Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

19 May 2010
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:12:00 Win2K-f 119.161.113.135 (KCN-TV.NE.JP):
KUMAMOTO CABLE NETWORK CORPORATION,
KUMAMOTO, KUMAMOTO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
115 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
535e5bf353
NEW
c663ef90fc
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:00:20:00 WinXP 203.133.137.245 (ZTV.NE.JP):
ZTV CO. LTD,
NAGOYA, TOKYO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 03f912899b
NEW
none[0] none:none
none|none lines=64 trace
T:00:28:00 Win2K-f 69.193.74.22 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
00:33:00 WinXP 206.246.29.101 (-):
SENECA TELEPHONE,
SENECA, MISSOURI, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
3 lines
Yeah : 0.8
profile
none summary
tarball
41 of 41 97465e5d46
NEW
none[none] none:none
none|none none none
T:00:59:00 Win2K-f 96.8.215.231 (GVTC.COM):
GUADALUPE VALLEY TELEPHONE COOPERATIVE INC,
NEW BRAUNFELS, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
39 of 40
9bdd2c95b1
NEW
cd456ac095
NEW
d1bbd693ba [0]
d75caee680[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:01:29:00 WinXP 121.120.9.34 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:01:38:00 WinXP 173.171.142.175 (RR.COM):
ROAD RUNNER HOLDCO LLC,
TAMPA, FLORIDA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
03882d1026
NEW
8eb4708ff1
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:01:44:00 Win2K-f 61.250.125.119 (KRLINE.NET):
KRNIC,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
n/a   135 pcap raw alerts
ruleset
other
5 lines
Yeah : 0.8
profile
none summary
tarball
none none none none none none none
T:01:47:00 WinXP 70.122.217.85 (RR.COM):
ROAD RUNNER HOLDCO LLC,
TEXAS CITY, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
79 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:06:00 WinXP 110.12.71.184 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
83.133.119.206:65520 DE:proxim.ircgalaxy.pl
US:microsoft.com
MD:ad.ghura.pl
CN:ad.lometr.pl
MD:li1i16b0.com
CN:ku1.installstorm.com
CN:down.installstorm.com
US:mst.com.ua
BR:www.sextoy.com.br
JP:164.46.227.120:443
MD:195.170.178.55:443
BR:201.20.45.207:443
BR:201.76.50.168:443
UA:212.82.216.42:443
JP:219.94.155.204:443
US:69.57.128.35:443
US:69.61.11.226:443
UA:82.193.122.190:443
135 pcap raw alerts
ruleset
irc
http
138 lines
Yeah : 1.8
profile
none summary
tarball
36 of 41
30 of 33
28 of 33
18 of 41
6 of 41
05265022c4
NEW
533d15b5ce
NEW
58c343a8d8
NEW
a1fdcee696
NEW
a8b84e9abe
NEW
none[none]
c67adf46e2[0]
none [0]
none [none]
none [none]
none:none
ASM:Graph
none:none
none:none
none:none
none|none
tElock|
Armadillo|
none|none
none|none
none
lines=126
embedded dns
lines=91
none
none
none
trace
trace
none
none
T:03:17:00 Win2K-f 122.146.80.161 (SPARQNET.NET):
NEW CENTRY INFOCOM TECH. CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:17:00 Win2K-f 114.74.204.20 (OPTUSNET.COM.AU):
OPTUS INTERNET - RETAIL,
MELBOURNE, VICTORIA, AU. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
40 of 41
56703b9d17
NEW
c55e86f7e9
NEW
de8764ef05 [0]
c790c10ad1[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:03:34:00 WinXP 222.230.153.150 (VECTANT.NE.JP):
SEIKA CORPORATION,
YOKOHAMA, KANAGAWA, JP. (100Mbps)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 831f4ee0a7
NEW
none[0] none:none
none|none lines=60 trace
T:04:04:00 WinXP 144.138.37.69 (TMNS.NET.AU):
TELSTRAINTERNET31,
CANBERRA, AUSTRALIAN CAPITAL TERRITORY, AU. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
1 of 41
53bfe15e91
NEW
bb598daecf
NEW
1473091351 [0]
128bc5471a[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
04:17:00 WinXP 77.111.157.93 (ZELKANET.HU):
CATV CLIENTS VI. (ZELKANET DYNAMIC POOL),
HU. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:04:23:00 Win2K-f 174.79.248.218 (COX.NET):
COX COMMUNICATIONS,
ATLANTA, GEORGIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:05:12:00 WinXP 194.19.234.252 (-):
BTG,
RIGA, RIGA, LV. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:05:47:00 Win2K-f 113.253.100.222 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HONG KONG, HONG KONG (SAR), HK. (DSL)
n/a   135 pcap raw alerts
ruleset
other
1002 lines
Yeah : 1.3
profile
none summary
tarball
35 of 41 559acaa271
NEW
none[3] none:none
none|none none trace
T:05:58:00 WinXP 91.64.75.227 (SUPERKABEL.DE):
KABEL-DEUTSCHLAND-CUSTOMER-SERVICES,
KIEL, SCHLESWIG-HOLSTEIN, DE. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
42 of 42 c46f4552da
NEW
ce6ff736cf [0] none:none
none|none none trace
T:06:05:00 Win2K-f 196.208.27.232 (TELKOMADSL.CO.ZA):
AFRINIC,
DURBAN, KWAZULU-NATAL, ZA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
113 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:06:20:00 Win2K-f 218.32.100.64 (SDTV.NET.TW):
SAN DA CATV CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
143 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
37 of 41
a205366bef
NEW
efaef2451a
NEW
82bbbe4789 [0]
5382f9a037[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=64
embedded dns
lines=91
trace
trace
T:07:20:00 WinXP 207.5.164.171 (SUSCOM-MAINE.NET):
GREAT WORKS INTERNET,
BRUNSWICK, MAINE, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
79 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:07:51:00 WinXP 125.4.247.21 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
TOKYO, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
40 of 41
2b9840a764
NEW
cf1c3ff0b0
NEW
a7dbe16bd8 [0]
none [none]
ASM:Graph
none:none
Armadillo|
none|none
lines=91
none
trace
none
T:07:54:00 Win2K-f 123.50.225.154 (KCN-TV.NE.JP):
KUMAMOTO CABLE NETWORK CORPORATION,
KUMAMOTO, KUMAMOTO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
99 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 40
08517155d3
NEW
6eb9029327
NEW
a13e5eafa4 [0]
8cbcf621b4[0]
none:none
ASM:Graph
tElock|
tElock|
none
lines=64
embedded dns
trace
trace
T:08:42:00 WinXP 87.116.236.9 (TNP.PL):
NETWORK OF INTERNET SERVICE PROVIDER,
WARSAW, WARSZAWA, PL. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 5818023061
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:08:50:00 Win2K-f 69.193.68.239 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:10:22:00 WinXP 4.163.195.36 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DENVER, COLORADO, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
92 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:10:42:00 Win2K-f 208.110.57.2 (-):
PRIVATE CABLE ISP SUBSCRIBER (SCHAUMBURG IL MARKET),
JONESBORO, GEORGIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:11:35:00 WinXP 96.11.222.89 (RR.COM):
ROAD RUNNER HOLDCO LLC,
MIDDLETOWN, OHIO, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
19 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:12:06:00 WinXP 70.184.154.68 (COX.NET):
COX COMMUNICATIONS,
YUKON, OKLAHOMA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
91 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
38 of 41
53bfe15e91
NEW
97437a0627
NEW
1473091351 [0]
none [none]
ASM:Graph
none:none
tElock|
none|none
lines=75
embedded dns
none
trace
none
T:12:26:00 WinXP 79.163.244.169 (CENTERTEL.PL):
PTK CENTERTEL BROADBAND SERVICES,
WARSAW, WARSZAWA, PL. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:12:33:00 Win2K-f 24.213.224.238 (RR.COM):
ROAD RUNNER HOLDCO LLC,
AMSTERDAM, NOORD-HOLLAND, NL. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:12:34:00 WinXP 66.216.213.33 (NEWNANUTILITIES.ORG):
NEWNAN UTILITIES,
NEWNAN, GEORGIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
112 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 40
223e5baa96
NEW
ee6feade2d
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:12:39:00 WinXP 125.230.118.72 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
T:12:44:00 WinXP 110.12.29.187 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
114 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
5 of 41
14f47ffd1e
NEW
50437008d9
NEW
90bf4b99ff [0]
c1b09ac5d7[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=56
embedded dns
lines=90
trace
trace
T:12:58:00 WinXP 208.103.158.220 (CORETEL.NET):
CORETEL AMERICA INC,
MYERSTOWN, PENNSYLVANIA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
63 lines
Yeah : 1.3
profile
none summary
tarball
0 of 41 99726558f3
NEW
none[none] none:none
none|none none none
T:13:33:00 WinXP 180.67.20.208 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
83.133.119.206:65520 CN:proxima.ircgalaxy.pl
US:microsoft.com
CN:ad.lometr.pl
UA:www.epravda.com.ua
BR:www.saredrogarias.com.br
JP:ex2.broadserver.jp
JP:v.rentalserver.jp
EU:wow.merlin.org.ua
JP:www.jaif.or.jp
:www.mlh.co.jp
JP:www.ristex.jp
BR:www.sextoy.com.br
US:www.iknow.co.jp
115.125.150.234:443
BR:200.98.197.80:443
BR:201.20.45.207:443
BR:201.76.41.87:443
JP:202.218.203.244:443
JP:203.179.38.26:443
JP:203.79.51.228:443
JP:222.146.58.38:443
US:69.61.11.226:443
UA:77.120.110.76:443
135 pcap raw alerts
ruleset
irc
http
123 lines
Yeah : 1.8
profile
none summary
tarball
34 of 36
29 of 32
36 of 41
99b248336f
NEW
9d677c3f70
NEW
f0a4409bf8
NEW
c64bd1a776 [0]
77e75ff10f[0]
none [none]
ASM:Graph
ASM:Graph
none:none
Armadillo|
tElock|
none|none
lines=91
lines=120
embedded dns
none
trace
trace
none
T:13:53:00 WinXP 24.77.254.38 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
WINNIPEG, MANITOBA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
123 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 41
34cbe7a593
NEW
3e83a2d4d7
NEW
d38cb78003 [0]
b97fd63d29[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:14:51:00 Win2K-f 70.184.104.142 (COX.NET):
COX COMMUNICATIONS,
CHANDLER, ARIZONA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
40 of 41
3b3a6d7615
NEW
b7a694b220
NEW
ed7beb96f5 [0]
9f0354af30[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
14:56:00 Win2K-f 200.123.70.172 (TECHTELNET.NET):
TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:www.maxmind.com
EU:getmyip.co.uk
GB:www.vouchercodez.com
US:www.getmyip.org
:checkip.dyndns.org
US:67.15.94.80:80
US:75.126.138.202:80
445 pcap raw alerts
ruleset
http
4 lines
Yeah : 0.8
profile
none summary
tarball
8 of 37 4f88618d4f
NEW
none[3] none:none
UPX| none trace
T:15:00:00 WinXP 186.9.10.35 (IMOVIL.ENTELPCS.CL):
ENTEL PCS TELECOMUNICACIONES S.A,
SANTIAGO, REGION METROPOLITANA, CL. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 3ae357d17b
NEW
none[0] none:none
PolyEnE| lines=73 trace
T:15:01:00 WinXP 186.10.168.184 (-):
.
n/a :moscow-advokat.ru
BE:brussels.be.eu.undernet.org
AT:graz.at.eu.undernet.org
FI:london.uk.eu.undernet.org
SE:viking.dal.net
SE:coins.dal.net
:caen.fr.eu.undernet.org
:lulea.se.eu.undernet.org
SE:qis.md.us.dal.net
:washington.dc.us.undernet.org
SE:vancouver.dal.net
:gaspode.zanet.org.za
NL:diemen.nl.eu.undernet.org
SE:broadway.ny.us.dal.net
SE:ced.dal.net
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:15:04:00 Win2K-f 200.123.70.172 (TECHTELNET.NET):
TECHTEL LMDS COMUNICACIONES INTERACTIVAS S.A,
BUENOS AIRES, BUENOS AIRES, AR. (DSL)
n/a US:www.maxmind.com
EU:getmyip.co.uk
GB:www.vouchercodez.com
:checkip.dyndns.org
DE:131.220.6.26:80
445 pcap raw alerts
ruleset
http
7 lines
Yeah : 0.8
profile
none summary
tarball
8 of 37 4f88618d4f
NEW
none[3] none:none
UPX| none trace
T:16:57:00 WinXP 111.188.68.172 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:17:55:00 WinXP 174.6.21.151 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
WINNIPEG, MANITOBA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:19:22:00 Win2K-f 4.158.210.146 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
GRAND RAPIDS, MICHIGAN, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
166 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:19:26:00 WinXP 96.8.150.85 (GVTC.COM):
GUADALUPE VALLEY TELEPHONE COOPERATIVE INC,
NEW BRAUNFELS, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
39 of 40
9bdd2c95b1
NEW
cd456ac095
NEW
d1bbd693ba [0]
d75caee680[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:19:55:00 Win2K-f 173.22.149.35 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
SPRINGFIELD, MISSOURI, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:20:49:00 WinXP 98.191.207.25 (COX.NET):
COX COMMUNICATIONS,
ATLANTA, GEORGIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:20:52:00 Win2K-f 180.220.139.37 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 41
676ab5e987
NEW
983e7469c3
NEW
b96815f961 [0]
ebc346b04f[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=64
embedded dns
lines=91
trace
trace
T:21:31:00 Win2K-f 125.4.26.229 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
OSAKA, OSAKA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
0 of 32
33 of 33
07fabc79ef
NEW
53bfe15e91
NEW
none[0]
1473091351[0]
none:none
ASM:Graph
Armadillo|
tElock|
lines=90
lines=75
embedded dns
trace
trace
T:21:36:00 WinXP 69.193.68.239 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:22:05:00 WinXP 124.86.100.214 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
KAWASAKI, KANAGAWA, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
15 lines
Yeah : 1.3
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:22:20:00 WinXP 76.171.102.39 (RR.COM):
ROAD RUNNER HOLDCO LLC,
WILDOMAR, CALIFORNIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
85 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
22:21:00 WinXP 66.50.4.25 (PRTC.NET):
PRTC RAS,
SAN JUAN, PUERTO RICO, PR. (DSL)
60.190.222.139:65520 DE:proxim.ircgalaxy.pl
DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
irc
4 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41 5d26f533fd
NEW
none[none] none:none
none|none none none
T:23:43:00 WinXP 69.205.144.162 (RR.COM):
ROAD RUNNER HOLDCO LLC,
FULTON, NEW YORK, US. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 a0139d7ad8
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:23:46:00 WinXP 24.79.194.150 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
WINNIPEG, MANITOBA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
123 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41
38 of 41
34cbe7a593
NEW
3e83a2d4d7
NEW
d38cb78003 [0]
b97fd63d29[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:23:49:00 Win2K-f 4.227.251.162 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
BROOMFIELD, COLORADO, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none