Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:00:00 | WinXP | 202.147.210.232 (KCN-TV.NE.JP): KUMAMOTO CABLE NETWORK CORPORATION, KUMAMOTO, KUMAMOTO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:08:00 | WinXP | 95.88.215.226 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 3633185e02 NEW |
55d194738a [0] | none:none |
Armadillo| | none | trace | |
T:01:11:00 | Win2K-f | 78.9.84.36 (NET.PL): DIALOG, WROCLAW, DOLNOSLASKIE, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 55667c4a85 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:01:26:00 | WinXP | 95.84.45.223 (SAN.RU): NETWORK OF SARATOV BRANCH OF OJSC VOLGATELECOM, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ca8da15194 NEW |
b6fc2a1593 [0] | none:none |
Armadillo| | none | trace | |
T:01:27:00 | Win2K-f | 61.94.9.129 (TELKOM.NET.ID): PT TELKOM INDONESIA, JAKARTA, JAKARTA RAYA, ID. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 10 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:29:00 | Win2K-f | 95.58.3.186 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ec8ab501b3 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:01:43:00 | Win2K-f | 88.134.180.78 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 7793daa779 NEW |
5dac538fbc [0] | none:none |
Armadillo| | none | trace | |
T:01:44:00 | WinXP | 114.42.207.190 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
33 of 41 | de37f2fc47 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:01:54:00 | Win2K-f | 95.89.162.187 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
33 of 41 | b0c46107a6 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:01:58:00 | WinXP | 118.166.1.180 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ec8ab501b3 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:02:08:00 | Win2K-f | 114.38.179.248 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ec8ab501b3 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:02:13:00 | Win2K-f | 218.172.93.141 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 55667c4a85 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:02:16:00 | WinXP | 61.94.129.25 (TELKOM.NET.ID): PT. TELEKOMUNIKASI INDONESIA, JAKARTA, JAKARTA RAYA, ID. (DSL) |
66.252.13.212:16667 | US:bbs.moiservice.com US:attacke.100free.com DE:members.lycos.co.uk US:66.252.13.212:16667 |
445 | pcap | raw alerts ruleset |
ftp irc http 1080 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 41 38 of 40 10 of 41 |
11cde67678 NEW 331145624c NEW 7634ac1997 NEW |
9af8e2f833 [0] e7124c9b61[0] 9af8e2f833[0] |
none:none none:none none:none |
FSG| Stranik| FSG| |
none none none |
trace trace trace |
T:02:27:00 | Win2K-f | 78.239.29.44 (PROXAD.NET): PROXAD INTERNET SERVICE PROVIDER IN FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | f4a8e6a51e NEW |
acd8693185 [0] | none:none |
Armadillo| | none | trace | |
T:02:42:00 | Win2K-f | 95.89.80.106 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ffda37e02b NEW |
2669ff2865 [0] | none:none |
Armadillo| | none | trace | |
T:03:12:00 | Win2K-f | 189.118.50.230 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | a55778ac1c NEW |
97e2f1618d [0] | none:none |
Armadillo| | none | trace | |
T:03:16:00 | WinXP | 94.251.138.176 (-): CUSTOMER IN CZESTOCHOWA, CZESTOCHOWA, SLASKIE, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 5d31fa2adf NEW |
8992c05119 [0] | none:none |
Armadillo| | none | trace | |
T:03:19:00 | Win2K-f | 94.251.131.118 (-): CUSTOMER IN CZESTOCHOWA, WARSAW, WARSZAWA, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 8ab6e70b64 NEW |
72feb43272 [0] | none:none |
Armadillo| | none | trace | |
T:03:27:00 | Win2K-f | 63.16.0.138 (UU.NET): UUNET TECHNOLOGIES INC, PHOENIX, ARIZONA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 84 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:53:00 | WinXP | 83.132.3.195 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, PT. (DSL) |
66.252.13.212:16667 | US:bbs.moiservice.com | 445 | pcap | raw alerts ruleset |
ftp irc 35 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | be7f428663 NEW |
0ee7526007 [0] | none:none |
Stranik| | none | trace |
T:04:00:00 | Win2K-f | 188.99.245.131 (ARCOR-IP.NET): ARCOR-DSL-NET, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 3d5b054328 NEW |
29e313e61c [0] | none:none |
Armadillo| | none | trace | |
T:04:13:00 | WinXP | 62.182.71.11 (DOBROE.RU): ZHANR-NET, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 41 | c34d3ada53 NEW |
9b9b17a286 [0] | none:none |
Armadillo| | none | trace | |
T:04:17:00 | WinXP | 88.173.112.19 (PROXAD.NET): PROXAD / FREE SAS, ISSY-LES-MOULINEAUX, ILE-DE-FRANCE, FR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 7016d3fe8b NEW |
3a5ff804e9 [0] | none:none |
Armadillo| | none | trace | |
T:04:56:00 | WinXP | 125.224.139.22 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
33 of 41 | de37f2fc47 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:05:08:00 | Win2K-f | 80.171.191.38 (HANSENET.DE): HANSENET-ADSL, HAMBURG, HAMBURG, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ec8ab501b3 NEW |
bac4cc6eec [0] | none:none |
Armadillo| | none | trace | |
T:05:10:00 | Win2K-f | 70.184.102.222 (COX.NET): COX COMMUNICATIONS, PHOENIX, ARIZONA, US. (100Mbps) |
193.104.94.11:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:colopin.cn EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc 119 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 36 35 of 36 |
bea8cb1865 NEW fac78fde16 NEW |
154de51a66 [0] 882896ab05[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:05:23:00 | Win2K-f | 24.167.191.86 (RR.COM): ROAD RUNNER HOLDCO LLC, HIGH POINT, NORTH CAROLINA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:32:00 | WinXP | 114.48.240.71 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:05:48:00 | Win2K-f | 218.173.245.123 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 41 | 6c4f8d0b05 NEW |
c15495ec45 [0] | none:none |
Armadillo| | none | trace | |
T:06:14:00 | WinXP | 114.48.83.168 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 95308db598 NEW |
afdd2b80c4 [0] | none:none |
PolyEnE| | none | trace |
T:06:51:00 | WinXP | 24.234.132.15 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 52 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:07:32:00 | Win2K-f | 208.101.212.196 (MNCABLE.NET): SJOBERG CABLE, BAUDETTE, MINNESOTA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 291 lines |
Yeah : 1.3 profile |
none | summary tarball |
22 of 41 | 75af48afe4 NEW |
7a25f9e3cf [0] | none:none |
StarForce| | none | trace | |
T:07:39:00 | WinXP | 109.169.135.23 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
66.252.13.212:16667 | US:bbs.moiservice.com US:attacke.100free.com DE:members.lycos.co.uk DE:www.tripod.lycos.co.uk DE:www.multimania.co.uk US:205.134.160.58:80 US:66.252.13.212:16667 |
445 | pcap | raw alerts ruleset |
ftp irc http 107 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | ac24fa21de NEW |
374bf86707 [0] | none:none |
Stranik| | none | trace |
T:07:54:00 | WinXP | 203.91.165.87 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 80 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:23:00 | WinXP | 85.122.40.157 (-): SC AMBAVI TELECOM SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:16:00 | WinXP | 188.132.36.196 (-): SA-ETTIHADETISALAT, RIYADH, AR RIYAD, SA. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:10:00 | WinXP | 173.19.216.239 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, IOWA CITY, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
73d9e10cba NEW de3bdf7b4e NEW |
15076d5de4 [0] ff08fc71e3[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:13:05:00 | WinXP | 63.28.36.19 (UU.NET): UUNET TECHNOLOGIES INC, WINCHESTER, VIRGINIA, US. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com RU:www.bbin.ru :wpad US:spi.domainsponsor.com RU:195.200.213.54:80 US:204.13.161.51:80 US:208.73.210.125:80 |
445 | pcap | raw alerts ruleset |
http http http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:13:31:00 | WinXP | 95.75.125.173 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
193.104.94.11:65520 | CN:proxim.ircgalaxy.pl CN:dl.guarddog2009.com :komojoke.cn CN:config1007.iwillhavesexygirls.com CN:maillist.iwillhavesexygirls.com EU:colopin.cn FR:193.104.94.11:65520 EU:91.206.201.39:80 |
445 | pcap | raw alerts ruleset |
http irc 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 41 15 of 41 7 of 41 29 of 41 37 of 39 |
2fa130feec NEW 83192a6119 NEW 85c00cc118 NEW 9354673997 NEW dab4da4e21 NEW |
8a06db2aef [0] fdc95e1fab[0] none [3] 60e874b776[0] e63b813015[0] |
none:none none:none none:none none:none ASM:Graph |
Armadillo| none|none StarForce| none|none PolyEnE| |
none none none none lines=134 |
trace trace trace trace trace |
T:13:31:00 | WinXP | 89.204.177.54 (O2.IE): O2 IRELAND MOBILE PHONE OPERATOR, DUBLIN, DUBLIN, IE. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad US:204.13.161.51:80 |
445 | pcap | raw alerts ruleset |
http http http http 23 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | da9e21ae21 NEW |
d3271206dd [0] | none:none |
ASPack| | none | trace |
T:14:23:00 | Win2K-f | 71.116.212.170 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:43:00 | Win2K-f | 219.114.247.138 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 40 |
024410ad21 NEW b0cedd71bb NEW |
96d0267b80 [0] f6e156bdca[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:15:03:00 | WinXP | 83.185.27.226 (TELE2.SE): TELE2-MOBILE-INTERNET, SE. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | none:none |
PolyEnE| | none | trace |
T:15:27:00 | WinXP | 65.29.28.225 (RR.COM): ROAD RUNNER HOLDCO LLC, GERMANTOWN, WISCONSIN, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:15:57:00 | Win2K-f | 68.151.243.247 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, EDMONTON, ALBERTA, CA. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:16:18:00 | Win2K-f | 4.143.86.166 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CLEVELAND, OHIO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 39 37 of 39 |
166484192b NEW 2a1e547005 NEW |
0c886fcb7b [0] 5c75fa020a[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:16:38:00 | WinXP | 173.19.82.74 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CEDAR RAPIDS, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
3bff218b8f NEW 7eaf7b4470 NEW |
b570b734be [0] 8e0b194526[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:18:20:00 | WinXP | 217.203.129.173 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | f2a8dafb30 NEW |
1d0f660523 [0] | none:none |
PolyEnE| | none | trace |
T:18:37:00 | WinXP | 208.100.226.27 (1DIAL.COM): AD-BASE SYSTEMS INC. (DBA GLOBALPOPS), ATHENS, ALABAMA, US. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | dd02947289 NEW |
none[0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:20:06:00 | WinXP | 60.56.35.67 (EONET.NE.JP): K-OPTICOM CORPORATION, NISHINOMIYA, HYOGO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 8ab0fb88b8 NEW |
968cc91789 [0] | none:none |
none|none | none | trace | |
T:20:24:00 | Win2K-f | 203.91.160.116 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:21:21:00 | Win2K-f | 99.174.146.106 (PACBELL.NET): AT&T INTERNET SERVICES, HOUSTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:22:19:00 | Win2K-f | 65.184.62.103 (RR.COM): ROAD RUNNER HOLDCO LLC, WILMINGTON, NORTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 36 of 41 |
84ace068d1 NEW c584af4fcd NEW |
c822a7d0e4 [0] bdfcf0a930[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:22:21:00 | WinXP | 83.185.28.103 (TELE2.SE): TELE2-MOBILE-INTERNET, SE. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 522832a551 NEW |
0c7f5442b0 [0] | none:none |
PolyEnE| | none | trace |
T:22:33:00 | WinXP | 114.48.225.253 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:23:37:00 | Win2K-f | 173.29.83.184 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, DAVENPORT, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:23:51:00 | WinXP | 220.137.59.15 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |