Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:20:00 | Win2K-f | 173.168.59.206 (RR.COM): ROAD RUNNER HOLDCO LLC, LUTZ, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:00:58:00 | WinXP | 95.75.24.19 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | dc53a6780d NEW |
none[none] | none:none |
none|none | none | none |
01:22:00 | WinXP | 115.164.48.133 (-): DIGI TELECOMMUNICATIONS SDN BHD, SHAH ALAM, SELANGOR, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
23 of 40 | 0fe5d0db2b NEW |
none[none] | none:none |
none|none | none | none |
T:01:57:00 | WinXP | 180.220.135.41 (-): . |
62.193.249.122:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | ecfbf321d3 NEW |
none[none] | none:none |
none|none | none | none |
02:33:00 | WinXP | 95.75.24.19 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | dc53a6780d NEW |
none[none] | none:none |
none|none | none | none |
T:02:39:00 | Win2K-f | 196.208.46.77 (DIAL-UP.NET): AFRINIC, KLERKSDORP, NORTH-WEST, ZA. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 133 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:45:00 | WinXP | 92.115.136.193 (HOST-STATIC-92-115-28-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:38:00 | WinXP | 114.51.55.81 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:03:55:00 | WinXP | 122.146.243.61 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:47:00 | Win2K-f | 60.248.116.212 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
05:08:00 | WinXP | 95.58.201.179 (DIAL.ONLINE.KZ): KAZAKHTELECOM DATA NETWORK ADMINISTRATION, KZ. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b NEW |
none[0] | none:none |
PolyEnE| | lines=73 | trace |
T:05:19:00 | WinXP | 115.165.74.2 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:05:38:00 | WinXP | 24.242.103.245 (RR.COM): ROAD RUNNER HOLDCO LLC, BEAUMONT, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:06:23:00 | WinXP | 111.82.84.20 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 12 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:50:00 | WinXP | 85.65.205.141 (BARAK-ONLINE.NET): BARAK I.T.C, HOLON, TEL AVIV, IL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:21:00 | Win2K-f | 110.11.246.223 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | US:microsoft.com DE:proxim.ircgalaxy.pl LV:ad.ghura.pl EU:wow.merlin.org.ua US:www.iknow.co.jp UA:weather.co.ua BR:ssl876.locaweb.com.br US:www.stone.co.ua EU:accounts.comodo.od.ua UA:www.rulez.org.ua :www.imagemfolheados.com.br :ex2.broadser JP:ssl.form-mailer.jp UA:193.178.147.110:443 JP:202.214.40.79:443 UA:212.111.198.59:443 US:67.15.97.220:443 UA:77.120.121.35:443 UA:77.120.99.240:443 DE:83.133.119.206:65520 EU:91.196.95.24:443 |
135 | pcap | raw alerts ruleset |
irc http 134 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 30 of 33 28 of 33 25 of 40 |
5310d6ea56 NEW 533d15b5ce NEW 58c343a8d8 NEW 9362a3aee3 NEW |
none[none] c67adf46e2[0] none [0] none [none] |
none:none ASM:Graph none:none none:none |
none|none tElock| Armadillo| none|none |
none lines=126 embedded dns lines=91 none |
none trace trace none |
07:37:00 | WinXP | 75.24.16.136 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, YOUNGSTOWN, OHIO, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 24137d8412 NEW |
73a916deb4 [0] | none:none |
PolyEnE| | none | trace |
T:07:40:00 | Win2K-f | 112.70.32.206 (EONET.NE.JP): K-OPTICOM CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | JP:g105.secure.ne.jp JP:www.marantz.jp :www.pirateparty.in.ua :itmedia.smartseminar.jp :cps-h3.ep.sci.hokudai.ac.jp BR:www.guiaseshop.com.br JP:www.ristex.jp JP:133.87.45.189:443 GB:193.169.188.64:443 UA:193.178.147.110:443 UA:195.214.214.53:443 JP:202.164.228.11:443 JP:202.218.111.122:443 JP:202.226.91.62:443 JP:222.146.58.38:443 US:64.131.68.169:443 US:64.79.197.143:443 US:68.232.187.4:443 US:69.57.128.35:443 US:69.72.149.166:443 EU:91.196.95.24:443 |
445 | pcap | raw alerts ruleset |
irc 9 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:07:45:00 | WinXP | 186.9.21.207 (IMOVIL.ENTELPCS.CL): ENTEL PCS TELECOMUNICACIONES S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:50:00 | Win2K-f | 203.70.99.54 (SEED.NET.TW): SEEDNET-TAIPEIDP-S, TAIPEI, T'AI-PEI, TW. (DSL) |
60.190.222.139:65520 | DE:proxim.ircgalaxy.pl LV:ad.ghura.pl US:www.stone.co.ua EU:wow.merlin.org.ua JP:ssl.form-mailer.jp :www.mlh.co.jp US:www.wolfram.co.jp :shop.poziti UA:spooky.cartoons.org.ua 115.125.150.234:443 JP:131.113.221.138:443 US:140.177.205.54:443 US:140.177.205.56:443 UA:195.214.214.53:443 BR:201.20.45.207:443 US:67.15.97.220:443 US:68.232.187.4:443 UA:77.120.121.35:443 UA:82.193.122.190:443 DE:83.133.119.206:65520 |
445 | pcap | raw alerts ruleset |
irc http 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 5310d6ea56 NEW |
none[none] | none:none |
none|none | none | none |
T:09:04:00 | WinXP | 189.64.102.202 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 8e6c896ded NEW |
none[none] | none:none |
none|none | none | none | |
T:09:36:00 | Win2K-f | 97.81.120.218 (CHARTER.COM): CHARTER COMMUNICATIONS, ATHENS, GEORGIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 40 of 42 |
1692cd58db NEW fe6db79f7f NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
10:21:00 | WinXP | 109.162.95.132 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:37:00 | WinXP | 151.81.187.236 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | a779e859a5 NEW |
none[none] | none:none |
none|none | none | none |
T:10:43:00 | WinXP | 114.48.55.81 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:11:02:00 | WinXP | 79.163.244.6 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 97264c7178 NEW |
none[none] | none:none |
none|none | none | none |
T:11:12:00 | Win2K-f | 4.177.217.139 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LA MESA, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 496 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 42 | 4d458547f7 NEW |
none[none] | none:none |
none|none | none | none | |
T:11:14:00 | WinXP | 115.186.123.168 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, KARACHI, SINDH, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | a3c82ff952 NEW |
none[none] | none:none |
none|none | none | none |
T:12:42:00 | Win2K-f | 24.67.59.163 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VERNON, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 144 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | 10980f4df2 NEW |
1fd3385a95 [0] | ASM:Graph |
none|none | lines=556 | trace | |
T:13:29:00 | Win2K-f | 216.152.4.82 (-): CITY OF WILSON, PEA RIDGE, ARKANSAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:14:43:00 | Win2K-f | 70.182.70.58 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
60.190.222.139:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl DE:www.miltenyibiotec.co.jp BR:www.billboxrecords.com.br UA:masterkey.com.ua GB:forum.gryada.org.ua UA:hosting.cnrg.com.ua EU:wow.merlin.org.ua US:www.wolfram.co.jp US:140.177.205.54:443 GB:193.169.188.64:443 BR:201.20.45.207:443 BR:201.76.50.168:443 UA:212.82.216.42:443 US:68.232.187.4:443 US:69.57.128.35:443 UA:77.120.104.50:443 DE:83.133.119.206:65520 EU:91.203.146.30:443 |
135 | pcap | raw alerts ruleset |
irc http 135 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 32 of 36 35 of 36 |
305339a5c3 NEW bea8cb1865 NEW fac78fde16 NEW |
none[none] 154de51a66[0] 882896ab05[0] |
none:none ASM:Graph ASM:Graph |
none|none Armadillo| tElock| |
none lines=91 lines=126 embedded dns |
none trace trace |
T:15:35:00 | Win2K-f | 86.175.46.71 (WLMS-BROADBAND.COM): BT BROADBAND, BELFAST, NORTHERN IRELAND, UK. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl LV:ad.ghura.pl JP:www.marantz.jp :www.irt JP:www.ristex.jp UA:www.rulez.org.ua BR:loja.tray.com.br JP:www.jica.go.jp GB:forum.gryada.org.ua BR:www.billboxrecords.com.br UA:weather.co.ua 115.125.150.227:443 174.123.60.178:443 191.132.154.190:443 GB:193.169.188.64:443 UA:193.178.147.110:443 BR:200.234.192.141:443 JP:202.218.203.244:443 JP:202.226.91.62:443 JP:203.179.38.26:443 JP:203.180.136.89:443 JP:222.146.58.38:443 US:68.232.187.4:443 UA:77.120.121.35:443 EU:79.171.122.236:443 |
445 | pcap | raw alerts ruleset |
irc http 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 305339a5c3 NEW |
none[none] | none:none |
none|none | none | none |
T:15:57:00 | WinXP | 174.39.177.176 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, NORTH PLATTE, NEBRASKA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 4025289fc5 NEW |
none[none] | none:none |
none|none | none | none |
T:17:45:00 | Win2K-f | 60.250.199.56 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:58:00 | WinXP | 76.179.83.103 (RR.COM): ROAD RUNNER HOLDCO LLC, CARMEL, MAINE, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:26:00 | WinXP | 209.250.52.76 (WISPNET.NET): WISPNET LLC, WINCHESTER, KENTUCKY, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
36 of 38 | 5865b09945 NEW |
4d99f4784a [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:18:49:00 | Win2K-f | 173.29.141.154 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:18:52:00 | Win2K-f | 97.81.120.218 (CHARTER.COM): CHARTER COMMUNICATIONS, ATHENS, GEORGIA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 40 of 42 |
1692cd58db NEW fe6db79f7f NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:19:14:00 | WinXP | 110.11.206.190 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl JP:ss1.coressl.jp JP:form.cao.go.jp JP:ir.kagoshima-u.ac.jp US:forums.ubuntulinux.jp JP:k.jfc.go.jp :newsletter.go BR:www.imusica.com.br JP:125.53.25.30:443 JP:163.209.180.1:443 UA:193.110.163.66:443 UA:195.214.214.53:443 BR:200.234.192.141:443 BR:201.20.45.207:443 BR:201.49.212.100:443 JP:61.120.56.37:443 US:64.131.68.169:443 US:66.249.8.126:443 US:68.232.187.4:443 US:69.72.149.166:443 DE:83.133.119.206:65520 |
135 | pcap | raw alerts ruleset |
irc http 148 lines |
Yeah : 1.8 profile |
none | summary tarball |
none 39 of 41 31 of 33 |
5310d6ea56 NEW ab9c4b5f21 NEW d789c8d157 NEW |
none[none] 5fe48b2dcc[0] 5f6572479f[0] |
none:none ASM:Graph ASM:Graph |
none|none Armadillo| PolyEnE| |
none lines=42 lines=113 embedded dns |
none trace trace |
T:20:12:00 | WinXP | 119.234.194.161 (-): SINGTEL MOBILE, SG. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace | |
T:20:18:00 | WinXP | 114.51.44.198 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:20:19:00 | WinXP | 187.47.32.23 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 32ca1b92dc NEW |
none[none] | none:none |
none|none | none | none |
T:21:38:00 | Win2K-f | 72.190.98.232 (RR.COM): ROAD RUNNER HOLDCO LLC, ARLINGTON, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 37 of 39 |
1da4193446 NEW 6278c9374a NEW |
8a97c8536a [none] cc7aaf6ea9[none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:17:00 | Win2K-f | 70.128.25.15 (PARAGOULD.NET): PARAGOULD CITY LIGHT & WATER, PARAGOULD, ARKANSAS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:22:37:00 | WinXP | 121.120.99.192 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 39 | fa0b828ca9 NEW |
none[none] | none:none |
none|none | none | none |
T:23:21:00 | WinXP | 115.164.46.234 (-): DIGI TELECOMMUNICATIONS SDN BHD, SHAH ALAM, SELANGOR, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
24 of 40 | ed440e5d9c NEW |
none[none] | none:none |
none|none | none | none |
T:23:57:00 | WinXP | 75.37.173.251 (SBCGLOBAL.NET): JASON LEE, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
18 of 35 0 of 33 |
218ce30f5c NEW a08f3b74a4 NEW |
none[3] none [0] |
none:none none:none |
none|none Armadillo| |
none lines=90 |
trace trace |