Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:23:00 | Win2K-f | 59.124.11.166 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :www.mail.ru :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 86 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:00:33:00 | Win2K-f | 219.80.255.41 (TFN.NET.TW): TAIWAN FIXED NETWORK CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 1 of 33 |
53bfe15e91 NEW c562e2226d NEW |
1473091351 [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=75 embedded dns none |
trace none |
T:01:25:00 | Win2K-f | 173.28.199.202 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:01:25:00 | WinXP | 112.197.72.101 (-): SAIGON TOURIST CABLE TELEVISION, VN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:33:00 | Win2K-f | 71.98.205.79 (VERIZON.NET): VERIZON INTERNET SERVICES INC, CLEARWATER, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 459d2bddeb NEW |
10fac04dd2 [0] | ASM:Graph |
none|none | lines=546 | trace | |
T:01:58:00 | Win2K-f | 61.46.137.187 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:02:46:00 | WinXP | 217.202.248.22 (-): TELECOM ITALIA MOBILE, ROME, LAZIO, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:54:00 | WinXP | 121.120.48.33 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:23:00 | WinXP | 79.163.130.184 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | f2dab28f3c NEW |
none[none] | none:none |
none|none | none | none |
T:03:27:00 | WinXP | 213.66.164.142 (TELIA.COM): TELIA NETWORK SERVICES, DANDERYD, STOCKHOLMS LAN, SE. (DSL) |
n/a | RU:siliconfireware.ru RU:auction.nic.ru :www.google-analytics.com RU:domain-parking.ru RU:www.bbin.ru RU:www.binbank.ru :wpad :www.proxy-socks.net |
445 | pcap | raw alerts ruleset |
http http http http 59 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 6c21e2c88b NEW |
none[none] | none:none |
none|none | none | none |
03:54:00 | Win2K-f | 117.102.80.5 (-): BIZNET-CSBLOCKBLOCK, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | US:www.maxmind.com :checkip.dyndns.org EU:getmyip.co.uk :www.getmyip.org US:67.15.94.80:80 EU:78.40.35.134:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:02:00 | Win2K-f | 117.102.80.5 (-): BIZNET-CSBLOCKBLOCK, JAKARTA, JAKARTA RAYA, ID. (100Mbps) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :www.mail.ru US:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 78 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:04:42:00 | Win2K-f | 92.36.209.80 (NET.BA): BH TELECOM D.D. SARAJEVO, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:04:44:00 | WinXP | 118.174.154.145 (TOTBB.NET): TOT PUBLIC COMPANY LIMITED BANGKOK, CHIANG MAI, CHIANG MAI, TH. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 9419477a49 NEW |
none[none] | none:none |
none|none | none | none | |
T:04:46:00 | Win2K-f | 77.40.66.70 (RELINFO.RU): OJSC VOLGATELECOM, YOSHKAR-OLA, MARIY-EL, RU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 6f6eefac6f NEW |
none[3] | none:none |
ASPack| | none | trace | |
T:04:47:00 | WinXP | 118.101.20.251 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, JELEBU, NEGERI SEMBILAN, MY. (DSL) |
74.117.174.82:16667 | CA:bbs.moiservice.com | 445 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | ad33ad156f NEW |
none[none] | none:none |
none|none | none | none |
T:04:47:00 | Win2K-f | 89.152.238.167 (CPE.NETCABO.PT): TVCABO-PORTUGAL CABLE MODEM NETWORK, PORTO, PORTO, PT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 423b289b4e NEW |
none[none] | none:none |
none|none | none | none | |
T:04:48:00 | WinXP | 116.87.197.216 (MAXONLINE.COM.SG): STARHUB CABLE VISION LTD, SINGAPORE, SINGAPORE, SG. (DSL) |
74.117.174.82:2081 | CA:s.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 56044b237c NEW |
none[none] | none:none |
none|none | none | none |
T:04:50:00 | Win2K-f | 59.116.107.88 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | df8365a408 NEW |
none[none] | none:none |
none|none | none | none | |
T:05:12:00 | WinXP | 125.233.146.34 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
74.117.174.82:9890 | CA:f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 50 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 NEW |
none[0] | none:none |
ASProtect| | lines=585 embedded dns |
trace |
T:05:17:00 | WinXP | 77.254.219.130 (INETIA.PL): NETIA, KRAKOW, MALOPOLSKIE, PL. (DSL) |
74.117.174.82:2010 | :adware.rxmods.net CA:f.unicat.org |
139 | pcap | raw alerts ruleset |
ftp irc 45 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | 6f6eefac6f NEW |
none[3] | none:none |
ASPack| | none | trace |
T:05:30:00 | Win2K-f | 125.230.56.87 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
74.117.174.82:9890 | CA:f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 44 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 NEW |
none[0] | none:none |
ASProtect| | lines=585 embedded dns |
trace |
T:05:39:00 | Win2K-f | 123.218.232.27 (OCN.NE.JP): OPEN COMPUTER NETWORK, YOKOHAMA, KANAGAWA, JP. (DSL) |
74.117.174.82:9890 | CA:f.unicat.org US:attacke.100free.com DE:www.members.lycos.co.uk |
445 | pcap | raw alerts ruleset |
ftp irc http 1061 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 43 30 of 42 13 of 31 |
c093f2bf08 NEW c665fbb6e4 NEW e8d4d8cde1 NEW |
none[none] none [none] none [0] |
none:none none:none none:none |
none|none none|none ASProtect| |
none none lines=585 embedded dns |
none none trace |
T:05:40:00 | Win2K-f | 78.8.194.199 (NET.PL): DYNAMIC BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:54:00 | WinXP | 95.58.241.242 (DIAL.ONLINE.KZ): KAZAKHTELECOM DATA NETWORK ADMINISTRATION, KZ. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:15:00 | Win2K-f | 77.45.53.247 (COM.PL): ASTA-NET CUSTOMERS, WARSAW, WARSZAWA, PL. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:25:00 | WinXP | 121.120.124.38 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | a69eed6caa NEW |
none[none] | none:none |
none|none | none | none |
T:06:27:00 | Win2K-f | 78.8.15.188 (NET.PL): DYNAMIC BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:37:00 | Win2K-f | 70.60.199.198 (RR.COM): ROAD RUNNER HOLDCO LLC, MONROE, NORTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:37:00 | WinXP | 178.187.237.152 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
74.117.174.82:9890 | CA:f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 50 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 NEW |
none[0] | none:none |
ASProtect| | lines=585 embedded dns |
trace |
T:07:42:00 | WinXP | 59.116.98.108 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:53:00 | Win2K-f | 24.79.7.67 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 123 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 41 38 of 41 |
34cbe7a593 NEW 3e83a2d4d7 NEW |
d38cb78003 [0] b97fd63d29[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:08:04:00 | WinXP | 113.253.213.113 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 38 of 41 |
a5ceb6c29d NEW adadfc0e1c NEW |
d64cd9d18b [0] 0f57439d82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:08:37:00 | WinXP | 71.23.184.116 (CLEARWIRE-DNS.NET): CLEARWIRE US LLC, KIRKLAND, WASHINGTON, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:05:00 | WinXP | 61.227.142.1 (PRESTONAUTO.COM): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:09:30:00 | WinXP | 79.163.171.42 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:56:00 | Win2K-f | 59.116.98.108 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:56:00 | WinXP | 70.66.149.221 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, PARKSVILLE, BRITISH COLUMBIA, CA. (DSL) |
n/a | US:gg.arrancar.org US:69.43.160.145:555 |
135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 39 | ce28648035 NEW |
126d2f4655 [0] | ASM:Graph |
none|none | lines=546 | trace |
T:12:19:00 | Win2K-f | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 81 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:30:00 | WinXP | 79.132.211.223 (MORVA.NET): MORVA ISP, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | RU:siliconfireware.ru RU:auction.nic.ru :www.google-analytics.com RU:domain-parking.ru RU:ebookfinaltrash.ru :www.epartner.ru :erotds.net :eropod.com EU:videoxx-vitrina.com RU:whatdo.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http 607 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:13:24:00 | WinXP | 4.227.198.45 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DENVER, COLORADO, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
13:52:00 | WinXP | 114.43.53.222 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:01:00 | WinXP | 119.154.33.233 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:23:00 | Win2K-f | 61.230.223.23 (PRESTONAUTO.COM): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
62.193.249.122:3305 | EU:httpw.cz.cc | 135 | pcap | raw alerts ruleset |
irc 697 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 43 | 674de4ba57 NEW |
none[none] | none:none |
none|none | none | none |
T:14:37:00 | WinXP | 72.48.79.7 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS SAN ANTONIO HUB, SAN ANTONIO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:29:00 | WinXP | 114.136.186.30 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
16:53:00 | WinXP | 201.69.115.186 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | d81d6ee5a4 NEW |
none[none] | none:none |
none|none | none | none |
T:16:58:00 | Win2K-f | 24.88.71.34 (RR.COM): ROAD RUNNER HOLDCO LLC, CHAPIN, SOUTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 37 of 41 |
5c39773b13 NEW a1acc403a2 NEW |
c64405f2e9 [0] 54ef26c2f9[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:17:34:00 | WinXP | 79.163.184.58 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
19:32:00 | WinXP | 79.163.150.171 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, BYDGOSZCZ, KUJAWSKO-POMORSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:22:00 | WinXP | 122.73.111.161 (JWS.COM): CHINA TIETONG TELECOMMUNICATIONS CORPORATION, BEIJING, BEIJING, CN. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:21:01:00 | Win2K-f | 184.74.74.92 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:49:00 | WinXP | 61.228.149.39 (PRESTONAUTO.COM): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:07:00 | Win2K-f | 61.215.146.218 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
62.193.249.122:3305 | EU:cx10man.weedns.com JP:fx010413.whyI.org FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 41 | cc88f4f016 NEW |
3d17903825 [0] | ASM:Graph |
StarForce| | lines=3262 embedded dns |
trace |