Snort mailing list archives

Unknown EK

From: Community Proposed <lists () packetmail net>
Date: Tue, 2 Jul 2013 17:42:12 -0500

Unknown malvertising EK campaign isolated with and which pDNS shows pointed only to and respectively.  The PCRE produces a few benign false positives,
considering the cost/risk the PCRE is worth it.  Might be able to get away with
some proxy blocks on this one.  Popular hosts such as BBC are being used.

Global Hosts identified:

Global URLs identified:

regex((?-i)http:\/\/[^\x2f]+\/[a-z]{1,6}\d?\/[a-f0-9]{8,10}\.htm$)  Unknown EK
initial landing and stage-1

Validation, as well as hits, after expansion and contraction of search criteria
for this campaign :

select date_time, http_status, media_type, url_body_size, dest_ip, url,
url_referrer, user_agent
from webwasher_full where day>='2013-06-01' and http_status <> '407' and
(url rlike 'http:\\/\\/[^\\x2f]+\\/[a-z]{1,6}\\d?\\/[a-f0-9]{8}\\.htm$' or url
like '%/app.jar' or url like '%/cm2.jar' or dest_ip like '' or
dest_ip like '');

{See attached Unknown_EK.tsv please note HTTP Referers and UAs}

PCRE Validation
select date_time, http_status, media_type, url_body_size, dest_ip, url,
url_referrer, user_agent
from webwasher_full where day>='2013-06-01' and http_status <> '407' and
(url rlike 'http:\\/\\/[^\\x2f]+\\/[a-z]{1,6}\\d?\\/[a-f0-9]{8}\\.htm$');

{See attached PCRE_Validation.tsv please note HTTP Referers and UAs}

Looking at the PCAP {see attached} this signature may be good to match the
payload, but these signatures are untested and I am coming off a long day and
my eyes are shot.  They may need some TLC:

Unknown Malvertising Exploit Kit Hostile Jar pipe.class";
file_data; content:"PK"; depth:0; 
content:"|00|pipe.class"; fast_pattern; distance:0; 
content:"|00|inc.class"; distance:0; 
content:"|00|fdp.class"; distance:0; 
classtype:trojan-activity; sid:x; rev:1;)

Unknown Malvertising Exploit Kit stage-1 redirect";
content:"<html><body><script>|0a|var "; fast_pattern; 
content;"document.createElement("; within:80; 
content:".setAttribute(|22|archive|22|, "; within:65; 
content:".setAttribute(|22|codebase|22|, "; within:65; 
content:".setAttribute(|22|id|22|, "; within:65; 
content:".setAttribute(|22|code|22|, "; within:65; 
content:"|22|)|3b 0a|document.body.appendChild("; within:65; 
content:"</script>|0a|</body>|0a|</html>|0a 0a|"; 
classtype:trojan-activity; sid:x; rev:1;)

Unknown Malvertising Exploit Kit Hostile Jar app.jar";
content:"/app.jar"; http_uri; 
content:") Java/"; http_header; 
classtype:trojan-activity; sid:x; rev:1;)

Unknown Malvertising Exploit Kit Hostile Jar cm2.jar";
content:"/cm2.jar"; http_uri; 
content:") Java/"; http_header; 
classtype:trojan-activity; sid:x; rev:1;)


Attachment: UnknownEK_Inet.pcap

[01/Jul/2013:12:17:53 -0600]301text/html350218.30.109.70 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C)
[01/Jul/2013:12:19:13 -0600]200text/html296218.30.109.70 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C)
[01/Jul/2013:16:27:35 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[01/Jul/2013:16:27:35 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[01/Jul/2013:16:27:36 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[02/Jul/2013:10:10:04 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C; .NET4.0E; AskTbWBG/
[02/Jul/2013:10:10:04 -0600]200text/html323205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C; .NET4.0E; AskTbWBG/
[02/Jul/2013:10:10:05 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C; .NET4.0E; AskTbWBG/
[02/Jul/2013:10:48:02 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[02/Jul/2013:10:48:03 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[02/Jul/2013:10:48:04 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[02/Jul/2013:10:59:22 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
[02/Jul/2013:10:59:22 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
[02/Jul/2013:10:59:23 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
[02/Jul/2013:11:48:35 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[02/Jul/2013:11:48:35 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[02/Jul/2013:11:48:35 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[02/Jul/2013:14:08:29 -0600]2000396205.185.158.220 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:08:35 -0600]2000338205.185.158.220 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:38 -0600]50203277205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:39 -0600]50203277205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:39 -0600]50203277205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:25:41 -0600]2000713882.208.46.164 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[07/Jun/2013:08:10:58 -0600]200text/html19322174.132.22.20 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)
[08/Jun/2013:13:23:24 -0600]4030455882.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[10/Jun/2013:11:38:18 -0600]200text/html25843464.154.62.195 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.4; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; MS-RTC LM 8)
[10/Jun/2013:13:35:55 -0600]200text/html28517209.200.68.33,d.aWMMozilla/5.0 (Windows NT 6.1; rv:21.0) Gecko/20100101 Firefox/21.0
[14/Jun/2013:15:14:46 -0600]200text/html20646174.132.22.20 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.110 Safari/537.36
[14/Jun/2013:15:15:10 -0600]200text/html20542174.132.22.20 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.110 Safari/537.36
[17/Jun/2013:10:27:49 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[17/Jun/2013:10:27:49 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[17/Jun/2013:10:27:49 -0600]200text/html321205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[17/Jun/2013:10:31:26 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:10:31:26 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:10:31:26 -0600]200text/html320205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:11:55:48 -0600]200text/html396205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[17/Jun/2013:12:51:41 -0600]200text/html396205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[17/Jun/2013:15:36:47 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:36:47 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:36:47 -0600]200text/html320205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:46:46 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1)
[17/Jun/2013:15:46:46 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1)
[17/Jun/2013:15:46:46 -0600]200text/html321205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1)
[17/Jun/2013:16:10:05 -0600]200text/html396205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[18/Jun/2013:15:11:03 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:11:03 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:11:03 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:36:55 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:36:55 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:36:56 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:16:20:49 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:16:20:49 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:16:20:49 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:18:49 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:18:50 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:18:50 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:33:33 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:33:34 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:33:34 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[29/Jun/2013:11:19:38 -0600]4030456282.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[29/Jun/2013:11:19:58 -0600]4030456282.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[29/Jun/2013:11:19:58 -0600]4030456282.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[17/Jun/2013:12:48:29 -0600]2000201205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[17/Jun/2013:12:48:29 -0600]4040479205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[17/Jun/2013:15:46:46 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1)
[17/Jun/2013:10:27:49 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[17/Jun/2013:15:36:47 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:10:31:26 -0600]200text/html587205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[02/Jul/2013:14:21:45 -0600]50203264205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:45 -0600]50203264205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:46 -0600]50203264205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[17/Jun/2013:16:10:05 -0600]200text/html396205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[17/Jun/2013:11:55:48 -0600]200text/html396205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[17/Jun/2013:12:51:41 -0600]200text/html396205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[17/Jun/2013:10:27:49 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[17/Jun/2013:10:31:26 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:36:47 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:46:46 -0600]200text/html1043205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1)
[02/Jul/2013:14:21:38 -0600]50203277205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:39 -0600]50203277205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:39 -0600]50203277205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[17/Jun/2013:10:27:53 -0600]40304383205.185.158.219 (Windows XP 5.1) Java/1.6.0_24
[17/Jun/2013:10:27:53 -0600]40304383205.185.158.219 (Windows XP 5.1) Java/1.6.0_24
[17/Jun/2013:10:27:53 -0600]40304383205.185.158.219 (Windows XP 5.1) Java/1.6.0_24
[17/Jun/2013:10:27:54 -0600]40304383205.185.158.219 (Windows XP 5.1) Java/1.6.0_24
[17/Jun/2013:15:36:52 -0600]40304442205.185.158.219 (Windows XP 5.1) Java/1.5.0_18
[17/Jun/2013:10:31:31 -0600]40304383205.185.158.219 (Windows XP 5.1) Java/1.5.0_18
[17/Jun/2013:15:46:47 -0600]40304441205.185.158.219 (compatible; MSIE 6.0; Win32)
[02/Jul/2013:14:21:40 -0600]50203273205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:40 -0600]50203273205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:14:21:41 -0600]50203273205.185.158.219 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[17/Jun/2013:10:27:49 -0600]200text/html321205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[17/Jun/2013:10:31:26 -0600]200text/html320205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:36:47 -0600]200text/html320205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
[17/Jun/2013:15:46:46 -0600]200text/html321205.185.158.219 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1)
[17/Jun/2013:10:27:54 -0600]404text/html482205.185.158.219 (Windows XP 5.1) Java/1.6.0_24
[17/Jun/2013:10:27:54 -0600]404text/html482205.185.158.219 (Windows XP 5.1) Java/1.6.0_24
[17/Jun/2013:15:36:52 -0600]404text/html482205.185.158.219 (Windows XP 5.1) Java/1.5.0_18
[17/Jun/2013:15:36:53 -0600]404text/html482205.185.158.219 (Windows XP 5.1) Java/1.5.0_18
[17/Jun/2013:10:31:31 -0600]404text/html482205.185.158.219 (Windows XP 5.1) Java/1.5.0_18
[17/Jun/2013:10:31:31 -0600]404text/html482205.185.158.219 (Windows XP 5.1) Java/1.5.0_18
[17/Jun/2013:15:46:47 -0600]404text/html482205.185.158.219 (compatible; MSIE 6.0; Win32)
[08/Jun/2013:13:23:24 -0600]4030455882.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[29/Jun/2013:11:19:38 -0600]4030456282.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[29/Jun/2013:11:19:58 -0600]4030456282.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[29/Jun/2013:11:19:58 -0600]4030456282.208.46.164 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[02/Jul/2013:13:20:37 -0600]200text/html201205.185.158.220
[02/Jul/2013:13:20:33 -0600]200text/html201205.185.158.220
[02/Jul/2013:13:20:35 -0600]200text/html201205.185.158.220
[02/Jul/2013:13:20:34 -0600]200text/html201205.185.158.220
[02/Jul/2013:13:20:34 -0600]200text/html201205.185.158.220
[02/Jul/2013:14:08:30 -0600]4040480205.185.158.220 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[18/Jun/2013:17:33:38 -0600]404text/html479205.185.158.220 (compatible; MSIE 8.0; Win32)
[18/Jun/2013:16:20:50 -0600]404text/html479205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[18/Jun/2013:16:20:51 -0600]404text/html479205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[18/Jun/2013:15:11:04 -0600]404text/html479205.185.158.220 (compatible; MSIE 6.0; Win32)
[18/Jun/2013:15:37:06 -0600]404text/html479205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[18/Jun/2013:15:37:06 -0600]404text/html479205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[02/Jul/2013:10:10:14 -0600]404text/html479205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[02/Jul/2013:10:10:14 -0600]404text/html479205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[18/Jun/2013:17:18:54 -0600]200text/html61327205.185.158.220 (Windows XP 5.1) Java/1.6.0_20-rev
[18/Jun/2013:17:33:37 -0600]404text/html345205.185.158.220 (compatible; MSIE 8.0; Win32)
[18/Jun/2013:16:20:50 -0600]404text/html345205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[18/Jun/2013:15:11:04 -0600]404text/html345205.185.158.220 (compatible; MSIE 6.0; Win32)
[18/Jun/2013:15:37:06 -0600]404text/html345205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[02/Jul/2013:10:48:10 -0600]200text/html88220205.185.158.220 (Windows XP 5.1) Java/1.6.0_20-rev
[02/Jul/2013:10:10:13 -0600]404text/html345205.185.158.220 (Windows XP 5.1) Java/1.5.0_18
[02/Jul/2013:10:59:26 -0600]200text/html88220205.185.158.220 (Windows XP 5.1) Java/1.6.0_20-rev
[02/Jul/2013:13:51:40 -0600]404text/html403205.185.158.220
[02/Jul/2013:13:51:38 -0600]404text/html403205.185.158.220
[02/Jul/2013:13:51:39 -0600]404text/html403205.185.158.220
[02/Jul/2013:11:48:44 -0600]200text/html88220205.185.158.220 (Windows XP 5.1) Java/1.6.0_24
[02/Jul/2013:13:51:39 -0600]404text/html403205.185.158.220
[02/Jul/2013:13:51:39 -0600]404text/html403205.185.158.220
[18/Jun/2013:17:18:49 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:33:33 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:15:11:03 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:36:55 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[02/Jul/2013:10:48:02 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[02/Jul/2013:10:10:04 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C; .NET4.0E; AskTbWBG/
[02/Jul/2013:14:08:29 -0600]2000396205.185.158.220 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[02/Jul/2013:10:59:22 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
[02/Jul/2013:11:48:35 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[02/Jul/2013:14:08:35 -0600]2000338205.185.158.220 (X11; Linux x86_64) Presto/2.12.388 Version/12.15
[01/Jul/2013:16:27:35 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:16:20:49 -0600]200text/html1044205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:18:50 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:33:34 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:15:11:03 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:36:55 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[02/Jul/2013:10:48:03 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[02/Jul/2013:10:10:04 -0600]200text/html323205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C; .NET4.0E; AskTbWBG/
[02/Jul/2013:10:59:22 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
[02/Jul/2013:11:48:35 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[01/Jul/2013:16:27:35 -0600]200text/html325205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:16:20:49 -0600]200text/html324205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:16:20:49 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[01/Jul/2013:16:27:36 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:17:18:50 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[18/Jun/2013:15:11:03 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.2; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:15:36:56 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB0.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E)
[18/Jun/2013:17:33:34 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.3; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
[02/Jul/2013:10:59:23 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2)
[02/Jul/2013:10:48:04 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; AskTbGET-SRS/
[02/Jul/2013:11:48:35 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; MS-RTC LM 8; .NET4.0C; .NET4.0E)
[02/Jul/2013:10:10:05 -0600]200text/html591205.185.158.220 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; .NET4.0C; .NET4.0E; AskTbWBG/
[10/Jun/2013:13:35:55 -0600]200text/html28517209.200.68.33,d.aWMMozilla/5.0 (Windows NT 6.1; rv:21.0) Gecko/20100101 Firefox/21.0
[10/Jun/2013:11:38:18 -0600]200text/html25843464.154.62.195 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB7.4; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; MS-RTC LM 8)
This email is sponsored by Windows:

Build for Windows Store.
Snort-sigs mailing list
Snort-sigs () lists sourceforge net

Please visit for the latest news about Snort!

Current thread: