Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
00:06:00 | WinXP | 151.20.163.98 (20-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, BOLOGNA, EMILIA-ROMAGNA, IT. (DIAL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:00:11:00 | WinXP | 114.51.80.32 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | c116e6a741 NEW |
none[none] | none:none |
none|none | none | none | |
01:19:00 | Win2K-f | 111.252.209.140 (-): . |
n/a | US:www.maxmind.com EU:getmyip.co.uk US:www.vouchercodes.net DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 1006 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:01:25:00 | WinXP | 111.255.135.119 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:01:46:00 | WinXP | 121.121.40.116 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | 2c94e3fd00 NEW |
none[none] | none:none |
none|none | none | none |
T:02:26:00 | WinXP | 188.176.69.167 (DSL.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | b502f83a7c NEW |
28f5be93b0 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:02:58:00 | WinXP | 98.124.108.75 (HOMESC.COM): HOME TELEPHONE COMPANY INC, MONCKS CORNER, SOUTH CAROLINA, US. (100Mbps) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:03:36:00 | Win2K-f | 122.149.70.186 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 38 of 41 |
e45dbd676e NEW e6047c4e0c NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:04:56:00 | WinXP | 115.117.144.236 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, IN. (100Mbps) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:05:35:00 | WinXP | 111.248.167.50 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:06:07:00 | WinXP | 186.25.161.244 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 43 | 6753eafdbe NEW |
none[none] | none:none |
none|none | none | none |
T:06:14:00 | WinXP | 59.161.114.136 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, NEW DELHI, DELHI, IN. (DIAL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
06:29:00 | WinXP | 113.36.132.228 (UCOM.NE.JP): UCOM CORP, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 0f77d6439f NEW |
none[none] | none:none |
none|none | none | none |
T:06:33:00 | Win2K-f | 220.128.218.212 (HINET.NET): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 none |
2bc8f15054 NEW 964911406f NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:06:33:00 | WinXP | 83.97.155.11 (CM-83-97-159-10.TELECABLE.ES): TELECABLE, BARCELONA, CATALONIA, ES. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:06:59:00 | WinXP | 83.58.15.240 (RIMA-TDE.NET): TELEFONICA DE ESPANA(NCC#2005070725), SEVILLA, ANDALUCIA, ES. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 420b1a76c4 NEW |
none[none] | none:none |
none|none | none | none |
T:07:16:00 | Win2K-f | 65.50.34.15 (BILTMORECOMMUNICATIONS.NET): DIRECPATH LLC, ATLANTA, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 37 of 40 |
5d445c59d8 NEW 8a54950abb NEW |
892e12db7b [0] f6b9e43917[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:07:25:00 | WinXP | 111.188.171.205 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
83.133.119.197:65520 | CN:proxim.ircgalaxy.pl US:mx1.hotmail.com US:mailin-03.mx.aol.com :ftp.icq.com **:yutunrz.1dumb.com **:mcduii.3-a.net US:mailin-02.mx.aol.com :jdjsloy.dynserv.com CN:88.perfectexe.com **:wyqggvow.afraid.org **:nttstziinpa.hn.org US:fcnhysydw.yi.org DE:citi-bank.ru **:dlivmg.1dumb.com **:neytteybbo.3-a.net :fzzdik.dynserv.com :pkvgzaecagx.afraid.org **:yraqztt.hn.org US:143.215.15.60:80 CN:218.10.17.178:88 US:64.12.90.33:25 |
445 | pcap | raw alerts ruleset |
http irc http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 | a3a45a2597 NEW |
none[none] | none:none |
none|none | none | none |
T:08:04:00 | WinXP | 186.180.100.93 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:08:25:00 | WinXP | 61.227.187.146 (PRESTONAUTO.COM): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | fa18d66b7d NEW |
none[none] | none:none |
none|none | none | none |
T:08:37:00 | WinXP | 121.121.242.139 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 24137d8412 NEW |
73a916deb4 [0] | none:none |
PolyEnE| | none | trace | |
T:08:43:00 | WinXP | 93.102.173.54 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
08:44:00 | Win2K-f | 203.76.139.235 (-): HCL, BANGALORE, KARNATAKA, IN. (100Mbps) |
n/a | US:www.maxmind.com EU:checkip.dyndns.org DE:131.220.6.26:80 |
445 | pcap | raw alerts ruleset |
http 5 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:08:44:00 | Win2K-f | 123.195.251.36 (KBRONET.COM.TW): TUNG HO MULTIMEDIA CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:06:00 | WinXP | 69.26.16.247 (WESTRIV.COM): WEST RIVER TELECOMMUNICATIONS, HAZEN, NORTH DAKOTA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 46112c6cd7 NEW |
none[none] | none:none |
none|none | none | none |
T:09:08:00 | WinXP | 180.69.231.205 (-): HANARO TELECOM, SEOUL, SEOUL-T'UKPYOLSI, KR. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 131 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 42 |
14f47ffd1e NEW 6a73d63341 NEW |
90bf4b99ff [0] none [none] |
ASM:Graph none:none |
tElock| none|none |
lines=56 embedded dns none |
trace none |
T:09:11:00 | WinXP | 111.188.155.68 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 | dc467897c8 NEW |
none[none] | none:none |
none|none | none | none |
T:09:14:00 | Win2K-f | 65.31.49.154 (RR.COM): ROAD RUNNER HOLDCO LLC, SPRINGFIELD, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:09:15:00 | WinXP | 114.48.29.251 (E-MOBILE.NE.JP): EMOBILE LTD, KAWASAKI, KANAGAWA, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | 729d50c7a5 NEW |
none[none] | none:none |
none|none | none | none | |
T:09:26:00 | Win2K-f | 64.179.204.127 (SPEAKEASY.NET): ALTAMONTE SPRINGS, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 440 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 42 | 0e31a4cd01 NEW |
none[none] | none:none |
none|none | none | none | |
T:09:37:00 | WinXP | 27.97.78.128 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:09:46:00 | WinXP | 204.111.187.102 (SHENTEL.NET): SHENTEL SERVICE COMPANY, BLACKSBURG, VIRGINIA, US. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:10:02:00 | WinXP | 206.246.4.47 (OLEMAC.NET): MCDONALD COUNTY INTERNET, NEW YORK, NEW YORK, US. (DSL) |
n/a | DE:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
T:10:11:00 | Win2K-f | 112.140.16.50 (T-COM.NE.JP): TOKAI CORPORATION, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 40 of 43 |
284980cc88 NEW 9ebe7df19f NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:10:58:00 | WinXP | 81.198.141.42 (-): ADDRESS POOL FOR LTC-HOME CUSTOMERS, RIGA, RIGA, LV. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 41 | 9d38d43309 NEW |
none[none] | none:none |
none|none | none | none |
T:11:10:00 | WinXP | 124.44.185.9 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), HACHIOJI, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | c66d771507 NEW |
none[none] | none:none |
none|none | none | none | |
11:32:00 | WinXP | 178.167.143.242 (FINEBLANK.COM): EU-ZZ, UK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 40 | dc467897c8 NEW |
none[none] | none:none |
none|none | none | none |
11:33:00 | Win2K-f | 203.76.139.235 (-): HCL, BANGALORE, KARNATAKA, IN. (100Mbps) |
n/a | US:www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org US:208.43.124.51:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:11:49:00 | WinXP | 85.64.39.80 (BARAK-ONLINE.NET): BARAK I.T.C, JERUSALEM, YERUSHALAYIM, IL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 0f77d6439f NEW |
none[none] | none:none |
none|none | none | none |
T:12:25:00 | WinXP | 61.89.242.85 (KCN.NE.JP): KINTETSU CABLE NETWORK LTD, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 43 40 of 43 |
b0290639db NEW b66ca7bc34 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:12:29:00 | WinXP | 65.31.49.154 (RR.COM): ROAD RUNNER HOLDCO LLC, SPRINGFIELD, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:12:30:00 | WinXP | 111.188.37.132 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:13:55:00 | WinXP | 187.80.34.154 (CAMPUSEAI.ORG): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 43 | d24e438fc9 NEW |
none[none] | none:none |
none|none | none | none |
T:15:52:00 | WinXP | 186.40.200.78 (-): . |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 9df76ecb4a NEW |
none[none] | none:none |
none|none | none | none |
T:16:06:00 | WinXP | 95.247.142.3 (BUSINESS.TELECOMITALIA.IT): TELECOM ITALIA WIRELINE SERVICES, ROME, LAZIO, IT. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
14 of 42 | 26307edf36 NEW |
none[none] | none:none |
none|none | none | none | |
T:16:06:00 | WinXP | 190.227.138.235 (NET.AR): TELECOM PERSONAL BS AS, AR. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | f2f3d8239c NEW |
none[none] | none:none |
none|none | none | none |
T:17:21:00 | WinXP | 93.102.173.105 (REV.OPTIMUS.PT): OPTIMUS PORTUGAL, PT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
18:07:00 | Win2K-f | 210.212.213.82 (-): THE TRANSPORT COMMISSIONER, HYDERABAD, ANDHRA PRADESH, IN. (100Mbps) |
n/a | US:www.maxmind.com EU:getmyip.co.uk :checkip.dyndns.org US:208.43.124.51:80 EU:78.40.35.134:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
3 of 37 | d9cb288f31 NEW |
45603a001c [0] | ASM:Graph |
UPX| | lines=174 embedded dns |
trace |
T:19:52:00 | WinXP | 190.58.5.21 (TSTT.NET.TT): TELECOMMUNICATION SERVICES OF TRINIDAD AND TOBAGO, TT. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:20:03:00 | WinXP | 183.82.226.81 (-): . |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 42 | 33ffb2cb88 NEW |
none[none] | none:none |
none|none | none | none |
T:20:06:00 | Win2K-f | 69.193.78.147 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:30:00 | WinXP | 85.64.39.80 (BARAK-ONLINE.NET): BARAK I.T.C, JERUSALEM, YERUSHALAYIM, IL. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 0f77d6439f NEW |
none[none] | none:none |
none|none | none | none |
21:41:00 | WinXP | 190.58.5.21 (TSTT.NET.TT): TELECOMMUNICATION SERVICES OF TRINIDAD AND TOBAGO, TT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:22:33:00 | WinXP | 27.54.19.67 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 43 | 9628f8fb6e NEW |
none[none] | none:none |
none|none | none | none | |
T:22:42:00 | WinXP | 4.224.141.132 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |
22:52:00 | WinXP | 190.58.0.107 (TSTT.NET.TT): TELECOMMUNICATION SERVICES OF TRINIDAD AND TOBAGO, SAN FERNANDO, SAN FERNANDO, TT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:23:07:00 | WinXP | 112.78.67.155 (-): VIBO TELECOM INC, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | c049e988f2 NEW |
none[none] | none:none |
none|none | none | none |
T:23:11:00 | Win2K-f | 66.60.106.38 (FIRSTDIGITAL.COM): FIRSTDIGITAL COMMUNICATIONS LLC, ROSEVILLE, CALIFORNIA, US. (100Mbps) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:23:20:00 | Win2K-f | 98.103.22.25 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 42 37 of 41 |
359d245014 NEW 3d25e55087 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
23:20:00 | WinXP | 112.78.67.155 (-): VIBO TELECOM INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | c049e988f2 NEW |
none[none] | none:none |
none|none | none | none |
T:23:47:00 | WinXP | 113.10.95.221 (-): STARHUB HSDPA SG, SG. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
23:58:00 | WinXP | 4.224.141.132 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, INDIANAPOLIS, INDIANA, US. (DIAL) |
n/a | DE:moscow-advokat.ru DE:82.98.86.164:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c NEW |
none[0] | none:none |
PolyEnE| | lines=93 embedded dns |
trace |