Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:19:00 | Win2K-f | 114.201.12.208 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
193.104.94.11:65520 | US:microsoft.com DE:proxima.ircgalaxy.pl CN:av.ghura.pl CN:q.kfgrtjer.cn EU:colopin.cn :pozemle.cn |
135 | pcap | raw alerts ruleset |
irc http 118 lines |
Yeah : 1.8 profile |
none | summary tarball |
4 of 41 31 of 41 29 of 41 34 of 36 23 of 41 29 of 32 |
14c958f874 NEW 3d174375ea NEW 785e86954f NEW 99b248336f NEW 9b6ea363eb NEW 9d677c3f70 NEW |
none[none] none [none] c6edee8e8b[0] c64bd1a776[0] none [none] 77e75ff10f[0] |
none:none none:none none:none none:none none:none none:none |
none|none none|none PeStubOEP| Armadillo| none|none tElock| |
none none none none none none |
none none trace trace none trace |
T:02:50:00 | Win2K-f | 64.144.35.70 (MEGAPATH.NET): MEGAPATH NETWORKS INC, JERSEY CITY, NEW JERSEY, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:44:00 | WinXP | 216.152.2.100 (-): CITY OF WILSON, PEA RIDGE, ARKANSAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:55:00 | Win2K-f | 173.74.167.197 (VERIZON.NET): VERIZON INTERNET SERVICES INC, PLANO, TEXAS, US. (DSL) |
212.54.2.171:3305 | TH:cx10man.weedns.com JP:fx010413.whyI.org AR:gynoman.weedns.com RU:g.0x20.biz TH:c010x1.co.cc AR:commgr.co.cc FI:telephone.dd.blueline.be RU:89.208.33.88:3305 92.240.234.164:3305 |
135 | pcap | raw alerts ruleset |
irc 698 lines |
Yeah : 1.8 profile |
none | summary tarball |
34 of 41 | deffdf68e8 NEW |
2b011e15ba [0] | none:none |
StarForce| | none | trace |
T:05:15:00 | WinXP | 195.95.87.47 (DIAL.SCARLET.BE): PI-BELGIUM, ANTWERP, ANTWERPEN, BE. (DIAL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | b0bcbc2d7c NEW |
none[none] | none:none |
none|none | none | none |
T:05:17:00 | Win2K-f | 218.117.136.125 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, KITAKYUSHU, FUKUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:20:00 | WinXP | 4.141.62.101 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, WARRENSBURG, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 153 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:54:00 | WinXP | 75.60.205.88 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:07:00 | Win2K-f | 208.126.117.125 (NETINS.NET): WESTERN IOWA TELEPHONE, MOVILLE, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:21:00 | Win2K-f | 219.254.99.212 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
88.198.228.238:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl CN:www.brans.pl EU:colopin.cn |
135 | pcap | raw alerts ruleset |
irc http 138 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 41 30 of 33 28 of 33 29 of 41 18 of 40 |
3d174375ea NEW 533d15b5ce NEW 58c343a8d8 NEW 785e86954f NEW c44b28de51 NEW |
none[none] c67adf46e2[0] none [0] c6edee8e8b[0] none [none] |
none:none ASM:Graph none:none none:none none:none |
none|none tElock| Armadillo| PeStubOEP| none|none |
none lines=126 embedded dns lines=91 none none |
none trace trace trace none |
T:07:10:00 | WinXP | 119.77.158.125 (UBBN.NET): UNION BROADBAND NETWORK, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 97e402001a NEW |
none[none] | none:none |
none|none | none | none |
T:08:06:00 | Win2K-f | 66.25.117.205 (RR.COM): ROAD RUNNER HOLDCO LLC, BIRMINGHAM, ALABAMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:25:00 | Win2K-f | 174.6.21.151 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:25:00 | WinXP | 65.32.223.95 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:55:00 | Win2K-f | 207.5.194.120 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:09:19:00 | Win2K-f | 65.34.30.26 (RR.COM): ROAD RUNNER HOLDCO LLC, CLERMONT, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:30:00 | WinXP | 63.227.6.89 (CSUOHIO.EDU): QWEST COMMUNICATIONS CORPORATION, DENVER, COLORADO, US. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 7dd92cbd4b NEW |
none[none] | none:none |
none|none | none | none | |
T:09:51:00 | WinXP | 77.253.122.117 (INETIA.PL): INTERNETIA, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | ed96c03ca8 NEW |
c0028e9e98 [0] | none:none |
PolyEnE| | none | trace |
T:09:54:00 | Win2K-f | 208.113.27.206 (DSL4U.CA): ACCELERATED CONNECTIONS, SCARBOROUGH, ONTARIO, CA. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 187 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 154e28f846 NEW |
4d85da80b1 [0] | none:none |
none|none | none | trace | |
T:10:33:00 | Win2K-f | 174.0.24.11 (KODIAKPETROLEUM.COM): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 228 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
none:none none:none |
Armadillo| PolyEnE| |
none none |
trace trace |
T:10:51:00 | Win2K-f | 96.8.147.169 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 40 |
9bdd2c95b1 NEW cd456ac095 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:10:57:00 | WinXP | 95.74.144.196 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | ASM:Graph |
none|none | lines=61 | trace | |
T:11:13:00 | WinXP | 4.224.105.157 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, COLUMBUS, OHIO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 119 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
11:25:00 | WinXP | 78.92.160.81 (T-ONLINE.HU): T-ONLINE CATV CLIENT POOL, BUDAPEST, BUDAPEST, HU. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 01c4a6b3eb NEW |
dd524b0259 [0] | none:none |
PolyEnE| | none | trace |
T:11:33:00 | WinXP | 173.20.14.225 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MASON CITY, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:11:37:00 | Win2K-f | 69.193.74.22 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:02:00 | Win2K-f | 24.213.224.238 (RR.COM): ROAD RUNNER HOLDCO LLC, AMSTERDAM, NOORD-HOLLAND, NL. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:22:00 | Win2K-f | 70.166.107.90 (COX.NET): COX COMMUNICATIONS, PHOENIX, ARIZONA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1009 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 39 | 633319e478 NEW |
none[none] | none:none |
none|none | none | none | |
T:12:24:00 | WinXP | 117.99.20.214 (-): GPRS-SUBSCRIBERS-IN-EAST, BHUBANESHWAR, ORISSA, IN. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ca8bd5c40e NEW |
9cb687217f [0] | none:none |
PolyEnE| | none | trace |
T:12:54:00 | Win2K-f | 24.86.84.208 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1003 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 41 | 4e482110e9 NEW |
none[none] | none:none |
none|none | none | none | |
14:15:00 | WinXP | 88.154.27.183 (-): LIMITED LIABILITY COMPANY ASTELIT, UA. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:14:31:00 | WinXP | 70.183.160.46 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (DSL) |
88.198.228.238:65520 193.104.94.11:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:q.kfgrtjer.cn EU:colopin.cn CN:config1130.iwillhavesexygirls.com CN:av.ghura.pl :pozemle.cn CN:210.51.36.215:88 EU:91.206.201.39:80 |
135 | pcap | raw alerts ruleset |
irc http 130 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 41 29 of 41 18 of 41 23 of 41 32 of 36 10 of 41 35 of 36 |
3d174375ea NEW 785e86954f NEW 99d68b5c5b NEW 9b6ea363eb NEW bea8cb1865 NEW efb275f9df NEW fac78fde16 NEW |
none[none] c6edee8e8b[0] none [none] none [none] 154de51a66[0] none [none] 882896ab05[0] |
none:none none:none none:none none:none ASM:Graph none:none none:none |
none|none PeStubOEP| none|none none|none Armadillo| none|none tElock| |
none none none none lines=91 none none |
none trace none none trace none trace |
T:14:59:00 | Win2K-f | 122.49.235.131 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=81 lines=75 embedded dns |
trace trace |
T:16:23:00 | Win2K-f | 98.141.9.117 (CAVTEL.NET): CAVALIER TELEPHONE, VIRGINIA BEACH, VIRGINIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
16:46:00 | Win2K-f | 190.49.164.85 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:16:50:00 | WinXP | 4.243.101.37 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, RICHMOND, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 68 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:16:51:00 | Win2K-f | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:01:00 | Win2K-f | 190.49.164.85 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:01:00 | Win2K-f | 203.91.165.198 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:17:09:00 | WinXP | 166.164.120.130 (MYVZW.COM): SERVICE PROVIDER CORPORATION, RUSSELLVILLE, ARKANSAS, US. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | none:none |
PolyEnE| | none | trace |
T:18:21:00 | WinXP | 189.48.244.190 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, RIO DE JANEIRO, RIO DE JANEIRO, BR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 9d94bc6743 NEW |
a42cc1cd6b [0] | none:none |
PolyEnE| | none | trace |
T:18:41:00 | WinXP | 121.121.154.33 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8015c2d45f NEW |
749cbc2739 [0] | none:none |
PolyEnE| | none | trace |
T:18:51:00 | Win2K-f | 65.33.134.51 (RR.COM): ROAD RUNNER HOLDCO LLC, APOPKA, FLORIDA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:10:00 | Win2K-f | 70.123.100.231 (RR.COM): ROAD RUNNER HOLDCO LLC, COPPELL, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:21:00 | WinXP | 115.165.80.195 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:20:12:00 | Win2K-f | 75.60.211.162 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, COLUMBUS, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:45:00 | Win2K-f | 208.36.224.184 (XO.NET): ALTUS COMMUNICATIONS GROUP INC, GEORGETOWN, SOUTH CAROLINA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:20:58:00 | Win2K-f | 68.146.136.164 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
92.240.234.164:3305 | :cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 612 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 | 9ce56f9f19 NEW |
261c9da48f [0] | none:none |
StarForce| | none | trace |
T:21:18:00 | Win2K-f | 174.3.75.99 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, TORONTO, ONTARIO, CA. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 592 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 3fc86a2f40 NEW |
none[none] | none:none |
none|none | none | none | |
T:21:50:00 | Win2K-f | 59.120.228.224 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 53 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | 57ce4acac2 NEW |
none[0] | none:none |
Armadillo| | lines=90 | trace | |
T:22:19:00 | Win2K-f | 24.85.47.14 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 603 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 288edf00ad NEW |
5c93343272 [0] | none:none |
StarForce| | none | trace | |
T:22:22:00 | WinXP | 209.248.123.198 (FALCONBROADBAND.NET): VANION INC, COLORADO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |