Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:26:00 | WinXP | 115.164.227.49 (-): DIGI TELECOMMUNICATIONS SDN BHD, SHAH ALAM, SELANGOR, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:00:33:00 | Win2K-f | 122.59.177.43 (GLOBAL-GATEWAY.NET.NZ): TELECOM NEW ZEALAND LIMITED, NZ. (DSL) |
n/a | :relifegame.com US:ad.yieldmanager.com :content.yieldmanager.com :cookex.amp.yahoo.com US:clubsofforex.info EU:prnc.ezv4.com EU:www.hopa.com EU:78.110.17.135:80 |
135 | pcap | raw alerts ruleset |
http 43 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:43:00 | Win2K-f | 218.160.176.192 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:searchportal.information.com :cdn.dsultra.com US:ads1.revenue.net US:panther1.cpxinteractive.com :ad.doubleclick.net :b.collective-media.net :segment-pixel.invitemedia.com :ads.undertone.com US:ib.adnxs.com :a.collective-media.net US:ads.bluelithium.com 209.197.7.124:80 CA:74.122.140.23:80 74.125.19.148:80 75.101.205.96:80 |
445 | pcap | raw alerts ruleset |
http 47 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:00:50:00 | Win2K-f | 175.124.187.243, 173.192.153.178 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
n/a | :sb.perfectexe.com :bb.iwillhavebigdick.com LV:nemerk.com CN:exe2.perfectexe.com CN:2b.perfectexe.com :childbehaviourproblem.com US:ad.yieldmanager.com 174.120.120.170:80 US:66.94.240.25:80 LV:91.188.60.16:80 |
135 | pcap | raw alerts ruleset |
irc http 364 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 41 19 of 42 34 of 39 41 of 43 19 of 42 |
36bb7118f0 NEW 8b4a36f5a7 NEW 9b5bd50972 NEW b4afa1df1d NEW ba4a3d55fa NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:00:56:00 | Win2K-f | 203.91.183.77 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:01:17:00 | Win2K-f | 115.131.36.97 (-): 3G MOBILE SERVICE PROVIDER, BRISBANE, QUEENSLAND, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:01:27:00 | Win2K-f | 114.74.250.53 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, MELBOURNE, VICTORIA, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 350 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace | |
T:01:37:00 | WinXP | 77.20.225.161 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:01:51:00 | Win2K-f | 173.28.128.212 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, DAVENPORT, IOWA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:02:05:00 | WinXP | 59.103.214.114 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:sys.zief.pl DE:citi-bank.ru DE:213.155.0.224:80 CN:60.190.222.139:65520 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 757c7019f5 NEW |
none[none] | none:none |
none|none | none | none |
T:03:43:00 | WinXP | 121.123.36.129 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:53:00 | Win2K-f | 110.12.45.150 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | CN:proxima.ircgalaxy.pl US:microsoft.com :bb.iwillhavebigdick.com LV:nemerk.com 173.192.153.178:80 LV:91.188.60.16:80 |
135 | pcap | raw alerts ruleset |
irc 109 lines |
Yeah : 1.8 profile |
none | summary tarball |
34 of 36 29 of 32 |
99b248336f NEW 9d677c3f70 NEW |
c64bd1a776 [0] 77e75ff10f[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=120 embedded dns |
trace trace |
T:04:01:00 | Win2K-f | 209.226.141.110 (BELL.CA): BELL CANADA, WELLAND, ONTARIO, CA. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:23:00 | WinXP | 114.175.81.185 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:28:00 | Win2K-f | 125.58.112.7 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 39 of 41 |
23018e5a28 NEW 41eec40656 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:05:01:00 | WinXP | 60.35.48.18 (PLALA.OR.JP): NTT PLALA INC, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:05:07:00 | WinXP | 115.164.112.51 (-): DIGI TELECOMMUNICATIONS SDN BHD, SHAH ALAM, SELANGOR, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:05:09:00 | WinXP | 121.121.33.203 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:05:17:00 | WinXP | 92.115.140.235 (HOST-STATIC-92-115-28-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:05:28:00 | WinXP | 216.183.50.121 (GRANDERIVER.COM): VTX BROADBAND INC, PEARSALL, TEXAS, US. (DIAL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | bbfa82b051 NEW |
none[none] | none:none |
none|none | none | none |
T:05:31:00 | WinXP | 175.123.172.91 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 5 of 41 |
14f47ffd1e NEW 50437008d9 NEW |
90bf4b99ff [0] c1b09ac5d7[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=56 embedded dns lines=90 |
trace trace |
T:05:34:00 | Win2K-f | 75.15.239.70 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, BAKERSFIELD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
1e12f5145a NEW f208493e65 NEW |
617af909de [0] 5100adb4f9[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:05:44:00 | Win2K-f | 4.250.0.49 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, EATONTOWN, NEW JERSEY, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
06:09:00 | WinXP | 112.78.71.99 (-): VIBO TELECOM INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | cf346981b5 NEW |
2eb6c94f0a [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
06:33:00 | WinXP | 216.183.50.121 (GRANDERIVER.COM): VTX BROADBAND INC, PEARSALL, TEXAS, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | bbfa82b051 NEW |
none[none] | none:none |
none|none | none | none |
06:45:00 | WinXP | 121.121.33.203 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:56:00 | WinXP | 212.152.105.62 (-): TIM HELLAS TELECOMMUNICATIONS S.A, ATHENS, ATTIKI, GR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:07:02:00 | WinXP | 77.253.123.46 (INETIA.PL): INTERNETIA, LUBLIN, LUBELSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | d74b8d6c6b NEW |
none[none] | none:none |
none|none | none | none |
T:07:11:00 | WinXP | 92.86.47.88 (TELELINK-RO.COM): ARTELECOM, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:07:15:00 | WinXP | 119.103.146.85 (163DATA.COM.CN): CHINANET HUBEI PROVINCE NETWORK, WUHAN, HUBEI, CN. (DSL) |
n/a | DE:citi-bank.ru :wpad DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
07:22:00 | WinXP | 77.253.123.46 (INETIA.PL): INTERNETIA, LUBLIN, LUBELSKIE, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | d74b8d6c6b NEW |
none[none] | none:none |
none|none | none | none |
T:07:25:00 | WinXP | 4.153.2.165 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, NORTH AUGUSTA, SOUTH CAROLINA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 82 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:42:00 | WinXP | 95.57.28.39 (METRO.ONLINE.KZ): JSC KAZAKHTELECOM KARAGANDA AFFILIATE, KARAGANDA, WEST KAZAKHSTAN, KZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | 02ff806b69 NEW |
none[none] | none:none |
none|none | none | none |
T:08:06:00 | WinXP | 115.130.1.163 (-): 3G MOBILE SERVICE PROVIDER, ELTHAM, VICTORIA, AU. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:08:29:00 | Win2K-f | 4.138.49.31 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, KNOXVILLE, TENNESSEE, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
09:23:00 | Win2K-f | 94.81.219.78 (-): PATERNA GROUP SRL, TORINO, PIEMONTE, IT. (100Mbps) |
n/a | US:www.maxmind.com :www.getmyip.org US:checkip.dyndns.org :getmyip.co.uk DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | dc331fb791 NEW |
none[3] | none:none |
UPX| | none | trace |
T:09:32:00 | WinXP | 109.125.0.56 (STERLINGSTUDENTS.NET): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 01c4a6b3eb NEW |
dd524b0259 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:43:00 | WinXP | 121.120.107.78 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 90d364b188 NEW |
none[none] | none:none |
none|none | none | none |
T:09:56:00 | WinXP | 178.167.200.244 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | a47c6c159a NEW |
none[none] | none:none |
none|none | none | none | |
10:24:00 | WinXP | 121.120.107.78 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | eda3b7766c NEW |
7556343561 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:06:00 | Win2K-f | 4.143.210.36 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, HOMEWOOD, ILLINOIS, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:37:00 | WinXP | 93.108.5.185 (REV.VODAFONE.PT): GPRS POOLS, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:11:53:00 | WinXP | 69.225.20.251 (PACBELL.NET): AT&T INTERNET SERVICES, MODESTO, CALIFORNIA, US. (DSL) |
n/a | RU:siliconfireware.ru RU:auction.nic.ru US:www.google-analytics.com RU:domain-parking.ru RU:ebookfinaltrash.ru :www.epartner.ru EU:erotds.net :eropod.com EU:videoxx-vitrina.com RU:whatdo.ru :wpad |
445 | pcap | raw alerts ruleset |
http http http http 46 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
T:12:33:00 | Win2K-f | 61.34.251.246 (BORA.NET): DACOM CORP, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl LV:ad.ghura.pl :bb.iwillhavebigdick.com LV:nemerk.com 173.192.153.178:80 LV:91.188.59.199:80 LV:91.188.60.16:80 |
135 | pcap | raw alerts ruleset |
irc 158 lines |
Yeah : 1.8 profile |
none | summary tarball |
38 of 40 38 of 40 |
66863cfb13 NEW e8dfca0741 NEW |
fca240f318 [0] 20dfd2147c[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=125 embedded dns |
trace trace |
T:12:43:00 | WinXP | 79.162.152.51 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:12:58:00 | Win2K-f | 208.88.70.103 (-): BBW 4 ACES TOWER CUSTOMER SUBNET, SHREVEPORT, LOUISIANA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:13:00:00 | Win2K-f | 4.227.253.57 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, DENVER, COLORADO, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:13:03:00 | Win2K-f | 93.102.67.179 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, COIMBRA, COIMBRA, PT. (DSL) |
60.190.222.139:65520 | CN:proxim.ircgalaxy.pl LV:ad.ghura.pl :bb.iwillhavebigdick.com LV:nemerk.com US:microsoft.com 173.192.153.178:80 DE:83.133.119.206:65520 LV:91.188.59.199:80 LV:91.188.60.16:80 |
445 | pcap | raw alerts ruleset |
irc 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:06:00 | WinXP | 212.233.142.31 (OPTISPRINT.NET): OPTISPRINT INTERNET POOLS, BG. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | d74b8d6c6b NEW |
none[none] | none:none |
none|none | none | none |
T:13:16:00 | WinXP | 92.40.20.180 (THREE.CO.UK): MOBILE BROADBAND SERVICE, MANCHESTER, ENGLAND, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | cb7a1c872d NEW |
none[none] | none:none |
none|none | none | none | |
T:14:34:00 | WinXP | 189.119.162.240 (TIMBRASIL.COM.BR): COMITE GESTOR DA INTERNET NO BRASIL, SãO PAULO, SAO PAULO, BR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:35:00 | WinXP | 89.195.137.215 (-): ORANGE HIGH SPEED INTERNET, LONDON, ENGLAND, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 2479e25b22 NEW |
none[none] | none:none |
none|none | none | none |
T:15:40:00 | WinXP | 75.92.45.167 (CLEARWIRE-DNS.NET): CLEARWIRE US LLC, SPRINGDALE, ARKANSAS, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:03:00 | WinXP | 71.101.167.97 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LAKELAND, FLORIDA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:16:12:00 | Win2K-f | 24.109.83.131 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SIDNEY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | baa07a6a42 NEW |
none[none] | none:none |
none|none | none | none | |
16:21:00 | WinXP | 75.92.45.167 (CLEARWIRE-DNS.NET): CLEARWIRE US LLC, SPRINGDALE, ARKANSAS, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:16:41:00 | Win2K-f | 4.188.31.152 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, CHICAGO, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 253 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 38 of 42 |
464f4b6177 NEW 61ab444924 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:17:14:00 | Win2K-f | 4.224.141.161 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:17:19:00 | WinXP | 76.205.115.24 (SBCGLOBAL.NET): AT&T INTERNET SERVICES, CLEVELAND, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 74 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 33 33 of 33 |
4ca3056804 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:17:21:00 | Win2K-f | 96.8.235.34 (GVTC.COM): GUADALUPE VALLEY TELEPHONE COOPERATIVE INC, NEW BRAUNFELS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 40 of 42 |
377ae8c2fd NEW 7cfdf42414 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:17:39:00 | Win2K-f | 174.42.155.142 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS, LITTLE ROCK, ARKANSAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 121 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
53aa804019 NEW 95ddd4a823 NEW |
29c6cdbf45 [0] 9e78315a6d[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:18:48:00 | WinXP | 173.29.246.167 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:22:00 | Win2K-f | 118.83.140.106 (NKNO.J-CNET.JP): CITY TV NAKANO LIMITED, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 122 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 36 34 of 36 |
0b951c2832 NEW e4ed4df0f0 NEW |
5fe761661a [0] de471fc380[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:19:30:00 | Win2K-f | 116.125.162.9 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 41 33 of 33 |
8b41cb7a41 NEW 97fef473b9 NEW |
ef18d720f3 [0] ff4e7d6992[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=90 lines=64 embedded dns |
trace trace |
T:20:11:00 | WinXP | 74.160.97.246 (BELLSOUTH.NET): BELLSOUTH.NET INC, DULUTH, GEORGIA, US. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:20:37:00 | WinXP | 113.10.71.83 (-): STARHUB HSDPA SG, SINGAPORE, SINGAPORE, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | ecb443d06e NEW |
none[none] | none:none |
none|none | none | none |
T:21:51:00 | WinXP | 172.162.221.191 (AOL.COM): AMERICA ONLINE, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:36:00 | Win2K-f | 180.70.142.21 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
60.190.222.139:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com LV:ad.ghura.pl :bb.iwillhavebigdick.com LV:nemerk.com 173.192.153.178:80 DE:83.133.119.206:65520 LV:91.188.59.199:80 LV:91.188.60.16:80 |
135 | pcap | raw alerts ruleset |
irc 153 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 41 31 of 33 |
ab9c4b5f21 NEW d789c8d157 NEW |
5fe48b2dcc [0] 5f6572479f[0] |
ASM:Graph ASM:Graph |
Armadillo| PolyEnE| |
lines=42 lines=113 embedded dns |
trace trace |
T:22:46:00 | WinXP | 64.175.160.91 (PACBELL.NET): AT&T INTERNET SERVICES, CARLSBAD, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:59:00 | Win2K-f | 118.167.5.229 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
60.190.222.139:65520 | DE:proxima.ircgalaxy.pl LV:ad.ghura.pl :bb.iwillhavebigdick.com LV:nemerk.com 173.192.153.178:80 DE:83.133.119.206:65520 LV:91.188.59.199:80 LV:91.188.60.16:80 |
445 | pcap | raw alerts ruleset |
irc 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:23:29:00 | Win2K-f | 122.146.82.46 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:23:58:00 | WinXP | 117.254.190.27 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |