Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:08:00 | Win2K-f | 180.72.252.249 (-): . |
91.193.194.67:65520 68.178.232.100:80 | CN:proxim.ircgalaxy.pl US:microsoft.com EU:ii.derquda.com :a.95622.com US:iowacampus.com US:images01.tzimg.com US:domdex.com CN:lb.perfectexe.com US:blogtaletadio.com US:as.casalemedia.com EU:www.derquda.com :pagead2.googlesyndication.com US:images-pw.secureserver.net US:64.202.167.128:80 |
445 | pcap | raw alerts ruleset |
http irc 130 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 40 12 of 42 1 of 42 |
2382c263f9 NEW b34dda1468 NEW cdec20fa79 NEW |
none[none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
T:00:11:00 | WinXP | 112.78.64.149 (-): VIBO TELECOM INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:00:20:00 | WinXP | 180.69.164.225 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
83.133.119.197:65520 | DE:proxima.ircgalaxy.pl US:microsoft.com EU:ii.derquda.com CN:lb.perfectexe.com CN:exe4.perfectexe.com EU:www.derquda.com CN:2b.perfectexe.com EU:justnewleft.ru US:get.whitesmoke.com CN:hn.yigeyuming.com US:c0007083.cdn2.cloudfiles.rackspacecloud.com US:track.zugo.com :apple.skincaremiracle.info US:devtbtrack.zugo.com :a.95622.com |
135 | pcap | raw alerts ruleset |
irc http 177 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 40 22 of 42 6 of 43 28 of 42 17 of 42 39 of 41 2 of 43 12 of 42 29 of 43 31 of 33 5 of 43 |
2382c263f9 NEW 426ecca5d8 NEW 816f141f2b NEW 8809b6417c NEW 9c4e9dd50f NEW ab9c4b5f21 NEW b2c1ecbb4e NEW b34dda1468 NEW b34e640329 NEW d789c8d157 NEW e895dc9399 NEW |
none[none] none [none] none [none] none [none] none [none] 5fe48b2dcc[0] none [none] none [none] none [none] 5f6572479f[0] none [none] |
none:none none:none none:none none:none none:none ASM:Graph none:none none:none none:none ASM:Graph none:none |
none|none none|none none|none none|none none|none Armadillo| none|none none|none none|none PolyEnE| none|none |
none none none none none lines=42 none none none lines=113 embedded dns none |
none none none none none trace none none none trace none |
00:29:00 | WinXP | 112.78.64.149 (-): VIBO TELECOM INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:29:00 | WinXP | 94.153.199.206 (KYIVSTAR.NET): UA-KYIVSTAR, UA. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | aad01847fa NEW |
none[none] | none:none |
none|none | none | none |
T:02:12:00 | WinXP | 121.58.203.157 (CCTLL.COM): COMCLARK-BROADBAND-NETWORK, MANILA, MANILA, PH. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | cb6cf950fc NEW |
none[none] | none:none |
none|none | none | none |
04:45:00 | Win2K-f | 122.160.71.49 (122.AIRTELBROADBAND.IN): ABTS-DSL-DEL, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :www.getmyip.org EU:checkip.dyndns.org IN:122.160.71.49:9234 US:208.43.124.51:80 EU:78.40.35.134:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:05:55:00 | WinXP | 79.163.108.185 (CENTERTEL.PL): PTK CENTERTEL BROADBAND SERVICES, WARSAW, WARSZAWA, PL. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:06:23:00 | WinXP | 121.120.103.75 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
06:54:00 | WinXP | 178.24.88.66 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | 5e8ccc4190 NEW |
8d5f86583f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:07:34:00 | WinXP | 200.148.50.20 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:09:01:00 | WinXP | 115.186.123.100 (HOSTS-WORLDCALL.NET.PK): WORLDCALL TELECOM LTD, KARACHI, SINDH, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | a3c82ff952 NEW |
none[none] | none:none |
none|none | none | none |
09:05:00 | WinXP | 210.209.140.171 (TCOL.COM.TW): MONAD DIGITNAMIC CORP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | 866ac9b262 NEW |
none[none] | none:none |
none|none | none | none |
T:09:16:00 | Win2K-f | 69.19.176.169 (O1.COM): O1 DIALUP SERVICES, LOS ANGELES, CALIFORNIA, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:09:21:00 | WinXP | 121.120.35.95 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
33 of 35 | e9fcd6f257 NEW |
2e05bc2272 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:09:46:00 | WinXP | 121.121.99.236 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | b269b15ffd NEW |
none[none] | none:none |
none|none | none | none |
T:10:09:00 | WinXP | 115.83.10.43 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | f3a1894898 NEW |
none[none] | none:none |
none|none | none | none |
T:10:56:00 | WinXP | 92.251.160.246 (-): H3G IRELAND SUBSCRIBERS, IE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:25:00 | Win2K-f | 64.213.220.180 (HBCI.COM): HIAWATHA BROADBAND COMMUNICATIONS, WINONA, MINNESOTA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
68b5e580f0 NEW b475ce7c0b NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:11:44:00 | WinXP | 98.124.88.61 (HOMESC.COM): HOME TELEPHONE COMPANY INC, MONCKS CORNER, SOUTH CAROLINA, US. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
11:45:00 | WinXP | 115.83.10.43 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | f3a1894898 NEW |
none[none] | none:none |
none|none | none | none |
T:11:49:00 | WinXP | 121.121.219.103 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
12:07:00 | WinXP | 114.46.213.6 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:12:19:00 | Win2K-f | 70.182.253.239, 222.170.127.203 (INVALID IPV4 ADDRESS): INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS) |
91.193.194.67:65520 | US:microsoft.com CN:proxim.ircgalaxy.pl EU:ii.derquda.com CN:lb.perfectexe.com EU:www.derquda.com CN:exe4.perfectexe.com CN:2b.perfectexe.com CN:hn.yigeyuming.com :a.95622.com :1.95622.com US:iowacampus.com US:images01.tzimg.com US:209.59.194.240:80 |
135 | pcap | raw alerts ruleset |
irc http 151 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 40 28 of 42 17 of 42 29 of 43 32 of 36 35 of 36 |
2382c263f9 NEW 8809b6417c NEW 9c4e9dd50f NEW b34e640329 NEW bea8cb1865 NEW fac78fde16 NEW |
none[none] none [none] none [none] none [none] 154de51a66[0] 882896ab05[0] |
none:none none:none none:none none:none ASM:Graph ASM:Graph |
none|none none|none none|none none|none Armadillo| tElock| |
none none none none lines=91 lines=126 embedded dns |
none none none none trace trace |
T:12:27:00 | Win2K-f | 186.61.28.60 (-): . |
n/a | :blowloan.info US:ad.yieldmanager.com :cookex.amp.yahoo.com US:content.yieldmanager.com :ad.doubleclick.net US:cdn.doubleverify.com CN:122.224.6.48:10167 US:63.217.232.59:80 74.125.224.27:80 |
445 | pcap | raw alerts ruleset |
http 29 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:12:37:00 | WinXP | 113.210.129.194 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
12:38:00 | Win2K-f | 210.7.76.130 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org EU:getmyip.co.uk US:www.vouchercodes.net US:208.43.124.51:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 0.8 profile |
none | summary tarball |
0 of 43 3 of 37 |
3866e18f0e NEW d9cb288f31 NEW |
none[none] 45603a001c[0] |
none:none ASM:Graph |
none|none UPX| |
none lines=174 embedded dns |
none trace |
T:12:47:00 | Win2K-f | 210.7.76.130 (DIRECT.NET.IN): TATA COMMUNICATIONS INTERNET SERVICES LTD, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:www.maxmind.com :checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:13:25:00 | WinXP | 87.19.221.200 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 42 | d1ee5191a5 NEW |
none[none] | none:none |
none|none | none | none |
T:14:15:00 | Win2K-f | 46.162.213.33 (-): . |
n/a | US:gg.arrancar.org US:69.43.160.145:555 |
135 | pcap | raw alerts ruleset |
other 158 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 9b9df225df NEW |
none[none] | none:none |
none|none | none | none |
T:14:20:00 | WinXP | 173.31.100.178 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MIDDLETOWN, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 40 of 43 |
1bafff1e61 NEW 8511a51872 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:15:22:00 | WinXP | 173.24.187.72 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MARION, KENTUCKY, US. (DSL) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:15:54:00 | Win2K-f | 60.250.199.56 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 38 35 of 38 |
38ed850a0e NEW b9297745a1 NEW |
46990f37cd [0] 4294884d84[0] |
ASM:Graph ASM:Graph |
Armadillo| tElock| |
lines=91 lines=64 embedded dns |
trace trace |
T:16:11:00 | WinXP | 90.151.112.254 (PERMONLINE.RU): DYNAMIC DISTRIBUTION IP'S FOR BROADBAND SERVICES, MOSCOW, MOSCOW CITY, RU. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 43 | 60c4a8055b NEW |
none[none] | none:none |
none|none | none | none |
T:16:28:00 | WinXP | 188.215.22.228 (HOST-STATIC-92-115-28-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
43 of 43 | a47fdfe79f NEW |
none[none] | none:none |
none|none | none | none |
T:16:31:00 | WinXP | 178.167.196.134 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:17:02:00 | WinXP | 4.252.90.27 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SIDNEY, OHIO, US. (DIAL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 131 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:17:46:00 | WinXP | 190.120.140.113 (EMTEL.NET.CO): COLOMBIA MVIL, TOCAIMA, CUNDINAMARCA, CO. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | 488d27fe97 NEW |
none[none] | none:none |
none|none | none | none |
T:18:32:00 | Win2K-f | 61.222.227.12 (-): TAIWAN PROVINCE RUNNING WATER CO. LTD. DI SEVERN DISTRICT MANAGE CHU, KAOHSIUNG, T'AI-WAN, TW. (100Mbps) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:59:00 | WinXP | 121.120.140.71 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none | |
T:20:03:00 | WinXP | 173.26.22.210 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, MIDDLETOWN, NEW YORK, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:20:00 | WinXP | 121.73.102.234 (TELSTRACLEAR.NET): TELSTRACLEAR WELLINGTON CABLE CUSTOMERS, WELLINGTON, WELLINGTON, NZ. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 02b2b6af5f NEW |
none[none] | none:none |
none|none | none | none |
20:28:00 | WinXP | 88.18.72.132 (RIMA-TDE.NET): TELEFONICA DE ESPANA, BILBAO, PAIS VASCO, ES. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 420b1a76c4 NEW |
none[none] | none:none |
none|none | none | none |
T:20:31:00 | Win2K-f | 96.11.193.156 (RR.COM): ROAD RUNNER HOLDCO LLC, WEST CHESTER, OHIO, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 45885d17fa NEW |
none[none] | none:none |
none|none | none | none | |
T:20:32:00 | WinXP | 112.78.73.242 (-): VIBO TELECOM INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
20:33:00 | WinXP | 121.121.27.212 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:21:24:00 | WinXP | 199.120.66.154 (NETINS.NET): NETINS INC, NEWTON, IOWA, US. (100Mbps) |
n/a | :moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | ff851345d8 NEW |
none[none] | none:none |
none|none | none | none |
T:21:26:00 | WinXP | 121.120.6.104 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
194.14.236.50:6667 | :moscow-advokat.ru SE:qis.md.us.dal.net |
445 | pcap | raw alerts ruleset |
http irc 13 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | c17ac78929 NEW |
none[none] | none:none |
none|none | none | none |
T:21:49:00 | Win2K-f | 68.101.52.24 (COX.NET): COX COMMUNICATIONS INC, MACON, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:22:54:00 | Win2K-f | 72.185.238.141 (RR.COM): ROAD RUNNER HOLDCO LLC, TAMPA, FLORIDA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 37 of 39 |
1da4193446 NEW 6278c9374a NEW |
8a97c8536a [none] cc7aaf6ea9[none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:55:00 | WinXP | 115.80.96.104 (TAIWANMOBILE.NET): TAIWAN MOBILE CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:12:00 | Win2K-f | 24.123.254.138 (RR.COM): ROAD RUNNER HOLDCO LLC, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 222 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 40 |
1d4664020a NEW 57c9e1ed90 NEW |
74a768552f [0] 7908a19bf7[0] |
ASM:Graph ASM:Graph |
Armadillo| PolyEnE| |
lines=91 lines=64 embedded dns |
trace trace |