Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:11:00 | Win2K-f | 94.127.200.179 (VINF.RU): NETWORK OF METROMAX LTD. DIMITROVGRAD BRANCH, RU. (DSL) |
n/a | US:msn.com EE:www.starman.ee :www.betneed.com US:cnn.com :www.fiftpose.com :google.com :www.runfoods.com :www.formmesh.com FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
http irc 16 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:18:00 | Win2K-f | 222.230.153.147 (VECTANT.NE.JP): SEIKA CORPORATION, YOKOHAMA, KANAGAWA, JP. (100Mbps) |
88.198.228.238:65520 | US:hophealth.com CN:proxima.ircgalaxy.pl CN:av.lometr.pl CN:down1130.iwillhavesexygirls.com CN:1130.kfgrtjer.cn :bfkq.com :jsactivity.com US:search.toptravellingtips.com US:search.articleswave.co.uk 204.27.57.154:8392 US:208.43.250.167:80 |
445 | pcap | raw alerts ruleset |
http irc 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 41 23 of 41 15 of 41 0 of 40 6 of 41 14 of 41 |
2102e402d1 NEW 357486dae7 NEW 992ba5790f NEW a449ee10ce NEW d61a351c60 NEW e5fd00eddc NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
00:51:00 | Win2K-f | 93.80.235.27 (CORBINA.RU): BROADBAND CUSTOMERS IN MOSCOW, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | :in1.7cy.net US:microsoft.com US:cnn.com US:msn.com 174.133.57.140:80 FI:194.215.38.3:80 US:204.152.184.139:80 204.27.57.154:8392 GB:212.117.177.140:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
irc 28 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:52:00 | Win2K-f | 218.211.83.237 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:09:00 | Win2K-f | 96.8.145.191 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
77656a2953 NEW a77e51636f NEW |
13296a6198 [0] c5e16ba6b7[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
02:21:00 | Win2K-f | 82.114.252.62 (SCTS.RU): SARATOV DIGITAL PHONE NETWORK LTD, SARATOV, SARATOV, RU. (DSL) |
n/a | EE:www.starman.ee US:ahttskb.org :uofgdzalgrd.biz US:ehnrokeu.org BG:betbg.net :hanzkcbgd.net :ndvvl.biz :zebmadt.net :pxvlgoxbgin.com US:dumvcdpww.info :aszgbvaphhp.net US:microsoft.com :jcqnpq.com US:pijktwhziu.info :mpkqljyb.net NL:cyizqgq.org :faqqtpmpab.biz :yattuzaz.biz :tprfbjz.com :qkvrsqwlac.info NL:ejphjg.org :zuqod.net :google.com :hxqwdejx.biz :jirohcm.biz :adcbtdyfpc.com :rdvpej.org :emmgascnja.net :cegemkqa.biz US:rgomficsxk.info :ttvue.net US:jiwkucr.org :skpzpmqy.info :in1.7cy.net :bplbj.biz :yxalhys.net US:yaraffoib.org :ytrsvqyec.net US:knfztn.info :qejprfvdfgo.org NL:ofvkwvu.org :flvsurhspcw.net US:sqggv.info :xbczn.biz US:yahoo.com US:cnn.com FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 EE:62.65.192.25:80 US:74.208.64.145:80 |
445 | pcap | raw alerts ruleset |
http irc 17 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
04:52:00 | Win2K-f | 117.196.180.46 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), INDORE, MADHYA PRADESH, IN. (DSL) |
n/a | US:msn.com :google.com US:microsoft.com US:yahoo.com 174.133.57.140:80 FI:194.215.38.3:80 US:204.152.184.139:80 204.27.57.154:8392 GB:212.117.177.140:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http irc 30 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:05:19:00 | Win2K-f | 68.146.136.164 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 40 of 41 |
19f9cb1f21 NEW a9d40bc96b NEW |
8b1482be5d [0] b07fa6d434[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:06:15:00 | Win2K-f | 208.82.42.99 (ENERGIZE.NET): PULASKI ELECTRIC SYSTEM, PULASKI, TENNESSEE, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:26:00 | Win2K-f | 67.55.179.41 (NETINS.NET): WESTERN IOWA TELEPHONE, MOVILLE, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
06:51:00 | Win2K-f | 201.255.160.55 (COM.AR): TELEFONICA DE ARGENTINA, BUENOS AIRES, BUENOS AIRES, AR. (DSL) |
193.104.94.11:65520 | US:cnn.com CN:down1130.iwillhavesexygirls.com CN:1130.kfgrtjer.cn :google.com US:microsoft.com 174.133.57.140:80 FI:194.215.38.3:80 US:204.152.184.139:80 204.27.57.154:8392 EE:62.65.192.24:80 EE:62.65.192.25:80 |
445 | pcap | raw alerts ruleset |
irc http 34 lines |
Yeah : 1.3 profile |
none | summary tarball |
15 of 41 14 of 41 |
992ba5790f NEW e5fd00eddc NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:08:39:00 | WinXP | 4.186.21.8 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NORTH BERGEN, NEW JERSEY, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:42:00 | WinXP | 79.162.141.190 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.219.245.212:80 | FR:proxim.ircgalaxy.pl RU:citi-bank.ru CN:122.195.190.197:65520 |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:09:12:00 | Win2K-f | 99.164.23.178 (SBCGLOBAL.NET): RANI PAL LLC, PLANO, TEXAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 402 lines |
Yeah : 1.3 profile |
none | summary tarball |
11 of 36 | c4c5a56ffe NEW |
8bef2f9170 [0] | none:none |
StarForce| | none | trace | |
T:09:38:00 | Win2K-f | 173.20.140.66 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, ALBANY, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5e3a9c2d9d NEW 630308d06b NEW |
dbc48b815a [0] 847d302e37[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:10:21:00 | Win2K-f | 211.211.90.245 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
88.198.228.238:65520 | FR:proxim.ircgalaxy.pl US:microsoft.com CN:down1130.iwillhavesexygirls.com :bfkq.com :jsactivity.com US:search.toptravellingtips.com US:search.articleswave.co.uk :sendfan.com 173.45.105.218:8392 US:208.43.250.167:80 DE:88.198.228.238:65520 |
135 | pcap | raw alerts ruleset |
irc http 252 lines |
Yeah : 1.8 profile |
none | summary tarball |
14 of 40 8 of 40 0 of 40 12 of 40 6 of 41 38 of 40 37 of 40 |
34e792d03a NEW 401988e228 NEW 7ba3aa37f5 NEW c907a23903 NEW d61a351c60 NEW db5004d480 NEW ebaffa4dd0 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none |
none none none none none none none |
10:21:00 | Win2K-f | 93.91.200.60 (-): NEWROZ TELECOM ADSL SUBSCRIBERS, IQ. (DSL) |
n/a | US:msn.com EE:www.starman.ee US:cnn.com :commerceclick.co.uk FI:194.215.38.3:80 EE:195.50.195.10:443 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:09:00 | Win2K-f | 114.48.22.244 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
193.104.94.11:65520 | FR:proxim.ircgalaxy.pl CN:www.liagand.cn CN:down1130.iwillhavesexygirls.com |
445 | pcap | raw alerts ruleset |
http irc 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
14 of 40 0 of 40 12 of 40 |
34e792d03a NEW 9f03bee05a NEW c907a23903 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
T:12:02:00 | Win2K-f | 204.181.140.250 (SPRINTLINK.NET): SPRINT, BETHEL, CONNECTICUT, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 120 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
4d4b7efca2 NEW 539d61fc06 NEW |
ec83dac222 [0] c3af874c93[0] |
none:none none:none |
Armadillo| tElock| |
none none |
trace trace |
T:12:29:00 | WinXP | 186.9.72.218 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
12:34:00 | WinXP | 60.249.94.30 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [none] | none:none |
PolyEnE| | none | trace |
13:07:00 | Win2K-f | 211.72.29.35 (-): CHUANG DUN TECHNOLOGY CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com US:www.getmyip.org :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
13:11:00 | WinXP | 186.9.72.218 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:31:00 | WinXP | 70.183.160.46 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (DSL) |
122.195.190.197:65520 88.198.228.238:65520 | FR:proxim.ircgalaxy.pl US:microsoft.com CN:www.liagand.cn CN:down1130.iwillhavesexygirls.com :bfkq.com :jsactivity.com CN:122.195.190.197:65520 204.27.57.210:80 DE:88.198.228.238:65520 |
135 | pcap | raw alerts ruleset |
irc http 201 lines |
Yeah : 1.8 profile |
none | summary tarball |
14 of 40 0 of 39 32 of 36 12 of 40 5 of 41 35 of 36 |
34e792d03a NEW 8338dc27de NEW bea8cb1865 NEW c907a23903 NEW d697b76f39 NEW fac78fde16 NEW |
none[none] none [none] 154de51a66[0] none [none] none [none] 882896ab05[0] |
none:none none:none ASM:Graph none:none none:none none:none |
none|none none|none Armadillo| none|none none|none tElock| |
none none lines=91 none none none |
none none trace none none trace |
T:13:42:00 | WinXP | 87.173.103.4 (T-DIALIN.NET): DEUTSCHE TELEKOM AG, BERLIN, BERLIN, DE. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
13:50:00 | Win2K-f | 173.45.68.68 (XLHOST.COM): XLHOST.COM INC, COLUMBUS, OHIO, US. (100Mbps) |
n/a | US:www.maxmind.com EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 7 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:14:34:00 | Win2K-f | 208.98.181.179 (DIRECTCOM.COM): DIRECT COMMUNICATIONS CABLE LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
14:37:00 | Win2K-f | 95.27.71.102 (CORBINA.NET): INVESTELEKTROSVIAZ LTD, RU. (DSL) |
n/a | :google.com US:msn.com FR:proxim.ircgalaxy.pl US:yahoo.com 204.27.57.154:8392 DE:88.198.228.238:65520 |
445 | pcap | raw alerts ruleset |
http 19 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
14:49:00 | Win2K-f | 187.9.40.242 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:microsoft.com US:yahoo.com GB:www.businesstomb.com FR:proxim.ircgalaxy.pl US:www.maxmind.com US:msn.com :commerceclick.co.uk US:cnn.com FR:193.104.94.11:65520 204.27.57.154:8392 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
http 21 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
15:07:00 | Win2K-f | 77.81.112.100 (IPN.RO): SC PLANET RIVULUS SRL, RO. (DSL) |
88.198.228.238:65520 | US:yahoo.com CN:av.lometr.pl CN:210.51.36.215:88 GB:212.117.177.140:80 |
445 | pcap | raw alerts ruleset |
irc http 31 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 41 | 357486dae7 NEW |
none[none] | none:none |
none|none | none | none |
T:15:16:00 | WinXP | 174.3.75.99 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, TORONTO, ONTARIO, CA. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 38 of 41 |
9850931e93 NEW e770121662 NEW |
443d54cb48 [0] ac4b533671[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:16:24:00 | WinXP | 114.48.177.216 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 07cd99a10b NEW |
f8f0f72da6 [none] | none:none |
PolyEnE| | none | trace |
T:16:30:00 | WinXP | 76.89.228.31 (RR.COM): ROAD RUNNER HOLDCO LLC, MORENO VALLEY, CALIFORNIA, US. (DSL) |
213.219.245.212:80 | RU:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
T:16:45:00 | Win2K-f | 70.184.248.143 (COX.NET): COX COMMUNICATIONS, TULSA, OKLAHOMA, US. (DSL) |
122.195.190.197:65520 | FR:proxim.ircgalaxy.pl US:microsoft.com CN:www.liagand.cn CN:down1130.iwillhavesexygirls.com :bfkq.com :jsactivity.com US:search.toptravellingtips.com US:66.96.221.101:8392 |
135 | pcap | raw alerts ruleset |
irc http 210 lines |
Yeah : 1.8 profile |
none | summary tarball |
14 of 40 8 of 40 0 of 40 32 of 33 29 of 33 12 of 40 2 of 41 |
34e792d03a NEW 401988e228 NEW 52339ad817 NEW 87e1117f2a NEW b4fe4581c3 NEW c907a23903 NEW ef725f64f4 NEW |
none[none] none [none] none [none] 3ff643aae6[0] 599b835896[0] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none tElock| Armadillo| none|none none|none |
none none none none none none none |
none none none trace trace none none |
T:16:49:00 | Win2K-f | 69.109.212.52 (PACBELL.NET): PLTNCA INTERNAL, SAN FRANCISCO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:58:00 | Win2K-f | 122.27.22.157 (OCN.NE.JP): OPEN COMPUTER NETWORK, KOBE, HYOGO, JP. (DSL) |
n/a | US:as.casalemedia.com :images.ddc.com :s7.addthis.com US:cdn.optmd.com US:domdex.com :download.macromedia.com US:i.casalemedia.com :a.collective-media.net :b.collective-media.net :ad.yieldmanager.com US:ad.adtegrity.net US:fpdownload2.macromedia.com US:www.gogogo.com FR:proxim.ircgalaxy.pl |
445 | pcap | raw alerts ruleset |
http 48 lines |
Argh : 0.3 profile |
none | summary tarball |
10 of 40 0 of 40 |
cfbb0ddcce NEW ff630379b9 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
17:18:00 | Win2K-f | 200.45.161.102 (NET.AR): MIDAS-TELECOM, RECONQUISTA, SANTA FE, AR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org EU:getmyip.co.uk US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:27:00 | Win2K-f | 200.45.161.102 (NET.AR): MIDAS-TELECOM, RECONQUISTA, SANTA FE, AR. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 8 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:40:00 | Win2K-f | 203.91.177.84 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:11:00 | Win2K-f | 110.14.214.164 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
193.104.94.11:65520 | US:microsoft.com FR:proxim.ircgalaxy.pl CN:down1130.iwillhavesexygirls.com CN:1130.kfgrtjer.cn :bfkq.com :jsactivity.com US:search.toptravellingtips.com US:search.articleswave.co.uk :www.articleswave.co.uk US:208.43.250.167:80 |
135 | pcap | raw alerts ruleset |
irc http 246 lines |
Yeah : 1.8 profile |
none | summary tarball |
0 of 40 37 of 41 10 of 40 0 of 40 38 of 41 9 of 40 6 of 40 |
47c76e0bdf NEW 598636aa73 NEW 688afae42a NEW 7c84ac0401 NEW a57ddcdef0 NEW a8f322b237 NEW ee47b2f51d NEW |
none[none] 613af3f9a2[0] none [none] none [none] none [4] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none Armadillo| none|none none|none PolyEnE| none|none none|none |
none none none none none none none |
none trace none none trace none none |
18:24:00 | Win2K-f | 89.44.80.17 (ACX.RO): SC-NET-AND-COMPUTERS-SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:msn.com EE:www.starman.ee US:trafficconverter.biz US:microsoft.com :google.com US:www.w3.org US:otbkfmoytka.org US:bmofuwwmvsv.info NL:fjkyzeo.org US:skods.info US:mnvungmivmy.org US:xnhbxwb.org :mninp.net :ihnds.biz :zvpxxyimfs.com :tsnzkll.org NL:svxhaiej.info :tgbejxrvv.com :rqplhwt.biz :llcmflgm.biz :yummkapc.net US:kulgj.info :remlxtc.info NL:nudceahr.org :lrkkkogcem.biz :edxbpxyqgy.net FI:194.215.38.3:80 EE:195.50.195.10:443 GB:212.117.177.140:80 EE:62.65.192.24:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
18:51:00 | WinXP | 76.89.228.31 (RR.COM): ROAD RUNNER HOLDCO LLC, MORENO VALLEY, CALIFORNIA, US. (DSL) |
n/a | RU:citi-bank.ru RU:213.219.245.212:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |