Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:29:00 | WinXP | 72.43.62.54 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
00:45:00 | WinXP | 124.107.238.119 (PLDT.NET): SPCC7300I08_CONSUMER, MANILA, MANILA, PH. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:00:46:00 | WinXP | 114.46.228.21 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:00:48:00 | WinXP | 79.162.174.145 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:03:00 | WinXP | 188.195.181.211 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. (DSL) |
n/a | :moscow-advokat.ru SE:ced.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 1511a3f219 NEW |
none[none] | none:none |
none|none | none | none |
T:01:06:00 | Win2K-f | 220.216.56.107 (THN.NE.JP): TOKAI CORPORATION, SHIZUOKA, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:01:42:00 | WinXP | 124.44.82.242 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:02:17:00 | Win2K-f | 178.235.207.140 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:20:00 | WinXP | 77.255.59.229 (COM.PL): NETIA, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:23:00 | Win2K-f | 88.222.144.149 (-): KAUNAS MEGANET CORE6 NETWORK, KAUNAS, KAUNO APSKRITIS, LT. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:23:00 | Win2K-f | 94.52.192.27 (-): NEW COM TELECOMUNICATII SA, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:25:00 | Win2K-f | 86.63.104.124 (COM.PL): ASTA-NET CUSTOMERS, WARSAW, WARSZAWA, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:32:00 | WinXP | 77.243.221.45 (VARSAT.NET): GPINETKFT, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:35:00 | WinXP | 87.110.69.144 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:43:00 | Win2K-f | 188.173.127.248 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:55:00 | Win2K-f | 77.254.207.3 (INETIA.PL): NETIA, KRAKOW, MALOPOLSKIE, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:58:00 | WinXP | 95.87.217.108 (-): NET1-POSRV, BG. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:02:59:00 | WinXP | 89.39.48.14 (FDX.RO): SC FULL DUPLEX SRL, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
38 of 41 | fe87c62b51 NEW |
fe87c62b51 [1] | ASM:Graph |
pex| | lines=19 | trace |
T:03:10:00 | Win2K-f | 188.173.5.155 (RIPE.NET): EUROPEAN REGIONAL REGISTRY, UK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:03:12:00 | Win2K-f | 218.163.157.80 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:03:20:00 | Win2K-f | 91.139.193.84 (-): CABLETEL_CMTS, SOFIA, GRAD SOFIYA, BG. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:03:22:00 | WinXP | 178.36.31.147 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:03:41:00 | Win2K-f | 85.193.238.146 (ELPOS.NET): CABLE TV ELPOS LTD. THRID POOL, BIALYSTOK, PODLASKIE, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:03:48:00 | WinXP | 84.108.57.27 (BEZEQINT.NET): CABLES-CUSTOMERS-CONNECTION, TEL AVIV, TEL AVIV, IL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:04:07:00 | Win2K-f | 178.37.36.96 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:04:16:00 | WinXP | 113.252.177.79 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:04:20:00 | WinXP | 59.113.97.54 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:04:35:00 | Win2K-f | 77.253.42.213 (INETIA.PL): INTERNETIA, KATOWICE, SLASKIE, PL. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
9 of 43 | 250ab16ccf NEW |
none[none] | none:none |
none|none | none | none | |
T:04:42:00 | WinXP | 151.67.10.202 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:05:10:00 | Win2K-f | 78.139.86.44 (-): CLOSED JOINT STOCK COMPANY RADIOTELEPHONE, RU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | e3faefa56a NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
T:05:29:00 | Win2K-f | 85.67.102.213 (BACS-NET.HU): FIBERNET COMMUNICATION CO, BUDAPEST, BUDAPEST, HU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | e3faefa56a NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace | |
05:50:00 | WinXP | 93.102.103.18 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, COIMBRA, COIMBRA, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:06:01:00 | Win2K-f | 178.36.100.196 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:06:02:00 | WinXP | 121.121.138.64 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:03:00 | WinXP | 188.195.33.101 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:06:04:00 | WinXP | 113.38.45.185 (UCOM.NE.JP): UCOM CORP, JP. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
5 of 42 | a030d175a3 NEW |
none[none] | none:none |
none|none | none | none | |
T:06:10:00 | Win2K-f | 78.62.201.56 (ZEBRA.LT): LIETUVOS, LT. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 10 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:19:00 | WinXP | 174.0.132.203 (KODIAKPETROLEUM.COM): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:06:19:00 | WinXP | 123.194.136.31 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | :moscow-advokat.ru :lia.zanet.net SE:ozbytes.dal.net SE:ced.dal.net :caen.fr.eu.undernet.org SE:vancouver.dal.net SE:qis.md.us.dal.net :gaspode.zanet.org.za NL:london.uk.eu.undernet.org AT:graz.at.eu.undernet.org NL:diemen.nl.eu.undernet.org :los-angeles.ca.us.undernet.org :washington.dc.us.undernet.org SE:coins.dal.net SE:broadway.ny.us.dal.net SE:viking.dal.net |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 04d4170d3b NEW |
none[none] | none:none |
none|none | none | none |
T:06:33:00 | WinXP | 86.220.140.5 (ABO.WANADOO.FR): IP2000-ADSL-BAS, PARIS, ILE-DE-FRANCE, FR. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:06:39:00 | Win2K-f | 61.120.236.220 (THN.NE.JP): TOKAI CORPORATION, NUMAZU, SHIZUOKA, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 99 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 40 of 41 |
6a6aaa5b73 NEW 8bde6dd126 NEW |
63889c9976 [0] 885c68f500[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=42 lines=64 embedded dns |
trace trace |
T:06:39:00 | Win2K-f | 78.60.245.158 (ZEBRA.LT): JOINT STOCK COMPANY TEO LT AB, VILNIUS, VILNIAUS APSKRITIS, LT. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:07:04:00 | WinXP | 121.121.31.213 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:07:04:00 | Win2K-f | 137.118.142.188 (WILKES.NET): NEONOVA NETWORK SERVICES, NORTH WILKESBORO, NORTH CAROLINA, US. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:07:11:00 | WinXP | 27.54.10.237 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:07:19:00 | WinXP | 41.237.162.56 (TEDATA.NET): AFRINIC, CAIRO, AL QAHIRAH, EG. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:07:29:00 | Win2K-f | 64.213.218.246 (HBCI.COM): HIAWATHA BROADBAND COMMUNICATIONS, WINONA, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
68b5e580f0 NEW b475ce7c0b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
07:44:00 | Win2K-f | 200.226.17.211 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net :www.getmyip.org :checkip.dyndns.org US:208.43.124.51:80 US:217.160.239.39:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:08:00:00 | WinXP | 78.55.253.32 (ALICEDSL.DE): HANSENET-ADSL, BAMBERG, BAYERN, DE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 500518ab72 NEW |
none[none] | none:none |
none|none | none | none |
T:08:03:00 | WinXP | 115.165.83.29 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
T:08:04:00 | Win2K-f | 151.67.10.202 (51-151.NET24.IT): IUNET-BNET, IT. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:08:29:00 | WinXP | 82.67.66.189 (PROXAD.NET): PROXAD / FREE SAS, GRENOBLE, RHONE-ALPES, FR. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:08:30:00 | Win2K-f | 184.74.109.228 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
08:41:00 | Win2K-f | 113.252.81.162 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | US:www.maxmind.com US:checkip.dyndns.org EU:getmyip.co.uk US:www.vouchercodes.net :www.getmyip.org DE:131.220.6.26:80 US:217.160.239.39:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:09:06:00 | WinXP | 121.121.115.151 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:09:55:00 | WinXP | 204.111.25.170 (SHENTEL.NET): SHENTEL SERVICE COMPANY, EDINBURG, VIRGINIA, US. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:10:07:00 | WinXP | 77.20.211.8 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:29:00 | WinXP | 211.19.65.65 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), YOKOHAMA, KANAGAWA, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | c66d771507 NEW |
none[none] | none:none |
none|none | none | none | |
10:44:00 | WinXP | 186.40.85.35 (E-CORPNET.ORG): TELEFONICA MOVIL DE CHILE S.A, CL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 53146906c7 NEW |
none[none] | none:none |
none|none | none | none |
T:11:21:00 | WinXP | 46.109.162.240 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 2c94e3fd00 NEW |
none[none] | none:none |
none|none | none | none |
11:33:00 | WinXP | 114.46.202.241 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
12:01:00 | WinXP | 89.229.191.86 (MM.PL): SZEL-SAT, PL. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 5818023061 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:12:48:00 | WinXP | 88.132.124.80 (PRTELECOM.HU): PRTELECOM-CP, HU. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
8 of 42 | a2706bad6a NEW |
none[none] | none:none |
none|none | none | none | |
T:13:17:00 | WinXP | 69.19.183.122 (O1.COM): O1 DIALUP SERVICES, SAN DIEGO, CALIFORNIA, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 234 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 40 of 41 |
2e3bf6d5ef NEW 6a3ace8b0c NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:13:49:00 | WinXP | 77.64.196.208 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 95d1a78f0d NEW |
none[none] | none:none |
none|none | none | none | |
T:14:00:00 | Win2K-f | 93.179.213.232 (3S.PL): NET-LAND NETWORK, PL. (DSL) |
n/a | US:m.DRD3H.COM | 139 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | c03793a035 NEW |
1d04d6dc84 [0] | ASM:Graph |
ASPack| | lines=3292 embedded dns |
trace |
T:14:09:00 | WinXP | 79.163.56.215 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 5c6df5141d NEW |
none[none] | none:none |
none|none | none | none |
T:14:44:00 | WinXP | 41.35.12.25 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
15:16:00 | Win2K-f | 59.120.247.234 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:getmyip.co.uk US:www.vouchercodes.net EU:checkip.dyndns.org US:208.43.124.51:80 US:217.160.239.39:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:15:18:00 | WinXP | 96.14.52.100 (WINDSTREAM.NET): ALLTEL MIP CUSTOMERS - PHOENIX, MESA, ARIZONA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:16:04:00 | Win2K-f | 4.153.8.156 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MILAN, TENNESSEE, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
17:03:00 | WinXP | 64.33.132.65 (AIRSTREAMCOMM.NET): TRI COUNTY TELEPHONE, WISCONSIN, US. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 0cfab99612 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
17:20:00 | Win2K-f | 122.225.53.238 (163DATA.COM.CN): CHINANET-ZJ JIAXING NODE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:17:55:00 | WinXP | 46.154.128.132 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:18:04:00 | Win2K-f | 122.225.53.238 (163DATA.COM.CN): CHINANET-ZJ JIAXING NODE NETWORK, BEIJING, BEIJING, CN. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:18:50:00 | Win2K-f | 216.4.109.254 (TMA.ORG): XO COMMUNICATIONS, NEW ORLEANS, LOUISIANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 41 of 43 |
02c8f02035 NEW 0e395f5cf9 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:20:02:00 | WinXP | 123.192.176.48 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:27:00 | WinXP | 113.210.219.3 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | ef96217736 NEW |
none[none] | none:none |
none|none | none | none |
T:23:29:00 | Win2K-f | 72.48.102.93 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS SAN MARCOS, SAN MARCOS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |