Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:16:00 | Win2K-f | 72.184.225.130 (RR.COM): ROAD RUNNER HOLDCO LLC, AUBURNDALE, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 37 of 39 |
1da4193446 NEW 6278c9374a NEW |
8a97c8536a [none] cc7aaf6ea9[none] |
none:none none:none |
none|none none|none |
none none |
none none |
00:17:00 | Win2K-f | 115.186.151.170 (115-186-128-10.NAYATEL.PK): MICRONET BROADBAND (PVT) LTD, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.getmyip.org :checkip.dyndns.org 115.186.151.170:5459 DE:131.220.6.26:80 208.78.70.70:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:00:33:00 | Win2K-f | 98.141.163.101 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:17:00 | Win2K-f | 113.254.54.36 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:02:29:00 | WinXP | 79.165.232.183 (QWERTY.RU): BRAS E-320-04 DHCP-POOL, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :www.proxy-socks.net :wpad |
445 | pcap | raw alerts ruleset |
http http http 29 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:02:50:00 | Win2K-f | 118.83.151.139 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 254 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
6d9c899101 NEW f78c670c4a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:02:58:00 | WinXP | 118.231.110.189 (FETNET.NET): FAR EASTONE TELECOMMUNICATION CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
03:19:00 | WinXP | 60.234.102.171 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:24:00 | Win2K-f | 211.204.11.46 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 6 of 41 |
5213395833 NEW 9fdf6de4a9 NEW |
515eacbc36 [0] 794f9a1087[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=56 embedded dns lines=90 |
trace trace |
T:04:26:00 | WinXP | 116.122.222.223 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl CN:ku.perfectexe.com CN:mm.perfectexe.com US:sendinvest.com :findhobbits.com CN:pic.iwillhavesexygirls.com US:search.toptravellingtips.com :www.xunttsyiinb.com 204.45.71.42:80 64.79.86.26:80 |
135 | pcap | raw alerts ruleset |
irc http 203 lines |
Yeah : 1.8 profile |
none | summary tarball |
22 of 41 0 of 41 30 of 33 28 of 33 22 of 41 21 of 41 13 of 41 23 of 40 |
4833d19a28 NEW 5006761b11 NEW 533d15b5ce NEW 58c343a8d8 NEW 64f7eed703 NEW c6a2d2b990 NEW ceb9fe30e6 NEW da9d2c34d9 NEW |
none[none] none [none] c67adf46e2[0] none [0] none [none] none [none] none [none] none [none] |
none:none none:none ASM:Graph none:none none:none none:none none:none none:none |
none|none none|none tElock| Armadillo| none|none none|none none|none none|none |
none none lines=126 embedded dns lines=91 none none none none |
none none trace trace none none none none |
T:04:28:00 | Win2K-f | 123.163.139.84 (163DATA.COM.CN): CHINANET HENAN PROVINCE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
04:55:00 | Win2K-f | 38.101.195.3 (COGENTCO.COM): PSINET INC, NEW YORK, NEW YORK, US. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org :checkip.dyndns.org EU:getmyip.co.uk DE:131.220.6.26:80 208.78.70.70:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:56:00 | WinXP | 93.102.184.119 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
n/a | DE:proxim.ircgalaxy.pl DE:citi-bank.ru DE:213.155.0.224:80 CN:60.190.222.139:65520 |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 9bb68450cd NEW |
c2d5ac2315 [0] | ASM:Graph |
PolyEnE| | lines=73 embedded dns |
trace |
T:05:03:00 | Win2K-f | 38.101.195.3 (COGENTCO.COM): PSINET INC, NEW YORK, NEW YORK, US. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:05:09:00 | Win2K-f | 116.254.77.11 (THN.NE.JP): TOKAI CORPORATION, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:05:52:00 | WinXP | 71.68.86.246 (RR.COM): ROAD RUNNER HOLDCO LLC, CHARLOTTE, NORTH CAROLINA, US. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:07:15:00 | WinXP | 111.188.50.161 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:07:16:00 | Win2K-f | 202.127.92.104 (TTN.NE.JP): TANNAN CABLE TELEVISION CORPORATION, FUKUI, FUKUI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
08:09:00 | WinXP | 109.86.135.183 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:52:00 | Win2K-f | 4.159.5.113 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, GRAND RAPIDS, MICHIGAN, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 119 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:07:00 | WinXP | 70.183.164.197 (COX.NET): COX COMMUNICATIONS, PROVIDENCE, RHODE ISLAND, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
09:23:00 | WinXP | 121.121.126.136 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 912a073945 NEW |
7874c7f21e [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:37:00 | Win2K-f | 110.93.96.167 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
10:14:00 | Win2K-f | 187.50.189.15 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org US:www.getmyip.org EU:getmyip.co.uk GB:www.vouchercodez.com 208.78.70.70:80 US:67.15.94.80:80 |
445 | pcap | raw alerts ruleset |
http 46 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:10:28:00 | Win2K-f | 58.85.250.132 (ZAQ.NE.JP): J:COM WEST CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 91 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 33 of 33 |
2b9840a764 NEW 53bfe15e91 NEW |
a7dbe16bd8 [0] 1473091351[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=75 embedded dns |
trace trace |
T:10:41:00 | WinXP | 71.107.136.253 (VERIZON.NET): VERIZON INTERNET SERVICES INC, HUNTINGTON BEACH, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:00:00 | Win2K-f | 69.193.68.239 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:11:00 | WinXP | 64.188.193.147 (-): WINDJAMMER COMMUNICATIONS LLC, BOSTON, MASSACHUSETTS, US. (DSL) |
n/a | EU:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:www.bbin.ru RU:www.binbank.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http 50 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | db03c02347 NEW |
none[none] | none:none |
none|none | none | none |
T:12:34:00 | Win2K-f | 4.163.193.220 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DENVER, COLORADO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 232 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 40 of 42 |
7549900329 NEW b71514f095 NEW |
4b13f1921b [0] f6aa3689d1[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:13:04:00 | WinXP | 175.112.246.20 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 37 of 41 |
14f47ffd1e NEW 1d7d8f40e3 NEW |
90bf4b99ff [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=56 embedded dns none |
trace none |
T:14:01:00 | WinXP | 187.46.76.126 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ca491cb1a4 NEW |
none[none] | none:none |
none|none | none | none |
T:17:23:00 | Win2K-f | 68.146.75.67 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
270559591a NEW b3ae886db6 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:17:50:00 | WinXP | 63.21.188.190 (UU.NET): UUNET TECHNOLOGIES INC, OCALA, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 135 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
|
T:18:18:00 | Win2K-f | 24.164.94.38 (RR.COM): ROAD RUNNER HOLDCO LLC, DAYTON, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:19:00 | Win2K-f | 207.5.121.144 (MICROLNK.COM): MICROLNK LLC, OMAHA, NEBRASKA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:43:00 | WinXP | 200.100.213.145 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 41 | 9552bbcf07 NEW |
none[none] | none:none |
none|none | none | none |
T:18:59:00 | WinXP | 24.234.237.108 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:22:00 | WinXP | 76.185.209.19 (RR.COM): ROAD RUNNER HOLDCO LLC, BEDFORD, TEXAS, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d6df3972a0 NEW |
none[0] | none:none |
PolyEnE| | lines=65 | trace |
T:19:46:00 | Win2K-f | 69.196.204.115 (CINERGYCOM.NET): CINERGY COMMUNICATIONS COMPANY, EVANSVILLE, INDIANA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 208 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 0b095f0cef NEW |
none[none] | none:none |
none|none | none | none | |
T:19:48:00 | WinXP | 114.51.17.124 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:19:59:00 | WinXP | 114.51.7.123 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:20:10:00 | WinXP | 60.234.103.144 (ORCON.NET.NZ): ORCON INTERNET LTD SUPPORT, AUCKLAND, AUCKLAND, NZ. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:50:00 | Win2K-f | 175.117.173.67 (-): . |
83.133.119.206:65520 | US:microsoft.com CN:proxima.ircgalaxy.pl LV:ad.ghura.pl CN:ku.perfectexe.com CN:mm.perfectexe.com US:sendinvest.com :findhobbits.com CN:pic.iwillhavesexygirls.com US:search.toptravellingtips.com CN:122.224.4.121:250 |
135 | pcap | raw alerts ruleset |
irc http 257 lines |
Yeah : 1.8 profile |
none | summary tarball |
13 of 41 22 of 41 15 of 40 39 of 41 21 of 41 0 of 41 21 of 41 31 of 33 |
17ad929104 NEW 64f7eed703 NEW 7394f1d263 NEW ab9c4b5f21 NEW c6a2d2b990 NEW cd1593cc14 NEW d734736107 NEW d789c8d157 NEW |
none[none] none [none] none [none] 5fe48b2dcc[0] none [none] none [none] none [none] 5f6572479f[0] |
none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph |
none|none none|none none|none Armadillo| none|none none|none none|none PolyEnE| |
none none none lines=42 none none none lines=113 embedded dns |
none none none trace none none none trace |