Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:01:02:00 | WinXP | 124.241.169.210 (STARCAT.NE.JP): KMN CORPORATION, NAGOYA, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 40 39 of 39 |
b8e6f4caf7 NEW fb92b91fe7 NEW |
f81eac6379 [0] fe88ab8768[0] |
none:none none:none |
tElock| Armadillo| |
none none |
trace trace |
T:01:51:00 | Win2K-f | 115.165.71.28 (CATV02.ITSCOM.JP): ITS COMMUNICATIONS INC, YOKOHAMA, KANAGAWA, JP. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:02:01:00 | WinXP | 121.121.245.46 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:02:17:00 | WinXP | 91.65.49.33 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, BERLIN, BERLIN, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 39262275d2 NEW |
none[none] | none:none |
none|none | none | none | |
T:02:23:00 | WinXP | 218.20.70.2 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:02:43:00 | Win2K-f | 211.75.159.211 (KENNY.COM.TW): CHUNGHWA TELECOM DATA COMMUNICATION BUSINESS GROUP, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:03:09:00 | WinXP | 213.109.225.38 (IPAPER.COM): BLOCK FOR PI ASSIGNMENTS, GLASGOW, SCOTLAND, UK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
38 of 42 | 0d1eb4df79 NEW |
none[none] | none:none |
none|none | none | none |
T:04:16:00 | WinXP | 139.55.175.178 (WINDSTREAM.NET): WINDSTREAM COMMUNICATIONS INC, LINCOLN, NEBRASKA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:05:03:00 | WinXP | 95.83.195.202 (-): O2 IRELAND MOBILE BROADBAND OPEN.INTERNET APN, DUBLIN, DUBLIN, IE. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
43 of 43 | 10f8c24609 NEW |
none[none] | none:none |
none|none | none | none |
T:05:06:00 | Win2K-f | 65.110.121.204 (WESTPA.NET): WESTPANET INC, WARREN, PENNSYLVANIA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 186 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | 0afff56a4c NEW |
none[none] | none:none |
none|none | none | none | |
T:05:11:00 | WinXP | 160.80.101.105 (NET.UNIROMA2.IT): UNIVERSITA' DEGLI STUDI DI ROMA 'TOR VERGATA', ROME, LAZIO, IT. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | c049e988f2 NEW |
none[none] | none:none |
none|none | none | none |
T:05:20:00 | WinXP | 151.20.166.62 (20-151.LIBERO.IT): FREE INTERNET DIAL-UP SERVICES, BOLOGNA, EMILIA-ROMAGNA, IT. (DIAL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:05:29:00 | Win2K-f | 203.190.146.55 (SOFT.NET): SOFTWARE TECHNOLOGY PARKS OF INDIA, NEW DELHI, DELHI, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
2fc89991b2 NEW 7bdf45b79a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
05:49:00 | WinXP | 88.7.251.182 (RIMA-TDE.NET): TELEFONICA DE ESPANA, BILBAO, PAIS VASCO, ES. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
42 of 43 | 420b1a76c4 NEW |
none[none] | none:none |
none|none | none | none |
T:05:59:00 | WinXP | 217.17.100.157 (-): CS-SAT-TRAKT, CS. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
34 of 34 | d20f157117 NEW |
738f555183 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
T:06:09:00 | Win2K-f | 175.112.120.207 (-): . |
83.133.119.197:65520 | DE:proxim.ircgalaxy.pl US:microsoft.com EU:ii.kakgezaebalsha.com CN:88.perfectexe.com CN:w.perfectexe.com CN:ck.perfectexe.com :showlease.com CN:s5.perfectexe.com US:i.nuseek.com :www.google-analytics.com :pagead2.googlesyndication.com US:mapsegypt.com US:64.74.223.141:80 |
135 | pcap | raw alerts ruleset |
irc http 239 lines |
Yeah : 1.8 profile |
none | summary tarball |
22 of 41 27 of 40 36 of 42 9 of 42 38 of 42 21 of 42 |
46db4a2874 NEW 6dc0a90bf4 NEW bf063bba17 NEW e4240d7958 NEW f269760f66 NEW ff7a9d9404 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none |
none none none none none none |
none none none none none none |
06:28:00 | Win2K-f | 194.225.115.82 (-): IRAN POLYMER INSTITUTE, TEHRAN, ESFAHAN, IR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
http 12 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:06:31:00 | Win2K-f | 122.49.244.141 (CCNET-AI.NE.JP): COMMUNITY NETWORK CENTER INC, TOYOKAWA, AICHI, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 NEW |
none[0] 1473091351[0] |
none:none ASM:Graph |
Armadillo| tElock| |
lines=90 lines=75 embedded dns |
trace trace |
T:06:40:00 | Win2K-f | 92.86.70.63 (TELELINK-RO.COM): ARTELECOM, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:microsoft.com :a.95622.com US:autoairlines.net CN:w.perfectexe.com US:zoo.parkingspa.com DE:proxim.ircgalaxy.pl :1.95622.com CN:2b.yigeyuming.com CN:60.190.222.139:65520 CN:60.190.223.75:10167 |
445 | pcap | raw alerts ruleset |
http irc 51 lines |
Argh : 0.3 profile |
none | summary tarball |
29 of 43 | b34e640329 NEW |
none[none] | none:none |
none|none | none | none |
T:07:05:00 | WinXP | 204.111.25.44 (SHENTEL.NET): SHENTEL SERVICE COMPANY, EDINBURG, VIRGINIA, US. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | 1096ba143e NEW |
none[none] | none:none |
none|none | none | none |
T:07:11:00 | WinXP | 98.124.88.6 (HOMESC.COM): HOME TELEPHONE COMPANY INC, MONCKS CORNER, SOUTH CAROLINA, US. (100Mbps) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 40 | d6997f4bc2 NEW |
none[none] | none:none |
none|none | none | none |
T:07:17:00 | WinXP | 151.60.237.234 (51-151.NET24.IT): IUNET-BNET, ROME, LAZIO, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 | 94e76c7ef4 NEW |
none[none] | none:none |
none|none | none | none |
T:07:21:00 | WinXP | 111.80.87.61 (HINET.NET): MOBILE BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:07:49:00 | WinXP | 111.188.153.193 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
42 of 42 | d454604121 NEW |
none[none] | none:none |
none|none | none | none |
T:07:54:00 | WinXP | 122.148.204.134 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:08:02:00 | Win2K-f | 203.196.72.251 (KAGACABLE.NE.JP): KAGA CABLE TELEVISION CO.LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
2fc89991b2 NEW 7bdf45b79a NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:08:09:00 | WinXP | 114.48.28.138 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
37 of 40 | 5285741560 NEW |
60590b8b67 [0] | ASM:Graph |
none|none | lines=59 | trace | |
T:09:35:00 | WinXP | 221.241.116.88 (UCOM.NE.JP): POWERBAND INC, TOKYO, TOKYO, JP. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
41 of 43 | fb486908b0 NEW |
none[none] | none:none |
none|none | none | none |
T:10:28:00 | Win2K-f | 24.155.168.155 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS, ARLINGTON, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:10:38:00 | WinXP | 151.83.108.210 (SER-PR2-MAX.IUNET.IT): INFOSTRADA, IT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:11:16:00 | WinXP | 24.103.10.122 (RR.COM): ROAD RUNNER HOLDCO LLC, NEW YORK, NEW YORK, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
T:11:26:00 | WinXP | 114.198.164.114 (-): GLOBALVIEW CATV CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
42 of 43 | ef96217736 NEW |
none[none] | none:none |
none|none | none | none |
T:11:33:00 | WinXP | 70.70.154.75 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, SURREY, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 1006 lines |
Yeah : 1.3 profile |
none | summary tarball |
36 of 42 | 0dcdae6890 NEW |
none[none] | none:none |
none|none | none | none | |
T:11:43:00 | WinXP | 119.154.78.37 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, LAHORE, PUNJAB, PK. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 39262275d2 NEW |
none[none] | none:none |
none|none | none | none |
T:11:45:00 | Win2K-f | 65.50.34.15 (BILTMORECOMMUNICATIONS.NET): DIRECPATH LLC, ATLANTA, GEORGIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 37 of 40 |
5d445c59d8 NEW 8a54950abb NEW |
892e12db7b [0] f6b9e43917[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
12:10:00 | WinXP | 119.154.78.37 (PIE.NET.PK): PAKISTAN TELECOMMUNICATION COMPANY LIMITED, LAHORE, PUNJAB, PK. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 41 | 39262275d2 NEW |
none[none] | none:none |
none|none | none | none |
T:12:37:00 | Win2K-f | 27.98.36.202 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 39 of 41 |
5799ab6538 NEW f38e8d97da NEW |
2713679411 [0] 83f1400243[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
T:13:24:00 | WinXP | 98.190.183.102 (COX.NET): COX COMMUNICATIONS, GAINESVILLE, FLORIDA, US. (DSL) |
83.133.119.197:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com CN:88.perfectexe.com EU:kakgezaebalsha.com CN:w.perfectexe.com CN:ck.perfectexe.com :drugcuring.com CN:s5.perfectexe.com US:i.nuseek.com :pagead2.googlesyndication.com :googleads.g.doubleclick.net US:modeljob.us US:searchportal.information.com US:208.73.210.125:80 EU:91.193.194.114:80 |
135 | pcap | raw alerts ruleset |
irc http 161 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 42 none 22 of 41 9 of 42 21 of 42 |
220c0b183d NEW 40a82f045f NEW 46db4a2874 NEW e4240d7958 NEW ff7a9d9404 NEW |
none[none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none none none |
T:14:01:00 | WinXP | 201.92.5.191 (STERLINGSTUDENTS.NET): COMITE GESTOR DA INTERNET NO BRASIL, BR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 13 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 NEW |
none[0] | none:none |
none|none | lines=60 | trace | |
T:14:14:00 | Win2K-f | 67.125.140.230 (PACBELL.NET): AT&T INTERNET SERVICES, FRESNO, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:14:19:00 | WinXP | 201.238.126.40 (TSTT.NET.TT): TELECOMMUNICATION SERVICES OF TRINIDAD AND TOBAGO, TT. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:14:28:00 | WinXP | 88.28.238.58 (RIMA-TDE.NET): TELEFONICA MOVILES ESPANA (NCC#2007041930), A CORUñA, GALICIA, ES. (DSL) |
n/a | RU:siliconfireware.ru RU:auction.nic.ru :www.google-analytics.com RU:domain-parking.ru :www.proxy-socks.net :wpad US:new.egg.com US:199.67.205.200:80 |
445 | pcap | raw alerts ruleset |
http http http http 41 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef NEW |
none[0] | none:none |
ASPack| | lines=281 embedded dns |
trace |
14:56:00 | WinXP | 121.120.137.42 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:15:37:00 | WinXP | 173.23.156.248 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, LEESBURG, INDIANA, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 NEW b7082104e4 NEW |
1473091351 [0] c5b49e7b82[0] |
ASM:Graph ASM:Graph |
tElock| tElock| |
lines=75 embedded dns lines=41 |
trace trace |
T:17:21:00 | Win2K-f | 173.200.73.19 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW a08f3b74a4 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:05:00 | WinXP | 219.127.8.182 (WAKWAK.NE.JP): XEPHION(NTT-ME CORPORATION), OKAYAMA, OKAYAMA, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 NEW |
none[0] | none:none |
none|none | lines=61 | trace | |
18:06:00 | WinXP | 92.251.227.174 (NETWORK-IE.NET): PROVIDER LOCAL REGISTRY, IE. (DSL) |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 NEW |
none[0] | none:none |
PolyEnE| | lines=68 | trace |
T:18:31:00 | WinXP | 65.31.49.154 (RR.COM): ROAD RUNNER HOLDCO LLC, SPRINGFIELD, OHIO, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 NEW 57ce4acac2 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:18:50:00 | WinXP | 211.133.210.239 (THN.NE.JP): TOKAI CORPORATION, JP. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
40 of 41 40 of 41 |
71e6f60517 NEW ab4e3226c4 NEW |
1ef1781501 [0] c2d0313e73[0] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=91 none |
trace trace |
19:21:00 | WinXP | 114.51.162.218 (E-MOBILE.NE.JP): EMOBILE LTD, TOKYO, TOKYO, JP. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
40 of 41 | d11b1f56f9 NEW |
none[none] | none:none |
none|none | none | none |
T:20:18:00 | Win2K-f | 121.246.187.130 (VSNL.NET.IN): INTERNET SERVICE PROVIDER, CALCUTTA, WEST BENGAL, IN. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 NEW 73f1082158 NEW |
1473091351 [0] none [0] |
ASM:Graph none:none |
tElock| Armadillo| |
lines=75 embedded dns lines=90 |
trace trace |
T:20:40:00 | Win2K-f | 98.175.173.224 (COX.NET): COX COMMUNICATIONS, OKLAHOMA CITY, OKLAHOMA, US. (DSL) |
83.133.119.197:65520 | EU:proxim.ircgalaxy.pl US:microsoft.com CN:88.perfectexe.com EU:kakgezaebalsha.com IT:mewgost.com CN:w.perfectexe.com CN:ck.perfectexe.com :casinosbig.com CN:s5.perfectexe.com US:i.nuseek.com :www.google-analytics.com IT:194.28.44.213:80 74.125.224.64:80 |
135 | pcap | raw alerts ruleset |
irc http 150 lines |
Yeah : 1.8 profile |
none | summary tarball |
39 of 42 none 22 of 41 29 of 43 33 of 42 9 of 42 21 of 42 |
220c0b183d NEW 40a82f045f NEW 46db4a2874 NEW 564048b35d NEW 5d6097956d NEW e4240d7958 NEW ff7a9d9404 NEW |
none[none] none [none] none [none] none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none none|none none|none |
none none none none none none none |
none none none none none none none |
T:20:47:00 | Win2K-f | 113.252.90.222 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. (DSL) |
n/a | :a.95622.com CA:highspeed4ginternet.com US:golfislam.com :cdn.dsultra.com 208.93.137.180:80 |
135 | pcap | raw alerts ruleset |
http irc 302 lines |
Yeah : 0.8 profile |
none | summary tarball |
18 of 41 16 of 41 19 of 42 35 of 42 |
51c413f474 NEW 9a93a3a549 NEW ac3bc57d0d NEW e87eeeabc4 NEW |
none[none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
T:21:29:00 | Win2K-f | 123.28.200.122 (LOCALHOST): VIETNAM POSTS AND TELECOMMUNICATIONS(VNPT), VN. (DSL) |
60.190.222.139:65520 | CN:ck.perfectexe.com :a.95622.com US:studentplaneticket.com :useraccounts.net CN:w.perfectexe.com IT:mewgost.com US:parklogic.com CN:proxim.ircgalaxy.pl US:i.nuseek.com :www.google-analytics.com CN:2b.yigeyuming.com EU:kakgezaebalsha.com US:airlinebuy.com CN:88.perfectexe.com :techpopular.com 69.64.147.243:80 |
445 | pcap | raw alerts ruleset |
http irc 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
22 of 41 | 46db4a2874 NEW |
none[none] | none:none |
none|none | none | none |
T:21:34:00 | WinXP | 121.120.41.67 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
T:21:39:00 | Win2K-f | 66.249.152.15 (DIGICELBROADBAND.COM): DIGICEL JAMAICA, MONTEGO BAY, SAINT JAMES, JM. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 39 35 of 38 |
2205443cc8 NEW b9297745a1 NEW |
04ce1ed773 [none] 4294884d84[0] |
none:none ASM:Graph |
none|none tElock| |
none lines=64 embedded dns |
none trace |
T:22:01:00 | WinXP | 24.155.231.159 (GRANDENETWORKS.NET): GRANDE COMMUNICATIONS SAN MARCOS, SAN MARCOS, TEXAS, US. (DSL) |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 41 38 of 41 |
d031b42d3f NEW fa14802705 NEW |
none[none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
T:22:43:00 | WinXP | 50.81.7.85 (-): . |
n/a | US:microsoft.com | 135 | pcap | raw alerts ruleset |
other 110 lines |
Yeah : 1.3 profile |
none | summary tarball |
38 of 40 38 of 40 |
474acf88e5 NEW 68f0c14692 NEW |
1f53944b24 [0] ccc1b24d53[0] |
ASM:Graph ASM:Graph |
tElock| Armadillo| |
lines=64 embedded dns lines=91 |
trace trace |
23:10:00 | WinXP | 1.114.115.26 (-): . |
n/a | DE:citi-bank.ru DE:213.155.0.224:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
41 of 42 | 69e7479380 NEW |
none[none] | none:none |
none|none | none | none |
T:23:27:00 | WinXP | 121.120.111.232 (MAXIS.NET.MY): MAXIS BROADBAND SDN BHD, KUALA LUMPUR, WILAYAH PERSEKUTUAN, MY. (DSL) |
213.155.0.224:80 | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
39 of 41 | d8040f84d4 NEW |
d683995e84 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |