Welcome to the Cyber-TA
SRI's Multiperspective Malware Infection Analysis Page


UNCENSORED PAGE


<Click here: to download BotHunter>

22 February 2011
<prev>   <next>

All data collection and analyses summarized in this page were 100% AUTO-GENERATED.

DEVELOPERS: Vinod Yegneswaran (SRI), Phillip Porras (SRI), Hassen Saidi (SRI)
Monirul Sharif (Georgia-Tech), Arvind Narayanan (University of Texas at Austin)

The data on this website is provided for research purposes only. It is provided
for your personal use only and is supplied AS IS, WITHOUT WARRANTY OF ANY KIND.
Use or reliance on this data is at your own risk.


Daily Summary Files: [DNS Lookups & Failed Connects] [ Attacker IPs ] [C&C Servers] [Binary Digests]
Cumulative Summary Files: [DNS Lookup Log] [Attacker IP Log] [C&C Server Log] [Antivirus Detection] [Code Segment Overlap]
[Behavioral Clusters] [Binary Digest Log]

[See Country Codes ]
Time
Victim
OS
Infection
Source
C&C
Server
DNS Lookups &
Failed Connects
Infection
Port
Packet
Trace
Detection
Signatures
Infection
Chatter
BotHunter
Analysis
Behavioral
Cluster
Forensic
Logs
Antivirus
Labels
Packed Malware_Binary Unpacked egg.exe
Unpacked egg.asm
Packer PEID
Data Strings
Syscall Trace
T:11:28:00 WinXP 109.86.228.117 (JWS.COM):
EU-ZZ,
UK. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 43 fb486908b0
NEW
none[none] none:none
none|none none none
T:11:30:00 WinXP 216.171.25.85 (PAVLOVMEDIA.COM):
88 WEST,
CHAMPAIGN, ILLINOIS, US. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
40 of 41 1096ba143e
NEW
none[none] none:none
none|none none none
T:11:34:00 WinXP 46.109.103.120 (-):
.
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 1.3
profile
none summary
tarball
39 of 43 7047b7ed15
NEW
none[none] none:none
none|none none none
T:11:57:00 WinXP 211.170.191.132, 222.170.127.203 (INVALID IPV4 ADDRESS):
INVALID IPV4 ADDRESS,
INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS, INVALID IPV4 ADDRESS. (INVALID IPV4 ADDRESS)
83.133.119.197:65520 DE:proxim.ircgalaxy.pl
US:microsoft.com
CN:lb.perfectexe.com
CN:boob.perfectexe.com
CN:2b.perfectexe.com
CN:hn.yigeyuming.com
:a.95622.com
:1.95622.com
:nationalizedbank.com
US:i.nuseek.com
:search.dmtracker.com
69.64.154.211:80
135 pcap raw alerts
ruleset
irc
http
152 lines
Yeah : 1.8
profile
none summary
tarball
37 of 43
28 of 42
29 of 43
41 of 43
32 of 36
35 of 36
44ad2dca6e
NEW
8809b6417c
NEW
b34e640329
NEW
b4afa1df1d
NEW
bea8cb1865
NEW
fac78fde16
NEW
none[none]
none [none]
none [none]
none [none]
154de51a66[0]
882896ab05[0]
none:none
none:none
none:none
none:none
ASM:Graph
ASM:Graph
none|none
none|none
none|none
none|none
Armadillo|
tElock|
none
none
none
none
lines=91
lines=126
embedded dns
none
none
none
none
trace
trace
T:11:59:00 WinXP 81.81.142.0 (WWW.E-COW.IT):
WIND TELECOMUNICAZIONI S.P.A,
ROME, LAZIO, IT. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
43 of 43 60f180249a
NEW
none[none] none:none
none|none none none
T:12:08:00 Win2K-f 173.31.98.3 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
MIDDLETOWN, NEW YORK, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 42
40 of 43
1bafff1e61
NEW
8511a51872
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:12:13:00 Win2K-f 24.32.218.204 (CEBRIDGE.NET):
CEBRIDGE CONNECTIONS,
OKLAHOMA CITY, OKLAHOMA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:12:29:00 WinXP 46.109.163.134 (-):
.
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
42 of 43 2c94e3fd00
NEW
none[none] none:none
none|none none none
12:30:00 WinXP 180.177.116.235 (-):
.
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
42 of 43 622f232702
NEW
none[none] none:none
none|none none none
T:12:35:00 Win2K-f 72.43.62.30 (RR.COM):
ROAD RUNNER HOLDCO LLC,
NEW YORK, NEW YORK, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 41
38 of 41
d031b42d3f
NEW
fa14802705
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:12:51:00 WinXP 164.132.134.144 (-):
IUNET S.P.A,
MILANO, LOMBARDIA, IT. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
43 of 43 60f180249a
NEW
none[none] none:none
none|none none none
T:12:55:00 Win2K-f 210.166.24.75 (CTT.NE.JP):
CABLE TELEVISION TOYAMA INCORPORETED,
TOYAMA, TOYAMA, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 43
41 of 43
95173a796c
NEW
c2f1f7d01e
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:13:08:00 Win2K-f 173.200.73.19 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:13:22:00 WinXP 64.179.173.118 (IW.NET):
PRAIRIEWAVE CABLE MODEM DHCP,
YANKTON, SOUTH DAKOTA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
38 of 40
38 of 40
67f1a33096
NEW
724cf0dc37
NEW
148e04eaab [0]
901dd267d4[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:13:40:00 WinXP 72.251.104.204 (1DIAL.COM):
AD-BASE SYSTEMS INC. (DBA GLOBALPOPS),
PITTSBURGH, PENNSYLVANIA, US. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
43 of 43 2b314ef150
NEW
none[none] none:none
none|none none none
T:13:45:00 Win2K-f 50.80.208.131 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41
38 of 41
692f9bb8df
NEW
d482a2bec3
NEW
2bf6f4e9f0 [0]
50a83c6b54[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:13:53:00 Win2K-f 211.20.8.211 (-):
LONG-YAW-CO.-TP-NET,
TAIPEI, T'AI-PEI, TW. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
40 of 43
5d445c59d8
NEW
9611f159ad
NEW
892e12db7b [0]
none [none]
ASM:Graph
none:none
tElock|
none|none
lines=64
embedded dns
none
trace
none
T:13:54:00 Win2K-f 24.43.40.80 (RR.COM):
ROAD RUNNER HOLDCO LLC,
LOS ANGELES, CALIFORNIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
158 lines
Yeah : 1.3
profile
none summary
tarball
37 of 41 51a03793ab
NEW
429f7618d3 [0] ASM:Graph
none|none lines=546 trace
14:38:00 Win2K-f 59.144.174.74 (59.AIRTELBROADBAND.IN):
ABTS-DSL-DEL,
NEW DELHI, DELHI, IN. (DSL)
n/a US:www.maxmind.com
EU:checkip.dyndns.org
445 pcap raw alerts
ruleset
http
14 lines
Yeah : 0.8
profile
none summary
tarball
3 of 37 d9cb288f31
NEW
45603a001c [0] ASM:Graph
UPX| lines=174
embedded dns
trace
T:14:40:00 WinXP 67.230.15.50 (INTELNET.NET.GT):
TELGUA,
GUATEMALA, GUATEMALA, GT. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
42 of 43 5f7781745b
NEW
none[none] none:none
none|none none none
T:14:47:00 Win2K-f 59.144.174.74 (59.AIRTELBROADBAND.IN):
ABTS-DSL-DEL,
NEW DELHI, DELHI, IN. (DSL)
n/a US:www.maxmind.com
EU:getmyip.co.uk
US:www.vouchercodes.net
445 pcap raw alerts
ruleset
http
1020 lines
Yeah : 0.8
profile
none summary
tarball
0 of 43
3 of 37
510203b0e0
NEW
d9cb288f31
NEW
none[none]
45603a001c[0]
none:none
ASM:Graph
none|none
UPX|
none
lines=174
embedded dns
none
trace
T:14:59:00 WinXP 119.150.234.86 (YOURNET.NE.JP):
FREEBIT CO. LTD,
TOKYO, TOKYO, JP. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
43 of 43 c8a7a509aa
NEW
none[none] none:none
none|none none none
T:15:07:00 WinXP 67.14.211.51 (ARTELCO.COM):
WORLD LYNX,
MAGAZINE, ARKANSAS, US. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 1.3
profile
none summary
tarball
41 of 42 ff90c1ff00
NEW
none[none] none:none
none|none none none
T:15:09:00 WinXP 24.29.229.55 (RR.COM):
ROAD RUNNER HOLDCO LLC,
KENT, OHIO, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
76 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:15:12:00 Win2K-f 184.74.71.220 (-):
.
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:16:05:00 WinXP 74.60.113.36 (CLEARWIRE-DNS.NET):
CLEARWIRE US LLC,
CHICAGO, ILLINOIS, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
16:07:00 WinXP 74.60.113.36 (CLEARWIRE-DNS.NET):
CLEARWIRE US LLC,
CHICAGO, ILLINOIS, US. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:16:47:00 WinXP 70.74.228.35 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
EDMONTON, ALBERTA, CA. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:17:10:00 WinXP 98.141.163.84 (CAVTEL.NET):
CAVALIER TELEPHONE,
PHILADELPHIA, PENNSYLVANIA, US. (DSL)
n/a   135 pcap raw alerts
ruleset
other
18 lines
Yeah : 1.3
profile
none summary
tarball
none none none none none none none
T:17:46:00 Win2K-f 118.83.2.176 (HTOJ.J-CNET.JP):
JCN-HTMNET,
HACHIOJI, TOKYO, JP. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
122 lines
Yeah : 1.3
profile
none summary
tarball
32 of 36
34 of 36
0b951c2832
NEW
e4ed4df0f0
NEW
5fe761661a [0]
de471fc380[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:18:10:00 Win2K-f 4.224.141.193 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
INDIANAPOLIS, INDIANA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
97 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:16:00 WinXP 96.48.62.2 (SHAWCABLE.NET):
SHAW COMMUNICATIONS INC,
MAPLE RIDGE, BRITISH COLUMBIA, CA. (DSL)
n/a :gg.arrancar.org 135 pcap raw alerts
ruleset
other
187 lines
Yeah : 1.3
profile
none summary
tarball
32 of 33 fc3b28a022
NEW
none[none] none:none
none|none none none
T:18:17:00 WinXP 123.194.162.142 (KBRONET.COM.TW):
TUNG HO MULTIMEDIA CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:moscow-advokat.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 43 04d4170d3b
NEW
none[none] none:none
none|none none none
T:18:28:00 WinXP 211.23.226.98 (-):
LIOU-TZUNG-YI-TC,
TAIPEI, T'AI-PEI, TW. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
37 of 40
5d445c59d8
NEW
8a54950abb
NEW
892e12db7b [0]
f6b9e43917[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=64
embedded dns
lines=91
trace
trace
T:18:34:00 Win2K-f 208.88.70.103 (-):
BBW 4 ACES TOWER CUSTOMER SUBNET,
SHREVEPORT, LOUISIANA, US. (100Mbps)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
78 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:42:00 WinXP 67.76.44.26 (EMBARQHSD.NET):
EMBARQ CORPORATION,
SEATTLE, WASHINGTON, US. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
29 of 29 986b59708d
NEW
none[0] none:none
PolyEnE| lines=57 trace
T:18:45:00 Win2K-f 70.64.3.116 (GASOC.COM):
SHAW COMMUNICATIONS INC,
SASKATOON, SASKATCHEWAN, CA. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 32
53bfe15e91
NEW
73f1082158
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:18:45:00 WinXP 118.233.193.153 (KBRONET.COM.TW):
TUNG HO MULTIMEDIA CO. LTD,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a DE:citi-bank.ru
:www.kelesoglugroup.com
:bleublanc.net
TH:kabinburi.ac.th
GR:bilimegitim.org
BR:juvenopolis.org.br
:buyukkarapinar.com
EU:karenoil.com
:cajovnanazemi.cz
**:beautiful-shop.rv.ua
US:cannabisverificationcenter.com
:clinicadematematica.com.br
US:construindia.com
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
41 of 43 d3e75ed535
NEW
none[none] none:none
none|none none none
T:19:03:00 WinXP 148.210.134.28 (NETDNS2.UACJ.MX):
UNIVERSIDAD AUTONOMA DE CIUDAD JUAREZ,
MX. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:19:03:00 WinXP 4.224.135.80 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
SOUTH BEND, INDIANA, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
155 lines
Yeah : 1.3
profile
none summary
tarball
35 of 41
38 of 43
4c339df01b
NEW
dafef3098c
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:19:25:00 WinXP 186.184.233.36 (-):
.
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
38 of 43 6753eafdbe
NEW
none[none] none:none
none|none none none
T:19:38:00 WinXP 74.60.113.36 (CLEARWIRE-DNS.NET):
CLEARWIRE US LLC,
CHICAGO, ILLINOIS, US. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
32 of 32 b502f83a7c
NEW
28f5be93b0 [0] ASM:Graph
PolyEnE| lines=73 trace
T:19:46:00 Win2K-f 4.227.248.167 (LEVEL3.NET):
LEVEL 3 COMMUNICATIONS INC,
DENVER, COLORADO, US. (DIAL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
141 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:19:51:00 WinXP 121.121.246.224 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
40 of 42 de4624560d
NEW
none[none] none:none
none|none none none
T:19:53:00 Win2K-f 24.106.163.138 (RR.COM):
ROAD RUNNER HOLDCO LLC,
COLUMBUS, OHIO, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41
39 of 41
0563ea7af7
NEW
7e1532574f
NEW
bc2e11a802 [0]
e6930769d0[0]
ASM:Graph
ASM:Graph
tElock|
Armadillo|
lines=65
embedded dns
lines=91
trace
trace
T:20:16:00 Win2K-f 71.154.12.98 (SBCGLOBAL.NET):
AT&T INTERNET SERVICES,
DALLAS, TEXAS, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
75 lines
Yeah : 1.3
profile
none summary
tarball
33 of 33
0 of 33
53bfe15e91
NEW
a08f3b74a4
NEW
1473091351 [0]
none [0]
ASM:Graph
none:none
tElock|
Armadillo|
lines=75
embedded dns
lines=90
trace
trace
T:20:21:00 WinXP 178.167.199.18 (FINEBLANK.COM):
EU-ZZ,
UK. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
20:30:00 WinXP 121.121.246.224 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
42 of 43 ac0d8a91cb
NEW
none[none] none:none
none|none none none
T:20:33:00 Win2K-f 60.250.36.114 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
34 of 38
35 of 38
38ed850a0e
NEW
b9297745a1
NEW
46990f37cd [0]
4294884d84[0]
ASM:Graph
ASM:Graph
Armadillo|
tElock|
lines=91
lines=64
embedded dns
trace
trace
T:20:37:00 WinXP 121.121.129.37 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
3 lines
Yeah : 1.3
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:20:48:00 WinXP 186.184.237.166 (-):
.
213.155.0.224:80 DE:citi-bank.ru
:althawry.org
:www.careerdesk.org
:arthur.niria.biz
:amsamex.com
:apple-pie.in
:ahmediye.net
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
38 of 43 6753eafdbe
NEW
none[none] none:none
none|none none none
T:20:48:00 WinXP 210.209.143.127 (TCOL.COM.TW):
MONAD DIGITNAMIC CORP,
TAIPEI, T'AI-PEI, TW. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
39 of 41 866ac9b262
NEW
none[none] none:none
none|none none none
T:21:18:00 Win2K-f 173.168.182.128 (RR.COM):
ROAD RUNNER HOLDCO LLC,
OLDSMAR, FLORIDA, US. (DSL)
n/a US:microsoft.com 135 pcap raw alerts
ruleset
other
110 lines
Yeah : 1.3
profile
none summary
tarball
40 of 41
40 of 40
1761e9db94
NEW
d1e83e2d0a
NEW
none[none]
none [none]
none:none
none:none
none|none
none|none
none
none
none
none
T:21:20:00 WinXP 14.99.65.221 (-):
.
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:21:25:00 WinXP 70.45.233.87 (METROCAST.NET):
SAN JUAN CABLE LLC,
SAN JUAN, PUERTO RICO, PR. (DSL)
n/a DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:21:45:00 WinXP 121.123.3.103 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
2 lines
Yeah : 0.8
profile
none summary
tarball
42 of 43 af29b1f33c
NEW
none[none] none:none
none|none none none
22:52:00 WinXP 121.123.3.103 (MAXIS.NET.MY):
MAXIS BROADBAND SDN BHD,
KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL)
n/a   445 pcap raw alerts
ruleset
other
0 lines
Argh : 0.3
profile
none summary
tarball
none none none none none none none
22:57:00 WinXP 173.21.55.193 (MCHSI.COM):
MEDIACOM COMMUNICATIONS CORP,
COLUMBUS, GEORGIA, US. (DSL)
n/a DE:citi-bank.ru
DE:213.155.0.224:80
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
26 of 28 7d99b0e910
NEW
none[0] none:none
PolyEnE| lines=68 trace
T:23:21:00 WinXP 114.40.218.204 (HINET.NET):
CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP,
TAIPEI, T'AI-PEI, TW. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
41 of 43 fb486908b0
NEW
none[none] none:none
none|none none none
T:23:27:00 WinXP 14.96.195.229 (-):
.
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
34 of 34 d20f157117
NEW
738f555183 [0] ASM:Graph
PolyEnE| lines=68 trace
T:23:40:00 WinXP 59.103.210.3 (PIE.NET.PK):
PAKISTAN TELECOMMUNICATION COMPANY LIMITED,
ISLAMABAD, ISLAMABAD, PK. (DSL)
213.155.0.224:80 DE:citi-bank.ru 445 pcap raw alerts
ruleset
http
2 lines
Yeah : 1.3
profile
none summary
tarball
38 of 43 0ac5562cc6
NEW
none[none] none:none
none|none none none
23:56:00 WinXP 174.42.189.102 (WINDSTREAM.NET):
ALLTEL MIP CUSTOMERS - WARRENSVILLE HEIGHTS,
SALISBURY, NORTH CAROLINA, US. (DSL)
n/a DE:moscow-advokat.ru
DE:82.98.86.164:6667
445 pcap raw alerts
ruleset
http
1 line
Yeah : 0.8
profile
none summary
tarball
none f13860c2c4
NEW
none[none] none:none
none|none none none