Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:02:30:00 | WinXP | 188.241.104.68 (-): EUROFIBER, RO. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:02:49:00 | WinXP | 188.38.28.89 (VODAFONE.COM.TR): VODAFONE TELEKOMUNIKASYON A.S, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
36 of 43 | 12698a7c11 NEW |
none[none] | none:none |
none|none | none | none |
T:02:59:00 | Win2K-f | 203.196.74.159 (KAGACABLE.NE.JP): KAGA CABLE TELEVISION CO.LTD, TOKYO, TOKYO, JP. (DSL) |
62.193.249.122:3305 | KR:cx10man.weedns.com EU:fx010413.whyI.org KR:gynoman.weedns.com FR:g.0x20.biz FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 714 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 41 | b8076e37ae NEW |
52953fed05 [0] | none:none |
StarForce| | none | trace |
T:03:10:00 | WinXP | 180.218.124.244 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 42 | 751685117f NEW |
none[none] | none:none |
none|none | none | none |
T:03:17:00 | Win2K-f | 173.27.241.96 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, STREAMWOOD, ILLINOIS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:35:00 | WinXP | 151.82.180.228 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:03:50:00 | WinXP | 194.28.6.80 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:04:01:00 | Win2K-f | 76.189.230.178 (RR.COM): ROAD RUNNER HOLDCO LLC, TWINSBURG, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:04:02:00 | Win2K-f | 216.209.111.139 (BELL.CA): SYMPATICO (BELL NEXXIA), NORTH BAY, ONTARIO, CA. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 218 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 41 | d2b40c91a1 NEW |
fbaa414397 [0] | ASM:Graph |
Armadillo| | lines=91 | trace | |
T:04:26:00 | WinXP | 117.254.92.221 (STERLINGSTUDENTS.NET): NIB (NATIONAL INTERNET BACKBONE), NEW DELHI, DELHI, IN. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 986b59708d NEW |
none[0] | none:none |
PolyEnE| | lines=57 | trace |
T:04:32:00 | WinXP | 217.17.108.228 (SATTRAKT.NET): IP ADDRESSES FOR CABLE MODEM CUSTOMERS, RS. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:04:42:00 | WinXP | 112.110.136.169 (-): GPRS VAS SERVICES, IN. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:05:02:00 | WinXP | 121.121.26.25 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 8fc7967af9 NEW |
none[none] | none:none |
none|none | none | none |
T:05:35:00 | Win2K-f | 218.210.80.111 (SPARQNET.NET): NEW CENTRY INFOCOM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
05:49:00 | WinXP | 121.121.26.25 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 8fc7967af9 NEW |
none[none] | none:none |
none|none | none | none |
T:05:54:00 | WinXP | 211.75.159.211 (KENNY.COM.TW): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:05:56:00 | Win2K-f | 70.182.94.31 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
83.133.119.206:65520 | CN:proxim.ircgalaxy.pl US:microsoft.com CN:image.perfectexe.com GB:www.derquda.com :streqa.com CN:exe3.perfectexe.com EU:bestkind.ru EU:anotherdomainname.in **:sb.perfectexe.com |
135 | pcap | raw alerts ruleset |
irc http 149 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 43 29 of 43 15 of 43 30 of 43 14 of 43 12 of 43 32 of 36 15 of 43 1 of 43 35 of 36 |
09a070e67a NEW 278df56902 NEW 3e90ae8532 NEW 40306feecb NEW 827e44840a NEW 9d85d68cde NEW bea8cb1865 NEW d802244b8f NEW e676b20138 NEW fac78fde16 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] 154de51a66[0] none [none] none [none] 882896ab05[0] |
none:none none:none none:none none:none none:none none:none ASM:Graph none:none none:none ASM:Graph |
none|none none|none none|none none|none none|none none|none Armadillo| none|none none|none tElock| |
none none none none none none lines=91 none none lines=126 embedded dns |
none none none none none none trace none none trace |
T:06:13:00 | Win2K-f | 85.173.12.114, 173.192.153.178 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
60.190.222.139:65520 | CN:exe3.perfectexe.com EU:bestkind.ru **:sb.perfectexe.com DE:proxim.ircgalaxy.pl CN:image.perfectexe.com GB:www.derquda.com :streqa.com CN:2b.yigeyuming.com CN:122.224.6.48:10167 |
445 | pcap | raw alerts ruleset |
http irc 143 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 43 25 of 41 15 of 43 30 of 43 14 of 43 14 of 43 41 of 43 30 of 42 |
278df56902 NEW 36bb7118f0 NEW 3e90ae8532 NEW 40306feecb NEW 827e44840a NEW b24dbb4c37 NEW b4afa1df1d NEW c05a0a77d7 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none none |
none none none none none none none none |
T:06:34:00 | WinXP | 119.154.106.160 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, ISLAMABAD, ISLAMABAD, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 40ebcd906a NEW |
none[none] | none:none |
none|none | none | none |
T:06:39:00 | Win2K-f | 216.228.172.116 (BENDCABLE.COM): BEND CABLE COMMUNICATIONS LLC, BEND, OREGON, US. (DSL) |
62.193.249.122:3305 | IT:cx10man.weedns.com FR:fx010413.whyI.org IT:gynoman.weedns.com FR:62.193.249.122:3305 |
135 | pcap | raw alerts ruleset |
irc 579 lines |
Yeah : 1.8 profile |
none | summary tarball |
36 of 41 | 83f6cb959d NEW |
445f56b6dd [0] | none:none |
StarForce| | none | trace |
T:07:06:00 | WinXP | 79.163.225.205 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:07:16:00 | WinXP | 88.28.231.109 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), MADRID, MADRID, ES. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:07:25:00 | Win2K-f | 152.48.222.69 (UNC.EDU): NORTH CAROLINA RESEARCH AND EDUCATION NETWORK, DURHAM, NORTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:07:35:00 | Win2K-f | 24.103.189.175 (RR.COM): ROAD RUNNER HOLDCO LLC, SYRACUSE, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 39 of 41 |
0563ea7af7 NEW 7e1532574f NEW |
bc2e11a802 [0] e6930769d0[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=65 embedded dns lines=91 |
trace trace |
T:07:39:00 | WinXP | 115.82.22.101 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 420b1a76c4 NEW |
none[none] | none:none |
none|none | none | none |
T:08:13:00 | WinXP | 89.218.160.201 (METRO.ONLINE.KZ): JSC KAZAKHTELECOM ATYRAU AFFILIATE, ALMATY, ALMATY CITY, KZ. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 8e8fff0d13 NEW |
none[none] | none:none |
none|none | none | none |
T:08:21:00 | WinXP | 121.121.1.40 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | a2f2d6ce34 NEW |
none[none] | none:none |
none|none | none | none |
T:09:19:00 | WinXP | 85.122.84.145 (ELKOE.RO): SC ELKO ELECTRONIC SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:27:00 | WinXP | 186.180.10.200 (-): . |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:09:41:00 | WinXP | 91.64.45.143 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
T:10:16:00 | WinXP | 118.232.188.21 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:10:34:00 | Win2K-f | 174.6.21.151 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:10:39:00 | WinXP | 178.167.163.21 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:21:00 | WinXP | 186.180.88.242 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 40ebcd906a NEW |
none[none] | none:none |
none|none | none | none |
T:12:20:00 | Win2K-f | 173.28.194.72 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHANHASSEN, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 39 of 41 |
10759405e0 NEW d08e00dfaf NEW |
292d343248 [0] 854c49d8c4[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
12:28:00 | WinXP | 78.130.3.130 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, LEIRIA, LEIRIA, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | cde003c748 NEW |
none[none] | none:none |
none|none | none | none |
T:12:39:00 | WinXP | 70.63.94.43 (RR.COM): ROAD RUNNER HOLDCO LLC, JACKSONVILLE, NORTH CAROLINA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:12:40:00 | WinXP | 60.250.246.160 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:13:01:00 | WinXP | 151.80.138.54 (51-151.NET24.IT): IUNET-BNET, GROSSETO, TOSCANA, IT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:13:20:00 | WinXP | 190.221.117.2 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 43 | 745f3ba11e NEW |
none[none] | none:none |
none|none | none | none |
T:14:05:00 | WinXP | 190.108.178.45 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, SANTIAGO, REGION METROPOLITANA, CL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | 6455904435 NEW |
none[none] | none:none |
none|none | none | none |
