Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

10 June 2010
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:09:00 WinXP 80.232.248.185 (-):
ADDRESS POOL FOR LTC-HOME CUSTOMERS,
RIGA, RIGA, LV. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
41 of 41 9d38d43309
NEW
none[none] none:none
none|none none none
T:00:27:00 WinXP 117.254.245.108 (STERLINGSTUDENTS.NET):
NIB (NATIONAL INTERNET BACKBONE),
NEW DELHI, DELHI, IN. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 41 eda3b7766c
NEW
7556343561 [0] ASM:Graph
PolyEnE| lines=68 trace
T:01:35:00 WinXP 203.196.77.57 (SPACELAN.NE.JP):
KANAZAWA CABLE TELEVISION NET CO. LTD,
KANAZAWA, ISHIKAWA, JP. (DSL)
n/a   135 pcap raw alerts
ruleset
other
637 lines
Yeah : 1.3
profile
none summary
tarball
28 of 41
39 of 41
b8076e37ae
NEW
db11b09a14
NEW
52953fed05 [0]
none [none]
none:none
none:none
StarForce|
none|none
none
none
trace
none
T:02:11:00 WinXP 114.51.194.151 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
37 of 40 5285741560
NEW
60590b8b67 [0] ASM:Graph
none|none lines=59 trace
T:02:37:00 Win2K-f 70.60.10.46 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HILLIARD, OHIO, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:03:41:00 Win2K-f 114.73.24.179 (OPTUSNET.COM.AU):
OPTUS INTERNET - RETAIL,
SYDNEY, NEW SOUTH WALES, AU. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:03:43:00 WinXP 188.176.68.232 (DSL.TELE.DK):
TDC-TELEDANMARK-BREDBAANDSADSL-NET,
DK. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:04:00:00 Win2K-f 69.193.15.140 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:04:24:00 Win2K-f 122.146.240.221 (SPARQNET.NET):
NEW CENTRY INFOCOM TECH. CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
80 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:04:27:00 WinXP 79.163.2.80 (CENTERTEL.PL):
PTK CENTERTEL BROADBAND SERVICES,
WARSAW, WARSZAWA, PL. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
05:14:00 WinXP 187.60.102.30 (VELOXZONE.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 41 2ea5285f04
NEW
none[none] none:none
none|none none none
T:05:34:00 WinXP 203.118.238.245 (-):
GRAND TAINAN TECHNOLOGY CO.LTD,
TAINAN, T'AI-WAN, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
126 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
5fae5f1583
NEW
a3395c110a
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:05:45:00 WinXP 80.104.248.203 (RETAIL.TELECOMITALIA.IT):
TELECOM ITALIA S.P.A,
ROME, LAZIO, IT. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
40 of 40 824d6a706e
NEW
a66fd13bcb [0] ASM:Graph
PolyEnE| lines=68 trace
T:06:44:00 WinXP 61.20.166.46 (FETNET.NET):
FAR EASTONE TELECOMMUNICATION CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:06:56:00 WinXP 210.142.254.23 (CATVNET.NE.JP):
CATV NETWORK SERVICES(STNET INCORPORATED),
OSAKA, OSAKA, JP. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:07:42:00 WinXP 70.128.25.15 (PARAGOULD.NET):
PARAGOULD CITY LIGHT & WATER,
PARAGOULD, ARKANSAS, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
11 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:07:44:00 Win2K-f 174.6.21.151 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
WINNIPEG, MANITOBA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:07:59:00 Win2K-f 216.220.92.245 (-):
MCKEAN COUNTY,
SMETHPORT, PENNSYLVANIA, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
136207a39a
NEW
f711fe78a3
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
08:08:00 WinXP 92.243.122.226 (92-243-120-010.NTS.SU):
NEW TELESYSTEMS LTD,
RU. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:08:55:00 Win2K-f 122.105.211.241 (OPTUSNET.COM.AU):
OPTUS INTERNET - RETAIL,
MELBOURNE, VICTORIA, AU. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:09:22:00 WinXP 111.188.50.67 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:09:34:00 Win2K-f 173.168.31.101 (RR.COM):
ROAD RUNNER HOLDCO LLC,
TAMPA, FLORIDA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
89 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
40 of 41
53bfe15e91
NEW
76db74375f
NEW
1473091351 [0]
none [none]
ASM:Graph
none:none
tElock|
none|none
lines=75
embedded dns
none
trace
none
T:09:59:00 WinXP 88.204.1.92 (ARIELNET.RU):
ARIEL LTD HOME NETWORK,
TOMSK, TOMSK, RU. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 ed96c03ca8
NEW
c0028e9e98 [0] ASM:Graph
PolyEnE| lines=68 trace
T:10:01:00 Win2K-f 69.196.204.23 (CINERGYCOM.NET):
CINERGY COMMUNICATIONS COMPANY,
EVANSVILLE, INDIANA, US. (DSL)
n/a US:gg.arrancar.org
US:69.43.160.145:555
135 pcap raw alerts
ruleset
other
204 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41 0b095f0cef
NEW
none[none] none:none
none|none none none
T:10:12:00 Win2K-f 59.120.228.224 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a   135 pcap raw alerts
ruleset
other
53 lines
Yeah : 1.3
profile
none summary
tarball
0 of 33 57ce4acac2
NEW
none[0] none:none
Armadillo| lines=90 trace
T:10:20:00 WinXP 211.76.55.149 (UBBN.NET):
UNION BROADBAND NETWORK,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
57ce4acac2
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:11:48:00 WinXP 208.103.158.45 (CORETEL.NET):
CORETEL AMERICA INC,
MYERSTOWN, PENNSYLVANIA, US. (DIAL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:12:37:00 WinXP 4.173.255.112 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
ROCKVILLE CENTRE, NEW YORK, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:12:46:00 Win2K-f 125.58.108.208 (STARCAT.NE.JP):
KMN CORPORATION,
NAGOYA, TOKYO, JP. (DSL)
62.193.249.122:3305 JP:cx10man.weedns.com 135 pcap raw alerts
ruleset
irc
573 lines
Yeah : 1.8
profile
none summary
tarball
39 of 40 70ec5c4b3f
NEW
f697adabdd [0] none:none
StarForce| none trace
T:13:16:00 WinXP 4.224.141.79 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
INDIANAPOLIS, INDIANA, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:13:26:00 WinXP 24.105.216.232 (MHCABLE.COM):
MID-HUDSON CABLEVISION INC. (CATSKILL),
COEYMANS HOLLOW, NEW YORK, US. (DSL)
60.190.222.139:65520 DE:proxim.ircgalaxy.pl
LV:ad.ghura.pl
US:secure.foxvideo.com.br
:www.stone.co.ua
JP:www.aandd.jp
BR:www.saredrogarias.com.br
BR:loja.tray.com.br
JP:bookweb.kinokuniya.co.jp
EU:avdesk.net.ua
JP:www.jaif.or.jp
RU:www.treasuryislandcasino.com.ua
EU:accounts.comodo.od.ua
CN:ku.perfectexe.com
JP:ssl.form-mailer.jp
BR:www.billboxrecords.com.br
US:sendinvest.com
JP:creative-nagoya.sakura.ne.jp
174.34.228.69:443
JP:202.164.228.11:443
JP:202.218.203.244:443
JP:202.226.91.62:443
US:69.57.128.35:443
US:69.61.11.226:443
UA:77.120.121.35:443
EU:79.171.122.236:443
EU:91.196.95.24:443
445 pcap raw alerts
ruleset
http
irc
25 lines
Yeah : 1.3
profile
none summary
tarball
35 of 36
36 of 41
22 of 41
19 of 41
04ed4d2967
NEW
f0a4409bf8
NEW
f9c51864c8
NEW
ff54d9a61b
NEW
e8aa304d1c [0]
none [none]
none [none]
none [none]
ASM:Graph
none:none
none:none
none:none
PolyEnE|
none|none
none|none
none|none
lines=131
none
none
none
trace
none
none
none
T:14:20:00 WinXP 173.22.149.35 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
SPRINGFIELD, MISSOURI, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
15:33:00 Win2K-f 188.19.150.119 (PERMONLINE.RU):
OJSC URALSVYAZINFORM,
RU. (DSL)
n/a US:www.maxmind.com
:checkip.dyndns.org
DE:131.220.6.26:80
445 pcap raw alerts
ruleset
http
5 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:15:37:00 Win2K-f 173.19.143.240 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
ALBANY, GEORGIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
39 of 41
3bff218b8f
NEW
7eaf7b4470
NEW
b570b734be [0]
8e0b194526[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=64
embedded dns
lines=91
trace
trace
T:15:46:00 Win2K-f 4.170.0.190 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
KEY BISCAYNE, FLORIDA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
172 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
38 of 41
3dfe0fa7fc
NEW
b187f8f2ac
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:16:12:00 WinXP 41.210.197.32 (SNETFAST.COM):
AFRINIC,
AO. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
13 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
T:16:29:00 Win2K-f 173.168.162.151 (RR.COM):
ROAD RUNNER HOLDCO LLC,
CLEARWATER, FLORIDA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:16:51:00 Win2K-f 70.183.54.87 (COX.NET):
COX COMMUNICATIONS,
TULSA, OKLAHOMA, US. (DSL)
60.190.222.139:65520 US:microsoft.com
DE:proxim.ircgalaxy.pl
LV:ad.ghura.pl
JP:www.marantz.jp
UA:shop.pozitiv.ks.ua
BR:www.saredrogarias.com.br
BR:loja.tray.com.br
US:140.177.205.56:443
JP:163.209.180.1:443
UA:195.214.214.53:443
BR:201.20.45.207:443
JP:202.218.111.122:443
UA:212.111.198.59:443
JP:222.146.58.38:443
UA:62.149.23.110:443
US:69.61.11.226:443
US:69.72.149.166:443
135 pcap raw alerts
ruleset
irc
http
132 lines
Yeah : 1.8
profile
none summary
tarball
36 of 41
32 of 36
35 of 36
05265022c4
NEW
bea8cb1865
NEW
fac78fde16
NEW
none[none]
154de51a66[0]
882896ab05[0]
none:none
ASM:Graph
ASM:Graph
none|none
Armadillo|
tElock|
none
lines=91
lines=126
embedded dns
none
trace
trace
T:17:02:00 WinXP 75.119.5.154 (LDMI.COM):
TALK AMERICA,
MICHIGAN, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
40 of 41 f45285574e
NEW
d984958bf9 [0] ASM:Graph
PolyEnE| lines=68 trace
T:17:20:00 WinXP 114.72.191.196 (OPTUSNET.COM.AU):
OPTUS INTERNET - RETAIL,
AU. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
61 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
T:17:27:00 WinXP 4.225.210.236 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DENVER, COLORADO, US. (DIAL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:17:29:00 Win2K-f 111.188.20.246 (E-MOBILE.NE.JP):
EMOBILE LTD,
TOKYO, TOKYO, JP. (DSL)
60.190.222.139:65520 DE:proxim.ircgalaxy.pl
LV:ad.ghura.pl
BR:www.billboxrecords.com.br
JP:www.kajima.co.jp
JP:form.cao.go.jp
JP:ss1.coressl.jp
JP:center.umin.ac.jp
JP:sv37.wadax.ne.jp
BR:loja.tray.com.br
US:www.iknow.co.jp
:www.imagemfolheados.com.br
UA:www.epravda.com.ua
CN:ku.perfectexe.com
:www.pirateparty.in.ua
JP:www.okilogistics.co.jp
JP:v.rentalserver.jp
JP:m-repo.lib.meiji.ac.jp
BR:www.guiaseshop.com.br
UA:www.rulez.org.ua
JP:www.marantz.jp
:cps-h3.ep.sci.hokudai.ac.jp
:vbmcom.com
JP:ex2.broadserver.jp
UA:opensvit.ua
GB:forum.gryada.org.ua
JP:creative-nagoya.sakura.ne.jp
UA:weather.co.ua
UA:bunker.org.ua
BR:www.sextoy.com.br
:www.stone.co.ua
:black.nightphantom.com
UA:www.indev.kiev.ua
UA:souvenirs.auction.ua
JP:bookweb.kinokuniya.co.jp
US:microsoft.com
JP:www.irtvnet.jp
JP:www.jaif.or.jp
US:forums.ubuntulinux.jp
JP:cg.ces.kyutech.ac.jp
:www.mlh.co.jp
JP:www.ristex.jp
JP:130.69.92.68:443
US:140.177.205.56:443
174.123.60.178:443
UA:193.178.147.110:443
BR:201.20.45.207:443
JP:202.218.170.179:443
JP:219.99.163.41:443
CN:60.190.222.139:65520
US:69.61.11.226:443
DE:83.133.119.206:65520
445 pcap raw alerts
ruleset
irc
http
40 lines
Yeah : 0.8
profile
none summary
tarball
36 of 41 138360a64d
NEW
none[none] none:none
none|none none none
T:17:41:00 WinXP 114.166.186.206 (OCN.NE.JP):
OPEN COMPUTER NETWORK,
JP. (DSL)
n/a   445 pcap raw alerts
ruleset
ftp
12 lines
Yeah : 0.8
profile
none summary
tarball
31 of 32 741e3b03b3
NEW
none[0] none:none
none|none lines=61 trace
T:17:48:00 Win2K-f 75.49.16.4 (SBCGLOBAL.NET):
AT&T INTERNET SERVICES,
COLUMBUS, OHIO, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:17:48:00 WinXP 219.234.80.181 (IAPCM.AC.CN):
BEIJING TELETRON TELECOM ENGINEERING CO. LTD,
BEIJING, BEIJING, CN. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:07:00 Win2K-f 180.71.180.45 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
83.133.119.206:65520 DE:proxima.ircgalaxy.pl
US:microsoft.com
LV:ad.ghura.pl
BR:loja.tray.com.br
JP:sv37.wadax.ne.jp
UA:isu2.tup.km.ua
:www.imagemfolheados.com.br
UA:www.indev.kiev.ua
:www.pirateparty.in.ua
JP:v.rentalserver.jp
EU:wow.merlin.org.ua
US:secure.foxvideo.com.br
UA:193.110.163.66:443
UA:193.178.147.110:443
JP:210.147.30.22:443
UA:212.111.198.59:443
JP:219.99.163.41:443
US:69.61.11.226:443
UA:77.120.104.50:443
EU:91.196.95.24:443
135 pcap raw alerts
ruleset
irc
http
173 lines
Yeah : 1.8
profile
none summary
tarball
36 of 41
39 of 41
31 of 33
138360a64d
NEW
ab9c4b5f21
NEW
d789c8d157
NEW
none[none]
5fe48b2dcc[0]
5f6572479f[0]
none:none
ASM:Graph
ASM:Graph
none|none
Armadillo|
PolyEnE|
none
lines=42
lines=113
embedded dns
none
trace
trace
T:18:28:00 Win2K-f 115.133.238.132 (115.IN-ADDR.ARPA):
CORE IP NETWORK DEVELOPMENT,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
n/a  
JP:163.209.180.1:443
JP:164.46.227.120:443
174.36.62.66:443
191.4.157.190:443
GB:193.169.188.64:443
UA:195.182.192.2:443
UA:195.214.214.53:443
PR:200.5.0.0:443
JP:202.218.203.244:443
JP:222.146.58.38:443
US:64.131.68.169:443
EU:91.196.95.24:443
445 pcap raw alerts
ruleset
irc
20 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
T:18:40:00 Win2K-f 115.135.134.70 (115.IN-ADDR.ARPA):
CORE IP NETWORK DEVELOPMENT,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
60.190.222.139:65520 LV:ad.ghura.pl
JP:ir.kagoshima-u.ac.jp
PL:ssl.aukro.ua
UA:bunker.org.ua
JP:www.nrw.co.jp
:nodes.com.ua
JP:ex2.broadserver.jp
EU:wow.merlin.org.ua
JP:www.science-forum.co.jp
JP:163.209.180.1:443
JP:164.46.227.120:443
UA:195.182.192.2:443
UA:195.214.214.53:443
BR:200.192.143.87:443
JP:202.191.113.9:443
JP:202.218.203.244:443
JP:219.99.163.41:443
US:64.131.68.169:443
US:69.57.128.35:443
US:69.61.11.226:443
95.169.190.41:443
445 pcap raw alerts
ruleset
irc
http
24 lines
Yeah : 0.8
profile
none summary
tarball
36 of 41 05265022c4
NEW
none[none] none:none
none|none none none
T:19:16:00 Win2K-f 207.5.228.153 (SUSCOM-MAINE.NET):
GREAT WORKS INTERNET,
BRUNSWICK, MAINE, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
291 lines
Yeah : 1.3
profile
none summary
tarball
39 of 40 1db29886ac
NEW
none[none] none:none
none|none none none
T:21:36:00 WinXP 99.74.97.95 (JWS.COM):
AT&T INTERNET SERVICES,
US. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:21:43:00 WinXP 98.149.93.189 (RR.COM):
ROAD RUNNER HOLDCO LLC,
OXNARD, CALIFORNIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
1100 lines
Yeah : 1.3
profile
none summary
tarball
23 of 41 1e758743ca
NEW
none[none] none:none
none|none none none
T:22:28:00 WinXP 72.241.69.111 (EOPA.ORG):
BUCKEYE CABLEVISION INC,
TOLEDO, OHIO, US. (DSL)
62.193.249.122:3305 EU:cx10man.weedns.com 135 pcap raw alerts
ruleset
irc
695 lines
Yeah : 1.8
profile
none summary
tarball
38 of 41 ecfbf321d3
NEW
none[none] none:none
none|none none none
T:22:36:00 WinXP 79.163.36.80 (CENTERTEL.PL):
PTK CENTERTEL BROADBAND SERVICES,
WARSAW, WARSZAWA, PL. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:22:45:00 WinXP 76.175.127.40 (RR.COM):
ROAD RUNNER HOLDCO LLC,
PERRIS, CALIFORNIA, US. (100Mbps)
n/a   135 pcap raw alerts
ruleset
other
1099 lines
Yeah : 1.3
profile
none summary
tarball
31 of 41 0f8abb24d9
NEW
none[3] none:none
none|none none trace
T:23:02:00 WinXP 121.120.222.9 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
23:23:00 WinXP 121.120.222.9 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace