Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

03 November 2010
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:00:11:00 WinXP 121.120.67.232 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
42 of 43 b46489628e
NEW
none[none] none:none
none|none none none
00:22:00 WinXP 117.252.68.153 (STERLINGSTUDENTS.NET):
NIB (NATIONAL INTERNET BACKBONE),
NEW DELHI, DELHI, IN. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
36 of 42 e18a983c20
NEW
none[none] none:none
none|none none none
T:00:46:00 WinXP 161.53.193.130 (-):
CARNET-MOBILECARNET,
HR. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
42 of 43 95d1a78f0d
NEW
none[none] none:none
none|none none none
T:00:49:00 WinXP 122.146.227.243 (SPARQNET.NET):
NEW CENTRY INFOCOM TECH. CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:01:03:00 WinXP 222.230.153.157 (VECTANT.NE.JP):
SEIKA CORPORATION,
YOKOHAMA, KANAGAWA, JP. (100Mbps)
n/a   445 pcap raw alerts
ruleset
shell
ftp
14 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 831f4ee0a7
NEW
none[0] none:none
none|none lines=60 trace
T:01:32:00 Win2K-f 60.250.246.160 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
34 of 38
35 of 38
38ed850a0e
NEW
b9297745a1
NEW
46990f37cd [0]
4294884d84[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:02:36:00 Win2K-f 122.196.34.226 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
OSAKA, OSAKA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
71e6f60517
NEW
ab4e3226c4
NEW
1ef1781501 [0]
c2d0313e73[0]
ASM:Graph
none:none
Armadillo|
tElock|
lines=91
none
trace
trace
T:02:39:00 WinXP 118.232.32.225 (KBRONET.COM.TW):
TUNG HO MULTIMEDIA CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
35 of 37 8d0809971a
NEW
none[none] none:none
none|none none none
T:02:51:00 WinXP 178.179.127.94 (FINEBLANK.COM):
EU-ZZ,
UK. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:02:56:00 WinXP 113.255.184.104 (HUTCHCITY.COM):
HUTCHISON GLOBAL COMMUNICATIONS,
HK. (DSL)
70.107.249.167:7000 US:dns.aswend.com 135 pcap raw alerts
ruleset
irc
430 lines
Yeah : 1.8
profile
none summary
tarball
38 of 41 88730549bb
NEW
none[none] none:none
none|none none none
T:02:57:00 WinXP 93.177.237.176 (LVDATS.LV):
LVDATS-NET,
RIGA, RIGA, LV. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
42 of 43 88f3393e20
NEW
none[none] none:none
none|none none none
T:03:22:00 Win2K-f 211.75.159.211 (KENNY.COM.TW):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
57ce4acac2
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:03:29:00 Win2K-f 61.205.90.8 (EONET.NE.JP):
K-OPTICOM CORPORATION,
TOKYO, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
222 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
71e6f60517
NEW
ab4e3226c4
NEW
1ef1781501 [0]
c2d0313e73[0]
ASM:Graph
none:none
Armadillo|
tElock|
lines=91
none
trace
trace
T:03:30:00 WinXP 61.164.138.181 (-):
THE PEOPLE RAISE THE ELECTRIC APPLIANCE GROUP LIMITED COMPANY,
BEIJING, BEIJING, CN. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
03:50:00 WinXP 180.218.124.244 (-):
.
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 42 751685117f
NEW
none[none] none:none
none|none none none
T:03:51:00 WinXP 69.85.96.37 (ELLIJAY.COM):
ELLIJAY COMMUNITY TELEVISION,
BLUE RIDGE, GEORGIA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
05:56:00 WinXP 188.28.125.121 (THREE.CO.UK):
HUTCHISON 3G UK LIMITED,
UK. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 42 dc2dc01b37
NEW
none[none] none:none
none|none none none
T:06:28:00 WinXP 180.66.174.228, 173.192.153.178 (INVALID IPV4 ADDRESS):
INVALID IPV4 ADDRESS,
INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS)
n/a CN:irc.zief.pl
US:microsoft.com
GB:ad.ghura.pl
:bb.iwillhavebigdick.com
CN:exe3.perfectexe.com
GB:www.derquda.com
:sb.perfectexe.com
:streqa.com
EU:bestkind.ru
EU:anotherdomainname.in
173.192.153.178:80
US:63.223.117.12:443
DE:83.133.119.206:80
135 pcap raw alerts
ruleset
irc
http
613 lines
Yeah : 1.3
profile
none summary
tarball
5 of 43
37 of 41
40 of 41
13 of 42
31 of 43
41 of 43
25 of 43
36 of 43
2deb2753bb
NEW
34cd9e2f76
NEW
376a6b6ecd
NEW
788d33c88a
NEW
8b2002c413
NEW
b4afa1df1d
NEW
b6a0b73e41
NEW
c69512a223
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
T:06:42:00 WinXP 118.232.33.244 (KBRONET.COM.TW):
TUNG HO MULTIMEDIA CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
37 of 39 fa0b828ca9
NEW
none[none] none:none
none|none none none
T:07:14:00 Win2K-f 219.234.80.181 (IAPCM.AC.CN):
BEIJING TELETRON TELECOM ENGINEERING CO. LTD,
BEIJING, BEIJING, CN. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:07:30:00 WinXP 121.121.70.114 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:08:16:00 WinXP 83.68.95.120 (TNP.PL):
TELENETMIELECPPP,
WARSAW, WARSZAWA, PL. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 5818023061
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:08:30:00 WinXP 69.193.78.147 (RR.COM):
ROAD RUNNER HOLDCO LLC,
HERNDON, VIRGINIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:08:47:00 Win2K-f 173.20.142.187 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
ALBANY, GEORGIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
38 of 41
692f9bb8df
NEW
d482a2bec3
NEW
2bf6f4e9f0 [0]
50a83c6b54[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:09:12:00 WinXP 117.39.149.181 (163DATA.COM.CN):
CHINANET SHANXI(SN) PROVINCE NETWORK,
BEIJING, BEIJING, CN. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:10:20:00 WinXP 117.254.172.185 (STERLINGSTUDENTS.NET):
NIB (NATIONAL INTERNET BACKBONE),
NEW DELHI, DELHI, IN. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
42 of 43 c2462f2c37
NEW
none[none] none:none
none|none none none
T:10:49:00 WinXP 188.28.186.217 (THREE.CO.UK):
HUTCHISON 3G UK LIMITED,
UK. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 42 360661195e
NEW
none[none] none:none
none|none none none
T:10:53:00 WinXP 92.47.114.12 (DIAL.ONLINE.KZ):
JSC KAZAKHTELECOM EAST KAZAKHSTAN AFFILIATE,
SEMIPALATINSK, EAST KAZAKHSTAN, KZ. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
42 of 43 95d1a78f0d
NEW
none[none] none:none
none|none none none
T:11:12:00 WinXP 79.163.8.207 (CENTERTEL.PL):
PTK CENTERTEL BROADBAND SERVICES,
WARSAW, WARSZAWA, PL. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 42 97264c7178
NEW
none[none] none:none
none|none none none
T:11:24:00 WinXP 50.9.203.238 (-):
.
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:11:28:00 WinXP 173.30.238.216 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
SPRINGFIELD, MISSOURI, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:11:32:00 WinXP 189.53.120.220 (EMBRATEL.NET.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
BR. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
T:12:24:00 WinXP 152.48.222.64 (UNC.EDU):
NORTH CAROLINA RESEARCH AND EDUCATION NETWORK,
DURHAM, NORTH CAROLINA, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:13:17:00 Win2K-f 75.37.173.251 (SBCGLOBAL.NET):
JASON LEE,
PLANO, TEXAS, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:13:28:00 WinXP 109.52.228.173 (JWS.COM):
EU-ZZ,
UK. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
29 of 29 986b59708d
NEW
none[0] none:none
PolyEnE| lines=57 trace
T:13:38:00 WinXP 204.116.230.30 (COMPORIUM.NET):
WEST CAROLINA RURAL TELEPHONE COOP,
COLUMBIA, SOUTH CAROLINA, US. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:13:45:00 WinXP 216.211.243.130 (NORWOODLIGHT.COM):
NORWOOD LIGHT BROADBAND,
NORWOOD, MASSACHUSETTS, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:14:11:00 WinXP 70.44.40.143 (PTD.NET):
PENTELEDATA INC. - CABLE,
MILFORD, PENNSYLVANIA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:14:13:00 WinXP 64.150.147.19 (SCCOAST.NET):
HTC CABLE MODEM IP POOL,
CONWAY, SOUTH CAROLINA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 36 1595515522
NEW
none[none] none:none
none|none none none
T:14:15:00 WinXP 92.41.46.101 (THREE.CO.UK):
MOBILE BROADBAND SERVICE,
UK. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
37 of 42 912f4547f0
NEW
none[none] none:none
none|none none none
T:14:50:00 WinXP 186.85.202.159 (HOODPACKAGING.COM):
TV CABLE S.A,
CO. (DSL)
n/a   445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
15:12:00 WinXP 96.13.108.34 (WINDSTREAM.NET):
ALLTEL MIP CUSTOMERS - ATLANTA,
THOMASVILLE, GEORGIA, US. (DSL)
n/a :moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
25 of 25 7f60162c2c
NEW
none[0] none:none
PolyEnE| lines=93
embedded dns
trace
T:15:19:00 WinXP 77.41.53.114 (QWERTY.RU):
BRAS E-320-24 DHCP-POOL,
MOSCOW, MOSCOW CITY, RU. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
42 of 43 5d82eae84d
NEW
none[none] none:none
none|none none none
T:15:28:00 WinXP 95.74.149.101 (-):
TELECOM ITALIA MOBILE,
ROME, LAZIO, IT. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:15:29:00 WinXP 201.158.79.185 (CABLEXTREMO.COM.MX):
CABLEVISION DE SALTILLO SA DE CV,
SALTILLO, COAHUILA DE ZARAGOZA, MX. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
39 of 41 d8040f84d4
NEW
d683995e84 [0] ASM:Graph
PolyEnE| lines=73 trace
T:15:41:00 Win2K-f 75.38.94.36 (SBCGLOBAL.NET):
DANNY CHON DBA,
PLANO, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:15:51:00 WinXP 189.119.236.155 (TIMBRASIL.COM.BR):
COMITE GESTOR DA INTERNET NO BRASIL,
SãO PAULO, SAO PAULO, BR. (DSL)
83.133.119.206:65520 GB:proxim.ircgalaxy.pl
DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
irc
3 lines
Yeah : 1.3
profile
none summary
tarball
40 of 43 e158a924e8
NEW
none[none] none:none
none|none none none
T:16:12:00 WinXP 173.28.196.190 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
CHANHASSEN, MINNESOTA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:16:27:00 WinXP 64.130.176.186 (SCRTC.COM):
SOUTH CENTRAL RURAL TELEPHONE CO,
SAN JOSE, CALIFORNIA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
40 of 42 a5afad5d2f
NEW
none[none] none:none
none|none none none
T:16:31:00 WinXP 173.25.187.113 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
SAN RAFAEL, CALIFORNIA, US. (DSL)
n/a   445 pcap raw alerts
ruleset
shell
ftp
16 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 1a2c0e6130
NEW
none[0] none:none
none|none lines=60 trace
T:16:34:00 WinXP 70.44.40.143 (PTD.NET):
PENTELEDATA INC. - CABLE,
MILFORD, PENNSYLVANIA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:16:48:00 WinXP 178.92.43.23 (FINEBLANK.COM):
EU-ZZ,
UK. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 41 eda3b7766c
NEW
7556343561 [0] ASM:Graph
PolyEnE| lines=68 trace
T:17:04:00 WinXP 24.207.16.223 (-):
DELTA DCCNET HIGH SPEED INTERNET,
DELTA, BRITISH COLUMBIA, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
39 of 41
53aa804019
NEW
95ddd4a823
NEW
29c6cdbf45 [0]
9e78315a6d[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=64
embedded dns
lines=91
trace
trace
T:17:42:00 Win2K-f 202.124.5.37, 173.192.153.178 (INVALID IPV4 ADDRESS):
INVALID IPV4 ADDRESS,
INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS)
194.8.251.67:65520 CN:proxima.ircgalaxy.pl
US:microsoft.com
:bb.iwillhavebigdick.com
GB:www.derquda.com
:streqa.com
EU:bestkind.ru
CN:exe3.perfectexe.com
:sb.perfectexe.com
EU:anotherdomainname.in
CN:sy2.perfectexe.com
109.196.143.133:80
US:63.223.117.12:443
135 pcap raw alerts
ruleset
irc
http
124 lines
Yeah : 1.8
profile
none summary
tarball
13 of 42
5 of 43
13 of 42
30 of 32
31 of 43
39 of 42
41 of 43
25 of 43
18276220c8
NEW
2deb2753bb
NEW
788d33c88a
NEW
8390780c27
NEW
8b2002c413
NEW
adc7a3a471
NEW
b4afa1df1d
NEW
b6a0b73e41
NEW
none[none]
none [none]
none [none]
none [4]
none [none]
none [none]
none [none]
none [none]
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
tElock|
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
trace
none
none
none
none
T:17:51:00 Win2K-f 203.77.80.90, 173.192.153.178 (INVALID IPV4 ADDRESS):
INVALID IPV4 ADDRESS,
INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS)
60.190.222.139:65520 CN:proxima.ircgalaxy.pl
GB:ad.ghura.pl
:bb.iwillhavebigdick.com
CN:exe3.perfectexe.com
:sb.perfectexe.com
GB:www.derquda.com
:streqa.com
EU:bestkind.ru
EU:anotherdomainname.in
CN:sy2.perfectexe.com
173.224.212.93:443
184.82.18.196:443
US:66.240.171.29:443
US:66.240.171.36:443
EU:91.217.162.104:80
445 pcap raw alerts
ruleset
http
irc
235 lines
Yeah : 1.3
profile
none summary
tarball
13 of 42
18 of 42
5 of 43
25 of 41
13 of 42
31 of 43
17 of 42
34 of 39
41 of 43
25 of 43
18276220c8
NEW
284d34faac
NEW
2deb2753bb
NEW
36bb7118f0
NEW
788d33c88a
NEW
8b2002c413
NEW
99e40412c8
NEW
9b5bd50972
NEW
b4afa1df1d
NEW
b6a0b73e41
NEW
none[none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none [none]
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none:none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none|none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
none
T:17:51:00 WinXP 76.241.140.210 (SBCGLOBAL.NET):
AT&T INTERNET SERVICES,
CLEVELAND, OHIO, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
59 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
8 of 33
53bfe15e91
NEW
b7082104e4
NEW
1473091351 [0]
c5b49e7b82[0]
ASM:Graph
ASM:Graph
tElock|
tElock|
lines=75
embedded dns
lines=41
trace
trace
18:05:00 WinXP 216.211.243.130 (NORWOODLIGHT.COM):
NORWOOD LIGHT BROADBAND,
NORWOOD, MASSACHUSETTS, US. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:18:07:00 Win2K-f 184.74.74.92 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:10:00 WinXP 24.42.35.232 (-):
LIBERTY CABLEVISION OF PUERTO RICO LTD,
PR. (DSL)
n/a RU:siliconfireware.ru
RU:auction.nic.ru
:www.google-analytics.com
RU:domain-parking.ru
RU:ebookfinaltrash.ru
:www.epartner.ru
:erotds.net
EU:eropod.com
:google.com
:www.google.com
:clients1.google.com
:wpad
GB:welcome3.smile.co.uk
GB:195.92.84.198:80
445 pcap raw alerts
ruleset
http
http
http
http
117 lines
Yeah : 0.8
profile
none summary
tarball
29 of 29 a12cab51ef
NEW
none[0] none:none
ASPack| lines=281
embedded dns
trace
T:18:31:00 WinXP 66.19.0.134 (MCLEODUSA.NET):
PAETEC COMMUNICATIONS INC,
HIRAM, GEORGIA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
90 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:32:00 Win2K-f 24.153.122.34 (MYACTV.NET):
ANTIETAM CABLE TELEVISION INC,
HAGERSTOWN, MARYLAND, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:42:00 Win2K-f 173.25.93.63 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
GOLD BAR, WASHINGTON, US. (DSL)
n/a IT:cx10man.weedns.com
JP:fx010413.whyI.org
EU:gynoman.weedns.com
KR:g.0x20.biz
KR:telephone.dd.blueline.be
FR:62.193.249.122:3305
135 pcap raw alerts
ruleset
irc
578 lines
Yeah : 1.3
profile
none summary
tarball
36 of 41 83f6cb959d
NEW
445f56b6dd [0] none:none
StarForce| none trace
T:19:28:00 WinXP 70.63.94.43 (RR.COM):
ROAD RUNNER HOLDCO LLC,
JACKSONVILLE, NORTH CAROLINA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:19:45:00 Win2K-f 4.234.6.254 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
BOCA RATON, FLORIDA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:20:25:00 WinXP 218.119.176.169 (BBTEC.NET):
JAPAN NATION-WIDE NETWORK OF SOFTBANK BB CORP,
TOKYO, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:21:04:00 Win2K-f 70.65.29.164 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
RED DEER, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
186 lines
Yeah : 1.3
profile
none summary
tarball
34 of 39 ce28648035
NEW
126d2f4655 [0] ASM:Graph
none|none lines=546 trace
21:35:00 WinXP 188.28.76.37 (THREE.CO.UK):
HUTCHISON 3G UK LIMITED,
UK. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 42 dc2dc01b37
NEW
none[none] none:none
none|none none none
22:03:00 WinXP 115.164.184.246 (-):
DIGI TELECOMMUNICATIONS SDN BHD,
SHAH ALAM, SELANGOR, MY. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:22:13:00 WinXP 111.125.94.252 (-):
INTERNET SERVICE PROVIDER,
PH. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 986b59708d
NEW
none[0] none:none
PolyEnE| lines=57 trace
T:22:25:00 WinXP 180.69.187.103 (-):
HANARO TELECOM,
SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
3 of 41
33 of 33
8b41cb7a41
NEW
97fef473b9
NEW
ef18d720f3 [0]
ff4e7d6992[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=90
lines=64
embedded dns
trace
trace
T:22:38:00 Win2K-f 122.196.27.31 (ZAQ.NE.JP):
J:COM WEST CO. LTD,
OSAKA, OSAKA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
111 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 41
71e6f60517
NEW
ab4e3226c4
NEW
1ef1781501 [0]
c2d0313e73[0]
ASM:Graph
none:none
Armadillo|
tElock|
lines=91
none
trace
trace
T:22:44:00 WinXP 122.146.226.96 (SPARQNET.NET):
NEW CENTRY INFOCOM TECH. CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:23:22:00 Win2K-f 173.22.251.57 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
VALDOSTA, GEORGIA, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
39 of 41
10759405e0
NEW
d08e00dfaf
NEW
292d343248 [0]
854c49d8c4[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:23:57:00 WinXP 117.254.168.37 (STERLINGSTUDENTS.NET):
NIB (NATIONAL INTERNET BACKBONE),
NEW DELHI, DELHI, IN. (DSL)
n/a   445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
40 of 42 4579d6b186
NEW
none[none] none:none
none|none none none