T:14:36:00 | WinXP | 84.225.111.83 (-): PANNON GSM TELECOMMUNICATIONS PLC, HU. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | f8b57d78bf NEW |
none[none] | none:none |
none|none | none | none |
T:16:14:00 | WinXP | 174.39.165.199 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - OMAHA, NORTH PLATTE, NEBRASKA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
35 of 37 | 0e486d1271 NEW |
none[none] | none:none |
none|none | none | none |
T:16:29:00 | Win2K-f | 173.168.162.214 (RR.COM): ROAD RUNNER HOLDCO LLC, CLEARWATER, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:17:30:00 | WinXP | 96.15.181.76 (-): ALLTEL SIP CUSTOMERS - LITTLE ROCK, HOT SPRINGS NATIONAL PARK, ARKANSAS, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 3df86eba85 NEW |
f0c55dd699 [0] | none:none |
PolyEnE| | none | trace |
17:38:00 | WinXP | 96.15.181.76 (-): ALLTEL SIP CUSTOMERS - LITTLE ROCK, HOT SPRINGS NATIONAL PARK, ARKANSAS, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | 3df86eba85 NEW |
f0c55dd699 [0] | none:none |
PolyEnE| | none | trace |
T:18:47:00 | Win2K-f | 173.26.25.56 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, KENT, WASHINGTON, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:19:00:00 | WinXP | 75.18.154.82 (SBCGLOBAL.NET): KS CHANDI & SONS INC, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 40 of 41 |
1e12f5145a NEW f208493e65 NEW |
617af909de [0] 5100adb4f9[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:19:02:00 | WinXP | 152.48.222.64 (UNC.EDU): NORTH CAROLINA RESEARCH AND EDUCATION NETWORK, DURHAM, NORTH CAROLINA, US. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:45:00 | Win2K-f | 24.249.134.70 (COX.NET): COX COMMUNICATIONS, DODGE CITY, KANSAS, US. (DSL) |
194.8.251.67:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com CN:image.perfectexe.com GB:www.derquda.com :streqa.com EU:bestkind.ru EU:anotherdomainname.in 173.192.153.178:80 US:209.222.0.219:443 US:63.223.117.12:443 CA:74.117.63.232:443 |
135 | pcap | raw alerts ruleset |
irc http 146 lines |
Yeah : 1.8 profile |
none | summary tarball |
11 of 41 25 of 43 29 of 43 15 of 43 14 of 43 32 of 36 15 of 43 35 of 36 |
0441fdb31a NEW 09a070e67a NEW 278df56902 NEW 3e90ae8532 NEW 827e44840a NEW bea8cb1865 NEW d802244b8f NEW fac78fde16 NEW |
none[none] none [none] none [none] none [none] none [none] 154de51a66[0] none [none] 882896ab05[0] |
none:none none:none none:none none:none none:none ASM:Graph none:none ASM:Graph |
none|none none|none none|none none|none none|none Armadillo| none|none tElock| |
none none none none none lines=91 none lines=126 embedded dns |
none none none none none trace none trace |
T:21:01:00 | WinXP | 4.229.120.108 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, PONTIAC, MICHIGAN, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 129 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:35:00 | WinXP | 81.92.50.235 (MYQ.GR): Q TELECOMMUNICATIONS S.A, ATHENS, ATTIKI, GR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:21:36:00 | Win2K-f | 117.195.132.162 (10/24.BSNL.IN): NIB (NATIONAL INTERNET BACKBONE), HYDERABAD, ANDHRA PRADESH, IN. (DSL) |
60.190.222.139:65520 | EU:bestkind.ru DE:proxim.ircgalaxy.pl CN:image.perfectexe.com GB:www.derquda.com :streqa.com **:sb.perfectexe.com US:microsoft.com 173.192.153.178:80 US:209.222.0.219:443 CN:221.206.88.194:80 US:63.223.117.12:443 |
445 | pcap | raw alerts ruleset |
irc http 35 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 43 15 of 43 14 of 43 |
278df56902 NEW 3e90ae8532 NEW 827e44840a NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
T:21:40:00 | Win2K-f | 174.107.232.255 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:21:52:00 | Win2K-f | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:21:54:00 | WinXP | 4.243.45.221 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SEATTLE, WASHINGTON, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 160 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:22:17:00 | WinXP | 94.253.154.208 (XNET.HR): BNET HRVATSKA, HR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 6e6fde936f NEW |
none[none] | none:none |
none|none | none | none |
T:22:33:00 | WinXP | 121.121.238.9 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |