Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:17:00 | WinXP | 121.121.46.99 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 7c9abadc61 NEW |
none[none] | none:none |
none|none | none | none |
T:01:17:00 | Win2K-f | 173.25.95.80 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, GOLD BAR, WASHINGTON, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:01:34:00 | WinXP | 213.66.164.68 (TELIA.COM): TELIA NETWORK SERVICES, DANDERYD, STOCKHOLMS LAN, SE. (DSL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com RU:www.bbin.ru RU:www.binbank.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http 57 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 6c21e2c88b NEW |
none[none] | none:none |
none|none | none | none |
T:02:01:00 | Win2K-f | 60.248.162.75 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 35 of 38 |
2205443cc8 NEW b9297745a1 NEW |
04ce1ed773 [none] 4294884d84[0] |
none:none ASM:Graph |
none|none tElock| |
none lines=64 embedded dns |
none trace |
T:03:06:00 | WinXP | 121.120.176.179 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | bca34996f1 NEW |
none[none] | none:none |
none|none | none | none |
T:03:11:00 | WinXP | 203.91.184.97 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:12:00 | Win2K-f | 75.37.173.251 (SBCGLOBAL.NET): JASON LEE, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:42:00 | Win2K-f | 58.123.70.43 (HANANET.NET): HANARO TELECOM INC, KR. (DSL) |
83.133.119.206:65520 | LV:proxima.ircgalaxy.pl US:microsoft.com :rastu.com.ua BR:loja.tray.com.br JP:www.jica.go.jp BR:www.digimer.com.br UA:isu2.tup.km.ua JP:www.okilogistics.co.jp BR:www.guiaseshop.com.br :itmedia.smartseminar.jp US:www.iknow.co.jp CN:ku.perfectexe.com :www.mlh.co.jp 115.125.150.234:443 UA:193.178.147.110:443 BR:200.192.143.87:443 JP:202.214.40.79:443 JP:202.226.91.62:443 JP:203.179.38.26:443 UA:212.42.72.183:443 CN:222.170.127.203:88 US:69.61.11.226:443 UA:77.120.121.35:443 |
135 | pcap | raw alerts ruleset |
irc http 125 lines |
Yeah : 1.8 profile |
none | summary tarball |
36 of 41 none 38 of 40 |
05265022c4 NEW 6a4845ca11 NEW ffafd341d9 NEW |
none[none] c23d00870b[0] 294fb27545[0] |
none:none ASM:Graph ASM:Graph |
none|none tElock| Armadillo| |
none lines=120 embedded dns lines=91 |
none trace trace |
T:04:03:00 | Win2K-f | 61.228.65.205 (PRESTONAUTO.COM): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:www.miltenyibiotec.co.jp JP:www.marantz.jp JP:bookweb.kinokuniya.co.jp UA:souvenirs.auction.ua JP:m-repo.lib.meiji.ac.jp JP:130.69.92.68:443 JP:164.46.227.120:443 174.123.60.178:443 191.4.157.190:443 UA:193.110.163.66:443 BR:200.234.192.141:443 BR:201.20.45.207:443 JP:202.218.111.122:443 JP:210.171.131.16:443 UA:213.186.115.36:443 UA:62.149.23.110:443 US:64.131.68.169:443 US:69.57.128.35:443 EU:91.196.95.24:443 |
445 | pcap | raw alerts ruleset |
irc 33 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:04:05:00 | WinXP | 70.168.54.131 (COX.NET): COX COMMUNICATIONS INC, SAN DIEGO, CALIFORNIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:09:00 | Win2K-f | 95.28.73.223 (CORBINA.RU): INVESTELEKTROSVIAZ LTD, MOSCOW, MOSCOW CITY, RU. (100Mbps) |
83.133.119.206:65520 | UA:bunker.org.ua JP:ssl.form-mailer.jp JP:newsletter.gov-online.go.jp :www.stone.co.ua JP:ex2.broadserver.jp EU:avdesk.net.ua CN:ku.perfectexe.com JP:131.113.221.138:443 US:140.177.205.56:443 174.34.228.69:443 UA:195.214.214.53:443 BR:201.20.45.207:443 JP:202.214.40.79:443 JP:202.218.170.179:443 JP:202.218.203.244:443 JP:203.179.38.26:443 US:64.79.197.143:443 US:69.57.128.35:443 US:69.61.11.226:443 EU:79.171.122.236:443 UA:82.193.122.190:443 |
445 | pcap | raw alerts ruleset |
irc http 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 | 05265022c4 NEW |
none[none] | none:none |
none|none | none | none |
T:04:24:00 | WinXP | 173.25.142.254 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, DES MOINES, IOWA, US. (DSL) |
62.193.249.122:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | ecfbf321d3 NEW |
none[none] | none:none |
none|none | none | none |
T:04:32:00 | Win2K-f | 115.165.47.47 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, TOKYO, TOKYO, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:52:00 | WinXP | 24.234.68.105 (COX.NET): COX COMMUNICATIONS INC, LAS VEGAS, NEVADA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:23:00 | Win2K-f | 174.116.112.43 (ROGERS.COM): ROGERS CABLE COMMUNICATIONS INC, ST. JOHN'S, NEWFOUNDLAND AND LABRADOR, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:07:00 | Win2K-f | 155.239.252.10 (TELKOM-IPNET.CO.ZA): AFRINIC, PRETORIA, GAUTENG, ZA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
06:39:00 | Win2K-f | 219.84.1.123 (SO-NET.NET.TW): SONY NETWORK TAIWAN LIMITED, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:www.getmyip.org 208.78.70.70:80 US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:06:58:00 | Win2K-f | 70.169.52.29 (COX.NET): COX COMMUNICATIONS, TULSA, OKLAHOMA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1008 lines |
Yeah : 1.3 profile |
none | summary tarball |
19 of 41 | aebf0a1c1d NEW |
none[none] | none:none |
none|none | none | none | |
T:07:14:00 | WinXP | 124.169.24.247 (IINET.NET.AU): IINET LIMITED, PERTH, WESTERN AUSTRALIA, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 98 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:19:00 | WinXP | 173.22.160.135 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, SPRINGFIELD, MISSOURI, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:09:17:00 | WinXP | 151.82.32.115 (51-151.NET24.IT): IUNET-BNET, MILANO, LOMBARDIA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 9e23f46428 NEW |
none[none] | none:none |
none|none | none | none |
T:10:03:00 | WinXP | 67.127.244.194 (PACBELL.NET): APW KNOX SEEMAN, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:31:00 | Win2K-f | 174.0.2.104 (KODIAKPETROLEUM.COM): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
ASM:Graph ASM:Graph |
Armadillo| PolyEnE| |
lines=91 lines=64 embedded dns |
trace trace |
T:10:34:00 | Win2K-f | 198.182.77.10 (ACES.NET): LOGIN INC, PORTLAND, OREGON, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:01:00 | Win2K-f | 208.125.168.66 (RR.COM): ROAD RUNNER HOLDCO LLC, CLIFTON PARK, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:07:00 | Win2K-f | 222.223.194.28 (163DATA.COM.CN): CHINANET HEBEI PROVINCE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | NL:wow.blackirc.us | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:25:00 | WinXP | 212.129.93.242 (-): METEOR MOBILE BROADBAND, DUBLIN, DUBLIN, IE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:34:00 | Win2K-f | 173.29.250.187 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 40 |
067917e07b NEW d764c1dcb2 NEW |
dae35b319c [0] 3d2bc60c5d[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:12:19:00 | Win2K-f | 113.252.100.184 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:12:35:00 | WinXP | 61.218.191.251 (-): LIAN HONG BUSINESS CO. LTD, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
761a66b891 NEW 98d05c039b NEW |
b469dac5dc [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=64 embedded dns none |
trace none |
T:13:23:00 | Win2K-f | 70.60.198.57 (RR.COM): ROAD RUNNER HOLDCO LLC, MONROE, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:34:00 | WinXP | 82.249.221.176 (PROXAD.NET): PROXAD / FREE SAS, FOURMIES, NORD-PAS-DE-CALAIS, FR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
13:37:00 | WinXP | 95.74.79.222 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:13:49:00 | WinXP | 122.105.134.114 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:10:00 | Win2K-f | 4.177.18.48 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 36 of 40 |
47d3548e36 NEW d8722af110 NEW |
ab13346633 [0] ab30a55931[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:14:36:00 | Win2K-f | 75.15.224.148 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, BAKERSFIELD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
1e12f5145a NEW f208493e65 NEW |
617af909de [0] 5100adb4f9[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:14:38:00 | WinXP | 109.86.35.37 (JWS.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:59:00 | Win2K-f | 118.7.15.115 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:14:00 | Win2K-f | 200.100.48.1 (TELESP.NET.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | f053b5551a NEW |
none[none] | none:none |
none|none | none | none | |
T:15:54:00 | Win2K-f | 98.141.163.84 (CAVTEL.NET): CAVALIER TELEPHONE, PHILADELPHIA, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:15:59:00 | Win2K-f | 95.71.21.205 (LEBGOK.RU): JSC CENTRAL TELECOMMUNICATION COMPANY BRANCH BELSVYAZ, MOSCOW, MOSCOW CITY, RU. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 4990271049 NEW |
none[none] | none:none |
none|none | none | none | |
T:16:32:00 | WinXP | 175.115.187.191 (-): . |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl BR:loja.tray.com.br US:www.wolfram.co.jp BR:www.digimer.com.br JP:form.cao.go.jp JP:www.aandd.jp PL:ssl.aukro.ua BR:www.saredrogarias.com.br JP:g105.secure.ne.jp :la2.meganet.org.ua UA:hosting.cnrg.com.ua GB:forum.gryada.org.ua JP:newsletter.gov-online.go.jp US:140.177.205.54:443 GB:193.169.188.64:443 BR:200.192.143.87:443 BR:200.98.197.80:443 JP:202.164.228.11:443 JP:202.218.111.122:443 JP:202.218.203.244:443 JP:203.180.136.89:443 JP:210.147.30.22:443 US:64.79.197.143:443 UA:77.120.121.35:443 |
135 | pcap | raw alerts ruleset |
irc http 134 lines |
Yeah : 1.8 profile |
none | summary tarball |
30 of 33 28 of 33 36 of 41 |
533d15b5ce NEW 58c343a8d8 NEW f0a4409bf8 NEW |
c67adf46e2 [0] none [0] none [none] |
ASM:Graph none:none none:none |
tElock| Armadillo| none|none |
lines=126 embedded dns lines=91 none |
trace trace none |
T:16:37:00 | Win2K-f | 184.80.69.109 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:16:50:00 | Win2K-f | 211.23.226.98 (-): LIOU-TZUNG-YI-TC, TAIPEI, T'AI-PEI, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 37 of 40 |
5d445c59d8 NEW 8a54950abb NEW |
892e12db7b [0] f6b9e43917[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:17:11:00 | WinXP | 114.51.169.250 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:17:44:00 | WinXP | 114.51.156.30 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | c116e6a741 NEW |
none[none] | none:none |
none|none | none | none | |
T:17:48:00 | WinXP | 64.213.117.216 (GBLX.NET): GLOBAL CROSSING, PLANO, TEXAS, US. (DSL) |
178.162.144.201:16667 | :bbs.moiservice.com | 135 | pcap | raw alerts ruleset |
irc 351 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | 6ac1465843 NEW |
none[none] | none:none |
none|none | none | none |
T:18:20:00 | WinXP | 121.121.109.138 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | LV:irc.zief.pl DE:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http irc 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | 3b15d3688b NEW |
none[none] | none:none |
none|none | none | none |
T:18:23:00 | WinXP | 173.211.136.97 (-): . |
178.162.144.201:16667 | :bbs.moiservice.com | 135 | pcap | raw alerts ruleset |
irc 349 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | a90b46fedd NEW |
none[none] | none:none |
none|none | none | none |
T:19:05:00 | WinXP | 67.253.86.47 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
19:05:00 | WinXP | 113.152.69.235 (DION.NE.JP): UQ COMMUNICATIONS INC, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 8015c2d45f NEW |
749cbc2739 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
20:32:00 | Win2K-f | 203.70.152.244 (SEED.NET.TW): SEEDNET-KAOHSIUNGDP-S, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com US:www.getmyip.org EU:getmyip.co.uk :checkip.dyndns.org US:67.15.94.80:80 US:75.126.138.202:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:21:11:00 | WinXP | 75.79.60.134 (DSLEXTREME.COM): DSL EXTREME, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:gg.arrancar.org US:69.43.160.145:555 |
135 | pcap | raw alerts ruleset |
other 187 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | cb8ebf02a0 NEW |
none[none] | none:none |
none|none | none | none |
T:21:20:00 | WinXP | 117.254.30.106 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:21:23:00 | Win2K-f | 122.146.81.220 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:26:00 | WinXP | 70.183.2.6 (COX.NET): COX COMMUNICATIONS, FAIRFAX, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:31:00 | Win2K-f | 202.137.148.29 (-): TELECOMMUNICATION SERVICE, VIENTIANE, VIENTIANE, LA. (DSL) |
62.193.249.122:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 595 lines |
Yeah : 1.8 profile |
none | summary tarball |
22 of 41 | 5069160ffe NEW |
65a33ca939 [0] | none:none |
StarForce| | none | trace |
T:22:49:00 | WinXP | 110.93.96.77 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:23:18:00 | Win2K-f | 174.0.153.238 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 101 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
5ade4f733a NEW ebef84c042 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:23:54:00 | WinXP | 117.254.152.161 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:23:56:00 | Win2K-f | 203.90.121.150 (AKAMAITECHNOLOGIES.COM): HCL INFINET LIMITED, BANGALORE, KARNATAKA, IN. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 35 0 of 32 |
218ce30f5c NEW 73f1082158 NEW |
none[3] none [0] |
none:none none:none |
none|none Armadillo| |
none lines=90 |
trace trace |