Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:07:00 | WinXP | 61.46.164.93 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:00:49:00 | WinXP | 89.218.155.196 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 7595827457 NEW |
none[none] | none:none |
none|none | none | none |
T:00:55:00 | WinXP | 219.115.238.188 (ZAQ.NE.JP): K CABLE TELEVISION CORPORATION INC, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 183 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:02:01:00 | WinXP | 123.150.255.109 (163DATA.COM.CN): CHINANET TIANJIN PROVINCE NETWORK, TIANJIN, TIANJIN, CN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:02:21:00 | Win2K-f | 61.228.57.54 (PRESTONAUTO.COM): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:02:23:00 | WinXP | 202.128.67.167 (NETPCI.COM): STARTEC GLOBAL COMMUNCATIONS GUAM, AGANA, GUAM, GU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 38 of 40 |
25d536bea8 NEW 38fe0764dc NEW |
9cffc8f48e [0] de343dc6d8[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:02:37:00 | WinXP | 66.216.206.197 (NEWNANUTILITIES.ORG): NEWNAN UTILITIES, NEWNAN, GEORGIA, US. (DSL) |
62.193.249.122:3305 | EU:cx10man.weedns.com JP:fx010413.whyI.org FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 614 lines |
Yeah : 1.8 profile |
none | summary tarball |
40 of 42 | e30eff4db6 NEW |
none[none] | none:none |
none|none | none | none |
T:02:40:00 | Win2K-f | 180.188.216.169 (-): . |
62.193.249.122:3305 | FR:cx10man.weedns.com KR:fx010413.whyI.org EU:gynoman.weedns.com JP:210.166.223.51:3305 |
135 | pcap | raw alerts ruleset |
irc 609 lines |
Yeah : 1.8 profile |
none | summary tarball |
43 of 43 | d1bfe4618b NEW |
none[none] | none:none |
none|none | none | none |
T:02:43:00 | WinXP | 63.246.127.30 (ALTUSCGI.NET): PRIVATE CABLE ISP SUBSCRIBER (GEORGETOWN SC MARKET), GEORGETOWN, SOUTH CAROLINA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 41 of 43 |
02c8f02035 NEW 0e395f5cf9 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:03:21:00 | WinXP | 93.108.93.238 (REV.VODAFONE.PT): GPRS POOLS, LISBON, LISBOA, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
03:56:00 | WinXP | 122.122.2.130 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:21:00 | Win2K-f | 98.102.100.133 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
443030b837 NEW d14c55e282 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:04:30:00 | WinXP | 87.103.57.85 (REV.VODAFONE.PT): VODAFONE PORTUGAL, AMADORA, LISBOA, PT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:04:59:00 | WinXP | 70.62.194.139 (RR.COM): ROAD RUNNER HOLDCO LLC, LOS ANGELES, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:03:00 | Win2K-f | 72.48.216.109 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO HUB, HEWITT, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:05:11:00 | WinXP | 79.163.224.107 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru :adult-empire.com |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:05:33:00 | WinXP | 117.205.112.233 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:05:48:00 | WinXP | 218.163.43.119 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:22:00 | WinXP | 216.186.150.121 (KNOLOGY.NET): KNOLOGY INC, HUNTSVILLE, ALABAMA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:07:15:00 | WinXP | 76.189.184.16 (RR.COM): ROAD RUNNER HOLDCO LLC, CLEVELAND, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:27:00 | WinXP | 121.121.69.196 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 0f101d48e0 NEW |
none[none] | none:none |
none|none | none | none |
T:07:47:00 | WinXP | 88.188.173.182 (PROXAD.NET): PROXAD / FREE SAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
62.193.249.122:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
shell ftp irc 22 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:07:54:00 | WinXP | 119.154.68.44 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, LAHORE, PUNJAB, PK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 7d7da21a34 NEW |
none[none] | none:none |
none|none | none | none |
T:08:43:00 | WinXP | 189.65.88.17 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:08:57:00 | WinXP | 186.97.210.210 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 43 | baf0b65341 NEW |
none[none] | none:none |
none|none | none | none |
T:09:00:00 | WinXP | 87.103.4.125 (REV.VODAFONE.PT): VODAFONE PORTUGAL, LISBON, LISBOA, PT. (DIAL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:09:05:00 | WinXP | 208.126.113.66 (BUTLER-BREMER.COM): BUTLER-BREMER MUTUAL TELEPHONE, CLARKSVILLE, TENNESSEE, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 7d7da21a34 NEW |
none[none] | none:none |
none|none | none | none |
T:09:14:00 | WinXP | 79.163.144.139 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:09:17:00 | WinXP | 66.54.124.185 (DIGICELBROADBAND.COM): DIGICEL CAYMAN, KY. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 40 |
d08635ca20 NEW e2479cbb98 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:09:22:00 | Win2K-f | 112.201.171.66 (PLDT.NET): IPG, PH. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 290 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | e3e20593b6 NEW |
none[none] | none:none |
none|none | none | none | |
T:09:58:00 | WinXP | 174.76.19.78 (CAMPUSEAI.ORG): COX COMMUNICATIONS INC, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:07:00 | WinXP | 77.81.8.47 (-): SC COBALT IT SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:10:19:00 | WinXP | 79.163.86.82 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 708f64b1b7 NEW |
a18ef8ac1f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:23:00 | WinXP | 178.167.133.123 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | a47c6c159a NEW |
none[none] | none:none |
none|none | none | none | |
T:11:29:00 | Win2K-f | 4.153.2.42 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NORTH AUGUSTA, SOUTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 148 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:45:00 | WinXP | 109.175.192.251 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 43 | 5ed0874084 NEW |
none[none] | none:none |
none|none | none | none |
T:11:57:00 | WinXP | 92.47.18.90 (DIAL.ONLINE.KZ): JSC KAZAKHTELECOM SOUTH KAZAKHSTAN AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 7595827457 NEW |
none[none] | none:none |
none|none | none | none |
T:12:38:00 | WinXP | 92.40.7.191 (THREE.CO.UK): MOBILE BROADBAND SERVICE, MANCHESTER, ENGLAND, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:14:25:00 | WinXP | 4.157.32.194 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BUFFALO, NEW YORK, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 155 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:16:06:00 | WinXP | 98.134.221.200 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - LITTLE ROCK, CONWAY, ARKANSAS, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | d1b3b1de91 NEW |
none[none] | none:none |
none|none | none | none |
T:16:25:00 | Win2K-f | 114.74.240.65 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, MELBOURNE, VICTORIA, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1015 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 43 | 1649626b42 NEW |
none[none] | none:none |
none|none | none | none | |
T:16:52:00 | Win2K-f | 96.8.228.168 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 40 of 42 |
377ae8c2fd NEW 7cfdf42414 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:16:55:00 | WinXP | 95.88.65.26 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | c46f4552da NEW |
ce6ff736cf [0] | none:none |
none|none | none | trace | |
T:17:15:00 | Win2K-f | 65.188.51.23 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBIA, SOUTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 42 |
8d6ca7ac6d NEW fdc64deaa5 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:17:42:00 | Win2K-f | 122.146.243.241 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:38:00 | WinXP | 121.121.173.102 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | a3c82ff952 NEW |
none[none] | none:none |
none|none | none | none |
T:19:03:00 | Win2K-f | 70.75.150.64 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 38 of 41 |
4180c19d91 NEW b6e91e001c NEW |
9f3f2de385 [0] d2275a6cf5[0] |
ASM:Graph ASM:Graph |
Armadillo| PolyEnE| |
lines=91 lines=64 embedded dns |
trace trace |
19:16:00 | WinXP | 189.38.247.26 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:19:50:00 | WinXP | 4.153.249.181 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ROGERSVILLE, TENNESSEE, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
19:52:00 | WinXP | 4.153.249.181 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, ROGERSVILLE, TENNESSEE, US. (DIAL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | f502585714 NEW |
none[0] | none:none |
PolyEnE| | lines=63 | trace |
T:20:10:00 | WinXP | 81.92.50.235 (MYQ.GR): Q TELECOMMUNICATIONS S.A, ATHENS, ATTIKI, GR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:20:50:00 | WinXP | 24.124.65.89 (SUNFLOWER.COM): SUNFLOWER BROADBAND, LAWRENCE, KANSAS, US. (100Mbps) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 6e6fde936f NEW |
none[none] | none:none |
none|none | none | none |
T:21:37:00 | Win2K-f | 174.5.73.4 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
62.193.249.122:3305 | KR:cx10man.weedns.com IT:fx010413.whyI.org FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 695 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | ecfbf321d3 NEW |
none[none] | none:none |
none|none | none | none |
T:22:30:00 | WinXP | 173.212.34.195 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 51 lines |
Yeah : 1.3 profile |
none | summary tarball |
5 of 43 | 366a939e63 NEW |
none[none] | none:none |
none|none | none | none | |
T:23:01:00 | WinXP | 70.233.74.228 (PACBELL.NET): AT&T INTERNET SERVICES, WALLINGFORD, CONNECTICUT, US. (DSL) |
n/a | :www.google.com.au :jbeegvia.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | bb7681eca8 NEW |
none[3] | none:none |
tElock| | none | trace |