Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:10:00 | Win2K-f | 174.3.216.6 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CA. (DSL) |
n/a | PR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | c2766fa683 NEW |
none[none] | none:none |
none|none | none | none |
T:00:26:00 | Win2K-f | 123.195.180.130 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | PR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 20 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | e25842bcd6 NEW |
none[none] | none:none |
none|none | none | none |
T:00:33:00 | WinXP | 113.252.202.75 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | PR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 80563974df NEW |
afaf06d6cd [0] | ASM:Graph |
pex| | lines=42 | trace |
T:00:44:00 | Win2K-f | 24.76.4.211 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SELKIRK, MANITOBA, CA. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fa913f2b22 NEW |
none[none] | none:none |
none|none | none | none | |
T:00:49:00 | WinXP | 117.254.221.161 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:00:50:00 | WinXP | 24.79.195.251 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | PR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | 28de0bdf87 NEW |
none[none] | none:none |
none|none | none | none |
T:00:54:00 | Win2K-f | 82.132.73.219 (-): CROATIAN ACADEMIC AND RESEARCH NETWORK, HR. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 8887d42f5c NEW |
afaf06d6cd [0] | ASM:Graph |
pex| | lines=42 | trace | |
T:01:07:00 | WinXP | 88.31.227.75 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), PALMA DE MALLORCA, ISLAS BALEARES, ES. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ea08813f54 NEW |
none[none] | none:none |
none|none | none | none |
T:01:56:00 | WinXP | 111.67.49.163 (-): VMAX TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:02:23:00 | WinXP | 66.90.146.251 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS AUSTIN HUB, AUSTIN, TEXAS, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:57:00 | Win2K-f | 113.43.52.187 (UCOM.NE.JP): UCOM CORP, JP. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 02aada1158 NEW |
none[none] | none:none |
none|none | none | none | |
T:03:12:00 | WinXP | 24.79.193.26 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | PR:m.DRD3H.COM PR:207.166.122.75:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 12b5856655 NEW |
none[none] | none:none |
none|none | none | none |
T:03:14:00 | WinXP | 58.123.70.14 (HANANET.NET): HANARO TELECOM INC, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
T:03:55:00 | WinXP | 184.80.69.109 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:05:17:00 | WinXP | 151.81.36.121 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 36 | 1595515522 NEW |
none[none] | none:none |
none|none | none | none |
T:05:22:00 | WinXP | 93.102.84.24 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:47:00 | WinXP | 95.75.252.228 (-): TELECOM ITALIA MOBILE, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 8dc969b010 NEW |
none[none] | none:none |
none|none | none | none |
T:06:03:00 | Win2K-f | 70.71.226.159 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, ALDERGROVE, BRITISH COLUMBIA, CA. (DSL) |
n/a | PR:m.DRD3H.COM PR:207.166.122.75:6668 |
139 | pcap | raw alerts ruleset |
ftp irc 18 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | ffbb6cbe61 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
06:25:00 | WinXP | 93.102.84.24 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PORTO, PORTO, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:51:00 | Win2K-f | 211.207.234.98 (FRONTIEROIL.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 6 of 41 |
5213395833 NEW 9fdf6de4a9 NEW |
515eacbc36 [0] 794f9a1087[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=56 embedded dns lines=90 |
trace trace |
T:07:03:00 | WinXP | 117.254.89.111 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | d1377a8b90 NEW |
ad56da3672 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:07:08:00 | WinXP | 117.254.172.153 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | d1377a8b90 NEW |
ad56da3672 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:07:39:00 | WinXP | 110.93.97.12 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
5bbb57c115 NEW 75ac189d9e NEW |
03e5cb3c4a [0] 705dbaa801[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:07:47:00 | WinXP | 122.196.22.240 (ZAQ.NE.JP): J:COM WEST CO. LTD, OSAKA, OSAKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:08:13:00 | WinXP | 79.163.196.44 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:08:20:00 | WinXP | 178.92.202.80 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:08:23:00 | Win2K-f | 58.146.1.235 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:39:00 | WinXP | 119.26.168.14 (ZAQ.NE.JP): KANSAI MULTIMEDIA SERVICE COMPANY, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 88 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 37 of 41 |
53bfe15e91 NEW 89747f56b8 NEW |
1473091351 [0] bd6821b297[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=75 embedded dns lines=91 |
trace trace |
T:08:41:00 | Win2K-f | 113.254.34.216 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:gg.arrancar.org US:69.43.160.145:555 |
135 | pcap | raw alerts ruleset |
other 184 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 38 | 92e29a98bd NEW |
57d7791117 [0] | ASM:Graph |
none|none | lines=546 | trace |
T:09:01:00 | WinXP | 113.252.180.41 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
62.193.249.122:3305 | FR:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 698 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 41 | ecfbf321d3 NEW |
none[none] | none:none |
none|none | none | none |
T:09:17:00 | WinXP | 212.152.75.189 (B-ONLINE.GR): INTERNET SERVICE PROVIDER, ATHENS, ATTIKI, GR. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:09:19:00 | WinXP | 79.163.181.82 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:09:25:00 | WinXP | 79.163.162.172 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:09:45:00 | Win2K-f | 116.58.157.99 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:10:30:00 | WinXP | 213.188.247.246 (EBLCOM.CH): EBLCOM CABLETV, LIESTAL, BASEL-LANDSCHAFT, CH. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:10:52:00 | Win2K-f | 4.153.2.173 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NORTH AUGUSTA, SOUTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:14:00 | Win2K-f | 96.8.220.68 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:11:21:00 | WinXP | 71.23.202.128 (CLEARWIRE-DNS.NET): CLEARWIRE US LLC, KIRKLAND, WASHINGTON, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:25:00 | WinXP | 72.47.17.191 (CEBRIDGE.NET): CEBRIDGE CONNECTIONS, WOODWARD, OKLAHOMA, US. (DSL) |
n/a | PR:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | a8c7b1bcff NEW |
none[none] | none:none |
none|none | none | none |
T:11:44:00 | Win2K-f | 4.84.52.192 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, IRMO, SOUTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 42 |
8d6ca7ac6d NEW fdc64deaa5 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:11:50:00 | WinXP | 119.154.33.153 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:11:59:00 | Win2K-f | 66.195.238.24 (TWTELECOM.NET): TW TELECOM HOLDINGS INC, DAYTON, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 118 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 39 of 42 |
a1fac31325 NEW c018e17b5b NEW |
0fd057b5e2 [0] 8caee80d88[0] |
none:none none:none |
Armadillo| StarForce| |
none none |
trace trace |
12:07:00 | WinXP | 71.23.202.128 (CLEARWIRE-DNS.NET): CLEARWIRE US LLC, KIRKLAND, WASHINGTON, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 35 | 9716d7995a NEW |
c3a5354b6f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:12:22:00 | WinXP | 189.38.245.25 (VELOXZONE.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO BERNARDO DO CAMPO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 6eda5f32a0 NEW |
none[none] | none:none |
none|none | none | none |
T:14:00:00 | Win2K-f | 68.200.108.89 (RR.COM): ROAD RUNNER HOLDCO LLC, LARGO, FLORIDA, US. (DSL) |
62.193.249.122:3305 | JP:cx10man.weedns.com | 135 | pcap | raw alerts ruleset |
irc 607 lines |
Yeah : 1.8 profile |
none | summary tarball |
43 of 43 | 03e53fb32a NEW |
none[none] | none:none |
none|none | none | none |
T:14:53:00 | WinXP | 68.145.214.246 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 41 of 43 |
5119adadbd NEW cb6df05afd NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:42:00 | Win2K-f | 211.118.177.57 (BORA.NET): BORANET-NET, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
T:17:21:00 | WinXP | 71.101.51.199 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LAKELAND, FLORIDA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:17:34:00 | Win2K-f | 64.253.69.68 (INDUSTRYINET.COM): INDUSTRY I-NET INC, CARMINE, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:17:45:00 | Win2K-f | 63.246.53.97 (GEUSNET.COM): GEUS, GREENVILLE, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 41 of 43 |
02c8f02035 NEW 0e395f5cf9 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:18:16:00 | Win2K-f | 218.119.176.169 (BBTEC.NET): JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:32:00 | WinXP | 75.187.252.1 (RR.COM): ROAD RUNNER HOLDCO LLC, LORAIN, OHIO, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:34:00 | WinXP | 208.126.113.48 (BUTLER-BREMER.COM): BUTLER-BREMER MUTUAL TELEPHONE, CLARKSVILLE, TENNESSEE, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 7d7da21a34 NEW |
none[none] | none:none |
none|none | none | none |
18:39:00 | WinXP | 98.124.86.41 (HOMESC.COM): HOME TELEPHONE COMPANY INC, MONCKS CORNER, SOUTH CAROLINA, US. (100Mbps) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:55:00 | Win2K-f | 216.82.201.230 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS WACO HUB, WACO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:18:59:00 | WinXP | 117.104.11.240 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
6b315f5dbc NEW 7938865f8c NEW |
7604b94520 [0] a9b9e4904b[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:20:07:00 | WinXP | 61.215.165.127 (CABLENET.NE.JP): CABLENET SAITAMA CO. LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
10c560fc02 NEW 1b8d146832 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:20:25:00 | Win2K-f | 219.234.80.181 (IAPCM.AC.CN): BEIJING TELETRON TELECOM ENGINEERING CO. LTD, BEIJING, BEIJING, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 79 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:49:00 | WinXP | 116.123.219.145 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
T:21:37:00 | Win2K-f | 180.64.59.196 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 41 of 43 |
178b0be402 NEW c4be4e4a28 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:21:56:00 | WinXP | 121.120.41.198 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 5a160ffa85 NEW |
none[none] | none:none |
none|none | none | none |
22:16:00 | WinXP | 74.160.160.176 (BELLSOUTH.NET): BELLSOUTH.NET INC, LAWRENCEVILLE, GEORGIA, US. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
23:03:00 | WinXP | 182.62.104.156 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:29:00 | WinXP | 92.115.136.183 (HOST-STATIC-92-115-28-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:32:00 | Win2K-f | 219.255.3.101 (HANANET.NET): HANARO TELECOM INC, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.206:65520 | US:microsoft.com DE:proxima.ircgalaxy.pl LV:ad.ghura.pl :bb.iwillhavebigdick.com :kdert.com LV:streq.cn LV:bestkind.ru LV:kdddaber.com 173.192.153.178:80 173.236.31.98:80 GB:212.117.161.188:80 LV:91.188.59.199:80 LV:91.188.60.94:80 LV:91.188.60.96:80 |
135 | pcap | raw alerts ruleset |
irc http 153 lines |
Yeah : 1.8 profile |
none | summary tarball |
8 of 43 40 of 41 26 of 43 13 of 43 8 of 43 2 of 43 16 of 43 |
0d4c9b9be2 NEW 1824c59f34 NEW 2c19b67965 NEW 66317cddbd NEW 700246abe7 NEW 96440d7ad2 NEW d8ac5108c6 NEW |
none[none] da8a48fc3a[0] none [none] none [none] none [none] none [none] none [none] |
none:none ASM:Graph none:none none:none none:none none:none none:none |
none|none tElock| none|none none|none none|none none|none none|none |
none lines=112 embedded dns none none none none none |
none trace none none none none none |
T:23:43:00 | Win2K-f | 122.21.64.162 (OCN.NE.JP): OPEN COMPUTER NETWORK, HIROSHIMA, HIROSHIMA, JP. (DSL) |
n/a | 173.224.120.138:80 173.236.31.98:80 184.154.40.58:80 GB:212.117.161.188:80 CN:222.186.13.51:80 CN:60.191.254.235:80 67.212.184.226:80 |
135 | pcap | raw alerts ruleset |
http irc 41 lines |
Argh : 0.3 profile |
none | summary tarball |
13 of 42 12 of 42 19 of 43 |
4bd9563a04 NEW aa69156be6 NEW f9dd799a03 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
T:23:47:00 | WinXP | 87.57.16.244 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
23:55:00 | WinXP | 125.230.111.18 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:23:55:00 | WinXP | 121.73.249.79 (TELSTRACLEAR.NET): TELSTRACLEAR VIRTUAL ISP, NZ. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 02b2b6af5f NEW |
none[none] | none:none |
none|none | none | none |
T:23:58:00 | Win2K-f | 218.164.76.43 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TW. (DSL) |
n/a | US:microsoft.com 173.224.120.138:80 173.236.31.98:80 184.154.40.58:80 GB:212.117.161.188:80 CN:222.186.13.51:80 CN:60.191.254.235:80 67.212.184.226:80 |
445 | pcap | raw alerts ruleset |
irc 46 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |