41 de37f2fc47
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:01:54:00 Win2K-f 95.89.162.187 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
BERLIN, BERLIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
33 of 41 b0c46107a6
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:01:58:00 WinXP 118.166.1.180 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 ec8ab501b3
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:02:08:00 Win2K-f 114.38.179.248 (HINET.NET):
CHTD CHUNGHWA TELECOM CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 ec8ab501b3
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:02:13:00 Win2K-f 218.172.93.141 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 40 55667c4a85
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:02:16:00 WinXP 61.94.129.25 (TELKOM.NET.ID):
PT. TELEKOMUNIKASI INDONESIA,
JAKARTA, JAKARTA RAYA, ID. (DSL)
66.252.13.212:16667 US:bbs.moiservice.com
US:attacke.100free.com
DE:members.lycos.co.uk
US:66.252.13.212:16667
445 pcap raw alerts
ruleset
ftp
irc
http
1080 lines
Yeah : 1.3
profile
none summary
tarball
10 of 41
38 of 40
10 of 41
11cde67678
NEW
331145624c
NEW
7634ac1997
NEW
9af8e2f833 [0]
e7124c9b61[0]
9af8e2f833[0]
none:none
none:none
none:none
FSG|
Stranik|
FSG|
none
none
none
trace
trace
trace
T:02:27:00 Win2K-f 78.239.29.44 (PROXAD.NET):
PROXAD INTERNET SERVICE PROVIDER IN FRANCE,
FR. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 f4a8e6a51e
NEW
acd8693185 [0] none:none
Armadillo| none trace
T:02:42:00 Win2K-f 95.89.80.106 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
BERLIN, BERLIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 ffda37e02b
NEW
2669ff2865 [0] none:none
Armadillo| none trace
T:03:12:00 Win2K-f 189.118.50.230 (TIMBRASIL.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
SãO PAULO, SAO PAULO, BR. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
37 of 40 a55778ac1c
NEW
97e2f1618d [0] none:none
Armadillo| none trace
T:03:16:00 WinXP 94.251.138.176 (-):
CUSTOMER IN CZESTOCHOWA,
CZESTOCHOWA, SLASKIE, PL. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
38 of 41 5d31fa2adf
NEW
8992c05119 [0] none:none
Armadillo| none trace
T:03:19:00 Win2K-f 94.251.131.118 (-):
CUSTOMER IN CZESTOCHOWA,
WARSAW, WARSZAWA, PL. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 8ab6e70b64
NEW
72feb43272 [0] none:none
Armadillo| none trace
T:03:27:00 Win2K-f 63.16.0.138 (UU.NET):
UUNET TECHNOLOGIES INC,
PHOENIX, ARIZONA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
84 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:53:00 WinXP 83.132.3.195 (CPE.NETCABO.PT):
TVCABO-PORTUGAL CABLE MODEM NETWORK,
PT. (DSL)
66.252.13.212:16667 US:bbs.moiservice.com 445 pcap raw alerts
ruleset
ftp
irc
35 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41 be7f428663
NEW
0ee7526007 [0] none:none
Stranik| none trace
T:04:00:00 Win2K-f 188.99.245.131 (ARCOR-IP.NET):
ARCOR-DSL-NET,
DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 3d5b054328
NEW
29e313e61c [0] none:none
Armadillo| none trace
T:04:13:00 WinXP 62.182.71.11 (DOBROE.RU):
ZHANR-NET,
MOSCOW, MOSCOW CITY, RU. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
37 of 41 c34d3ada53
NEW
9b9b17a286 [0] none:none
Armadillo| none trace
T:04:17:00 WinXP 88.173.112.19 (PROXAD.NET):
PROXAD / FREE SAS,
ISSY-LES-MOULINEAUX, ILE-DE-FRANCE, FR. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
39 of 41 7016d3fe8b
NEW
3a5ff804e9 [0] none:none
Armadillo| none trace
T:04:56:00 WinXP 125.224.139.22 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
33 of 41 de37f2fc47
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:05:08:00 Win2K-f 80.171.191.38 (HANSENET.DE):
HANSENET-ADSL,
HAMBURG, HAMBURG, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 ec8ab501b3
NEW
bac4cc6eec [0] none:none
Armadillo| none trace
T:05:10:00 Win2K-f 70.184.102.222 (COX.NET):
COX COMMUNICATIONS,
PHOENIX, ARIZONA, US. (100Mbps)
193.104.94.11:65520 CN:proxim.ircgalaxy.pl
US:microsoft.com
EU:colopin.cn
EU:91.206.201.39:80
135 pcap raw alerts
ruleset
irc
119 lines
Yeah : 1.8
profile
none summary
tarball
32 of 36
35 of 36
bea8cb1865
NEW
fac78fde16
NEW
154de51a66 [0]
882896ab05[0]
ASM:Graph
none:none
Armadillo|
tElock|
lines=91
none
trace
trace
T:05:23:00 Win2K-f 24.167.191.86 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HIGH POINT, NORTH CAROLINA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
5 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:05:32:00 WinXP 114.48.240.71 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:05:48:00 Win2K-f 218.173.245.123 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
36 of 41 6c4f8d0b05
NEW
c15495ec45 [0] none:none
Armadillo| none trace
T:06:14:00 WinXP 114.48.83.168 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 41 95308db598
NEW
afdd2b80c4 [0] none:none
PolyEnE| none trace
T:06:51:00 WinXP 24.234.132.15 (COX.NET):
COX COMMUNICATIONS INC,
LAS VEGAS, NEVADA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
52 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33 a08f3b74a4
NEW
none[0] none:none
Armadillo| lines=90 trace
T:07:32:00 Win2K-f 208.101.212.196 (MNCABLE.NET):
SJOBERG CABLE,
BAUDETTE, MINNESOTA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
291 lines
Yeah : 1.3
profile
none summary
tarball
22 of 41 75af48afe4
NEW
7a25f9e3cf [0] none:none
StarForce| none trace
T:07:39:00 WinXP 109.169.135.23 (STERLINGSTUDENTS.NET):
EU-ZZ,
UK. (DSL)
66.252.13.212:16667 US:bbs.moiservice.com
US:attacke.100free.com
DE:members.lycos.co.uk
DE:www.tripod.lycos.co.uk
DE:www.multimania.co.uk
US:205.134.160.58:80
US:66.252.13.212:16667
445 pcap raw alerts
ruleset
ftp
irc
http
107 lines
Yeah : 1.3
profile
none summary
tarball
39 of 40 ac24fa21de
NEW
374bf86707 [0] none:none
Stranik| none trace
T:07:54:00 WinXP 203.91.165.87 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
80 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:09:23:00 WinXP 85.122.40.157 (-):
SC AMBAVI TELECOM SRL,
BUCHAREST, BUCURESTI, RO. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:11:16:00 WinXP 188.132.36.196 (-):
SA-ETTIHADETISALAT,
RIYADH, AR RIYAD, SA. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:12:10:00 WinXP 173.19.216.239 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
IOWA CITY, IOWA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
116 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 41
73d9e10cba
NEW
de3bdf7b4e
NEW
15076d5de4 [0]
ff08fc71e3[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:13:05:00 WinXP 63.28.36.19 (UU.NET):
UUNET TECHNOLOGIES INC,
WINCHESTER, VIRGINIA, US. (DSL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
RU:www.bbin.ru
:wpad
US:spi.domainsponsor.com
RU:195.200.213.54:80
US:204.13.161.51:80
US:208.73.210.125:80
445 pcap raw alerts
ruleset
http
http
http
5 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:13:31:00 WinXP 95.75.125.173 (-):
TELECOM ITALIA MOBILE,
IT. (DSL)
193.104.94.11:65520 CN:proxim.ircgalaxy.pl
CN:dl.guarddog2009.com
:komojoke.cn
CN:config1007.iwillhavesexygirls.com
CN:maillist.iwillhavesexygirls.com
EU:colopin.cn
FR:193.104.94.11:65520
EU:91.206.201.39:80
445 pcap raw alerts
ruleset
http
irc
20 lines
Yeah : 1.3
profile
none summary
tarball
10 of 41
15 of 41
7 of 41
29 of 41
37 of 39
2fa130feec
NEW
83192a6119
NEW
85c00cc118
NEW
9354673997
NEW
dab4da4e21
NEW
8a06db2aef [0]
fdc95e1fab[0]
none [3]
60e874b776[0]
e63b813015[0]
none:none
none:none
none:none
none:none
ASM:Graph
Armadillo|
none|none
StarForce|
none|none
PolyEnE|
none
none
none
none
lines=134
trace
trace
trace
trace
trace
T:13:31:00 WinXP 89.204.177.54 (O2.IE):
O2 IRELAND MOBILE PHONE OPERATOR,
DUBLIN, DUBLIN, IE. (DSL)
n/a DE:siliconfireware.ru
US:searchportal.information.com
US:spi.domainsponsor.com
GB:new.egg.com
:wpad
US:204.13.161.51:80
445 pcap raw alerts
ruleset
http
http
http
http
23 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 da9e21ae21
NEW
d3271206dd [0] none:none
ASPack| none trace
T:14:23:00 Win2K-f 71.116.212.170 (VERIZON.NET):
VERIZON INTERNET SERVICES INC,
LOS ANGELES, CALIFORNIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:14:43:00 Win2K-f 219.114.247.138 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
OSAKA, OSAKA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
38 of 40
024410ad21
NEW
b0cedd71bb
NEW
96d0267b80 [0]
f6e156bdca[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:15:03:00 WinXP 83.185.27.226 (TELE2.SE):
TELE2-MOBILE-INTERNET,
SE. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 912a073945
NEW
7874c7f21e [0] none:none
PolyEnE| none trace
T:15:27:00 WinXP 65.29.28.225 (RR.COM):
ROAD RUNNER HOLDCO LLC,
GERMANTOWN, WISCONSIN, US. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 0cfab99612
NEW
none[0] ASM:Graph
PolyEnE| lines=68 trace
T:15:57:00 Win2K-f 68.151.243.247 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
EDMONTON, ALBERTA, CA. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
222 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
38 of 41
4180c19d91
NEW
b6e91e001c
NEW
9f3f2de385 [0]
d2275a6cf5[0]
none:none
none:none
Armadillo|
PolyEnE|
none
none
trace
trace
T:16:18:00 Win2K-f 4.143.86.166 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
CLEVELAND, OHIO, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
112 lines
Yeah : 1.3
profile
none summary
tarball
37 of 39
37 of 39
166484192b
NEW
2a1e547005
NEW
0c886fcb7b [0]
5c75fa020a[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:16:38:00 WinXP 173.19.82.74 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CEDAR RAPIDS, IOWA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 41
3bff218b8f
NEW
7eaf7b4470
NEW
b570b734be [0]
8e0b194526[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:18:20:00 WinXP 217.203.129.173 (-):
TELECOM ITALIA MOBILE,
ROME, LAZIO, IT. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 f2a8dafb30
NEW
1d0f660523 [0] none:none
PolyEnE| none trace
T:18:37:00 WinXP 208.100.226.27 (1DIAL.COM):
AD-BASE SYSTEMS INC. (DBA GLOBALPOPS),
ATHENS, ALABAMA, US. (DIAL)
n/a RU:citi-bank.ru
RU:213.219.245.212:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
29 of 29 dd02947289
NEW
none[0] ASM:Graph
PolyEnE| lines=68 trace
T:20:06:00 WinXP 60.56.35.67 (EONET.NE.JP):
K-OPTICOM CORPORATION,
NISHINOMIYA, HYOGO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
39 of 40 8ab0fb88b8
NEW
968cc91789 [0] none:none
none|none none trace
T:20:24:00 Win2K-f 203.91.160.116 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:21:21:00 Win2K-f 99.174.146.106 (PACBELL.NET):
AT&T INTERNET SERVICES,
HOUSTON, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:22:19:00 Win2K-f 65.184.62.103 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WILMINGTON, NORTH CAROLINA, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
112 lines
Yeah : 1.3
profile
none summary
tarball
38 of 40
36 of 41
84ace068d1
NEW
c584af4fcd
NEW
c822a7d0e4 [0]
bdfcf0a930[0]
none:none
none:none
tElock|
Armadillo|
none
none
trace
trace
T:22:21:00 WinXP 83.185.28.103 (TELE2.SE):
TELE2-MOBILE-INTERNET,
SE. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 41 522832a551
NEW
0c7f5442b0 [0] none:none
PolyEnE| none trace
T:22:33:00 WinXP 114.48.225.253 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:23:37:00 Win2K-f 173.29.83.184 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
DAVENPORT, IOWA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
39 of 41
10759405e0
NEW
d08e00dfaf
NEW
292d343248 [0]
854c49d8c4[0]
none:none
none:none
Armadillo|
tElock|
none
none
trace
trace
T:23:51:00 WinXP 220.137.59.15 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
213.219.245.212:80 RU:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace