Detailed List of IPS rules used in ASG V8 and V7.508

Last update: Wed Feb 2 16:11:36 2011



Group Name# of attack rules# of warning rulesgoto
 
OS         
OS / Windows  2423    709    goto rules ...  
OS / Linux  4    19    goto rules ...  
OS / Other  30    53    goto rules ...  
 
Server         
Server / HTTP         
Server / HTTP / Common  22    70    goto rules ...  
Server / HTTP / Apache  10    18    goto rules ...  
Server / HTTP / Microsoft IIS  17    138    goto rules ...  
Server / HTTP / Other         
Server / HTTP / Coldfusion         
Server / HTTP / Frontpage  0    38    goto rules ...  
Server / HTTP / PHP  25    165    goto rules ...  
Server / HTTP / CGI  21    365    goto rules ...  
Server / Mail         
Server / Mail / Microsoft Exchange  12    5    goto rules ...  
Server / Mail / Sendmail  0    21    goto rules ...  
Server / Mail / POP3  11    29    goto rules ...  
Server / Mail / IMAP  34    44    goto rules ...  
Server / Mail / SMTP  165    45    goto rules ...  
Server / Database         
Server / Database / Microsoft  10    8    goto rules ...  
Server / Database / Oracle         
Server / Database / MySQL  16    19    goto rules ...  
Server / Database / Common SQL  60    113    goto rules ...  
Server / Database / Common SQL         
Server / Misc         
Server / Misc / DNS  24    265    goto rules ...  
Server / Misc / FTP  39    123    goto rules ...  
Server / Misc / SSH  0    8    goto rules ...  
Server / Misc / Backup  19    46    goto rules ...  
Server / Misc / TFTP         
Server / Misc / SNMP  3    4    goto rules ...  
Server / Misc / Authentication  7    12    goto rules ...  
Server / Misc / CVS  1    16    goto rules ...  
 
Client         
Client / Office  281    112    goto rules ...  
Client / Browser  246    67    goto rules ...  
Client / Email  17    3    goto rules ...  
Client / Multimedia  292    34    goto rules ...  
Client / Peer to Peer         
Client / Instant Messenger  8    2    goto rules ...  
 
Protocol Anomaly         
Protocol Anomaly / Invalid Traffic  7    13    goto rules ...  
Protocol Anomaly / ICMP         
Protocol Anomaly / IGMP         
Protocol Anomaly / RPC         
Protocol Anomaly / Misc         
 
Malware  1789    1827    goto rules ...  
Malware / Trojans         
Malware / DoS         

 goto Top

Group: OS

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: OS / Windows

# of attack rules in this group: 2423

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1239NETBIOS RFParalyze Attempt (more info ...)attempted-recon  2000-0347  1163  10392  
2005RPC portmap kcms_server request UDP (more info ...)rpc-portmap-decode  2003-0027  6665    URL
2007RPC kcms_server directory traversal attempt (more info ...)misc-attack  2003-0027  6665    URL
2103NETBIOS SMB Trans2 OPEN2 unicode maximum param count overflow attempt (more info ...)protocol-command-decode  2003-0201      
2123ATTACK-RESPONSES Microsoft cmd.exe banner (more info ...)successful-admin      11633  
2176NETBIOS SMB startup folder access (more info ...)attempted-recon        
2252NETBIOS SMB-DS DCERPC Remote Activation bind attempt (more info ...)attempted-admin  2003-0715  8458  11835  URL
2255RPC sadmind query with root credentials attempt TCP (more info ...)misc-attack        
2256RPC sadmind query with root credentials attempt UDP (more info ...)misc-attack        
2257NETBIOS DCERPC Messenger Service buffer overflow attempt (more info ...)attempted-admin  2003-0717  8826  11890  URL
2258NETBIOS SMB-DS DCERPC Messenger Service buffer overflow attempt (more info ...)attempted-admin  2003-0717  8826  11890  URL
2349NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters attempt (more info ...)protocol-command-decode  2006-6114  21220    
2401NETBIOS SMB Session Setup andx username overflow attempt (more info ...)protocol-command-decode    9752    URL
2403NETBIOS SMB Session Setup unicode username overflow attempt (more info ...)protocol-command-decode    9752    URL
2435WEB-CLIENT Microsoft emf metafile access (more info ...)attempted-user  2007-5746  9707    URL
2436WEB-CLIENT Microsoft wmf metafile access (more info ...)attempted-user        
2508NETBIOS DCERPC NCACN-IP-TCP lsass DsRolerUpgradeDownlevelServer overflow attempt (more info ...)attempted-admin  2003-0533  10108  12205  URL
2511NETBIOS DCERPC NCADG-IP-UDP lsass DsRolerUpgradeDownlevelServer overflow attempt (more info ...)attempted-admin  2003-0533  10108  12205  URL
2942NETBIOS DCERPC NCACN-IP-TCP winreg InitiateSystemShutdown attempt (more info ...)protocol-command-decode        URL
3018NETBIOS SMB NT Trans NT CREATE oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3019NETBIOS SMB NT Trans NT CREATE andx oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3020NETBIOS SMB NT Trans NT CREATE unicode oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3021NETBIOS SMB NT Trans NT CREATE unicode andx oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3022NETBIOS SMB-DS NT Trans NT CREATE oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3023NETBIOS SMB-DS NT Trans NT CREATE andx oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3024NETBIOS SMB-DS NT Trans NT CREATE unicode oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3025NETBIOS SMB-DS NT Trans NT CREATE unicode andx oversized Security Descriptor attempt (more info ...)protocol-command-decode  2004-1154      
3026NETBIOS SMB NT Trans NT CREATE SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3027NETBIOS SMB NT Trans NT CREATE andx SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3028NETBIOS SMB NT Trans NT CREATE unicode SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3029NETBIOS SMB NT Trans NT CREATE unicode andx SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3030NETBIOS SMB-DS NT Trans NT CREATE SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3031NETBIOS SMB-DS NT Trans NT CREATE andx SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3032NETBIOS SMB-DS NT Trans NT CREATE unicode SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3033NETBIOS SMB-DS NT Trans NT CREATE unicode andx SACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3034NETBIOS SMB NT Trans NT CREATE DACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3035NETBIOS SMB NT Trans NT CREATE andx DACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3036NETBIOS SMB NT Trans NT CREATE unicode DACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3037NETBIOS SMB NT Trans NT CREATE unicode andx DACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3038NETBIOS SMB-DS NT Trans NT CREATE DACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3039NETBIOS SMB-DS NT Trans NT CREATE andx DACL overflow attempt (more info ...)protocol-command-decode  2004-1154      
3079WEB-CLIENT Microsoft ANI file parsing overflow (more info ...)attempted-user  2007-1765      URL
3135NETBIOS SMB Trans2 QUERY_FILE_INFO attempt (more info ...)protocol-command-decode        
3136NETBIOS SMB Trans2 QUERY_FILE_INFO andx attempt (more info ...)protocol-command-decode        
3137NETBIOS SMB-DS Trans2 QUERY_FILE_INFO attempt (more info ...)protocol-command-decode        
3138NETBIOS SMB-DS Trans2 QUERY_FILE_INFO andx attempt (more info ...)protocol-command-decode        
3139NETBIOS SMB Trans2 FIND_FIRST2 attempt (more info ...)protocol-command-decode        
3140NETBIOS SMB Trans2 FIND_FIRST2 andx attempt (more info ...)protocol-command-decode        
3141NETBIOS SMB-DS Trans2 FIND_FIRST2 attempt (more info ...)protocol-command-decode        
3142NETBIOS SMB-DS Trans2 FIND_FIRST2 andx attempt (more info ...)protocol-command-decode        
3143NETBIOS SMB Trans2 FIND_FIRST2 command response overflow attempt (more info ...)protocol-command-decode  2005-0045  12484    URL
3144NETBIOS SMB Trans2 FIND_FIRST2 response andx overflow attempt (more info ...)protocol-command-decode  2005-0045  12484    URL
3146NETBIOS SMB-DS Trans2 FIND_FIRST2 response andx overflow attempt (more info ...)protocol-command-decode  2005-0045  12484    URL
3158NETBIOS DCERPC NCACN-IP-TCP ISystemActivator CoGetInstanceFromFile attempt (more info ...)protocol-command-decode  2003-0715      URL
3159NETBIOS DCERPC NCADG-IP-UDP ISystemActivator CoGetInstanceFromFile attempt (more info ...)protocol-command-decode  2003-0715      URL
3171NETBIOS DCERPC NCADG-IP-UDP msqueue function 4 overflow attempt (more info ...)attempted-admin  2005-0059      URL
3397NETBIOS DCERPC NCACN-IP-TCP ISystemActivator RemoteCreateInstance attempt (more info ...)protocol-command-decode  2003-0352  8205    URL
3398NETBIOS DCERPC NCADG-IP-UDP ISystemActivator RemoteCreateInstance attempt (more info ...)protocol-command-decode  2003-0352  8205    URL
3409NETBIOS DCERPC NCACN-IP-TCP IActivation remoteactivation overflow attempt (more info ...)attempted-admin  2003-0715  8205    URL
3552WEB-CLIENT OLE32 microsoft MSHTA masquerade attempt (more info ...)attempted-user  2005-0063  13132    URL
3967NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_QueryResConfList attempt (more info ...)protocol-command-decode  2005-1983  14513    URL
4072NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_DetectResourceConflict attempt (more info ...)protocol-command-decode  2005-1983  14513    URL
4145WEB-ACTIVEX Windows Trouble Shooter ActiveX Object Access (more info ...)attempted-user  2003-0662  8833    URL
4146WEB-ACTIVEX Share Point Portal Services Log Sink ActiveX Object Access (more info ...)attempted-user    14515    URL
4147WEB-ACTIVEX ActiveLabel ActiveX Object Access (more info ...)attempted-user  2002-0647  5558    URL
4148WEB-ACTIVEX DHTML Editing ActiveX clsid access (more info ...)attempted-user  2009-2519  1474    URL
4151WEB-ACTIVEX System Monitor Source Properties ActiveX Object Access (more info ...)attempted-user    7384    
4153WEB-ACTIVEX Eyedog ActiveX Object Access (more info ...)attempted-user  1999-0669  619    URL
4154WEB-ACTIVEX Active Setup ActiveX Object Access (more info ...)attempted-user  2000-0329  775    URL
4155WEB-ACTIVEX htmlfile ActiveX Object Access (more info ...)attempted-user  2001-0149  1718    URL
4157WEB-ACTIVEX MSN Setup BBS 4.71.0.10 ActiveX Object Access (more info ...)attempted-user  1999-1484  668    
4159WEB-ACTIVEX Multimedia File Property Sheet ActiveX Object Access (more info ...)attempted-user    5094    
4160WEB-ACTIVEX Microsoft Windows Reporting Tool ActiveX Object Access (more info ...)attempted-user  2003-0530  8454    URL
4161WEB-ACTIVEX DigWebX MSN ActiveX Object Access (more info ...)attempted-user    13946    URL
4162WEB-ACTIVEX DigWebX MSN ActiveX Object Access (more info ...)attempted-user    13946    URL
4163WEB-ACTIVEX DigWebX MSN ActiveX Object Access (more info ...)attempted-user    13946    URL
4164WEB-ACTIVEX DigWebX MSN ActiveX Object Access (more info ...)attempted-user    13946    URL
4165WEB-ACTIVEX Image Control 1.0 ActiveX Object Access (more info ...)attempted-user    12477    URL
4167WEB-ACTIVEX MSN Heartbeat ActiveX clsid access (more info ...)attempted-user    11367    URL
4168WEB-ACTIVEX Shell Automation Service ActiveX Object Access (more info ...)attempted-user    9335    
4171WEB-ACTIVEX Registration Wizard ActiveX Object Access (more info ...)attempted-user    671    URL
4172WEB-ACTIVEX Microsoft Agent v1.5 ActiveX clsid access (more info ...)attempted-user  2007-1205      URL
4173WEB-ACTIVEX MsnPUpld ActiveX Object Access (more info ...)attempted-user        URL
4174WEB-ACTIVEX Symantec RuFSI registry Information Class ActiveX Object Access (more info ...)attempted-user  2003-0470  8008    URL
4179WEB-ACTIVEX DirectX Files Viewer ActiveX Object Access (more info ...)attempted-user  2002-0975  5489    URL
4180WEB-ACTIVEX Kodak Image Scan Control ActiveX Object Access (more info ...)attempted-user        URL
4181WEB-ACTIVEX Smartcard Enrollment ActiveX Object Access (more info ...)attempted-user  2002-0699      URL
4182WEB-ACTIVEX MSN Chat v4.5, 4.6 ActiveX Object Access (more info ...)attempted-user  2002-0155  4707    URL
4183WEB-ACTIVEX HTML Help ActiveX Object Access (more info ...)attempted-user  2005-1208  13953    URL
4184WEB-ACTIVEX Certificate Enrollment ActiveX Object Access (more info ...)attempted-user  2002-0699  5593    URL
4185WEB-ACTIVEX Terminal Services Advanced Client ActiveX Object Access (more info ...)attempted-user  2002-0726  5554    URL
4186WEB-ACTIVEX Kodak Image Editing ActiveX Object Access (more info ...)attempted-user        URL
4187WEB-ACTIVEX Terminal Services Advanced Client ActiveX Object Access (more info ...)attempted-user  2002-0726  5554    URL
4188WEB-ACTIVEX RAV Online Scanner ActiveX Object Access (more info ...)attempted-user  2004-0936  11448    URL
4189WEB-ACTIVEX Third-Party Plugin ActiveX Object Access (more info ...)attempted-user  2003-0233      URL
4190WEB-ACTIVEX Kodak Thumbnail Image ActiveX Object Access (more info ...)attempted-user        URL
4191WEB-ACTIVEX MsnPUpld ActiveX Object Access (more info ...)attempted-user        URL
4192WEB-ACTIVEX HHOpen ActiveX Object Access (more info ...)attempted-user    669    URL
4193WEB-ACTIVEX Kodak Image Editing ActiveX Object Access (more info ...)attempted-user        URL
4197WEB-ACTIVEX DigWebX MSN ActiveX Object Access (more info ...)attempted-user    13946    URL
4200WEB-ACTIVEX Index Server Scope Administration ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4201WEB-ACTIVEX Queued Components Recorder ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4202WEB-ACTIVEX DirectAnimation ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4203WEB-ACTIVEX Microsoft Marquee Control ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4204WEB-ACTIVEX Microsoft DT PolyLine Control 2 ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4205WEB-ACTIVEX Microsoft Visual Database Tools Database Designer v7.0 ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4206WEB-ACTIVEX Microsoft MPEG-4 Video Decompressor Property Page ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4207WEB-ACTIVEX Microsoft MS Audio Decompressor Control Property Page ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4208WEB-ACTIVEX LexRefStEsObject Class ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4209WEB-ACTIVEX LexRefStFrObject Class ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4211WEB-ACTIVEX Microsoft DDS Library Shape Control ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4212WEB-ACTIVEX Microsoft DDS Generic Class ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4213WEB-ACTIVEX Microsoft DDS Picture Shape Control ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4214WEB-ACTIVEX Microsoft TipGW Init ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4215WEB-ACTIVEX Microsoft HTML Popup Window ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4216WEB-ACTIVEX CLSID_CComAcctImport ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4219WEB-ACTIVEX Microsoft Network Connections Tray ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4220WEB-ACTIVEX Microsoft Network and Dial-Up Connections ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4221WEB-ACTIVEX Microsoft ProxyStub Dispatch ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4223WEB-ACTIVEX Microsoft OpenCable Class ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4224WEB-ACTIVEX Microsoft VideoPort ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4225WEB-ACTIVEX Microsoft Repository ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4226WEB-ACTIVEX Microsoft DocHost User Interface Handler ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4227WEB-ACTIVEX Microsoft Network Connections ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4228WEB-ACTIVEX Microsoft Windows Start Menu ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4229WEB-ACTIVEX MSAPP Export Support for Microsoft Access ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4230WEB-ACTIVEX Search Assistant UI ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4231WEB-ACTIVEX Microsoft SysTray ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4232WEB-ACTIVEX Microsoft SysTray Invoker ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4233WEB-ACTIVEX Microsoft Visual Database Tools Query Designer v7.0 ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4234WEB-ACTIVEX Microsoft MSVTDGridCtrl7 ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4236WEB-ACTIVEX WMI ASDI Extension ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4245NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW overflow attempt (more info ...)attempted-admin  2005-2119  15056    URL
4246NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW overflow attempt (more info ...)attempted-admin  2005-2119  15056    URL
4358NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt (more info ...)protocol-command-decode  2005-2120  15065    URL
4648WEB-CLIENT wang image admin activex object access (more info ...)attempted-user        URL
4754NETBIOS DCERPC NCACN-IP-TCP locator nsi_binding_lookup_begin overflow attempt (more info ...)attempted-admin  2003-0003  6666    URL
4755NETBIOS DCERPC NCADG-IP-UDP locator nsi_binding_lookup_begin overflow attempt (more info ...)attempted-admin  2003-0003  6666    URL
4890WEB-ACTIVEX IAVIStream & IAVIFile Proxy ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4891WEB-ACTIVEX cfw Class ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4892WEB-ACTIVEX MTSEvents Class ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4893WEB-ACTIVEX Trident HTMLEditor ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4894WEB-ACTIVEX PSEnumVariant ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4895WEB-ACTIVEX PSTypeInfo ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4896WEB-ACTIVEX PSTypeLib ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4897WEB-ACTIVEX PSOAInterface ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4898WEB-ACTIVEX PSTypeComp ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4899WEB-ACTIVEX ISupportErrorInfo Interface ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4901WEB-ACTIVEX VMR Allocator Presenter 9 ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4902WEB-ACTIVEX Video Mixing Renderer 9 ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4903WEB-ACTIVEX VMR ImageSync 9 ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4904WEB-ACTIVEX Microsoft Repository Alias ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4905WEB-ACTIVEX Microsoft Repository Object ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4906WEB-ACTIVEX Microsoft Repository Interface Definition ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4907WEB-ACTIVEX Microsoft Repository Collection Definition ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4908WEB-ACTIVEX Microsoft Repository Method Definition ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4909WEB-ACTIVEX Microsoft Repository Property Definition ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4910WEB-ACTIVEX Microsoft Repository Relationship Definition ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4911WEB-ACTIVEX Microsoft Repository Type Library ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4912WEB-ACTIVEX Microsoft Repository Root ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4913WEB-ACTIVEX Microsoft Repository Workspace ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4914WEB-ACTIVEX Microsoft Repository Script Definition ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4915WEB-ACTIVEX Shortcut Handler ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
4982WEB-ACTIVEX Adodb.Stream ActiveX Object Access (more info ...)attempted-user  2004-0549  10514    URL
4983WEB-ACTIVEX Adodb.Stream ActiveX Object Access CreateObject Function (more info ...)attempted-user  2004-0549  10514    URL
5485NETBIOS DCERPC NCACN-IP-TCP llsrpc2 LlsrLicenseRequestW overflow attempt (more info ...)attempted-admin  2005-0050  12481    URL
5677NETBIOS SMB Session Setup username overflow attempt (more info ...)protocol-command-decode    9752    URL
5682NETBIOS SMB Session Setup unicode andx username overflow attempt (more info ...)protocol-command-decode    9752    URL
5740WEB-CLIENT Microsoft HTML help workshop file .hhp download attempt (more info ...)misc-activity        
5741WEB-CLIENT Microsoft HTML help workshop buffer overflow attempt (more info ...)attempted-user  2006-0564      URL
6002WEB-ACTIVEX Microsoft DT DDS Rectilinear GDD Layout ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6003WEB-ACTIVEX Microsoft DT DDS Rectilinear GDD Route ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6004WEB-ACTIVEX Microsoft DT DDS Circular Auto Layout Logic 2 ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6005WEB-ACTIVEX Microsoft DT DDS Straight Line Routing Logic 2 ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6006WEB-ACTIVEX Microsoft DT Icon Control ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6007WEB-ACTIVEX Microsoft DT DDS OrgChart GDD Layout ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6008WEB-ACTIVEX Microsoft DT DDS OrgChart GDD Route ActiveX Object Access (more info ...)attempted-user  2006-1186      URL
6009WEB-ACTIVEX RDS.Dataspace ActiveX Object Access (more info ...)attempted-user  2006-0003  17462    URL
6419NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW invalid uuid size attempt (more info ...)attempted-admin  2006-1184  17905    URL
6420NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW invalid uuid size attempt (more info ...)attempted-admin  2006-1184  17905    URL
6431NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW invalid second uuid size attempt (more info ...)attempted-admin  2006-1184  17905    URL
6432NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW invalid second uuid size attempt (more info ...)attempted-admin  2006-1184  17905    URL
6443NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContextW heap overflow attempt (more info ...)attempted-admin  2006-0034  17906    URL
6444NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContextW heap overflow attempt (more info ...)attempted-admin  2006-0034  17906    URL
6455NETBIOS DCERPC NCACN-IP-TCP msdtc BuildContext heap overflow attempt (more info ...)attempted-admin  2006-0034  17906    URL
6456NETBIOS DCERPC NCADG-IP-UDP msdtc BuildContext heap overflow attempt (more info ...)attempted-admin  2006-0034  17906    URL
6516WEB-ACTIVEX DXImageTransform.Microsoft.Light ActiveX function call access (more info ...)attempted-user  2006-2383      URL
6517WEB-ACTIVEX DXImageTransform.Microsoft.Light ActiveX CLSID access (more info ...)attempted-user  2006-2383      URL
6518WEB-ACTIVEX DXImageTransform.Microsoft.Light ActiveX CLSID unicode access (more info ...)attempted-user  2006-2383      URL
6682WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX function call access (more info ...)attempted-user        URL
6683WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX CLSID unicode access (more info ...)attempted-user        URL
6684WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX CLSID access (more info ...)attempted-user        URL
6685WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX CLSID unicode access (more info ...)attempted-user        URL
6686WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect2Inputs ActiveX CLSID access (more info ...)attempted-user        URL
6687WEB-ACTIVEX DXImageTransform.Microsoft.MMSpecialEffect1Input ActiveX function call access (more info ...)attempted-user        URL
6714NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences phonebook mode overflow attempt (more info ...)attempted-admin  2006-2371  18358    URL
6906NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences callback number overflow attempt (more info ...)attempted-admin  2006-2371  18358    URL
7003WEB-ACTIVEX ADODB.Recordset ActiveX function call access (more info ...)attempted-user  2006-5559  20704    URL
7004WEB-ACTIVEX Internet.HHCtrl.1 ActiveX function call access (more info ...)attempted-user  2006-3357  18769    URL
7006WEB-ACTIVEX ASControls.InstallEngineCtl ActiveX function call access (more info ...)attempted-user        
7007WEB-ACTIVEX AxDebugger.Document.1 ActiveX function call access (more info ...)attempted-user        
7008WEB-ACTIVEX DirectAnimation.DAUserData ActiveX function call access (more info ...)attempted-user        
7009WEB-ACTIVEX DirectAnimation.StructuredGraphicsControl ActiveX function call access (more info ...)attempted-user  2006-4777      URL
7010WEB-ACTIVEX HtmlDlgSafeHelper.HtmlDlgSafeHelper.1 ActiveX function call access (more info ...)attempted-user        
7011WEB-ACTIVEX HtmlDlgSafeHelper.HtmlDlgSafeHelper ActiveX function call access (more info ...)attempted-user        
7012WEB-ACTIVEX Internet.PopupMenu.1 ActiveX function call access (more info ...)attempted-user        
7013WEB-ACTIVEX Microsoft.ISCatAdm ActiveX function call access (more info ...)attempted-user        
7014WEB-ACTIVEX NMSA.ASFSourceMediaDescription.1 ActiveX function call access (more info ...)attempted-dos  2006-3897  19114    
7015WEB-ACTIVEX NMSA.MediaDescription ActiveX function call access (more info ...)attempted-user        
7016WEB-ACTIVEX Object.Microsoft.DXTFilter ActiveX function call access (more info ...)attempted-dos  2006-3512  18903    
7017WEB-ACTIVEX RDS.DataControl ActiveX function call access (more info ...)attempted-user  2006-3510  18900    
7018WEB-ACTIVEX Sysmon ActiveX function call access (more info ...)attempted-user        
7026WEB-ACTIVEX RDS.Dataspace ActiveX function call access (more info ...)attempted-user  2006-0003  17462    URL
7035NETBIOS SMB Trans mailslot heap overflow attempt (more info ...)protocol-command-decode  2006-3942  18864    URL
7036NETBIOS SMB Trans unicode mailslot heap overflow attempt (more info ...)protocol-command-decode  2006-3942  18864    URL
7039NETBIOS SMB Trans andx mailslot heap overflow attempt (more info ...)protocol-command-decode  2006-3942  18864    URL
7040NETBIOS SMB Trans unicode andx mailslot heap overflow attempt (more info ...)protocol-command-decode  2006-3942  18864    URL
7041NETBIOS-DG SMB Trans andx mailslot heap overflow attempt (more info ...)protocol-command-decode  2006-3942  18864    URL
7209NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrPathCanonicalize overflow attempt (more info ...)attempted-admin  2006-3439  19409    URL
7210NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrPathCanonicalize overflow attempt (more info ...)attempted-admin  2006-3439  19409    URL
7425WEB-ACTIVEX 9x8Resize ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7426WEB-ACTIVEX 9x8Resize ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7427WEB-ACTIVEX Allocator Fix ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7428WEB-ACTIVEX Allocator Fix ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7429WEB-ACTIVEX Bitmap ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7430WEB-ACTIVEX Bitmap ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7431WEB-ACTIVEX DirectFrame.DirectControl.1 ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7432WEB-ACTIVEX DirectFrame.DirectControl.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7433WEB-ACTIVEX DirectX Transform Wrapper Property Page ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7434WEB-ACTIVEX DirectX Transform Wrapper Property Page ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7435WEB-ACTIVEX Dynamic Casts ActiveX clsid access (more info ...)attempted-user  2006-3638      URL
7436WEB-ACTIVEX Dynamic Casts ActiveX function call (more info ...)attempted-user  2006-3638      URL
7437WEB-ACTIVEX Frame Eater ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7438WEB-ACTIVEX Frame Eater ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7439WEB-ACTIVEX HTML Help ActiveX clsid access (more info ...)attempted-user  2007-0214      URL
7440WEB-ACTIVEX HTML Help ActiveX clsid unicode access (more info ...)attempted-user  2007-0214      URL
7441WEB-ACTIVEX HTML Help ActiveX CLSID unicode access (more info ...)attempted-user  2005-1208  13953    URL
7442WEB-ACTIVEX mmAEPlugIn.AEPlugIn.1 ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7443WEB-ACTIVEX mmAEPlugIn.AEPlugIn.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7444WEB-ACTIVEX Mmedia.AsyncMHandler.1 ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7445WEB-ACTIVEX Mmedia.AsyncMHandler.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7446WEB-ACTIVEX Record Queue ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7447WEB-ACTIVEX Record Queue ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7448WEB-ACTIVEX ShotDetect ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7449WEB-ACTIVEX ShotDetect ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7450WEB-ACTIVEX Stetch ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7451WEB-ACTIVEX Stetch ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7452WEB-ACTIVEX WM Color Converter Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7453WEB-ACTIVEX WM Color Converter Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7454WEB-ACTIVEX Wmm2ae.dll ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7455WEB-ACTIVEX Wmm2ae.dll ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7456WEB-ACTIVEX Wmm2fxa.dll ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7457WEB-ACTIVEX Wmm2fxa.dll ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7458WEB-ACTIVEX Wmm2fxb.dll ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7459WEB-ACTIVEX Wmm2fxb.dll ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7460WEB-ACTIVEX WMT Audio Analyzer ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7461WEB-ACTIVEX WMT Audio Analyzer ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7462WEB-ACTIVEX WMT Black Frame Generator ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7463WEB-ACTIVEX WMT Black Frame Generator ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7464WEB-ACTIVEX WMT DeInterlace Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7465WEB-ACTIVEX WMT DeInterlace Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7466WEB-ACTIVEX WMT DeInterlace Prop Page ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7467WEB-ACTIVEX WMT DeInterlace Prop Page ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7468WEB-ACTIVEX WMT DirectX Transform Wrapper ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7469WEB-ACTIVEX WMT DirectX Transform Wrapper ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7470WEB-ACTIVEX WMT DV Extract Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7471WEB-ACTIVEX WMT DV Extract Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7472WEB-ACTIVEX WMT FormatConversion Prop Page ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7473WEB-ACTIVEX WMT FormatConversion Prop Page ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7474WEB-ACTIVEX WMT FormatConversion ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7475WEB-ACTIVEX WMT FormatConversion ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7476WEB-ACTIVEX WMT Import Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7477WEB-ACTIVEX WMT Import Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7478WEB-ACTIVEX WMT Interlacer ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7479WEB-ACTIVEX WMT Interlacer ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7480WEB-ACTIVEX WMT Log Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7481WEB-ACTIVEX WMT Log Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7482WEB-ACTIVEX WMT MuxDeMux Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7483WEB-ACTIVEX WMT MuxDeMux Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7484WEB-ACTIVEX WMT Sample Info Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7485WEB-ACTIVEX WMT Sample Info Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7486WEB-ACTIVEX WMT Screen Capture Filter Task Page ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7487WEB-ACTIVEX WMT Screen Capture Filter Task Page ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7488WEB-ACTIVEX WMT Screen capture Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7489WEB-ACTIVEX WMT Screen capture Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7490WEB-ACTIVEX WMT Switch Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7491WEB-ACTIVEX WMT Switch Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7492WEB-ACTIVEX WMT Virtual Renderer ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7493WEB-ACTIVEX WMT Virtual Renderer ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7494WEB-ACTIVEX WMT Virtual Source ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7495WEB-ACTIVEX WMT Virtual Source ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7496WEB-ACTIVEX WMT Volume ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7497WEB-ACTIVEX WMT Volume ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7498WEB-ACTIVEX WM TV Out Smooth Picture Filter ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7499WEB-ACTIVEX WM TV Out Smooth Picture Filter ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7500WEB-ACTIVEX WM VIH2 Fix ActiveX CLSID access (more info ...)attempted-user  2006-3638      URL
7501WEB-ACTIVEX WM VIH2 Fix ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638      URL
7502WEB-ACTIVEX tsuserex.ADsTSUserEx.1 ActiveX clsid access (more info ...)attempted-user  2006-4219  19570    URL
7503WEB-ACTIVEX tsuserex.ADsTSUserEx.1 ActiveX clsid unicode access (more info ...)attempted-user  2006-4219  19570    URL
7856SPYWARE-PUT Trackware winsysba-a runtime detection - track surfing activity (more info ...)successful-recon-limited        URL
7862WEB-ACTIVEX McSubMgr.IsAppExpired ActiveX function call access (more info ...)attempted-user  2006-3961  19265    
7863WEB-ACTIVEX McSubMgr.IsOldAppInstalled ActiveX function call access (more info ...)attempted-user  2006-3961  19265    
7864WEB-ACTIVEX McSubMgr ActiveX CLSID access (more info ...)attempted-user  2006-3961  19265    
7865WEB-ACTIVEX McSubMgr ActiveX CLSID unicode access (more info ...)attempted-user  2006-3961  19265    
7866WEB-ACTIVEX ADODB.Connection ActiveX clsid access (more info ...)attempted-user  2006-5559      URL
7867WEB-ACTIVEX ADODB.Connection ActiveX clsid unicode access (more info ...)attempted-user  2006-5559      URL
7868WEB-ACTIVEX ADODB.Recordset ActiveX CLSID access (more info ...)attempted-user  2006-5559  20704    
7869WEB-ACTIVEX ADODB.Recordset ActiveX CLSID unicode access (more info ...)attempted-user  2006-5559  20704    
7878WEB-ACTIVEX AxMetaStream.MetaStreamCtl ActiveX CLSID access (more info ...)attempted-user        URL
7879WEB-ACTIVEX AxMetaStream.MetaStreamCtl ActiveX CLSID unicode access (more info ...)attempted-user        URL
7880WEB-ACTIVEX AxMetaStream.MetaStreamCtlSecondary ActiveX CLSID access (more info ...)attempted-user        
7881WEB-ACTIVEX AxMetaStream.MetaStreamCtlSecondary ActiveX CLSID unicode access (more info ...)attempted-user        
7882WEB-ACTIVEX AccSync.AccSubNotHandler ActiveX CLSID access (more info ...)attempted-user        
7883WEB-ACTIVEX AccSync.AccSubNotHandler ActiveX CLSID unicode access (more info ...)attempted-user        
7884WEB-ACTIVEX AolCalSvr.ACCalendarListCtrl ActiveX CLSID access (more info ...)attempted-user        
7885WEB-ACTIVEX AolCalSvr.ACCalendarListCtrl ActiveX CLSID unicode access (more info ...)attempted-user        
7886WEB-ACTIVEX AolCalSvr.ACDictionary ActiveX CLSID access (more info ...)attempted-user        
7887WEB-ACTIVEX AolCalSvr.ACDictionary ActiveX CLSID unicode access (more info ...)attempted-user        
7890WEB-ACTIVEX AOL.MemExpWz ActiveX CLSID access (more info ...)attempted-user        
7891WEB-ACTIVEX AOL.MemExpWz ActiveX CLSID unicode access (more info ...)attempted-user        
7892WEB-ACTIVEX AOL Phobos Class ActiveX CLSID access (more info ...)attempted-user        
7893WEB-ACTIVEX AOL Phobos Class ActiveX CLSID unicode access (more info ...)attempted-user        
7894WEB-ACTIVEX AOL.PicDownloadCtrl ActiveX CLSID access (more info ...)attempted-user        
7895WEB-ACTIVEX AOL.PicDownloadCtrl ActiveX CLSID unicode access (more info ...)attempted-user        
7896WEB-ACTIVEX AOL.PicEditCtrl ActiveX CLSID access (more info ...)attempted-user        
7897WEB-ACTIVEX AOL.PicEditCtrl ActiveX CLSID unicode access (more info ...)attempted-user        
7898WEB-ACTIVEX AOL.PicSsvrCtrl ActiveX CLSID access (more info ...)attempted-user        
7899WEB-ACTIVEX AOL.PicSsvrCtrl ActiveX CLSID unicode access (more info ...)attempted-user        
7900WEB-ACTIVEX AOL.UPFCtrl ActiveX CLSID access (more info ...)attempted-user        
7901WEB-ACTIVEX AOL.UPFCtrl ActiveX CLSID unicode access (more info ...)attempted-user        
7902WEB-ACTIVEX CDDBControlAOL.CDDBAOLControl ActiveX clsid access (more info ...)attempted-user  2006-3134  23567    URL
7903WEB-ACTIVEX CDDBControlAOL.CDDBAOLControl ActiveX clsid unicode access (more info ...)attempted-user  2006-3134  23567    URL
7904WEB-ACTIVEX CDL Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7905WEB-ACTIVEX CDL Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
7906WEB-ACTIVEX CDO.KnowledgeSearchFolder ActiveX CLSID access (more info ...)attempted-user        
7907WEB-ACTIVEX CDO.KnowledgeSearchFolder ActiveX CLSID unicode access (more info ...)attempted-user        
7908WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX clsid access (more info ...)attempted-user    24188    URL
7909WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX clsid unicode access (more info ...)attempted-user    24188    URL
7910WEB-ACTIVEX DXImageTransform.Microsoft.DropShadow ActiveX CLSID access (more info ...)attempted-user        URL
7911WEB-ACTIVEX DXImageTransform.Microsoft.DropShadow ActiveX CLSID unicode access (more info ...)attempted-user        URL
7912WEB-ACTIVEX DX3DTransform.Microsoft.Shapes ActiveX CLSID access (more info ...)attempted-user        URL
7913WEB-ACTIVEX DX3DTransform.Microsoft.Shapes ActiveX CLSID unicode access (more info ...)attempted-user        URL
7914WEB-ACTIVEX DXImageTransform.Microsoft.NDFXArtEffects ActiveX CLSID access (more info ...)attempted-user  2006-3638  19340    URL
7915WEB-ACTIVEX DXImageTransform.Microsoft.NDFXArtEffects ActiveX CLSID unicode access (more info ...)attempted-user  2006-3638  19340    URL
7916WEB-ACTIVEX CLSID_IMimeInternational ActiveX CLSID access (more info ...)attempted-user        
7917WEB-ACTIVEX CLSID_IMimeInternational ActiveX CLSID unicode access (more info ...)attempted-user        
7918WEB-ACTIVEX CoAxTrackVideo Class ActiveX CLSID access (more info ...)attempted-user        
7919WEB-ACTIVEX CoAxTrackVideo Class ActiveX CLSID unicode access (more info ...)attempted-user        
7920WEB-ACTIVEX DsPropertyPages.OU ActiveX CLSID access (more info ...)attempted-user        
7921WEB-ACTIVEX DsPropertyPages.OU ActiveX CLSID unicode access (more info ...)attempted-user        
7922WEB-ACTIVEX DXImageTransform.Microsoft.RevealTrans ActiveX CLSID access (more info ...)attempted-user        URL
7923WEB-ACTIVEX DXImageTransform.Microsoft.RevealTrans ActiveX CLSID unicode access (more info ...)attempted-user        URL
7924WEB-ACTIVEX DXImageTransform.Microsoft.Shadow ActiveX CLSID access (more info ...)attempted-user        URL
7925WEB-ACTIVEX DXImageTransform.Microsoft.Shadow ActiveX CLSID unicode access (more info ...)attempted-user        URL
7926WEB-ACTIVEX DXTFilter ActiveX CLSID access (more info ...)attempted-user        
7927WEB-ACTIVEX DXTFilter ActiveX CLSID unicode access (more info ...)attempted-user        
7928WEB-ACTIVEX file or local Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7929WEB-ACTIVEX file or local Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
7930WEB-ACTIVEX FolderItem2 ActiveX CLSID access (more info ...)attempted-user        URL
7931WEB-ACTIVEX FolderItem2 ActiveX CLSID unicode access (more info ...)attempted-user        URL
7932WEB-ACTIVEX FolderItems3 ActiveX CLSID access (more info ...)attempted-user        
7933WEB-ACTIVEX FolderItems3 ActiveX CLSID unicode access (more info ...)attempted-user        
7936WEB-ACTIVEX DXImageTransform.Microsoft.Glow ActiveX CLSID access (more info ...)attempted-user        URL
7937WEB-ACTIVEX DXImageTransform.Microsoft.Glow ActiveX CLSID unicode access (more info ...)attempted-user        URL
7938WEB-ACTIVEX gopher Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7939WEB-ACTIVEX gopher Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
7940WEB-ACTIVEX DXImageTransform.Microsoft.Gradient ActiveX CLSID access (more info ...)attempted-user        URL
7941WEB-ACTIVEX DXImageTransform.Microsoft.Gradient ActiveX CLSID unicode access (more info ...)attempted-user        URL
7942WEB-ACTIVEX http Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7943WEB-ACTIVEX http Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
7944WEB-ACTIVEX https Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7945WEB-ACTIVEX https Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
7946WEB-ACTIVEX DXImageTransform.Microsoft.MaskFilter ActiveX CLSID access (more info ...)attempted-user        URL
7947WEB-ACTIVEX DXImageTransform.Microsoft.MaskFilter ActiveX CLSID unicode access (more info ...)attempted-user        URL
7948WEB-ACTIVEX Microsoft Common Browser Architecture ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7949WEB-ACTIVEX Microsoft Common Browser Architecture ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7950WEB-ACTIVEX Microsoft DirectAnimation Control ActiveX CLSID access (more info ...)attempted-user        
7951WEB-ACTIVEX Microsoft DirectAnimation Control ActiveX CLSID unicode access (more info ...)attempted-user        
7952WEB-ACTIVEX Microsoft DirectAnimation Windowed Control ActiveX CLSID access (more info ...)attempted-user        
7953WEB-ACTIVEX Microsoft DirectAnimation Windowed Control ActiveX CLSID unicode access (more info ...)attempted-user        
7954WEB-ACTIVEX Microsoft Forms 2.0 ComboBox ActiveX CLSID access (more info ...)attempted-user  1999-0384      URL
7955WEB-ACTIVEX Microsoft Forms 2.0 ComboBox ActiveX CLSID unicode access (more info ...)attempted-user  1999-0384      URL
7956WEB-ACTIVEX Microsoft Forms 2.0 ListBox ActiveX CLSID access (more info ...)attempted-user        URL
7957WEB-ACTIVEX Microsoft Forms 2.0 ListBox ActiveX CLSID unicode access (more info ...)attempted-user        URL
7958WEB-ACTIVEX mk Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7959WEB-ACTIVEX mk Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
7970WEB-ACTIVEX PostBootReminder object ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7971WEB-ACTIVEX PostBootReminder object ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7974WEB-ACTIVEX Rendezvous Class ActiveX CLSID access (more info ...)attempted-user        
7975WEB-ACTIVEX Rendezvous Class ActiveX CLSID unicode access (more info ...)attempted-user        
7976WEB-ACTIVEX ShellFolder for CD Burning ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7977WEB-ACTIVEX ShellFolder for CD Burning ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7981WEB-ACTIVEX Snapshot Viewer General Property Page Object ActiveX clsid access (more info ...)attempted-user  2008-2463      URL
7982WEB-ACTIVEX Snapshot Viewer General Property Page Object ActiveX clsid unicode access (more info ...)attempted-user  2008-2463      URL
7983WEB-ACTIVEX SuperBuddy Class ActiveX CLSID access (more info ...)attempted-user        
7984WEB-ACTIVEX SuperBuddy Class ActiveX CLSID unicode access (more info ...)attempted-user        
7985WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.1 ActiveX clsid access (more info ...)attempted-user  2006-3730  19030    URL
7986WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-3730  19030    URL
7987WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.2 ActiveX CLSID access (more info ...)attempted-user        
7988WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.2 ActiveX CLSID unicode access (more info ...)attempted-user        
7989WEB-ACTIVEX WIA FileSystem USD ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7990WEB-ACTIVEX WIA FileSystem USD ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7991WEB-ACTIVEX ACM Class Manager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7992WEB-ACTIVEX ACM Class Manager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7993WEB-ACTIVEX clbcatex.dll ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7994WEB-ACTIVEX clbcatex.dll ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7995WEB-ACTIVEX clbcatq.dll ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7996WEB-ACTIVEX clbcatq.dll ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7997WEB-ACTIVEX CLSID_ApprenticeICW ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
7998WEB-ACTIVEX CLSID_ApprenticeICW ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
7999WEB-ACTIVEX CLSID_CDIDeviceActionConfigPage ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8000WEB-ACTIVEX CLSID_CDIDeviceActionConfigPage ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8001WEB-ACTIVEX CommunicationManager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8002WEB-ACTIVEX CommunicationManager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8003WEB-ACTIVEX Content.mbcontent.1 ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8004WEB-ACTIVEX Content.mbcontent.1 ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8005WEB-ACTIVEX DiskManagement.Connection ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8006WEB-ACTIVEX DiskManagement.Connection ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8007WEB-ACTIVEX Dutch_Dutch Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8008WEB-ACTIVEX Dutch_Dutch Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8009WEB-ACTIVEX English_UK Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8010WEB-ACTIVEX English_UK Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8011WEB-ACTIVEX English_US Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8012WEB-ACTIVEX English_US Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8013WEB-ACTIVEX French_French Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8014WEB-ACTIVEX French_French Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8015WEB-ACTIVEX German_German Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8016WEB-ACTIVEX German_German Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8017WEB-ACTIVEX ICM Class Manager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8018WEB-ACTIVEX ICM Class Manager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8021WEB-ACTIVEX ISSimpleCommandCreator.1 ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8022WEB-ACTIVEX ISSimpleCommandCreator.1 ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8023WEB-ACTIVEX Italian_Italian Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8024WEB-ACTIVEX Italian_Italian Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8025WEB-ACTIVEX Microsoft HTML Window Security Proxy ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8026WEB-ACTIVEX Microsoft HTML Window Security Proxy ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8027WEB-ACTIVEX Microsoft WBEM Event Subsystem ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8028WEB-ACTIVEX Microsoft WBEM Event Subsystem ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8029WEB-ACTIVEX MidiOut Class Manager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8030WEB-ACTIVEX MidiOut Class Manager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8031WEB-ACTIVEX Mslablti.MarshalableTI.1 ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8032WEB-ACTIVEX Mslablti.MarshalableTI.1 ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8033WEB-ACTIVEX QC.MessageMover.1 ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8034WEB-ACTIVEX QC.MessageMover.1 ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8035WEB-ACTIVEX Spanish_Modern Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8036WEB-ACTIVEX Spanish_Modern Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8037WEB-ACTIVEX Swedish_Default Stemmer ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8038WEB-ACTIVEX Swedish_Default Stemmer ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8039WEB-ACTIVEX syncui.dll ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8040WEB-ACTIVEX syncui.dll ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8041WEB-ACTIVEX VFW Capture Class Manager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8042WEB-ACTIVEX VFW Capture Class Manager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8043WEB-ACTIVEX Video Effect Class Manager 1 Input ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8044WEB-ACTIVEX Video Effect Class Manager 1 Input ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8045WEB-ACTIVEX Video Effect Class Manager 2 Input ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8046WEB-ACTIVEX Video Effect Class Manager 2 Input ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8047WEB-ACTIVEX WaveIn Class Manager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8048WEB-ACTIVEX WaveIn Class Manager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8049WEB-ACTIVEX WaveOut and DSound Class Manager ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8050WEB-ACTIVEX WaveOut and DSound Class Manager ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8051WEB-ACTIVEX WDM Instance Provider ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8052WEB-ACTIVEX WDM Instance Provider ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8053WEB-ACTIVEX DirectAnimation.PathControl ActiveX CLSID access (more info ...)attempted-user  2006-4777  19738    
8054WEB-ACTIVEX DirectAnimation.PathControl ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777  19738    
8055WEB-ACTIVEX DirectAnimation.PathControl ActiveX function call access (more info ...)attempted-user  2006-4777  19738    
8062WEB-ACTIVEX ADODB.Stream ActiveX CLSID unicode access (more info ...)attempted-user  2004-0549  10514    URL
8063WEB-ACTIVEX ADODB.Stream ActiveX function call access (more info ...)attempted-user  2004-0549  10514    URL
8064WEB-ACTIVEX Scriptlet.Typelib ActiveX CLSID access (more info ...)attempted-user  2000-1061  598    URL
8065WEB-ACTIVEX Scriptlet.Typelib ActiveX CLSID unicode access (more info ...)attempted-user  2000-1061  598    URL
8066WEB-ACTIVEX Windows Scripting Host Shell ActiveX CLSID access (more info ...)attempted-user  2003-0532  8456    URL
8067WEB-ACTIVEX Windows Scripting Host Shell ActiveX CLSID unicode access (more info ...)attempted-user  2003-0532  8456    URL
8068WEB-ACTIVEX Windows Scripting Host Shell ActiveX function call access (more info ...)attempted-user        
8069WEB-ACTIVEX Microsoft Virtual Machine ActiveX CLSID access (more info ...)attempted-user  2000-1061  1754    URL
8070WEB-ACTIVEX Microsoft Virtual Machine ActiveX CLSID unicode access (more info ...)attempted-user  2000-1061  1754    URL
8253NETBIOS DCERPC NCACN-IP-TCP webdav DavrCreateConnection username overflow attempt (more info ...)attempted-admin  2006-0013  16636    URL
8363WEB-ACTIVEX Business Object Factory ActiveX CLSID access (more info ...)attempted-user        URL
8364WEB-ACTIVEX Business Object Factory ActiveX CLSID unicode access (more info ...)attempted-user        URL
8365WEB-ACTIVEX DExplore.AppObj.8.0 ActiveX CLSID access (more info ...)attempted-user        URL
8366WEB-ACTIVEX DExplore.AppObj.8.0 ActiveX CLSID unicode access (more info ...)attempted-user        URL
8367WEB-ACTIVEX Microsoft.DbgClr.DTE.8.0 ActiveX CLSID access (more info ...)attempted-user        URL
8368WEB-ACTIVEX Microsoft.DbgClr.DTE.8.0 ActiveX CLSID unicode access (more info ...)attempted-user        URL
8369WEB-ACTIVEX WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID access (more info ...)attempted-user  2006-4704      URL
8370WEB-ACTIVEX WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4704      URL
8373WEB-ACTIVEX VsmIDE.DTE ActiveX CLSID access (more info ...)attempted-user        URL
8374WEB-ACTIVEX VsmIDE.DTE ActiveX CLSID unicode access (more info ...)attempted-user        URL
8379WEB-ACTIVEX Xml2Dex ActiveX CLSID access (more info ...)attempted-user        
8380WEB-ACTIVEX Xml2Dex ActiveX CLSID unicode access (more info ...)attempted-user        
8391WEB-ACTIVEX RFXInstMgr Class ActiveX CLSID access (more info ...)attempted-user        
8392WEB-ACTIVEX RFXInstMgr Class ActiveX CLSID unicode access (more info ...)attempted-user        
8393WEB-ACTIVEX WebDetectFrm ActiveX CLSID access (more info ...)attempted-user        
8394WEB-ACTIVEX WebDetectFrm ActiveX CLSID unicode access (more info ...)attempted-user        
8395WEB-ACTIVEX DX3DTransform.Microsoft.CrShatter ActiveX CLSID access (more info ...)attempted-user        
8396WEB-ACTIVEX DX3DTransform.Microsoft.CrShatter ActiveX CLSID unicode access (more info ...)attempted-user        
8399WEB-ACTIVEX Microsoft.WebCapture ActiveX CLSID access (more info ...)attempted-user        
8400WEB-ACTIVEX Microsoft.WebCapture ActiveX CLSID unicode access (more info ...)attempted-user        
8403WEB-ACTIVEX XML Schema Cache 6.0 ActiveX CLSID access (more info ...)attempted-user        
8404WEB-ACTIVEX XML Schema Cache 6.0 ActiveX CLSID unicode access (more info ...)attempted-user        
8405WEB-ACTIVEX ActiveX clsid access (more info ...)attempted-user  2006-5745  20915    URL
8406WEB-ACTIVEX ActiveX clsid unicode access (more info ...)attempted-user  2006-5745  20915    URL
8407WEB-ACTIVEX VisualExec Control ActiveX CLSID access (more info ...)attempted-user        
8408WEB-ACTIVEX VisualExec Control ActiveX CLSID unicode access (more info ...)attempted-user        
8411WEB-ACTIVEX DocFind Command ActiveX CLSID access (more info ...)attempted-user        
8412WEB-ACTIVEX DocFind Command ActiveX CLSID unicode access (more info ...)attempted-user        
8417WEB-ACTIVEX TriEditDocument.TriEditDocument ActiveX function call access (more info ...)attempted-user  2006-3591  18946    URL
8418WEB-ACTIVEX DXImageTransform.Microsoft.RevealTrans ActiveX function call access (more info ...)attempted-user        URL
8419WEB-ACTIVEX WebViewFolderIcon.WebViewFolderIcon.1 ActiveX function call (more info ...)attempted-user  2006-3730  19030    URL
8420WEB-ACTIVEX DXImageTransform.Microsoft.Gradient ActiveX function call access (more info ...)attempted-user        URL
8421WEB-ACTIVEX OWC11.DataSourceControl.11 ActiveX function call access (more info ...)attempted-user        URL
8423WEB-ACTIVEX CEnroll.CEnroll.2 ActiveX function call access (more info ...)attempted-user        URL
8424WEB-ACTIVEX Microsoft Forms 2.0 ListBox ActiveX function call access (more info ...)attempted-user        URL
8425WEB-ACTIVEX DXImageTransform.Microsoft.NDFXArtEffects ActiveX function call access (more info ...)attempted-user  2006-3638  19340    URL
8478WEB-CLIENT Microsoft Publisher file download attempt (more info ...)misc-activity  2006-0001      URL
8717WEB-ACTIVEX VsaIDE.DTE ActiveX CLSID access (more info ...)attempted-user        URL
8718WEB-ACTIVEX VsaIDE.DTE ActiveX CLSID unicode access (more info ...)attempted-user        URL
8719WEB-ACTIVEX VisualStudio.DTE.8.0 ActiveX CLSID access (more info ...)attempted-user        URL
8720WEB-ACTIVEX VisualStudio.DTE.8.0 ActiveX CLSID unicode access (more info ...)attempted-user        URL
8725WEB-ACTIVEX System Monitor ActiveX CLSID access (more info ...)attempted-user  2000-1034  1899    URL
8726WEB-ACTIVEX System Monitor ActiveX CLSID unicode access (more info ...)attempted-user  2000-1034  1899    URL
8727WEB-ACTIVEX XMLHTTP 4.0 ActiveX clsid access (more info ...)attempted-user  2006-5745  20915    URL
8728WEB-ACTIVEX XMLHTTP 4.0 ActiveX clsid unicode access (more info ...)attempted-user  2006-5745  20915    URL
8735WEB-ACTIVEX BOWebAgent.Webagent.1 ActiveX CLSID access (more info ...)attempted-user        
8736WEB-ACTIVEX BOWebAgent.Webagent.1 ActiveX CLSID unicode access (more info ...)attempted-user        
8737WEB-ACTIVEX BOWebAgent.Webagent.1 ActiveX function call access (more info ...)attempted-user        
8741WEB-ACTIVEX DirectAnimation.DAFontStyle.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8742WEB-ACTIVEX DirectAnimation.DAFontStyle.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8743WEB-ACTIVEX DirectAnimation.DAFontStyle.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8744WEB-ACTIVEX DirectAnimation.DAEvent.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8745WEB-ACTIVEX DirectAnimation.DAEvent.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8746WEB-ACTIVEX DirectAnimation.DAEvent.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8747WEB-ACTIVEX DirectAnimation.DAEndStyle.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8748WEB-ACTIVEX DirectAnimation.DAEndStyle.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8749WEB-ACTIVEX DirectAnimation.DAEndStyle.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8750WEB-ACTIVEX LM.LMBehaviorFactory.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8751WEB-ACTIVEX LM.LMBehaviorFactory.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8752WEB-ACTIVEX LM.LMBehaviorFactory.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8753WEB-ACTIVEX LM.AutoEffectBvr.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8754WEB-ACTIVEX LM.AutoEffectBvr.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8755WEB-ACTIVEX LM.AutoEffectBvr.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8756WEB-ACTIVEX DirectAnimation.SpriteControl ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8757WEB-ACTIVEX DirectAnimation.SpriteControl ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8758WEB-ACTIVEX DirectAnimation.SpriteControl ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8759WEB-ACTIVEX DirectAnimation.SequencerControl ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8760WEB-ACTIVEX DirectAnimation.SequencerControl ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8761WEB-ACTIVEX DirectAnimation.SequencerControl ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8762WEB-ACTIVEX DirectAnimation.Sequence ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8763WEB-ACTIVEX DirectAnimation.Sequence ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8764WEB-ACTIVEX DirectAnimation.Sequence ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8765WEB-ACTIVEX DirectAnimation.DAView.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8766WEB-ACTIVEX DirectAnimation.DAView.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8767WEB-ACTIVEX DirectAnimation.DAView.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8768WEB-ACTIVEX DirectAnimation.DAVector3.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8769WEB-ACTIVEX DirectAnimation.DAVector3.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8770WEB-ACTIVEX DirectAnimation.DAVector3.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8771WEB-ACTIVEX DirectAnimation.DAVector2.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8772WEB-ACTIVEX DirectAnimation.DAVector2.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8773WEB-ACTIVEX DirectAnimation.DAVector2.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8774WEB-ACTIVEX DirectAnimation.DAUserData.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8775WEB-ACTIVEX DirectAnimation.DAUserData.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8776WEB-ACTIVEX DirectAnimation.DAUserData.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8777WEB-ACTIVEX DirectAnimation.DATransform3.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8778WEB-ACTIVEX DirectAnimation.DATransform3.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8779WEB-ACTIVEX DirectAnimation.DATransform3.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8780WEB-ACTIVEX DirectAnimation.DATransform2.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8781WEB-ACTIVEX DirectAnimation.DATransform2.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8782WEB-ACTIVEX DirectAnimation.DATransform2.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8783WEB-ACTIVEX DirectAnimation.DAString.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8784WEB-ACTIVEX DirectAnimation.DAString.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8785WEB-ACTIVEX DirectAnimation.DAString.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8786WEB-ACTIVEX DirectAnimation.DASound.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8787WEB-ACTIVEX DirectAnimation.DASound.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8788WEB-ACTIVEX DirectAnimation.DASound.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8789WEB-ACTIVEX DirectAnimation.DAPoint3.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8790WEB-ACTIVEX DirectAnimation.DAPoint3.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8791WEB-ACTIVEX DirectAnimation.DAPoint3.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8792WEB-ACTIVEX DirectAnimation.DAPoint2.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8793WEB-ACTIVEX DirectAnimation.DAPoint2.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8794WEB-ACTIVEX DirectAnimation.DAPoint2.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8795WEB-ACTIVEX DirectAnimation.DAPath2.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8796WEB-ACTIVEX DirectAnimation.DAPath2.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8797WEB-ACTIVEX DirectAnimation.DAPath2.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8798WEB-ACTIVEX DirectAnimation.DAPair.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8799WEB-ACTIVEX DirectAnimation.DAPair.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8800WEB-ACTIVEX DirectAnimation.DAPair.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8801WEB-ACTIVEX DirectAnimation.DANumber.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8802WEB-ACTIVEX DirectAnimation.DANumber.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8803WEB-ACTIVEX DirectAnimation.DANumber.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8804WEB-ACTIVEX DirectAnimation.DAMontage.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8805WEB-ACTIVEX DirectAnimation.DAMontage.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8806WEB-ACTIVEX DirectAnimation.DAMontage.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8807WEB-ACTIVEX DirectAnimation.DAMicrophone.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8808WEB-ACTIVEX DirectAnimation.DAMicrophone.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8809WEB-ACTIVEX DirectAnimation.DAMicrophone.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8810WEB-ACTIVEX DirectAnimation.DAMatte.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8811WEB-ACTIVEX DirectAnimation.DAMatte.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8812WEB-ACTIVEX DirectAnimation.DAMatte.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8813WEB-ACTIVEX DirectAnimation.DALineStyle.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8814WEB-ACTIVEX DirectAnimation.DALineStyle.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8815WEB-ACTIVEX DirectAnimation.DALineStyle.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8816WEB-ACTIVEX DirectAnimation.DAJoinStyle.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8817WEB-ACTIVEX DirectAnimation.DAJoinStyle.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8818WEB-ACTIVEX DirectAnimation.DAJoinStyle.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8819WEB-ACTIVEX DirectAnimation.DAImage.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8820WEB-ACTIVEX DirectAnimation.DAImage.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8821WEB-ACTIVEX DirectAnimation.DAImage.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8822WEB-ACTIVEX DirectAnimation.DAGeometry.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8823WEB-ACTIVEX DirectAnimation.DAGeometry.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8824WEB-ACTIVEX DirectAnimation.DAGeometry.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8825WEB-ACTIVEX DirectAnimation.DADashStyle.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8826WEB-ACTIVEX DirectAnimation.DADashStyle.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8827WEB-ACTIVEX DirectAnimation.DADashStyle.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8828WEB-ACTIVEX DirectAnimation.DAColor.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8829WEB-ACTIVEX DirectAnimation.DAColor.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8830WEB-ACTIVEX DirectAnimation.DAColor.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8831WEB-ACTIVEX DirectAnimation.DACamera.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8832WEB-ACTIVEX DirectAnimation.DACamera.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8833WEB-ACTIVEX DirectAnimation.DACamera.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8834WEB-ACTIVEX DirectAnimation.DABoolean.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8835WEB-ACTIVEX DirectAnimation.DABoolean.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8836WEB-ACTIVEX DirectAnimation.DABoolean.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8837WEB-ACTIVEX DirectAnimation.DABbox3.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8838WEB-ACTIVEX DirectAnimation.DABbox3.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8839WEB-ACTIVEX DirectAnimation.DABbox3.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8840WEB-ACTIVEX DirectAnimation.DABbox2.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8841WEB-ACTIVEX DirectAnimation.DABbox2.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8842WEB-ACTIVEX DirectAnimation.DABbox2.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8843WEB-ACTIVEX DirectAnimation.DAArray.1 ActiveX CLSID access (more info ...)attempted-user  2006-4777      URL
8844WEB-ACTIVEX DirectAnimation.DAArray.1 ActiveX CLSID unicode access (more info ...)attempted-user  2006-4777      URL
8845WEB-ACTIVEX DirectAnimation.DAArray.1 ActiveX function call access (more info ...)attempted-user  2006-4777      URL
8846WEB-ACTIVEX Microsoft Agent Character Custom Proxy Class ActiveX clsid access (more info ...)attempted-user  2007-1205      URL
8847WEB-ACTIVEX Microsoft Agent Character Custom Proxy Class ActiveX clsid unicode access (more info ...)attempted-user  2007-1205      URL
8848WEB-ACTIVEX Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid access (more info ...)attempted-user  2007-1205      URL
8849WEB-ACTIVEX Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid unicode access (more info ...)attempted-user  2007-1205      URL
8850WEB-ACTIVEX Microsoft Agent Custom Proxy Class ActiveX clsid access (more info ...)attempted-user  2007-1205      URL
8851WEB-ACTIVEX Microsoft Agent Custom Proxy Class ActiveX clsid unicode access (more info ...)attempted-user  2007-1205      URL
8852WEB-ACTIVEX Microsoft Agent v2.0 ActiveX clsid access (more info ...)attempted-user  2007-1205      URL
8853WEB-ACTIVEX Microsoft Agent v2.0 ActiveX clsid unicode access (more info ...)attempted-user  2007-1205      URL
8854WEB-ACTIVEX Microsoft Agent v2.0 ActiveX function call access (more info ...)attempted-user  2007-1205      URL
8855WEB-ACTIVEX Microsoft Agent v1.5 ActiveX clsid unicode access (more info ...)attempted-user  2007-1205      URL
8856WEB-ACTIVEX Microsoft Agent v1.5 ActiveX function call access (more info ...)attempted-user  2007-1205      URL
9027NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrJoinDomain2 overflow attempt (more info ...)attempted-admin  2006-4691    11921  URL
9129WEB-ACTIVEX WinZip FileView 6.1 ActiveX clsid access (more info ...)attempted-user  2006-5198  21108    URL
9130WEB-ACTIVEX WinZip FileView 6.1 ActiveX clsid unicode access (more info ...)attempted-user  2006-5198  21108    URL
9131WEB-ACTIVEX WinZip FileView 6.1 ActiveX function call access (more info ...)attempted-user  2006-5198  21108    URL
9427WEB-ACTIVEX Acer LunchApp.APlunch ActiveX clsid access (more info ...)attempted-user        URL
9428WEB-ACTIVEX Acer LunchApp.APlunch ActiveX clsid unicode access (more info ...)attempted-user        URL
9433WEB-CLIENT Microsoft Agent buffer overflow attempt (more info ...)attempted-user  2006-3445  21034    URL
9626WEB-ACTIVEX AcroPDF.PDF ActiveX clsid access (more info ...)attempted-user  2006-6236  21155    URL
9627WEB-ACTIVEX AcroPDF.PDF ActiveX clsid unicode access (more info ...)attempted-user  2006-6236  21155    URL
9629WEB-ACTIVEX Citrix.ICAClient ActiveX clsid access (more info ...)attempted-user  2006-6334  23246    URL
9630WEB-ACTIVEX Citrix.ICAClient ActiveX clsid unicode access (more info ...)attempted-user  2006-6334  23246    URL
9631WEB-ACTIVEX Citrix.ICAClient ActiveX function call access (more info ...)attempted-user  2006-6334  23246    URL
9640WEB-ACTIVEX ADODB.Connection ActiveX function call access (more info ...)attempted-user  2006-5559      URL
9769NETBIOS DCERPC NCACN-IP-TCP msqueue function 4 overflow attempt (more info ...)attempted-admin  2005-0059      URL
9793WEB-ACTIVEX YMMAPI.YMailAttach ActiveX clsid access (more info ...)attempted-user  2006-6603  21607    URL
9794WEB-ACTIVEX YMMAPI.YMailAttach ActiveX clsid unicode access (more info ...)attempted-user  2006-6603  21607    URL
9795WEB-ACTIVEX Panda ActiveScan ActiveScan.1 ActiveX clsid access (more info ...)attempted-user  2006-5966  21132    
9796WEB-ACTIVEX Panda ActiveScan ActiveScan.1 ActiveX clsid unicode access (more info ...)attempted-user  2006-5966  21132    
9797WEB-ACTIVEX Panda ActiveScan ActiveScan.1 ActiveX function call access (more info ...)attempted-user        
9798WEB-ACTIVEX Panda ActiveScan PAVPZ.SOS.1 ActiveX clsid access (more info ...)attempted-user  2006-5966  21132    
9799WEB-ACTIVEX Panda ActiveScan PAVPZ.SOS.1 ActiveX clsid unicode access (more info ...)attempted-user  2006-5966  21132    
9800WEB-ACTIVEX Panda ActiveScan PAVPZ.SOS.1 ActiveX function call access (more info ...)attempted-user        
9806NETBIOS DCERPC NCACN-IP-TCP brightstor-arc GetGroupStatus overflow attempt (more info ...)attempted-admin  2006-6076  21221    URL
9812WEB-ACTIVEX Yahoo Messenger YMailAttach ActiveX function call access (more info ...)attempted-user  2006-6603  21607    URL
9814WEB-ACTIVEX ICQPhone.SipxPhoneManager ActiveX clsid access (more info ...)attempted-user  2006-5650  20930    
9815WEB-ACTIVEX ICQPhone.SipxPhoneManager ActiveX clsid unicode access (more info ...)attempted-user  2006-5650  20930    
9816WEB-ACTIVEX ICQPhone.SipxPhoneManager ActiveX function call access (more info ...)attempted-user  2006-5650  20930    
9817WEB-ACTIVEX CEnroll.CEnroll.2 ActiveX clsid access (more info ...)attempted-user        URL
9818WEB-ACTIVEX CEnroll.CEnroll.2 ActiveX clsid unicode access (more info ...)attempted-user        URL
9820WEB-ACTIVEX OWC11.DataSourceControl.11 ActiveX function call access (more info ...)attempted-user  2006-3729  19069    URL
9821WEB-ACTIVEX TriEditDocument.TriEditDocument ActiveX clsid access (more info ...)attempted-user  2006-3591  18946    URL
9822WEB-ACTIVEX TriEditDocument.TriEditDocument ActiveX clsid unicode access (more info ...)attempted-user  2006-3591  18946    URL
9824WEB-ACTIVEX Rediff Bol Downloader ActiveX clsid access (more info ...)attempted-user  2006-6838  21831    
9825WEB-ACTIVEX Rediff Bol Downloader ActiveX clsid unicode access (more info ...)attempted-user  2006-6838  21831    
9826WEB-ACTIVEX Rediff Bol Downloader ActiveX function call access (more info ...)attempted-user  2006-6838  21831    
10013WEB-ACTIVEX CCRP FolderTreeView ActiveX clsid access (more info ...)attempted-user    22092    URL
10014WEB-ACTIVEX CCRP FolderTreeView ActiveX clsid unicode access (more info ...)attempted-user    22092    URL
10015WEB-ACTIVEX Oracle ORADC ActiveX clsid access (more info ...)attempted-user    22026    
10016WEB-ACTIVEX Oracle ORADC ActiveX clsid unicode access (more info ...)attempted-user    22026    
10017WEB-ACTIVEX Oracle ORADC ActiveX function call access (more info ...)attempted-user    22026    
10018NETBIOS DCERPC NCACN-IP-TCP brightstor-arc ReserveGroup attempt (more info ...)protocol-command-decode  2006-6917      URL
10050NETBIOS DCERPC NCACN-IP-TCP brightstor-arc2 ASDBLoginToComputer overflow attempt (more info ...)attempted-admin  2007-0169  22005    URL
10084WEB-ACTIVEX NCTAudioFile2 ActiveX clsid access (more info ...)attempted-user  2007-0018  33469    URL
10085WEB-ACTIVEX NCTAudioFile2 ActiveX clsid unicode access (more info ...)attempted-user  2007-0018  33469    URL
10086WEB-ACTIVEX NCTAudioFile2 ActiveX function call access (more info ...)attempted-user  2007-0018  33469    URL
10115WEB-CLIENT Microsoft WMF denial of service attempt (more info ...)web-application-attack  2006-4071  21992    
10128WEB-ACTIVEX Aliplay ActiveX clsid access (more info ...)attempted-user    22446    
10129WEB-ACTIVEX Aliplay ActiveX clsid unicode access (more info ...)attempted-user    22446    
10137WEB-ACTIVEX Microsoft Input Method Editor ActiveX clsid access (more info ...)attempted-user  2006-4697      URL
10138WEB-ACTIVEX Microsoft Input Method Editor ActiveX clsid unicode access (more info ...)attempted-user  2006-4697      URL
10139WEB-ACTIVEX Microsoft Input Method Editor ActiveX function call access (more info ...)attempted-user  2006-4697      URL
10140WEB-ACTIVEX Microsoft Input Method Editor 2 ActiveX clsid access (more info ...)attempted-user  2006-4697      URL
10141WEB-ACTIVEX Microsoft Input Method Editor 2 ActiveX clsid unicode access (more info ...)attempted-user  2006-4697      URL
10142WEB-ACTIVEX LexRefBilingualTextContext ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10143WEB-ACTIVEX LexRefBilingualTextContext ActiveX clsid unicode access (more info ...)attempted-user  2007-0219      URL
10144WEB-ACTIVEX LexRefBilingualTextContext ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10145WEB-ACTIVEX HTML Inline Sound Control ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10146WEB-ACTIVEX HTML Inline Sound Control ActiveX clsid unicode access (more info ...)attempted-user  2007-0219      URL
10147WEB-ACTIVEX HTML Inline Sound Control ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10148WEB-ACTIVEX HTML Inline Movie Control ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10149WEB-ACTIVEX HTML Inline Movie Control ActiveX clsid unicode access (more info ...)attempted-user  2007-0219      URL
10150WEB-ACTIVEX HTML Inline Movie Control ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10151WEB-ACTIVEX BlnSetUser Proxy ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10152WEB-ACTIVEX BlnSetUser Proxy ActiveX clsid unicode access (more info ...)attempted-user  2007-0219      URL
10153WEB-ACTIVEX BlnSetUser Proxy ActiveX function call access (more info ...)attempted-user  2007-0219      URL
10154WEB-ACTIVEX BlnSetUser Proxy 2 ActiveX clsid access (more info ...)attempted-user  2007-0219      URL
10155WEB-ACTIVEX BlnSetUser Proxy 2 ActiveX clsid unicode access (more info ...)attempted-user  2007-0219      URL
10156WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX clsid access (more info ...)attempted-user    22558    URL
10157WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX clsid unicode access (more info ...)attempted-user    22558    URL
10162WEB-ACTIVEX BrowseDialog ActiveX clsid access (more info ...)attempted-user    22110    
10163WEB-ACTIVEX BrowseDialog ActiveX clsid unicode access (more info ...)attempted-user    22110    
10170WEB-ACTIVEX Verisign ConfigCHK ActiveX clsid access (more info ...)attempted-user    22676    
10171WEB-ACTIVEX Verisign ConfigCHK ActiveX clsid unicode access (more info ...)attempted-user    22676    
10176WEB-ACTIVEX Windows Shell User Enumeration Object ActiveX clsid access (more info ...)attempted-user        
10177WEB-ACTIVEX Windows Shell User Enumeration Object ActiveX clsid unicode access (more info ...)attempted-user        
10178WEB-ACTIVEX Windows Shell User Enumeration Object ActiveX function call access (more info ...)attempted-user        
10189WEB-ACTIVEX DivXBrowserPlugin ActiveX clsid access (more info ...)attempted-user        
10190WEB-ACTIVEX DivXBrowserPlugin ActiveX clsid unicode access (more info ...)attempted-user        
10191WEB-ACTIVEX DivXBrowserPlugin ActiveX function call access (more info ...)attempted-user        
10214WEB-ACTIVEX Shockwave ActiveX Control ActiveX clsid access (more info ...)attempted-user  2006-6885  22842    
10215WEB-ACTIVEX Shockwave ActiveX Control ActiveX clsid unicode access (more info ...)attempted-user  2006-6885  22842    
10216WEB-ACTIVEX Shockwave ActiveX Control ActiveX function call access (more info ...)attempted-user  2006-6885  22842    
10387WEB-ACTIVEX McAfee ePolicy Orchestrator ActiveX clsid access (more info ...)attempted-user    22952    URL
10388WEB-ACTIVEX McAfee ePolicy Orchestrator ActiveX clsid unicode access (more info ...)attempted-user    22952    URL
10389WEB-ACTIVEX McAfee ePolicy Orchestrator ActiveX function call access (more info ...)attempted-user    22952    URL
10390WEB-ACTIVEX Symantec Support Controls SmartIssue ActiveX clsid access (more info ...)attempted-user  2006-6490  22564    URL
10391WEB-ACTIVEX Symantec Support Controls SmartIssue ActiveX clsid unicode access (more info ...)attempted-user  2006-6490  22564    URL
10392WEB-ACTIVEX Symantec Support Controls SmartIssue ActiveX function call access (more info ...)attempted-user  2006-6490  22564    URL
10404WEB-ACTIVEX SignKorea SKCommAX ActiveX clsid access (more info ...)attempted-user        
10405WEB-ACTIVEX SignKorea SKCommAX ActiveX clsid unicode access (more info ...)attempted-user        
10406WEB-ACTIVEX SignKorea SKCommAX ActiveX function call access (more info ...)attempted-user        
10412WEB-ACTIVEX IBM Lotus SameTime STJNILoader Alt CLSID ActiveX clsid access (more info ...)attempted-user  2007-1784  23201    URL
10413WEB-ACTIVEX IBM Lotus SameTime STJNILoader Alt CLSID ActiveX clsid unicode access (more info ...)attempted-user    23201    URL
10414WEB-ACTIVEX IBM Lotus SameTime STJNILoader Alt CLSID ActiveX function call access (more info ...)attempted-user    23201    URL
10415WEB-ACTIVEX IBM Lotus SameTime STJNILoader ActiveX clsid access (more info ...)attempted-user    23201    URL
10416WEB-ACTIVEX IBM Lotus SameTime STJNILoader ActiveX clsid unicode access (more info ...)attempted-user    23201    URL
10417WEB-ACTIVEX IBM Lotus SameTime STJNILoader ActiveX function call access (more info ...)attempted-user    23201    URL
10419WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX clsid access (more info ...)attempted-user  2007-1819  23239    URL
10420WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX clsid unicode access (more info ...)attempted-user  2007-1819  23239    URL
10421WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX function call access (more info ...)attempted-user  2007-1819  23239    URL
10422WEB-ACTIVEX HP Mercury Quality Center SPIDERLib ActiveX function call unicode access (more info ...)attempted-user  2007-1819  23239    URL
10423WEB-ACTIVEX Yahoo Audio Conferencing ActiveX clsid access (more info ...)attempted-user  2007-1680  23291    URL
10424WEB-ACTIVEX Yahoo Audio Conferencing ActiveX clsid unicode access (more info ...)attempted-user  2007-1680  23291    URL
10425WEB-ACTIVEX Yahoo Audio Conferencing ActiveX function call access (more info ...)attempted-user  2007-1680  23291    URL
10426WEB-ACTIVEX Yahoo Audio Conferencing ActiveX function call unicode access (more info ...)attempted-user  2007-1680  23291    URL
10427WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX clsid access (more info ...)attempted-user  2007-1112  23325    URL
10428WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX clsid unicode access (more info ...)attempted-user  2007-1112  23325    URL
10429WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX function call access (more info ...)attempted-user  2007-1112  23325    URL
10430WEB-ACTIVEX Kaspersky AntiVirus SysInfo ActiveX function call unicode access (more info ...)attempted-user  2007-1112  23325    URL
10431WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX clsid access (more info ...)attempted-user  2007-1112  23345    URL
10432WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX clsid unicode access (more info ...)attempted-user  2007-1112  23345    URL
10433WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX function call access (more info ...)attempted-user  2007-1112  23345    URL
10434WEB-ACTIVEX Kaspersky AntiVirus KAV60Info ActiveX function call unicode access (more info ...)attempted-user  2007-1112  23345    URL
10465WEB-ACTIVEX Microsoft Agent v1.5 ActiveX function call unicode access (more info ...)attempted-user  2007-1205      URL
10466WEB-ACTIVEX iPIX Image Well ActiveX clsid access (more info ...)attempted-user  2007-1687  23379    URL
10467WEB-ACTIVEX iPIX Image Well ActiveX clsid unicode access (more info ...)attempted-user  2007-1687  23379    URL
10468WEB-ACTIVEX iPIX Image Well ActiveX function call access (more info ...)attempted-user  2007-1687  23379    URL
10469WEB-ACTIVEX iPIX Image Well ActiveX function call access (more info ...)attempted-user  2007-1687  23379    URL
10470WEB-ACTIVEX iPIX Media Send Class ActiveX clsid access (more info ...)attempted-user  2007-1687  23379    URL
10471WEB-ACTIVEX iPIX Media Send Class ActiveX clsid unicode access (more info ...)attempted-user  2007-1687  23379    URL
10472WEB-ACTIVEX iPIX Media Send Class ActiveX function call access (more info ...)attempted-user  2007-1687  23379    URL
10473WEB-ACTIVEX iPIX Media Send Class ActiveX function call access (more info ...)attempted-user  2007-1687  23379    URL
10474WEB-ACTIVEX iPIX Media Send Class ActiveX function call unicode access (more info ...)attempted-user  2007-1687  23379    URL
10476WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX clsid access (more info ...)attempted-user    23420    
10477WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX clsid unicode access (more info ...)attempted-user    23420    
10478WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX function call access (more info ...)attempted-user    23420    
10479WEB-ACTIVEX MarkAny MaPrintModule_WORK ActiveX function call unicode access (more info ...)attempted-user    23420    
10978WEB-ACTIVEX Second Sight Software ActiveGS ActiveX clsid access (more info ...)attempted-user  2007-1690  23554    URL
10979WEB-ACTIVEX Second Sight Software ActiveGS ActiveX clsid unicode access (more info ...)attempted-user  2007-1690  23554    URL
10980WEB-ACTIVEX Second Sight Software ActiveGS ActiveX function call access (more info ...)attempted-user  2007-1690  23554    URL
10981WEB-ACTIVEX Second Sight Software ActiveGS ActiveX function call unicode access (more info ...)attempted-user  2007-1690  23554    URL
10982WEB-ACTIVEX Second Sight Software ActiveMod ActiveX clsid access (more info ...)attempted-user  2007-1691  23554    URL
10983WEB-ACTIVEX Second Sight Software ActiveMod ActiveX clsid unicode access (more info ...)attempted-user  2007-1691  23554    URL
10984WEB-ACTIVEX Second Sight Software ActiveMod ActiveX function call access (more info ...)attempted-user  2007-1691  23554    URL
10985WEB-ACTIVEX Second Sight Software ActiveMod ActiveX function call unicode access (more info ...)attempted-user  2007-1691  23554    URL
10986WEB-ACTIVEX GraceNote CDDB ActiveX clsid access (more info ...)attempted-user  2007-0443  23567    URL
10987WEB-ACTIVEX GraceNote CDDB ActiveX clsid unicode access (more info ...)attempted-user  2007-0443  23567    URL
10988WEB-ACTIVEX GraceNote CDDB ActiveX function call access (more info ...)attempted-user  2007-0443  23567    URL
10989WEB-ACTIVEX GraceNote CDDB ActiveX function call unicode access (more info ...)attempted-user  2007-0443  23567    URL
10991WEB-ACTIVEX Microgaming Download Helper ActiveX clsid access (more info ...)attempted-user    23595    URL
10992WEB-ACTIVEX Microgaming Download Helper ActiveX clsid unicode access (more info ...)attempted-user    23595    URL
10993WEB-ACTIVEX Microgaming Download Helper ActiveX function call access (more info ...)attempted-user    23595    URL
10994WEB-ACTIVEX Microgaming Download Helper ActiveX function call unicode access (more info ...)attempted-user    23595    URL
11176WEB-ACTIVEX PowerPoint Viewer ActiveX clsid access (more info ...)attempted-user    33243    URL
11177WEB-ACTIVEX PowerPoint Viewer ActiveX clsid unicode access (more info ...)attempted-user    33243    URL
11178WEB-ACTIVEX PowerPoint Viewer ActiveX function call access (more info ...)attempted-user    33243    URL
11179WEB-ACTIVEX PowerPoint Viewer ActiveX function call unicode access (more info ...)attempted-user    33243    URL
11197WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX function call access (more info ...)attempted-user    22558    URL
11198WEB-ACTIVEX ActiveX Soft DVD Tools ActiveX function call unicode access (more info ...)attempted-user    22558    URL
11206WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX clsid access (more info ...)attempted-user    23833    URL
11207WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX clsid unicode access (more info ...)attempted-user    23833    URL
11208WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX function call access (more info ...)attempted-user    23833    URL
11209WEB-ACTIVEX East Wind Software ADVDAUDIO ActiveX function call unicode access (more info ...)attempted-user    23833    URL
11210WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX clsid access (more info ...)attempted-user    23838    URL
11211WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX clsid unicode access (more info ...)attempted-user    23838    URL
11212WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX function call access (more info ...)attempted-user    23838    URL
11213WEB-ACTIVEX Sienzo Digital Music Mentor ActiveX function call unicode access (more info ...)attempted-user    23838    URL
11214WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX clsid access (more info ...)attempted-user    23853    URL
11215WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX clsid unicode access (more info ...)attempted-user    23853    URL
11216WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX function call access (more info ...)attempted-user    23853    URL
11217WEB-ACTIVEX VeralSoft HTTP File Uploader ActiveX function call unicode access (more info ...)attempted-user    23853    URL
11218WEB-ACTIVEX SmartCode VNC Manager ActiveX clsid access (more info ...)attempted-user    23869    URL
11219WEB-ACTIVEX SmartCode VNC Manager ActiveX clsid unicode access (more info ...)attempted-user    23869    URL
11220WEB-ACTIVEX SmartCode VNC Manager ActiveX function call access (more info ...)attempted-user    23869    URL
11221WEB-ACTIVEX SmartCode VNC Manager ActiveX function call unicode access (more info ...)attempted-user    23869    URL
11224WEB-ACTIVEX MSAuth ActiveX clsid access (more info ...)attempted-user  2007-2221      URL
11225WEB-ACTIVEX MSAuth ActiveX clsid unicode access (more info ...)attempted-user  2007-2221      URL
11226WEB-ACTIVEX MSAuth ActiveX function call access (more info ...)attempted-user  2007-2221      URL
11227WEB-ACTIVEX MSAuth ActiveX function call unicode access (more info ...)attempted-user  2007-2221      URL
11228WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX clsid access (more info ...)attempted-user  2007-0942      URL
11229WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX clsid unicode access (more info ...)attempted-user  2007-0942      URL
11230WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX clsid access (more info ...)attempted-user  2007-0940      URL
11231WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX clsid unicode access (more info ...)attempted-user  2007-0940      URL
11232WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX function call access (more info ...)attempted-user  2007-0940      URL
11233WEB-ACTIVEX Microsoft Cryptographic API COM 1 ActiveX function call unicode access (more info ...)attempted-user  2007-0940      URL
11234WEB-ACTIVEX Microsoft Cryptographic API COM 2 ActiveX clsid access (more info ...)attempted-user  2007-0940      URL
11235WEB-ACTIVEX Microsoft Cryptographic API COM 2 ActiveX clsid unicode access (more info ...)attempted-user  2007-0940      URL
11239WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX clsid access (more info ...)attempted-user        URL
11240WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX clsid unicode access (more info ...)attempted-user        URL
11241WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX function call access (more info ...)attempted-user        URL
11242WEB-ACTIVEX DXImageTransform.Microsoft.Redirect ActiveX function call unicode access (more info ...)attempted-user        URL
11243WEB-ACTIVEX DirectAnimation.DAstatics ActiveX clsid access (more info ...)attempted-user        URL
11244WEB-ACTIVEX DirectAnimation.DAstatics ActiveX clsid unicode access (more info ...)attempted-user        URL
11245WEB-ACTIVEX DirectAnimation.DAstatics ActiveX function call access (more info ...)attempted-user        URL
11246WEB-ACTIVEX DirectAnimation.DAstatics ActiveX function call unicode access (more info ...)attempted-user        URL
11247WEB-ACTIVEX Research In Motion TeamOn Import ActiveX clsid access (more info ...)attempted-user    23331    URL
11248WEB-ACTIVEX Research In Motion TeamOn Import ActiveX clsid unicode access (more info ...)attempted-user    23331    URL
11249WEB-ACTIVEX IE Address ActiveX clsid unicode access (more info ...)attempted-user        URL
11250WEB-ACTIVEX Sony Rootkit Uninstaller ActiveX clsid access (more info ...)attempted-user        URL
11251WEB-ACTIVEX Sony Rootkit Uninstaller ActiveX clsid unicode access (more info ...)attempted-user        URL
11252WEB-ACTIVEX IE Address ActiveX clsid access (more info ...)attempted-user        URL
11253WEB-ACTIVEX Microsoft MciWndx ActiveX clsid access (more info ...)attempted-user        
11254WEB-ACTIVEX Microsoft MciWndx ActiveX clsid unicode access (more info ...)attempted-user        
11255WEB-ACTIVEX Microsoft MciWndx ActiveX function call access (more info ...)attempted-user        
11256WEB-ACTIVEX Microsoft MciWndx ActiveX function call unicode access (more info ...)attempted-user        
11259WEB-ACTIVEX BarcodeWiz ActiveX clsid access (more info ...)attempted-user    23891    URL
11260WEB-ACTIVEX BarcodeWiz ActiveX clsid unicode access (more info ...)attempted-user    23891    URL
11261WEB-ACTIVEX BarcodeWiz ActiveX function call access (more info ...)attempted-user    23891    URL
11262WEB-ACTIVEX BarcodeWiz ActiveX function call unicode access (more info ...)attempted-user    23891    URL
11268WEB-ACTIVEX Symantec Norton AntiVirus ActiveX clsid access (more info ...)attempted-user  2006-3456  23822    URL
11269WEB-ACTIVEX Symantec Norton AntiVirus ActiveX clsid unicode access (more info ...)attempted-user  2006-3456  23822    URL
11270WEB-ACTIVEX Symantec Norton AntiVirus ActiveX function call access (more info ...)attempted-user  2006-3456  23822    URL
11271WEB-ACTIVEX Symantec Norton AntiVirus ActiveX function call unicode access (more info ...)attempted-user  2006-3456  23822    URL
11274WEB-ACTIVEX RControl ActiveX clsid access (more info ...)attempted-user    23914    URL
11275WEB-ACTIVEX RControl ActiveX clsid unicode access (more info ...)attempted-user    23914    URL
11276WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX clsid access (more info ...)attempted-user    23907    
11277WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX clsid unicode access (more info ...)attempted-user    23907    
11278WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX function call access (more info ...)attempted-user    23907    
11279WEB-ACTIVEX GDivX Zenith Player AVI Fixer ActiveX function call unicode access (more info ...)attempted-user    23907    
11280WEB-ACTIVEX FlexLabel ActiveX clsid access (more info ...)attempted-user        URL
11281WEB-ACTIVEX FlexLabel ActiveX clsid unicode access (more info ...)attempted-user        URL
11282WEB-ACTIVEX FlexLabel ActiveX function call access (more info ...)attempted-user        URL
11283WEB-ACTIVEX FlexLabel ActiveX function call unicode access (more info ...)attempted-user        URL
11284WEB-ACTIVEX AudioCDRipper ActiveX clsid access (more info ...)attempted-user    23900    
11285WEB-ACTIVEX AudioCDRipper ActiveX clsid unicode access (more info ...)attempted-user    23900    
11286WEB-ACTIVEX AudioCDRipper ActiveX function call access (more info ...)attempted-user    23900    
11287WEB-ACTIVEX AudioCDRipper ActiveX function call unicode access (more info ...)attempted-user    23900    
11291WEB-ACTIVEX Hewlett Packard HPQVWOCX.DL ActiveX clsid access (more info ...)attempted-user    24793    
11292WEB-ACTIVEX Hewlett Packard HPQVWOCX.DL ActiveX clsid unicode access (more info ...)attempted-user    24793    
11293WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX clsid access (more info ...)attempted-user    23954    URL
11294WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX clsid unicode access (more info ...)attempted-user    23954    URL
11295WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX function call access (more info ...)attempted-user    23954    URL
11296WEB-ACTIVEX IDAutomation Linear Bar Code ActiveX function call unicode access (more info ...)attempted-user    23954    URL
11297WEB-ACTIVEX Clever Database Comparer ActiveX clsid access (more info ...)attempted-user    23969    URL
11298WEB-ACTIVEX Clever Database Comparer ActiveX clsid unicode access (more info ...)attempted-user    23969    URL
11299WEB-ACTIVEX Clever Database Comparer ActiveX function call access (more info ...)attempted-user    23969    URL
11300WEB-ACTIVEX Clever Database Comparer ActiveX function call unicode access (more info ...)attempted-user    23969    URL
11301WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX clsid access (more info ...)attempted-user    23986    URL
11302WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX clsid unicode access (more info ...)attempted-user    23986    URL
11303WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX function call access (more info ...)attempted-user    23986    URL
11304WEB-ACTIVEX DB Software Laboratory DeWizardX ActiveX function call unicode access (more info ...)attempted-user    23986    URL
11324WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX function call access (more info ...)attempted-user  2007-0942      URL
11325WEB-ACTIVEX Microsoft Input Method Editor 3 ActiveX function call unicode access (more info ...)attempted-user  2007-0942      URL
11618EXPLOIT Trend Micro ServerProtect EarthAgent DCE-RPC Stack overflow (more info ...)attempted-admin  2007-2508  23866    
11822WEB-ACTIVEX Yahoo Webcam Upload ActiveX clsid access (more info ...)attempted-user  2007-3147  24341    
11823WEB-ACTIVEX Yahoo Webcam Upload ActiveX clsid unicode access (more info ...)attempted-user  2007-3147  24341    
11824WEB-ACTIVEX Yahoo Webcam Upload ActiveX function call access (more info ...)attempted-user  2007-3147  24341    
11825WEB-ACTIVEX Yahoo Webcam Upload ActiveX function call unicode access (more info ...)attempted-user  2007-3147  24341    
12010WEB-ACTIVEX RKD Software BarCode ActiveX clsid access (more info ...)attempted-user  2007-3435  24596    
12011WEB-ACTIVEX RKD Software BarCode ActiveX clsid unicode access (more info ...)attempted-user  2007-3435  24596    
12012WEB-ACTIVEX RKD Software BarCode ActiveX function call access (more info ...)attempted-user  2007-3435  24596    
12013WEB-ACTIVEX RKD Software BarCode ActiveX function call unicode access (more info ...)attempted-user  2007-3435  24596    
12069EXPLOIT Microsoft Windows Active Directory Crafted LDAP ModifyRequest (more info ...)attempted-admin  2007-0040      URL
12144BACKDOOR access remote pc runtime detection - rpc setup (more info ...)trojan-activity        
12187RPC portmap 2112 tcp rename_principal attempt (more info ...)rpc-portmap-decode  2007-2798  24653    URL
12188RPC portmap 2112 udp rename_principal attempt (more info ...)rpc-portmap-decode  2007-2798  24653    URL
12279WEB-CLIENT Microsoft XML substringData integer overflow attempt (more info ...)attempted-user  2008-1442      URL
12307NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetPagerNotifyConfig attempt (more info ...)protocol-command-decode  2007-4218  25395    
12317NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect-earthagent RPCFN_CopyAUSrc attempt (more info ...)protocol-command-decode  2007-4218  25395    
12326NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _AddTaskExportLogItem attempt (more info ...)protocol-command-decode  2007-4218  25395    
12332NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _TakeActionOnAFile attempt (more info ...)protocol-command-decode  2007-4218  25395    
12335NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_30010 overflow attempt (more info ...)attempted-admin  2007-4218  25395    
12341NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect Trent_req_num_a0030 attempt (more info ...)protocol-command-decode  2007-4218  25395    
12347NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetSvcImpersonateUser attempt (more info ...)protocol-command-decode  2007-4218  25395    
12393WEB-ACTIVEX Intuit QuickBooks Online Edition 1 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12394WEB-ACTIVEX Intuit QuickBooks Online Edition 1 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12395WEB-ACTIVEX Intuit QuickBooks Online Edition 2 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12396WEB-ACTIVEX Intuit QuickBooks Online Edition 2 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12397WEB-ACTIVEX Intuit QuickBooks Online Edition 3 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12398WEB-ACTIVEX Intuit QuickBooks Online Edition 3 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12399WEB-ACTIVEX Intuit QuickBooks Online Edition 4 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12400WEB-ACTIVEX Intuit QuickBooks Online Edition 4 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12401WEB-ACTIVEX Intuit QuickBooks Online Edition 5 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12402WEB-ACTIVEX Intuit QuickBooks Online Edition 5 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12403WEB-ACTIVEX Intuit QuickBooks Online Edition 6 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12404WEB-ACTIVEX Intuit QuickBooks Online Edition 6 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12405WEB-ACTIVEX Intuit QuickBooks Online Edition 7 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12406WEB-ACTIVEX Intuit QuickBooks Online Edition 7 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12407WEB-ACTIVEX Intuit QuickBooks Online Edition 8 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12408WEB-ACTIVEX Intuit QuickBooks Online Edition 8 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12409WEB-ACTIVEX Intuit QuickBooks Online Edition 9 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12410WEB-ACTIVEX Intuit QuickBooks Online Edition 9 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12411WEB-ACTIVEX Intuit QuickBooks Online Edition 10 ActiveX clsid access (more info ...)attempted-user  2007-4471  25544    URL
12412WEB-ACTIVEX Intuit QuickBooks Online Edition 10 ActiveX clsid unicode access (more info ...)attempted-user  2007-4471  25544    URL
12417WEB-ACTIVEX Microsoft Visual FoxPro ActiveX clsid access (more info ...)attempted-user  2007-5322  25977    
12418WEB-ACTIVEX Microsoft Visual FoxPro ActiveX clsid unicode access (more info ...)attempted-user  2007-5322  25977    
12419WEB-ACTIVEX Microsoft Visual FoxPro ActiveX function call access (more info ...)attempted-user  2007-5322  25977    
12420WEB-ACTIVEX Microsoft Visual FoxPro ActiveX function call unicode access (more info ...)attempted-user  2007-5322  25977    
12466WEB-ACTIVEX MW6 Technologies QRCode ActiveX clsid access (more info ...)attempted-user  2007-4982  25702    
12467WEB-ACTIVEX MW6 Technologies QRCode ActiveX clsid unicode access (more info ...)attempted-user  2007-4982  25702    
12489NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrWkstaGetInfo attempt (more info ...)protocol-command-decode  2006-6723      
12612WEB-ACTIVEX Microsoft Windows MFC Library ActiveX clsid access (more info ...)attempted-user  2007-4916  25697    
12613WEB-ACTIVEX Microsoft Windows MFC Library ActiveX clsid unicode access (more info ...)attempted-user  2007-4916  25697    
12614WEB-ACTIVEX Microsoft Windows MFC Library ActiveX function call access (more info ...)attempted-user  2007-4916  25697    
12615WEB-ACTIVEX Microsoft Windows MFC Library ActiveX function call unicode access (more info ...)attempted-user  2007-4916  25697    
12664MISC Microsoft Windows ShellExecute and IE7 url handling code execution attempt (more info ...)attempted-user  2007-3896  25945    URL
12687WEB-CLIENT Microsoft Windows ShellExecute and IE7 url handling code execution attempt (more info ...)attempted-user  2007-3896  25945    URL
12688WEB-CLIENT Microsoft Windows ShellExecute and IE7 url handling code execution attempt (more info ...)attempted-user  2007-3896  25945    URL
12751WEB-ACTIVEX RichFX Basic Player ActiveX clsid access (more info ...)attempted-user    26573    
12752WEB-ACTIVEX RichFX Basic Player ActiveX clsid unicode access (more info ...)attempted-user    26573    
12753WEB-ACTIVEX RichFX Basic Player ActiveX function call access (more info ...)attempted-user    26573    
12754WEB-ACTIVEX RichFX Basic Player ActiveX function call unicode access (more info ...)attempted-user    26573    
12755WEB-ACTIVEX PPStream PowerList ActiveX clsid access (more info ...)attempted-user    26580    
12756WEB-ACTIVEX PPStream PowerList ActiveX clsid unicode access (more info ...)attempted-user    26580    
12762WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX clsid access (more info ...)attempted-user  2007-6228  26656    
12763WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX clsid unicode access (more info ...)attempted-user  2007-6228  26656    
12764WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX function call access (more info ...)attempted-user  2007-6228  26656    
12765WEB-ACTIVEX Yahoo Toolbar Helper Class ActiveX function call unicode access (more info ...)attempted-user  2007-6228  26656    
12770SPECIFIC-THREATS obfuscated RDS.Dataspace ActiveX exploit attempt (more info ...)attempted-user  2006-0003  17462    URL
12771SPECIFIC-THREATS obfuscated BaoFeng Storm MPS.dll ActiveX exploit attempt (more info ...)attempted-user  2007-4816  25601    
12772SPECIFIC-THREATS obfuscated PPStream PowerPlayer ActiveX exploit attempt (more info ...)attempted-user  2007-4748  25502    
12773SPECIFIC-THREATS obfuscated Xunlei Thunder PPLAYER.DLL ActiveX exploit attempt (more info ...)attempted-user  2007-6144  26536    
12774SPECIFIC-THREATS obfuscated GlobalLink ConnectAndEnterRoom ActiveX exploit attempt (more info ...)attempted-user  2007-5722  26244    
12803WEB-ACTIVEX VideoLAN VLC ActiveX clsid access (more info ...)attempted-user  2007-6262  26675    URL
12804WEB-ACTIVEX VideoLAN VLC ActiveX clsid unicode access (more info ...)attempted-user  2007-6262  26675    URL
12805WEB-ACTIVEX VideoLAN VLC ActiveX function call access (more info ...)attempted-user  2007-6262  26675    URL
12806WEB-ACTIVEX VideoLAN VLC ActiveX function call unicode access (more info ...)attempted-user  2007-6262  26675    URL
12808NETBIOS DCERPC NCACN-IP-TCP spoolss OpenPrinter overflow attempt (more info ...)attempted-admin  2006-5854  21220    
12910NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 4 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12916NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 12 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12922NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 16 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12928NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 18 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12934NETBIOS DCERPC NCACN-IP-TCP brightstor-arc3 CA opcode 19 attempt (more info ...)protocol-command-decode  2007-5329  26015    
12946NETBIOS SMB-DS SMBv2 protocol negotiation attempt (more info ...)attempted-admin  2007-5351      URL
12947NETBIOS SMB SMBv2 protocol negotiation attempt (more info ...)attempted-admin  2007-5351      URL
12948WEB-ACTIVEX Vantage Linguistics 1 ActiveX clsid access (more info ...)attempted-user        URL
12949WEB-ACTIVEX Vantage Linguistics 1 ActiveX clsid unicode access (more info ...)attempted-user        URL
12950WEB-ACTIVEX Vantage Linguistics 2 ActiveX clsid access (more info ...)attempted-user        URL
12951WEB-ACTIVEX Vantage Linguistics 2 ActiveX clsid unicode access (more info ...)attempted-user        URL
12952WEB-ACTIVEX Vantage Linguistics 3 ActiveX clsid access (more info ...)attempted-user        URL
12953WEB-ACTIVEX Vantage Linguistics 3 ActiveX clsid unicode access (more info ...)attempted-user        URL
12954WEB-ACTIVEX DXLTPI.DLL ActiveX clsid access (more info ...)attempted-user        URL
12955WEB-ACTIVEX DXLTPI.DLL ActiveX clsid unicode access (more info ...)attempted-user        URL
12956WEB-ACTIVEX MSN Heartbeat ActiveX clsid unicode access (more info ...)attempted-user    11367    URL
12957WEB-ACTIVEX MSN Heartbeat 2 ActiveX clsid access (more info ...)attempted-user        URL
12958WEB-ACTIVEX MSN Heartbeat 2 ActiveX clsid unicode access (more info ...)attempted-user        URL
12959WEB-ACTIVEX MSN Heartbeat 3 ActiveX clsid access (more info ...)attempted-user        URL
12960WEB-ACTIVEX MSN Heartbeat 3 ActiveX clsid unicode access (more info ...)attempted-user        URL
12961WEB-ACTIVEX Intuit QuickBooks Online Import 1 ActiveX clsid access (more info ...)attempted-user        URL
12962WEB-ACTIVEX Intuit QuickBooks Online Import 1 ActiveX clsid unicode access (more info ...)attempted-user        URL
12963WEB-ACTIVEX Intuit QuickBooks Online Import 2 ActiveX clsid access (more info ...)attempted-user        URL
12964WEB-ACTIVEX Intuit QuickBooks Online Import 2 ActiveX clsid unicode access (more info ...)attempted-user        URL
12965WEB-ACTIVEX Intuit QuickBooks Online Import 3 ActiveX clsid access (more info ...)attempted-user        URL
12966WEB-ACTIVEX Intuit QuickBooks Online Import 3 ActiveX clsid unicode access (more info ...)attempted-user        URL
12967WEB-ACTIVEX Intuit QuickBooks Online Import 4 ActiveX clsid access (more info ...)attempted-user        URL
12968WEB-ACTIVEX Intuit QuickBooks Online Import 4 ActiveX clsid unicode access (more info ...)attempted-user        URL
12969WEB-ACTIVEX Intuit QuickBooks Online Import 5 ActiveX clsid access (more info ...)attempted-user        URL
12970WEB-ACTIVEX Intuit QuickBooks Online Import 5 ActiveX clsid unicode access (more info ...)attempted-user        URL
12971EXPLOIT microsoft directshow wav file overflow attempt (more info ...)attempted-user  2007-3895      URL
12972WEB-CLIENT Microsoft Media Player .asf markers detected (more info ...)attempted-user  2007-0064      URL
13158WEB_CLIENT Microsoft Media Player asf streaming format interchange data integer overflow attempt (more info ...)attempted-user  2007-0064      URL
13159WEB_CLIENT Microsoft Media Player asf streaming format audio error masking integer overflow attempt (more info ...)attempted-user  2007-0064      URL
13162NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters overflow attempt (more info ...)attempted-admin  2006-6114  21220    
13219WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX clsid access (more info ...)attempted-user  2007-6506  26950    
13220WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX clsid unicode access (more info ...)attempted-user  2007-6506  26950    
13224WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX clsid access (more info ...)attempted-user  2007-6535  26956    
13225WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX clsid unicode access (more info ...)attempted-user  2007-6535  26956    
13226WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX function call access (more info ...)attempted-user  2007-6535  26956    
13227WEB-ACTIVEX Yahoo Toolbar YShortcut ActiveX function call unicode access (more info ...)attempted-user  2007-6535  26956    
13250RPC portmap 390113 tcp request (more info ...)rpc-portmap-decode  2007-3618  25375    
13251RPC portmap 390113 udp request (more info ...)rpc-portmap-decode  2007-3618  25375    
13252RPC portmap 390113 tcp procedure 4 attempt (more info ...)rpc-portmap-decode  2007-3618  25375    
13253RPC portmap 390113 udp procedure 4 attempt (more info ...)rpc-portmap-decode  2007-3618  25375    
13254RPC portmap 390113 tcp request (more info ...)rpc-portmap-decode  2007-3618  25375    
13255RPC portmap 390113 udp request (more info ...)rpc-portmap-decode  2007-3618  25375    
13256RPC portmap 390113 tcp procedure 5 attempt (more info ...)rpc-portmap-decode  2007-3618  25375    
13257RPC portmap 390113 udp procedure 5 attempt (more info ...)rpc-portmap-decode  2007-3618  25375    
13266WEB-ACTIVEX SkyFex Client ActiveX clsid access (more info ...)attempted-user    27059    
13267WEB-ACTIVEX SkyFex Client ActiveX clsid unicode access (more info ...)attempted-user    27059    
13273WEB-ACTIVEX DivX Web Player ActiveX clsid access (more info ...)attempted-user    27106    
13274WEB-ACTIVEX DivX Web Player ActiveX clsid unicode access (more info ...)attempted-user    27106    
13275WEB-ACTIVEX DivX Web Player ActiveX function call access (more info ...)attempted-user    27106    
13276WEB-ACTIVEX DivX Web Player ActiveX function call unicode access (more info ...)attempted-user    27106    
13289WEB-ACTIVEX Gatway CWebLaunchCtl ActiveX clsid access (more info ...)attempted-user  2008-0220  27193    URL
13290WEB-ACTIVEX Gatway CWebLaunchCtl ActiveX clsid unicode access (more info ...)attempted-user  2008-0220  27193    URL
13294WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid access (more info ...)attempted-user  2008-0237  27201    
13295WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid unicode access (more info ...)attempted-user  2008-0237  27201    
13296WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid access (more info ...)attempted-user  2008-0237  27201    
13297WEB-ACTIVEX Microsoft Rich TextBox ActiveX clsid unicode access (more info ...)attempted-user  2008-0237  27201    
13298WEB-ACTIVEX Microsoft Rich TextBox ActiveX function call access (more info ...)attempted-user  2008-0237  27201    
13299WEB-ACTIVEX Microsoft Rich TextBox ActiveX function call unicode access (more info ...)attempted-user  2008-0237  27201    
13303WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX clsid access (more info ...)attempted-user  2008-0236  27205    
13304WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX clsid unicode access (more info ...)attempted-user  2008-0236  27205    
13305WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX function call access (more info ...)attempted-user  2008-0236  27205    
13306WEB-ACTIVEX Microsoft Visual FoxPro 2 ActiveX function call unicode access (more info ...)attempted-user  2008-0236  27205    
13312WEB-ACTIVEX StreamAudio ProxyManager ActiveX clsid access (more info ...)attempted-user  2008-0248  27247    
13313WEB-ACTIVEX StreamAudio ProxyManager ActiveX clsid unicode access (more info ...)attempted-user  2008-0248  27247    
13314WEB-ACTIVEX StreamAudio ProxyManager ActiveX function call access (more info ...)attempted-user  2008-0248  27247    
13315WEB-ACTIVEX StreamAudio ProxyManager ActiveX function call unicode access (more info ...)attempted-user  2008-0248  27247    
13321WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX clsid access (more info ...)attempted-user  2007-3041  25295    URL
13322WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX clsid unicode access (more info ...)attempted-user  2007-3041  25295    URL
13323WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX function call access (more info ...)attempted-user  2007-3041  25295    URL
13324WEB-ACTIVEX Microsoft Package and Deployment Wizard ActiveX function call unicode access (more info ...)attempted-user  2007-3041  25295    URL
13329WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX clsid access (more info ...)attempted-user  2008-0399  27360    
13330WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX clsid unicode access (more info ...)attempted-user  2008-0399  27360    
13331WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX function call access (more info ...)attempted-user  2008-0399  27360    
13332WEB-ACTIVEX Toshiba Surveillance Surveillix DVR ActiveX function call unicode access (more info ...)attempted-user  2008-0399  27360    
13333WEB-ACTIVEX HP Virtual Rooms ActiveX clsid access (more info ...)attempted-user  2008-0437  27384    
13334WEB-ACTIVEX HP Virtual Rooms ActiveX clsid unicode access (more info ...)attempted-user  2008-0437  27384    
13335WEB-ACTIVEX Lycos File Upload Component ActiveX clsid access (more info ...)attempted-user    27411    
13336WEB-ACTIVEX Lycos File Upload Component ActiveX clsid unicode access (more info ...)attempted-user    27411    
13337WEB-ACTIVEX Comodo AntiVirus ActiveX clsid access (more info ...)attempted-user    27424    
13338WEB-ACTIVEX Comodo AntiVirus ActiveX clsid unicode access (more info ...)attempted-user    27424    
13348WEB-ACTIVEX Move Networks Media Player ActiveX clsid access (more info ...)attempted-user    27438    
13349WEB-ACTIVEX Move Networks Media Player ActiveX clsid unicode access (more info ...)attempted-user    27438    
13350WEB-ACTIVEX Move Networks Media Player ActiveX function call access (more info ...)attempted-user    27438    
13351WEB-ACTIVEX Move Networks Media Player ActiveX function call unicode access (more info ...)attempted-user    27438    
13352WEB-ACTIVEX Lycos File Upload Component ActiveX function call access (more info ...)attempted-user    27411    
13353WEB-ACTIVEX Lycos File Upload Component ActiveX function call unicode access (more info ...)attempted-user    27411    
13354WEB-ACTIVEX HP Virtual Rooms ActiveX function call access (more info ...)attempted-user  2008-0437  27384    
13355WEB-ACTIVEX HP Virtual Rooms ActiveX function call unicode access (more info ...)attempted-user  2008-0437  27384    
13367NETBIOS DCERPC NCACN-IP-TCP spoolss GetPrinterData attempt (more info ...)protocol-command-decode  2006-6296  21401    
13419WEB-ACTIVEX Facebook Photo Uploader ActiveX clsid access (more info ...)attempted-user  2008-5711  27756    URL
13420WEB-ACTIVEX Facebook Photo Uploader ActiveX clsid unicode access (more info ...)attempted-user  2008-5711  27756    URL
13421WEB-ACTIVEX Facebook Photo Uploader ActiveX function call access (more info ...)attempted-user  2008-5711  27756    URL
13422WEB-ACTIVEX Facebook Photo Uploader ActiveX function call unicode access (more info ...)attempted-user  2008-5711  27756    URL
13423WEB-ACTIVEX SwiftView ActiveX clsid access (more info ...)attempted-user  2007-5602  27527    URL
13424WEB-ACTIVEX SwiftView ActiveX clsid unicode access (more info ...)attempted-user  2007-5602  27527    URL
13426WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX clsid access (more info ...)attempted-user    27579    
13427WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX clsid unicode access (more info ...)attempted-user    27579    
13428WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX function call access (more info ...)attempted-user    27579    
13429WEB-ACTIVEX Yahoo Music JukeBox DataGrid ActiveX function call unicode access (more info ...)attempted-user    27579    
13430WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX clsid access (more info ...)attempted-user    27578    
13431WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX clsid unicode access (more info ...)attempted-user    27578    
13432WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX function call access (more info ...)attempted-user    27578    
13433WEB-ACTIVEX Yahoo Music JukeBox MediaGrid ActiveX function call unicode access (more info ...)attempted-user    27578    
13446WEB-ACTIVEX GlobalLink HanGamePlugin ActiveX clsid access (more info ...)attempted-user    27626    
13447WEB-ACTIVEX GlobalLink HanGamePlugin ActiveX clsid unicode access (more info ...)attempted-user    27626    
13453WEB-CLIENT Microsoft DXLUTBuilder ActiveX clsid access (more info ...)attempted-user  2008-0078      URL
13455WEB-CLIENT Microsoft DXLUTBuilder ActiveX function call access (more info ...)attempted-user  2008-0078      URL
13457WEB-ACTIVEX Microsoft Forms 2.0 ActiveX clsid access (more info ...)attempted-user  2007-0065      URL
13459WEB-ACTIVEX Microsoft Forms 2.0 ActiveX function call access (more info ...)attempted-user  2007-0065      URL
13465WEB-CLIENT Microsoft Works file download request (more info ...)misc-activity        
13466WEB-CLIENT Microsoft Works file converter file section length headers memory corruption attempt (more info ...)attempted-user  2007-0216  27657    URL
13471EXPLOIT Microsoft Publisher invalid pathname overwrite (more info ...)attempted-user  2008-0104      URL
13473WEB-MISC Microsoft Publisher file download (more info ...)misc-activity        
13474WEB-CLIENT Microsoft WebDAV MiniRedir remote code execution attempt (more info ...)attempted-user  2008-0080      URL
13523WEB-ACTIVEX Novell iPrint ActiveX clsid access (more info ...)attempted-user  2008-2908  31370    URL
13524WEB-ACTIVEX Novell iPrint ActiveX clsid unicode access (more info ...)attempted-user  2008-2908  31370    URL
13525WEB-ACTIVEX Novell iPrint ActiveX function call access (more info ...)attempted-user  2008-2908  31370    URL
13526WEB-ACTIVEX Novell iPrint ActiveX function call unicode access (more info ...)attempted-user  2008-2908  31370    URL
13527WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX clsid access (more info ...)attempted-user    28010    
13528WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX clsid unicode access (more info ...)attempted-user    28010    
13529WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX function call access (more info ...)attempted-user    28010    
13530WEB-ACTIVEX D-Link MPEG4 SHM Audio Control ActiveX function call unicode access (more info ...)attempted-user    28010    
13531WEB-ACTIVEX 4xem VatCtrl ActiveX clsid access (more info ...)attempted-user    28010    
13532WEB-ACTIVEX 4xem VatCtrl ActiveX clsid unicode access (more info ...)attempted-user    28010    
13533WEB-ACTIVEX 4xem VatCtrl ActiveX function call access (more info ...)attempted-user    28010    
13534WEB-ACTIVEX 4xem VatCtrl ActiveX function call unicode access (more info ...)attempted-user    28010    
13535WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX clsid access (more info ...)attempted-user    28010    
13536WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX clsid unicode access (more info ...)attempted-user    28010    
13537WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX function call access (more info ...)attempted-user    28010    
13538WEB-ACTIVEX Vivotek RTSP MPEG4 SP Control ActiveX function call unicode access (more info ...)attempted-user    28010    
13539WEB-ACTIVEX Symantec Backup Exec ActiveX clsid access (more info ...)attempted-user  2007-6016  26904    URL
13540WEB-ACTIVEX Symantec Backup Exec ActiveX clsid unicode access (more info ...)attempted-user  2007-6016  26904    URL
13541WEB-ACTIVEX Symantec Backup Exec ActiveX function call access (more info ...)attempted-user  2007-6016  26904    URL
13542WEB-ACTIVEX Symantec Backup Exec ActiveX function call unicode access (more info ...)attempted-user  2007-6016  26904    URL
13543WEB-ACTIVEX Learn2 STRunner ActiveX clsid access (more info ...)attempted-user    28058    
13544WEB-ACTIVEX Learn2 STRunner ActiveX clsid unicode access (more info ...)attempted-user    28058    
13545WEB-ACTIVEX Learn2 STRunner ActiveX function call access (more info ...)attempted-user    28058    
13546WEB-ACTIVEX Learn2 STRunner ActiveX function call unicode access (more info ...)attempted-user    28058    
13547WEB-ACTIVEX Sony ImageStation ActiveX clsid access (more info ...)attempted-user  2008-0748  27715    
13548WEB-ACTIVEX Sony ImageStation ActiveX clsid unicode access (more info ...)attempted-user  2008-0748  27715    
13549WEB-ACTIVEX Sony ImageStation ActiveX function call access (more info ...)attempted-user  2008-0748  27715    
13550WEB-ACTIVEX Sony ImageStation ActiveX function call unicode access (more info ...)attempted-user  2008-0748  27715    
13572WEB-CLIENT Microsoft Powerpoint malformed shapeid arbitrary code execution attempt (more info ...)attempted-user  2008-0118      URL
13583WEB-CLIENT Microsoft SYmbolic LinK file download request (more info ...)misc-activity  2008-0112      URL
13585WEB-CLIENT Microsoft SYmbolic LinK file download (more info ...)misc-activity  2008-0112      URL
13595WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX clsid access (more info ...)attempted-user    28118    
13596WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX clsid unicode access (more info ...)attempted-user    28118    
13597WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX function call access (more info ...)attempted-user    28118    
13598WEB-ACTIVEX ICQ Toolbar toolbaru.dll ActiveX function call unicode access (more info ...)attempted-user    28118    
13599WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX clsid access (more info ...)attempted-user  2008-1307  28172    
13600WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX clsid unicode access (more info ...)attempted-user  2008-1307  28172    
13601WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX function call access (more info ...)attempted-user  2008-1307  28172    
13602WEB-ACTIVEX Kingsoft Antivirus Online Update Module ActiveX function call unicode access (more info ...)attempted-user  2008-1307  28172    
13619SPECIFIC-THREATS Microsoft getBulkRequest memory corruption attempt (more info ...)attempted-admin  2006-5583      URL
13621WEB-ACTIVEX CA BrightStor ListCtrl ActiveX clsid access (more info ...)attempted-user  2008-1472  28268    
13622WEB-ACTIVEX CA BrightStor ListCtrl ActiveX clsid unicode access (more info ...)attempted-user  2008-1472  28268    
13623WEB-ACTIVEX CA BrightStor ListCtrl ActiveX function call access (more info ...)attempted-user  2008-1472  28268    
13624WEB-ACTIVEX CA BrightStor ListCtrl ActiveX function call unicode access (more info ...)attempted-user  2008-1472  28268    
13626WEB-CLIENT Microsoft Access download attempt (more info ...)suspicious-filename-detect  2008-1092  26468    URL
13629WEB-CLIENT Microsoft Access JSDB download attempt (more info ...)suspicious-filename-detect  2008-1092  26468    URL
13630WEB-CLIENT Microsoft Access TJDB download attempt (more info ...)suspicious-filename-detect  2008-1092  26468    URL
13633WEB-CLIENT Microsoft Access MSISAM download attempt (more info ...)suspicious-filename-detect  2008-1092  26468    URL
13657WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX clsid access (more info ...)attempted-user  2007-6254  28292    
13658WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX clsid unicode access (more info ...)attempted-user  2007-6254  28292    
13659WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX function call access (more info ...)attempted-user  2007-6254  28292    
13660WEB-ACTIVEX BusinessObjects RptViewerAx ActiveX function call unicode access (more info ...)attempted-user  2007-6254  28292    
13661WEB-ACTIVEX VeralSoft HTTP File Upload ActiveX clsid access (more info ...)attempted-user    28301    
13662WEB-ACTIVEX VeralSoft HTTP File Upload ActiveX clsid unicode access (more info ...)attempted-user    28301    
13666WEB-CLIENT Microsoft GDI integer overflow attempt (more info ...)attempted-user  2008-1083      URL
13668WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX clsid access (more info ...)attempted-user  2008-1086      URL
13670WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX function call access (more info ...)attempted-user  2008-1086      URL
13672WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX clsid access (more info ...)attempted-user  2008-1086      URL
13674WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX function call access (more info ...)attempted-user  2008-1086      URL
13678MISC Microsoft EMF metafile access detected (more info ...)attempted-user  2008-1087      URL
13679WEB-ACTIVEX IBiz EBanking Integrator ActiveX clsid access (more info ...)attempted-user  2008-1725  28700    
13680WEB-ACTIVEX IBiz EBanking Integrator ActiveX clsid unicode access (more info ...)attempted-user  2008-1725  28700    
13681WEB-ACTIVEX CDNetworks Nefficient Download ActiveX clsid access (more info ...)attempted-user    28666    
13682WEB-ACTIVEX CDNetworks Nefficient Download ActiveX clsid unicode access (more info ...)attempted-user    28666    
13683WEB-ACTIVEX CDNetworks Nefficient Download ActiveX function call access (more info ...)attempted-user    28666    
13684WEB-ACTIVEX CDNetworks Nefficient Download ActiveX function call unicode access (more info ...)attempted-user    28666    
13685WEB-ACTIVEX Chilkat HTTP 1 ActiveX clsid access (more info ...)attempted-user  2008-1647  28546    
13686WEB-ACTIVEX Chilkat HTTP 1 ActiveX clsid unicode access (more info ...)attempted-user  2008-1647  28546    
13687WEB-ACTIVEX Chilkat HTTP 1 ActiveX function call access (more info ...)attempted-user  2008-1647  28546    
13688WEB-ACTIVEX Chilkat HTTP 1 ActiveX function call unicode access (more info ...)attempted-user  2008-1647  28546    
13689WEB-ACTIVEX Chilkat HTTP 2 ActiveX clsid access (more info ...)attempted-user  2008-1647  28546    
13690WEB-ACTIVEX Chilkat HTTP 2 ActiveX clsid unicode access (more info ...)attempted-user  2008-1647  28546    
13691WEB-ACTIVEX Chilkat HTTP 2 ActiveX function call access (more info ...)attempted-user  2008-1647  28546    
13692WEB-ACTIVEX Chilkat HTTP 2 ActiveX function call unicode access (more info ...)attempted-user  2008-1647  28546    
13699WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX clsid access (more info ...)attempted-user  2008-1786  28809    
13700WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX clsid unicode access (more info ...)attempted-user  2008-1786  28809    
13720WEB-ACTIVEX HP eSupportDiagnostics 3 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13721WEB-ACTIVEX HP eSupportDiagnostics 3 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13722WEB-ACTIVEX HP eSupportDiagnostics 4 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13723WEB-ACTIVEX HP eSupportDiagnostics 4 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13724WEB-ACTIVEX HP eSupportDiagnostics 5 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13725WEB-ACTIVEX HP eSupportDiagnostics 5 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13726WEB-ACTIVEX HP eSupportDiagnostics 6 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13727WEB-ACTIVEX HP eSupportDiagnostics 6 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13728WEB-ACTIVEX HP eSupportDiagnostics 7 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13729WEB-ACTIVEX HP eSupportDiagnostics 7 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13730WEB-ACTIVEX HP eSupportDiagnostics 8 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13731WEB-ACTIVEX HP eSupportDiagnostics 8 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13732WEB-ACTIVEX HP eSupportDiagnostics 9 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13733WEB-ACTIVEX HP eSupportDiagnostics 9 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13734WEB-ACTIVEX HP eSupportDiagnostics 10 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13735WEB-ACTIVEX HP eSupportDiagnostics 10 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13736WEB-ACTIVEX HP eSupportDiagnostics 11 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13737WEB-ACTIVEX HP eSupportDiagnostics 11 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13738WEB-ACTIVEX HP eSupportDiagnostics 12 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13739WEB-ACTIVEX HP eSupportDiagnostics 12 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13740WEB-ACTIVEX HP eSupportDiagnostics 13 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13741WEB-ACTIVEX HP eSupportDiagnostics 13 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13742WEB-ACTIVEX HP eSupportDiagnostics 14 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13743WEB-ACTIVEX HP eSupportDiagnostics 14 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13744WEB-ACTIVEX HP eSupportDiagnostics 15 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13745WEB-ACTIVEX HP eSupportDiagnostics 15 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13746WEB-ACTIVEX HP eSupportDiagnostics 16 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13747WEB-ACTIVEX HP eSupportDiagnostics 16 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13748WEB-ACTIVEX HP eSupportDiagnostics 17 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13749WEB-ACTIVEX HP eSupportDiagnostics 17 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13750WEB-ACTIVEX HP eSupportDiagnostics 18 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13751WEB-ACTIVEX HP eSupportDiagnostics 18 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13752WEB-ACTIVEX HP eSupportDiagnostics 19 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13753WEB-ACTIVEX HP eSupportDiagnostics 19 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13754WEB-ACTIVEX HP eSupportDiagnostics 20 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13755WEB-ACTIVEX HP eSupportDiagnostics 20 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13756WEB-ACTIVEX HP eSupportDiagnostics 21 ActiveX clsid access (more info ...)attempted-user  2008-0712  28929    URL
13757WEB-ACTIVEX HP eSupportDiagnostics 21 ActiveX clsid unicode access (more info ...)attempted-user  2008-0712  28929    URL
13758WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX clsid access (more info ...)attempted-user  2007-6255  28882    
13759WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX clsid unicode access (more info ...)attempted-user  2007-6255  28882    
13760WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX function call access (more info ...)attempted-user  2007-6255  28882    
13761WEB-ACTIVEX Microsoft HeartbeatCtl ActiveX function call unicode access (more info ...)attempted-user  2007-6255  28882    
13783WEB-ACTIVEX Yahoo Assistant ActiveX clsid access (more info ...)attempted-user  2008-2111  29065    
13784WEB-ACTIVEX Yahoo Assistant ActiveX clsid unicode access (more info ...)attempted-user  2008-2111  29065    
13785WEB-ACTIVEX Ourgame GLWorld ActiveX clsid access (more info ...)attempted-user  2008-0647  27626    
13786WEB-ACTIVEX Ourgame GLWorld ActiveX clsid unicode access (more info ...)attempted-user  2008-0647  27626    
13787WEB-ACTIVEX Ourgame GLWorld ActiveX function call access (more info ...)attempted-user  2008-0647  27626    
13788WEB-ACTIVEX Ourgame GLWorld ActiveX function call unicode access (more info ...)attempted-user  2008-0647  27626    
13798WEB-CLIENT Microsoft malware protection engine denial of service attempt (more info ...)attempted-dos  2008-1437      URL
13802WEB-CLIENT Microsoft malware protection engine denial of service attempt (more info ...)attempted-dos  2008-1438      URL
13825DOS Microsoft PGM fragment denial of service attempt (more info ...)attempted-dos  2008-1441      URL
13827DOS Microsoft PGM denial of service attempt (more info ...)attempted-dos  2008-1440      URL
13857WEB-ACTIVEX HP Instant Support DataManager ActiveX clsid access (more info ...)attempted-user  2008-0953  29536    URL
13858WEB-ACTIVEX HP Instant Support DataManager ActiveX clsid unicode access (more info ...)attempted-user  2008-0953  29536    URL
13859WEB-ACTIVEX HP Instant Support DataManager ActiveX function call access (more info ...)attempted-user  2008-0953  29536    URL
13860WEB-ACTIVEX HP Instant Support DataManager ActiveX function call unicode access (more info ...)attempted-user  2008-0953  29536    URL
13883WEB-ACTIVEX UUSee UUUpgrade ActiveX clsid access (more info ...)attempted-user    29963    
13884WEB-ACTIVEX UUSee UUUpgrade ActiveX clsid unicode access (more info ...)attempted-user    29963    
13885WEB-ACTIVEX UUSee UUUpgrade ActiveX function call access (more info ...)attempted-user    29963    
13886WEB-ACTIVEX UUSee UUUpgrade ActiveX function call unicode access (more info ...)attempted-user    29963    
13893WEB-CLIENT Microsoft malformed saved search heap corruption attempt (more info ...)attempted-admin  2008-1435      URL
13903WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX clsid access (more info ...)attempted-user  2008-2463      URL
13904WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX clsid unicode access (more info ...)attempted-user  2008-2463      URL
13905WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX function call access (more info ...)attempted-user  2008-2463      URL
13906WEB-ACTIVEX Microsoft Access Snapshot Viewer 1 ActiveX function call unicode access (more info ...)attempted-user  2008-2463      URL
13907WEB-ACTIVEX Microsoft Access Snapshot Viewer 2 ActiveX clsid access (more info ...)attempted-user  2008-2463      URL
13908WEB-ACTIVEX Microsoft Access Snapshot Viewer 2 ActiveX clsid unicode access (more info ...)attempted-user  2008-2463      URL
13911WEB-CLIENT Microsoft search file download attempt (more info ...)misc-activity        
13913WEB-ACTIVEX AcroPDF.PDF ActiveX function call access (more info ...)attempted-user  2006-6236  21155    URL
13914WEB-ACTIVEX AcroPDF.PDF ActiveX function call unicode access (more info ...)attempted-user  2006-6236  21155    URL
13965WEB-ACTIVEX Microsoft Message System ActiveX clsid access (more info ...)attempted-user  2008-0082      URL
13967WEB-ACTIVEX Microsoft Message System ActiveX function call access (more info ...)attempted-user  2008-0082      URL
13971WEB-CLIENT Microsoft Powerpoint TxMasterStyle10Atom atom numLevels buffer overflow attempt (more info ...)attempted-user  2008-1455      URL
13975WEB-CLIENT Microsoft Windows Event System ActiveX clsid access (more info ...)attempted-user  2008-1457      URL
13977WEB-CLIENT Microsoft Windows Event System ActiveX function call access (more info ...)attempted-user  2008-1457      URL
13979WEB-CLIENT Microsoft Windows Event System Subscription VBScript access (more info ...)attempted-user  2008-1457      URL
13982WEB-CLIENT Microsoft Powerpoint file download attempt (more info ...)misc-activity        
14013WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX clsid access (more info ...)attempted-user  2008-3558  30578    URL
14014WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX clsid unicode access (more info ...)attempted-user  2008-3558  30578    URL
14015WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX function call access (more info ...)attempted-user  2008-3558  30578    URL
14016WEB-ACTIVEX WebEx Meeting Manager atucfobj ActiveX function call unicode access (more info ...)attempted-user  2008-3558  30578    URL
14021WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX clsid access (more info ...)attempted-user  2008-3704  30674    URL
14022WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX clsid unicode access (more info ...)attempted-user  2008-3704  30674    URL
14023WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX function call access (more info ...)attempted-user  2008-3704  30674    URL
14024WEB-ACTIVEX Microsoft Visual Studio Msmask32 ActiveX function call unicode access (more info ...)attempted-user  2008-3704  30674    URL
14025WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid access (more info ...)attempted-user  2008-1786      
14026WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid unicode access (more info ...)attempted-user  2008-1786      
14027WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX function call access (more info ...)attempted-user  2008-1786  28809    
14028WEB-ACTIVEX CA DSM gui_cm_ctrls ActiveX function call unicode access (more info ...)attempted-user  2008-1786  28809    
14029WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid access (more info ...)attempted-user  2008-1786      
14030WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX clsid unicode access (more info ...)attempted-user  2008-1786      
14031WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX function call access (more info ...)attempted-user  2008-1786      
14032WEB-ACTIVEX Computer Associates gui_cm_ctrls ActiveX function call unicode access (more info ...)attempted-user  2008-1786      
14088WEB-ACTIVEX Aurigma unspecified 1 ActiveX clsid access (more info ...)attempted-user        URL
14089WEB-ACTIVEX Aurigma unspecified 1 ActiveX clsid unicode access (more info ...)attempted-user        URL
14090WEB-ACTIVEX Aurigma unspecified 2 ActiveX clsid access (more info ...)attempted-user        URL
14091WEB-ACTIVEX Aurigma unspecified 2 ActiveX clsid unicode access (more info ...)attempted-user        URL
14092WEB-ACTIVEX Aurigma unspecified 3 ActiveX clsid access (more info ...)attempted-user        URL
14093WEB-ACTIVEX Aurigma unspecified 3 ActiveX clsid unicode access (more info ...)attempted-user        URL
14094WEB-ACTIVEX Aurigma unspecified 4 ActiveX clsid access (more info ...)attempted-user        URL
14095WEB-ACTIVEX Aurigma unspecified 4 ActiveX clsid unicode access (more info ...)attempted-user        URL
14096WEB-ACTIVEX Aurigma unspecified 5 ActiveX clsid access (more info ...)attempted-user        URL
14097WEB-ACTIVEX Aurigma unspecified 5 ActiveX clsid unicode access (more info ...)attempted-user        URL
14098WEB-ACTIVEX Aurigma unspecified 6 ActiveX clsid access (more info ...)attempted-user        URL
14099WEB-ACTIVEX Aurigma unspecified 6 ActiveX clsid unicode access (more info ...)attempted-user        URL
14100WEB-ACTIVEX Aurigma unspecified 7 ActiveX clsid access (more info ...)attempted-user        URL
14101WEB-ACTIVEX Aurigma unspecified 7 ActiveX clsid unicode access (more info ...)attempted-user        URL
14102WEB-ACTIVEX Aurigma unspecified 8 ActiveX clsid access (more info ...)attempted-user        URL
14103WEB-ACTIVEX Aurigma unspecified 8 ActiveX clsid unicode access (more info ...)attempted-user        URL
14104WEB-ACTIVEX Aurigma unspecified 9 ActiveX clsid access (more info ...)attempted-user        URL
14105WEB-ACTIVEX Aurigma unspecified 9 ActiveX clsid unicode access (more info ...)attempted-user        URL
14106WEB-ACTIVEX Aurigma unspecified 10 ActiveX clsid access (more info ...)attempted-user        URL
14107WEB-ACTIVEX Aurigma unspecified 10 ActiveX clsid unicode access (more info ...)attempted-user        URL
14108WEB-ACTIVEX Aurigma unspecified 11 ActiveX clsid access (more info ...)attempted-user        URL
14109WEB-ACTIVEX Aurigma unspecified 11 ActiveX clsid unicode access (more info ...)attempted-user        URL
14110WEB-ACTIVEX Aurigma unspecified 12 ActiveX clsid access (more info ...)attempted-user        URL
14111WEB-ACTIVEX Aurigma unspecified 12 ActiveX clsid unicode access (more info ...)attempted-user        URL
14112WEB-ACTIVEX Aurigma unspecified 13 ActiveX clsid access (more info ...)attempted-user        URL
14113WEB-ACTIVEX Aurigma unspecified 13 ActiveX clsid unicode access (more info ...)attempted-user        URL
14114WEB-ACTIVEX Aurigma unspecified 14 ActiveX clsid access (more info ...)attempted-user        URL
14115WEB-ACTIVEX Aurigma unspecified 14 ActiveX clsid unicode access (more info ...)attempted-user        URL
14116WEB-ACTIVEX Aurigma unspecified 15 ActiveX clsid access (more info ...)attempted-user        URL
14117WEB-ACTIVEX Aurigma unspecified 15 ActiveX clsid unicode access (more info ...)attempted-user        URL
14118WEB-ACTIVEX Aurigma unspecified 16 ActiveX clsid access (more info ...)attempted-user        URL
14119WEB-ACTIVEX Aurigma unspecified 16 ActiveX clsid unicode access (more info ...)attempted-user        URL
14120WEB-ACTIVEX Aurigma unspecified 17 ActiveX clsid access (more info ...)attempted-user        URL
14121WEB-ACTIVEX Aurigma unspecified 17 ActiveX clsid unicode access (more info ...)attempted-user        URL
14122WEB-ACTIVEX Aurigma unspecified 18 ActiveX clsid access (more info ...)attempted-user        URL
14123WEB-ACTIVEX Aurigma unspecified 18 ActiveX clsid unicode access (more info ...)attempted-user        URL
14124WEB-ACTIVEX Aurigma unspecified 19 ActiveX clsid access (more info ...)attempted-user        URL
14125WEB-ACTIVEX Aurigma unspecified 19 ActiveX clsid unicode access (more info ...)attempted-user        URL
14126WEB-ACTIVEX Aurigma unspecified 20 ActiveX clsid access (more info ...)attempted-user        URL
14127WEB-ACTIVEX Aurigma unspecified 20 ActiveX clsid unicode access (more info ...)attempted-user        URL
14128WEB-ACTIVEX Aurigma unspecified 21 ActiveX clsid access (more info ...)attempted-user        URL
14129WEB-ACTIVEX Aurigma unspecified 21 ActiveX clsid unicode access (more info ...)attempted-user        URL
14130WEB-ACTIVEX Aurigma unspecified 22 ActiveX clsid access (more info ...)attempted-user        URL
14131WEB-ACTIVEX Aurigma unspecified 22 ActiveX clsid unicode access (more info ...)attempted-user        URL
14132WEB-ACTIVEX Aurigma unspecified 23 ActiveX clsid access (more info ...)attempted-user        URL
14133WEB-ACTIVEX Aurigma unspecified 23 ActiveX clsid unicode access (more info ...)attempted-user        URL
14134WEB-ACTIVEX Aurigma unspecified 24 ActiveX clsid access (more info ...)attempted-user        URL
14135WEB-ACTIVEX Aurigma unspecified 24 ActiveX clsid unicode access (more info ...)attempted-user        URL
14136WEB-ACTIVEX Aurigma unspecified 25 ActiveX clsid access (more info ...)attempted-user        URL
14137WEB-ACTIVEX Aurigma unspecified 25 ActiveX clsid unicode access (more info ...)attempted-user        URL
14138WEB-ACTIVEX Aurigma unspecified 26 ActiveX clsid access (more info ...)attempted-user        URL
14139WEB-ACTIVEX Aurigma unspecified 26 ActiveX clsid unicode access (more info ...)attempted-user        URL
14140WEB-ACTIVEX Aurigma unspecified 27 ActiveX clsid access (more info ...)attempted-user        URL
14141WEB-ACTIVEX Aurigma unspecified 27 ActiveX clsid unicode access (more info ...)attempted-user        URL
14142WEB-ACTIVEX Aurigma unspecified 28 ActiveX clsid access (more info ...)attempted-user        URL
14143WEB-ACTIVEX Aurigma unspecified 28 ActiveX clsid unicode access (more info ...)attempted-user        URL
14144WEB-ACTIVEX Aurigma unspecified 29 ActiveX clsid access (more info ...)attempted-user        URL
14145WEB-ACTIVEX Aurigma unspecified 29 ActiveX clsid unicode access (more info ...)attempted-user        URL
14146WEB-ACTIVEX Aurigma unspecified 30 ActiveX clsid access (more info ...)attempted-user        URL
14147WEB-ACTIVEX Aurigma unspecified 30 ActiveX clsid unicode access (more info ...)attempted-user        URL
14148WEB-ACTIVEX Aurigma unspecified 31 ActiveX clsid access (more info ...)attempted-user        URL
14149WEB-ACTIVEX Aurigma unspecified 31 ActiveX clsid unicode access (more info ...)attempted-user        URL
14150WEB-ACTIVEX Aurigma unspecified 32 ActiveX clsid access (more info ...)attempted-user        URL
14151WEB-ACTIVEX Aurigma unspecified 32 ActiveX clsid unicode access (more info ...)attempted-user        URL
14152WEB-ACTIVEX Aurigma unspecified 33 ActiveX clsid access (more info ...)attempted-user        URL
14153WEB-ACTIVEX Aurigma unspecified 33 ActiveX clsid unicode access (more info ...)attempted-user        URL
14154WEB-ACTIVEX Aurigma unspecified 34 ActiveX clsid access (more info ...)attempted-user        URL
14155WEB-ACTIVEX Aurigma unspecified 34 ActiveX clsid unicode access (more info ...)attempted-user        URL
14156WEB-ACTIVEX Aurigma unspecified 35 ActiveX clsid access (more info ...)attempted-user        URL
14157WEB-ACTIVEX Aurigma unspecified 35 ActiveX clsid unicode access (more info ...)attempted-user        URL
14158WEB-ACTIVEX Aurigma unspecified 36 ActiveX clsid access (more info ...)attempted-user        URL
14159WEB-ACTIVEX Aurigma unspecified 36 ActiveX clsid unicode access (more info ...)attempted-user        URL
14160WEB-ACTIVEX Aurigma unspecified 37 ActiveX clsid access (more info ...)attempted-user        URL
14161WEB-ACTIVEX Aurigma unspecified 37 ActiveX clsid unicode access (more info ...)attempted-user        URL
14162WEB-ACTIVEX Aurigma unspecified 38 ActiveX clsid access (more info ...)attempted-user        URL
14163WEB-ACTIVEX Aurigma unspecified 38 ActiveX clsid unicode access (more info ...)attempted-user        URL
14164WEB-ACTIVEX Aurigma unspecified 39 ActiveX clsid access (more info ...)attempted-user        URL
14165WEB-ACTIVEX Aurigma unspecified 39 ActiveX clsid unicode access (more info ...)attempted-user        URL
14166WEB-ACTIVEX Aurigma unspecified 40 ActiveX clsid access (more info ...)attempted-user        URL
14167WEB-ACTIVEX Aurigma unspecified 40 ActiveX clsid unicode access (more info ...)attempted-user        URL
14168WEB-ACTIVEX Aurigma unspecified 41 ActiveX clsid access (more info ...)attempted-user        URL
14169WEB-ACTIVEX Aurigma unspecified 41 ActiveX clsid unicode access (more info ...)attempted-user        URL
14170WEB-ACTIVEX Aurigma unspecified 42 ActiveX clsid access (more info ...)attempted-user        URL
14171WEB-ACTIVEX Aurigma unspecified 42 ActiveX clsid unicode access (more info ...)attempted-user        URL
14172WEB-ACTIVEX Aurigma unspecified 43 ActiveX clsid access (more info ...)attempted-user        URL
14173WEB-ACTIVEX Aurigma unspecified 43 ActiveX clsid unicode access (more info ...)attempted-user        URL
14174WEB-ACTIVEX Aurigma unspecified 44 ActiveX clsid access (more info ...)attempted-user        URL
14175WEB-ACTIVEX Aurigma unspecified 44 ActiveX clsid unicode access (more info ...)attempted-user        URL
14176WEB-ACTIVEX Aurigma unspecified 45 ActiveX clsid access (more info ...)attempted-user        URL
14177WEB-ACTIVEX Aurigma unspecified 45 ActiveX clsid unicode access (more info ...)attempted-user        URL
14178WEB-ACTIVEX Aurigma unspecified 46 ActiveX clsid access (more info ...)attempted-user        URL
14179WEB-ACTIVEX Aurigma unspecified 46 ActiveX clsid unicode access (more info ...)attempted-user        URL
14180WEB-ACTIVEX Aurigma unspecified 47 ActiveX clsid access (more info ...)attempted-user        URL
14181WEB-ACTIVEX Aurigma unspecified 47 ActiveX clsid unicode access (more info ...)attempted-user        URL
14182WEB-ACTIVEX Aurigma unspecified 48 ActiveX clsid access (more info ...)attempted-user        URL
14183WEB-ACTIVEX Aurigma unspecified 48 ActiveX clsid unicode access (more info ...)attempted-user        URL
14184WEB-ACTIVEX Aurigma unspecified 49 ActiveX clsid access (more info ...)attempted-user        URL
14185WEB-ACTIVEX Aurigma unspecified 49 ActiveX clsid unicode access (more info ...)attempted-user        URL
14186WEB-ACTIVEX Aurigma unspecified 50 ActiveX clsid access (more info ...)attempted-user        URL
14187WEB-ACTIVEX Aurigma unspecified 50 ActiveX clsid unicode access (more info ...)attempted-user        URL
14188WEB-ACTIVEX Aurigma unspecified 51 ActiveX clsid access (more info ...)attempted-user        URL
14189WEB-ACTIVEX Aurigma unspecified 51 ActiveX clsid unicode access (more info ...)attempted-user        URL
14190WEB-ACTIVEX Aurigma unspecified 52 ActiveX clsid access (more info ...)attempted-user        URL
14191WEB-ACTIVEX Aurigma unspecified 52 ActiveX clsid unicode access (more info ...)attempted-user        URL
14192WEB-ACTIVEX Aurigma unspecified 53 ActiveX clsid access (more info ...)attempted-user        URL
14193WEB-ACTIVEX Aurigma unspecified 53 ActiveX clsid unicode access (more info ...)attempted-user        URL
14194WEB-ACTIVEX Aurigma unspecified 54 ActiveX clsid access (more info ...)attempted-user        URL
14195WEB-ACTIVEX Aurigma unspecified 54 ActiveX clsid unicode access (more info ...)attempted-user        URL
14196WEB-ACTIVEX Aurigma unspecified 55 ActiveX clsid access (more info ...)attempted-user        URL
14197WEB-ACTIVEX Aurigma unspecified 55 ActiveX clsid unicode access (more info ...)attempted-user        URL
14198WEB-ACTIVEX Aurigma unspecified 56 ActiveX clsid access (more info ...)attempted-user        URL
14199WEB-ACTIVEX Aurigma unspecified 56 ActiveX clsid unicode access (more info ...)attempted-user        URL
14200WEB-ACTIVEX Aurigma unspecified 57 ActiveX clsid access (more info ...)attempted-user        URL
14201WEB-ACTIVEX Aurigma unspecified 57 ActiveX clsid unicode access (more info ...)attempted-user        URL
14202WEB-ACTIVEX Aurigma unspecified 58 ActiveX clsid access (more info ...)attempted-user        URL
14203WEB-ACTIVEX Aurigma unspecified 58 ActiveX clsid unicode access (more info ...)attempted-user        URL
14204WEB-ACTIVEX Aurigma unspecified 59 ActiveX clsid access (more info ...)attempted-user        URL
14205WEB-ACTIVEX Aurigma unspecified 59 ActiveX clsid unicode access (more info ...)attempted-user        URL
14206WEB-ACTIVEX Aurigma unspecified 60 ActiveX clsid access (more info ...)attempted-user        URL
14207WEB-ACTIVEX Aurigma unspecified 60 ActiveX clsid unicode access (more info ...)attempted-user        URL
14208WEB-ACTIVEX Aurigma unspecified 61 ActiveX clsid access (more info ...)attempted-user        URL
14209WEB-ACTIVEX Aurigma unspecified 61 ActiveX clsid unicode access (more info ...)attempted-user        URL
14210WEB-ACTIVEX Aurigma unspecified 62 ActiveX clsid access (more info ...)attempted-user        URL
14211WEB-ACTIVEX Aurigma unspecified 62 ActiveX clsid unicode access (more info ...)attempted-user        URL
14212WEB-ACTIVEX Aurigma unspecified 63 ActiveX clsid access (more info ...)attempted-user        URL
14213WEB-ACTIVEX Aurigma unspecified 63 ActiveX clsid unicode access (more info ...)attempted-user        URL
14214WEB-ACTIVEX Aurigma unspecified 64 ActiveX clsid access (more info ...)attempted-user        URL
14215WEB-ACTIVEX Aurigma unspecified 64 ActiveX clsid unicode access (more info ...)attempted-user        URL
14216WEB-ACTIVEX Aurigma unspecified 65 ActiveX clsid access (more info ...)attempted-user        URL
14217WEB-ACTIVEX Aurigma unspecified 65 ActiveX clsid unicode access (more info ...)attempted-user        URL
14218WEB-ACTIVEX Aurigma unspecified 66 ActiveX clsid access (more info ...)attempted-user        URL
14219WEB-ACTIVEX Aurigma unspecified 66 ActiveX clsid unicode access (more info ...)attempted-user        URL
14220WEB-ACTIVEX Aurigma unspecified 67 ActiveX clsid access (more info ...)attempted-user        URL
14221WEB-ACTIVEX Aurigma unspecified 67 ActiveX clsid unicode access (more info ...)attempted-user        URL
14222WEB-ACTIVEX Aurigma unspecified 68 ActiveX clsid access (more info ...)attempted-user        URL
14223WEB-ACTIVEX Aurigma unspecified 68 ActiveX clsid unicode access (more info ...)attempted-user        URL
14224WEB-ACTIVEX Aurigma unspecified 69 ActiveX clsid access (more info ...)attempted-user        URL
14225WEB-ACTIVEX Aurigma unspecified 69 ActiveX clsid unicode access (more info ...)attempted-user        URL
14226WEB-ACTIVEX Aurigma unspecified 70 ActiveX clsid access (more info ...)attempted-user        URL
14227WEB-ACTIVEX Aurigma unspecified 70 ActiveX clsid unicode access (more info ...)attempted-user        URL
14228WEB-ACTIVEX Aurigma unspecified 71 ActiveX clsid access (more info ...)attempted-user        URL
14229WEB-ACTIVEX Aurigma unspecified 71 ActiveX clsid unicode access (more info ...)attempted-user        URL
14231WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX clsid access (more info ...)attempted-user  2007-1682  30826    URL
14233WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX function call access (more info ...)attempted-user  2007-1682  30826    URL
14234WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX function call unicode access (more info ...)attempted-user  2007-1682  30826    URL
14239WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX clsid access (more info ...)attempted-user    30891    
14240WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX clsid unicode access (more info ...)attempted-user    30891    
14241WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX function call access (more info ...)attempted-user    30891    
14242WEB-ACTIVEX Friendly Technologies fwRemoteConfig ActiveX function call unicode access (more info ...)attempted-user    30891    
14243WEB-ACTIVEX Najdi.si Toolbar ActiveX clsid access (more info ...)attempted-user    30922    
14244WEB-ACTIVEX Najdi.si Toolbar ActiveX clsid unicode access (more info ...)attempted-user    30922    
14245WEB-ACTIVEX Najdi.si Toolbar ActiveX function call access (more info ...)attempted-user    30922    
14246WEB-ACTIVEX Najdi.si Toolbar ActiveX function call unicode access (more info ...)attempted-user    30922    
14247WEB-ACTIVEX Eyeball MessengerSDK ActiveX clsid access (more info ...)attempted-user  2008-3430  30424    
14248WEB-ACTIVEX Eyeball MessengerSDK ActiveX clsid unicode access (more info ...)attempted-user  2008-3430  30424    
14249WEB-ACTIVEX Eyeball MessengerSDK ActiveX function call access (more info ...)attempted-user  2008-3430  30424    
14250WEB-ACTIVEX Eyeball MessengerSDK ActiveX function call unicode access (more info ...)attempted-user  2008-3430  30424    
14251EXPLOIT Microsoft GDI malformed metarecord buffer overflow attempt (more info ...)attempted-user  2008-3014      URL
14259WEB-CLIENT Microsoft GDI EMF malformed file buffer overflow attempt (more info ...)attempted-user  2008-3012      URL
14266WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX clsid access (more info ...)attempted-user  2008-3957  31069    
14267WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX clsid unicode access (more info ...)attempted-user  2008-3957  31069    
14268WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX function call access (more info ...)attempted-user  2008-3957  31069    
14269WEB-ACTIVEX Microsoft Windows Image Acquisition Logger ActiveX function call unicode access (more info ...)attempted-user  2008-3957  31069    
14270WEB-ACTIVEX VieLib2.Vie2Locator ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14271WEB-ACTIVEX VieLib2.Vie2Locator ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14272WEB-ACTIVEX VieLib2.Vie2Locator ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14273WEB-ACTIVEX VieLib2.Vie2Locator ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14274WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14275WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14276WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14277WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14278WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14279WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14280WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14281WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14282WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14283WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14284WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14285WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14286WEB-ACTIVEX VMClientHosts Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14287WEB-ACTIVEX VMClientHosts Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14288WEB-ACTIVEX VMClientHosts Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14289WEB-ACTIVEX VMClientHosts Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14290WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14291WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14292WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14293WEB-ACTIVEX VhdCvtCom.DiskLibCreateParamObj ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14294WEB-ACTIVEX RemoteDirDlg Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14295WEB-ACTIVEX RemoteDirDlg Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14296WEB-ACTIVEX RemoteDirDlg Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14297WEB-ACTIVEX RemoteDirDlg Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14298WEB-ACTIVEX TeamListViewWnd Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14299WEB-ACTIVEX TeamListViewWnd Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14300WEB-ACTIVEX TeamListViewWnd Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14301WEB-ACTIVEX TeamListViewWnd Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14302WEB-ACTIVEX VMStatusbarCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14303WEB-ACTIVEX VMStatusbarCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14304WEB-ACTIVEX VMStatusbarCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14305WEB-ACTIVEX VMStatusbarCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14306WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14307WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14308WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14309WEB-ACTIVEX Vmc2vmx.CoVPCConfiguration ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14310WEB-ACTIVEX VmdbUpdate Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14311WEB-ACTIVEX VmdbUpdate Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14312WEB-ACTIVEX VmdbUpdate Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14313WEB-ACTIVEX VmdbUpdate Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14314WEB-ACTIVEX VMWare unspecified 1 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14315WEB-ACTIVEX VMWare unspecified 1 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14316WEB-ACTIVEX VmdbExecuteError Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14317WEB-ACTIVEX VmdbExecuteError Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14318WEB-ACTIVEX VmdbExecuteError Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14319WEB-ACTIVEX VmdbExecuteError Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14320WEB-ACTIVEX VMWare unspecified 2 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14321WEB-ACTIVEX VMWare unspecified 2 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14322WEB-ACTIVEX reconfig.SysImageUti ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14323WEB-ACTIVEX reconfig.SysImageUti ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14324WEB-ACTIVEX reconfig.SysImageUti ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14325WEB-ACTIVEX reconfig.SysImageUti ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14326WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14327WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14328WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14329WEB-ACTIVEX Microsoft Visual Database Tools Query Designer V7.0 ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14330WEB-ACTIVEX VmdbContext Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14331WEB-ACTIVEX VmdbContext Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14332WEB-ACTIVEX VmdbContext Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14333WEB-ACTIVEX VmdbContext Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14334WEB-ACTIVEX VMClientVMs Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14335WEB-ACTIVEX VMClientVMs Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14336WEB-ACTIVEX VMClientVMs Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14337WEB-ACTIVEX VMClientVMs Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14338WEB-ACTIVEX vmappPropObj Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14339WEB-ACTIVEX vmappPropObj Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14340WEB-ACTIVEX vmappPropObj Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14341WEB-ACTIVEX vmappPropObj Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14342WEB-ACTIVEX VMWare unspecified 3 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14343WEB-ACTIVEX VMWare unspecified 3 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14344WEB-ACTIVEX VMMsg Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14345WEB-ACTIVEX VMMsg Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14346WEB-ACTIVEX VMMsg Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14347WEB-ACTIVEX VMMsg Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14348WEB-ACTIVEX VMWare unspecified 4 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14349WEB-ACTIVEX VMWare unspecified 4 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14350WEB-ACTIVEX reconfig.PopulatedDi ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14351WEB-ACTIVEX reconfig.PopulatedDi ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14352WEB-ACTIVEX reconfig.PopulatedDi ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14353WEB-ACTIVEX reconfig.PopulatedDi ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14354WEB-ACTIVEX Elevated.ElevMgr ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14355WEB-ACTIVEX Elevated.ElevMgr ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14356WEB-ACTIVEX Elevated.ElevMgr ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14357WEB-ACTIVEX Elevated.ElevMgr ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14358WEB-ACTIVEX VMWare unspecified 5 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14359WEB-ACTIVEX VMWare unspecified 5 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14360WEB-ACTIVEX HardwareCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14361WEB-ACTIVEX HardwareCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14362WEB-ACTIVEX HardwareCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14363WEB-ACTIVEX HardwareCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14364WEB-ACTIVEX VMWare unspecified 6 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14365WEB-ACTIVEX VMWare unspecified 6 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14366WEB-ACTIVEX VmdbQuery Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14367WEB-ACTIVEX VmdbQuery Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14368WEB-ACTIVEX VmdbQuery Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14369WEB-ACTIVEX VmdbQuery Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14370WEB-ACTIVEX vmappPropObj2 Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14371WEB-ACTIVEX vmappPropObj2 Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14372WEB-ACTIVEX vmappPropObj2 Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14373WEB-ACTIVEX vmappPropObj2 Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14374WEB-ACTIVEX VmappPoll Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14375WEB-ACTIVEX VmappPoll Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14376WEB-ACTIVEX VmappPoll Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14377WEB-ACTIVEX VmappPoll Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14378WEB-ACTIVEX VMClient Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14379WEB-ACTIVEX VMClient Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14380WEB-ACTIVEX VMClient Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14381WEB-ACTIVEX VMClient Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14382WEB-ACTIVEX Pq2vcom.Pq2v ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14383WEB-ACTIVEX Pq2vcom.Pq2v ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14384WEB-ACTIVEX Pq2vcom.Pq2v ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14385WEB-ACTIVEX Pq2vcom.Pq2v ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14386WEB-ACTIVEX VmdbSchema Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14387WEB-ACTIVEX VmdbSchema Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14388WEB-ACTIVEX VmdbSchema Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14389WEB-ACTIVEX VmdbSchema Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14390WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14391WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14392WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14393WEB-ACTIVEX Vie2Lib.Vie2LinuxVolume ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14394WEB-ACTIVEX VixCOM.VixLib ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14395WEB-ACTIVEX VixCOM.VixLib ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14396WEB-ACTIVEX VixCOM.VixLib ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14397WEB-ACTIVEX VixCOM.VixLib ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14398WEB-ACTIVEX vmappsdk.CuiObj ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14399WEB-ACTIVEX vmappsdk.CuiObj ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14400WEB-ACTIVEX vmappsdk.CuiObj ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14401WEB-ACTIVEX vmappsdk.CuiObj ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14402WEB-ACTIVEX RemoteBrowseDlg Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14403WEB-ACTIVEX RemoteBrowseDlg Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14404WEB-ACTIVEX RemoteBrowseDlg Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14405WEB-ACTIVEX RemoteBrowseDlg Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14406WEB-ACTIVEX RegVmsCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14407WEB-ACTIVEX RegVmsCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14408WEB-ACTIVEX RegVmsCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14409WEB-ACTIVEX RegVmsCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14410WEB-ACTIVEX VmdbEnumTags Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14411WEB-ACTIVEX VmdbEnumTags Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14412WEB-ACTIVEX VmdbEnumTags Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14413WEB-ACTIVEX VmdbEnumTags Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14414WEB-ACTIVEX VMWare unspecified 7 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14415WEB-ACTIVEX VMWare unspecified 7 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14416WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14417WEB-ACTIVEX VieLib2.Vie2Process ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14418WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14419WEB-ACTIVEX VieLib2.Vie2Process ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14420WEB-ACTIVEX VmdbDatabase Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14421WEB-ACTIVEX VmdbDatabase Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14422WEB-ACTIVEX VmdbDatabase Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14423WEB-ACTIVEX VmdbDatabase Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14424WEB-ACTIVEX VMAppSdkUtil Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14425WEB-ACTIVEX VMAppSdkUtil Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14426WEB-ACTIVEX VMAppSdkUtil Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14427WEB-ACTIVEX VMAppSdkUtil Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14428WEB-ACTIVEX VMWare unspecified 8 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14429WEB-ACTIVEX VMWare unspecified 8 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14430WEB-ACTIVEX VMEnumStrings Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14431WEB-ACTIVEX VMEnumStrings Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14432WEB-ACTIVEX VMEnumStrings Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14433WEB-ACTIVEX VMEnumStrings Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14434WEB-ACTIVEX VMWare unspecified 9 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14435WEB-ACTIVEX VMWare unspecified 9 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14436WEB-ACTIVEX VMClientHost Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14437WEB-ACTIVEX VMClientHost Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14438WEB-ACTIVEX VMClientHost Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14439WEB-ACTIVEX VMClientHost Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14440WEB-ACTIVEX VMWare unspecified 10 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14441WEB-ACTIVEX VMWare unspecified 10 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14442WEB-ACTIVEX VMWare unspecified 11 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14443WEB-ACTIVEX VMWare unspecified 11 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14444WEB-ACTIVEX VMWare unspecified 12 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14445WEB-ACTIVEX VMWare unspecified 12 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14446WEB-ACTIVEX VMWare unspecified 13 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14447WEB-ACTIVEX VMWare unspecified 13 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14448WEB-ACTIVEX reconfig.SystemReconfigur ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14449WEB-ACTIVEX reconfig.SystemReconfigur ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14450WEB-ACTIVEX reconfig.SystemReconfigur ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14451WEB-ACTIVEX reconfig.SystemReconfigur ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14452WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14453WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14454WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14455WEB-ACTIVEX vmhwcfg.NwzCompleted ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14456WEB-ACTIVEX MksCompatCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14457WEB-ACTIVEX MksCompatCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14458WEB-ACTIVEX MksCompatCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14459WEB-ACTIVEX MksCompatCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14460WEB-ACTIVEX VMWare unspecified 14 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14461WEB-ACTIVEX VMWare unspecified 14 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14462WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14463WEB-ACTIVEX IntraProcessLogging.Logger ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14464WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14465WEB-ACTIVEX IntraProcessLogging.Logger ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14466WEB-ACTIVEX VMWare unspecified 15 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14467WEB-ACTIVEX VMWare unspecified 15 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14468WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14469WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14470WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14471WEB-ACTIVEX Elevated.HostDeviceInfos ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14472WEB-ACTIVEX VMWare unspecified 16 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14473WEB-ACTIVEX VMWare unspecified 16 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14474WEB-ACTIVEX VMWare unspecified 17 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14475WEB-ACTIVEX VMWare unspecified 17 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14476WEB-ACTIVEX reconfig.GuestInfo ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14477WEB-ACTIVEX reconfig.GuestInfo ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14478WEB-ACTIVEX reconfig.GuestInfo ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14479WEB-ACTIVEX reconfig.GuestInfo ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14480WEB-ACTIVEX VmappPropFrame Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14481WEB-ACTIVEX VmappPropFrame Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14482WEB-ACTIVEX VmappPropFrame Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14483WEB-ACTIVEX VmappPropFrame Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14484WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14485WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14486WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14487WEB-ACTIVEX VhdCvtCom.VhdConverter ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14488WEB-ACTIVEX VMSwitchCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14489WEB-ACTIVEX VMSwitchCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14490WEB-ACTIVEX VMSwitchCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14491WEB-ACTIVEX VMSwitchCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14492WEB-ACTIVEX VMWare unspecified 18 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14493WEB-ACTIVEX VMWare unspecified 18 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14494WEB-ACTIVEX VmdbUtil Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14495WEB-ACTIVEX VmdbUtil Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14496WEB-ACTIVEX VmdbUtil Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14497WEB-ACTIVEX VmdbUtil Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14498WEB-ACTIVEX VMWare unspecified 19 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14499WEB-ACTIVEX VMWare unspecified 19 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14500WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14501WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14502WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14503WEB-ACTIVEX VMwareVpcCvt.VpcC ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14504WEB-ACTIVEX VmdbCnxUtil Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14505WEB-ACTIVEX VmdbCnxUtil Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14506WEB-ACTIVEX VmdbCnxUtil Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14507WEB-ACTIVEX VmdbCnxUtil Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14508WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14509WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14510WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14511WEB-ACTIVEX Vmc2vmx.CoVPCDrive ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14512WEB-ACTIVEX VMWare unspecified 20 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14513WEB-ACTIVEX VMWare unspecified 20 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14514WEB-ACTIVEX VMClientVM Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14515WEB-ACTIVEX VMClientVM Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14516WEB-ACTIVEX VMClientVM Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14517WEB-ACTIVEX VMClientVM Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14518WEB-ACTIVEX VMWare unspecified 21 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14519WEB-ACTIVEX VMWare unspecified 21 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14520WEB-ACTIVEX Elevated.VMXCreator ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14521WEB-ACTIVEX Elevated.VMXCreator ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14522WEB-ACTIVEX Elevated.VMXCreator ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14523WEB-ACTIVEX Elevated.VMXCreator ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14524WEB-ACTIVEX VMWare unspecified 22 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14525WEB-ACTIVEX VMWare unspecified 22 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14526WEB-ACTIVEX HotfixWz Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14527WEB-ACTIVEX HotfixWz Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14528WEB-ACTIVEX HotfixWz Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14529WEB-ACTIVEX HotfixWz Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14530WEB-ACTIVEX VmdbUpdates Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14531WEB-ACTIVEX VmdbUpdates Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14532WEB-ACTIVEX VmdbUpdates Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14533WEB-ACTIVEX VmdbUpdates Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14534WEB-ACTIVEX VMListCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14535WEB-ACTIVEX VMListCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14536WEB-ACTIVEX VMListCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14537WEB-ACTIVEX VMListCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14538WEB-ACTIVEX CheckedListViewWnd Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14539WEB-ACTIVEX CheckedListViewWnd Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14540WEB-ACTIVEX CheckedListViewWnd Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14541WEB-ACTIVEX CheckedListViewWnd Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14542WEB-ACTIVEX VMWare unspecified 23 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14543WEB-ACTIVEX VMWare unspecified 23 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14544WEB-ACTIVEX VmdbTreeCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14545WEB-ACTIVEX VmdbTreeCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14546WEB-ACTIVEX VmdbTreeCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14547WEB-ACTIVEX VmdbTreeCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14548WEB-ACTIVEX Nwz Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14549WEB-ACTIVEX Nwz Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14550WEB-ACTIVEX Nwz Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14551WEB-ACTIVEX Nwz Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14552WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14553WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14554WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14555WEB-ACTIVEX Vmc2vmx.CoVPCDrives ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14556WEB-ACTIVEX MksCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14557WEB-ACTIVEX MksCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14558WEB-ACTIVEX MksCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14559WEB-ACTIVEX MksCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14560WEB-ACTIVEX VmappPropPath Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14561WEB-ACTIVEX VmappPropPath Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14562WEB-ACTIVEX VmappPropPath Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14563WEB-ACTIVEX VmappPropPath Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14564WEB-ACTIVEX VMWare unspecified 24 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14565WEB-ACTIVEX VMWare unspecified 24 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14566WEB-ACTIVEX PolicyCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14567WEB-ACTIVEX PolicyCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14568WEB-ACTIVEX PolicyCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14569WEB-ACTIVEX PolicyCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14570WEB-ACTIVEX VmdbParseError Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14571WEB-ACTIVEX VmdbParseError Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14572WEB-ACTIVEX VmdbParseError Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14573WEB-ACTIVEX VmdbParseError Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14574WEB-ACTIVEX NavigationCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14575WEB-ACTIVEX NavigationCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14576WEB-ACTIVEX NavigationCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14577WEB-ACTIVEX NavigationCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14578WEB-ACTIVEX VMList Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14579WEB-ACTIVEX VMList Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14580WEB-ACTIVEX VMList Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14581WEB-ACTIVEX VMList Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14582WEB-ACTIVEX VMWare unspecified 25 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14583WEB-ACTIVEX VMWare unspecified 25 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14584WEB-ACTIVEX VMWare unspecified 26 ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14585WEB-ACTIVEX VMWare unspecified 26 ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14586WEB-ACTIVEX CurrentVMCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14587WEB-ACTIVEX CurrentVMCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14588WEB-ACTIVEX CurrentVMCtl Class ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14589WEB-ACTIVEX CurrentVMCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14590WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX clsid access (more info ...)attempted-user  2008-3696  30934    URL
14591WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX clsid unicode access (more info ...)attempted-user  2008-3696  30934    URL
14592WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX function call access (more info ...)attempted-user  2008-3696  30934    URL
14593WEB-ACTIVEX VhdCvtCom.DiskLibHelper ActiveX function call unicode access (more info ...)attempted-user  2008-3696  30934    URL
14594WEB-ACTIVEX Peachtree Accounting 2004 ActiveX clsid access (more info ...)attempted-user    31096    
14595WEB-ACTIVEX Peachtree Accounting 2004 ActiveX clsid unicode access (more info ...)attempted-user    31096    
14596WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX clsid access (more info ...)attempted-user    31200    
14597WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX clsid unicode access (more info ...)attempted-user    31200    
14598WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX function call access (more info ...)attempted-user    31200    
14599WEB-ACTIVEX ComponentOne VSFlexGrid ActiveX function call unicode access (more info ...)attempted-user    31200    
14603WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX clsid access (more info ...)attempted-user    31227    
14604WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX clsid unicode access (more info ...)attempted-user    31227    
14605WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX function call access (more info ...)attempted-user    31227    
14606WEB-ACTIVEX Data Dynamics ActiveReport ARViewer2 ActiveX function call unicode access (more info ...)attempted-user    31227    
14607EXPLOIT CA Brightstor SUN RPC malformed string buffer overflow attempt (more info ...)attempted-admin  2007-2139  23635    
14611WEB-ACTIVEX VMWare VMCtl Class ActiveX clsid access (more info ...)attempted-user  2008-3892  30934    
14612WEB-ACTIVEX VMWare VMCtl Class ActiveX clsid unicode access (more info ...)attempted-user  2008-3892  30934    
14613WEB-ACTIVEX VMWare VMCtl Class ActiveX function call access (more info ...)attempted-user  2008-3892  30934    
14614WEB-ACTIVEX VMWare VMCtl Class ActiveX function call unicode access (more info ...)attempted-user  2008-3892  30934    
14631WEB-ACTIVEX SystemRequirementsLab ActiveX clsid access (more info ...)attempted-user        URL
14632WEB-ACTIVEX SystemRequirementsLab ActiveX clsid unicode access (more info ...)attempted-user        URL
14633WEB-ACTIVEX PhotoStockPlus ActiveX clsid access (more info ...)attempted-user  2008-0957  29279    URL
14634WEB-ACTIVEX PhotoStockPlus ActiveX clsid unicode access (more info ...)attempted-user  2008-0957  29279    URL
14635WEB-ACTIVEX Microsoft RSClientPrint ActiveX clsid access (more info ...)attempted-user  2008-3015      URL
14636WEB-ACTIVEX Microsoft RSClientPrint ActiveX clsid unicode access (more info ...)attempted-user  2008-3015      URL
14637WEB-ACTIVEX Microsoft PicturePusher ActiveX clsid access (more info ...)attempted-user  2008-4493  31632    
14638WEB-ACTIVEX Microsoft PicturePusher ActiveX clsid unicode access (more info ...)attempted-user  2008-4493  31632    
14639WEB-ACTIVEX Microsoft PicturePusher ActiveX function call access (more info ...)attempted-user  2008-4493  31632    
14640WEB-ACTIVEX Microsoft PicturePusher ActiveX function call unicode access (more info ...)attempted-user  2008-4493  31632    
14647NETBIOS-DG SMB Search Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14648NETBIOS-DG SMB Search unicode Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14649NETBIOS SMB Search Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14650NETBIOS SMB Search unicode Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14651NETBIOS-DG SMB Search andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14652NETBIOS-DG SMB Search unicode andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14653NETBIOS SMB Search andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14654NETBIOS SMB Search unicode andx Search filename size integer underflow attempt (more info ...)protocol-command-decode  2008-4038      URL
14661NETBIOS DCERPC NCACN-IP-TCP spoolss EnumJobs attempt (more info ...)protocol-command-decode  2008-1446      URL
14709NETBIOS SMB spoolss EnumJobs response WriteAndX unicode little endian attempt (more info ...)protocol-command-decode  2008-1446      URL
14711NETBIOS SMB spoolss EnumJobs response little endian attempt (more info ...)protocol-command-decode  2008-1446      URL
14712NETBIOS SMB spoolss EnumJobs response WriteAndX little endian attempt (more info ...)protocol-command-decode  2008-1446      URL
14713NETBIOS SMB spoolss EnumJobs response attempt (more info ...)protocol-command-decode  2008-1446      URL
14714NETBIOS SMB spoolss EnumJobs response unicode attempt (more info ...)protocol-command-decode  2008-1446      URL
14715NETBIOS SMB spoolss EnumJobs response WriteAndX attempt (more info ...)protocol-command-decode  2008-1446      URL
14716NETBIOS SMB spoolss EnumJobs response WriteAndX unicode attempt (more info ...)protocol-command-decode  2008-1446      URL
14717NETBIOS SMB spoolss EnumJobs response WriteAndX unicode little endian andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14718NETBIOS SMB spoolss EnumJobs response unicode little endian andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14719NETBIOS SMB spoolss EnumJobs response little endian andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14720NETBIOS SMB spoolss EnumJobs response WriteAndX little endian andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14721NETBIOS SMB spoolss EnumJobs response andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14722NETBIOS SMB spoolss EnumJobs response unicode andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14723NETBIOS SMB spoolss EnumJobs response WriteAndX andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14724NETBIOS SMB spoolss EnumJobs response WriteAndX unicode andx attempt (more info ...)protocol-command-decode  2008-1446      URL
14725NETBIOS DCERPC NCACN-IP-TCP mqqm QMGetRemoteQueueName overflow attempt (more info ...)attempted-admin  2008-3479      URL
14726NETBIOS DCERPC NCADG-IP-UDP mqqm QMGetRemoteQueueName overflow attempt (more info ...)attempted-admin  2008-3479      URL
14737NETBIOS DCERPC NCACN-IP-TCP host-integration bind attempt (more info ...)protocol-command-decode  2008-3466      URL
14744WEB-ACTIVEX Hummingbird HostExplorer ActiveX clsid access (more info ...)attempted-user    31783    
14745WEB-ACTIVEX Hummingbird HostExplorer ActiveX clsid unicode access (more info ...)attempted-user    31783    
14746WEB-ACTIVEX Autodesk DWF Viewer ActiveX clsid access (more info ...)attempted-user  2008-4472  31490    
14747WEB-ACTIVEX Autodesk DWF Viewer ActiveX clsid unicode access (more info ...)attempted-user  2008-4472  31490    
14748WEB-ACTIVEX Autodesk LiveUpdate ActiveX clsid access (more info ...)attempted-user  2008-4472  31490    
14749WEB-ACTIVEX Autodesk LiveUpdate ActiveX clsid unicode access (more info ...)attempted-user  2008-4472  31490    
14750WEB-ACTIVEX Autodesk LiveUpdate ActiveX function call access (more info ...)attempted-user  2008-4472  31490    
14751WEB-ACTIVEX Autodesk LiveUpdate ActiveX function call unicode access (more info ...)attempted-user  2008-4472  31490    
14752WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX clsid access (more info ...)attempted-user    31435    
14753WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX clsid unicode access (more info ...)attempted-user    31435    
14754WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX function call access (more info ...)attempted-user    31435    
14755WEB-ACTIVEX Novell ZENworks Desktop Management ActiveX function call unicode access (more info ...)attempted-user    31435    
14760WEB-ACTIVEX iseemedia LPViewer ActiveX clsid access (more info ...)attempted-user  2008-4384  31604    
14761WEB-ACTIVEX iseemedia LPViewer ActiveX clsid unicode access (more info ...)attempted-user  2008-4384  31604    
14762WEB-ACTIVEX iseemedia LPViewer ActiveX function call access (more info ...)attempted-user  2008-4384  31604    
14763WEB-ACTIVEX iseemedia LPViewer ActiveX function call unicode access (more info ...)attempted-user  2008-4384  31604    
14782NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt (more info ...)attempted-admin  2008-4250      URL
14783NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrpPathCanonicalize path canonicalization stack overflow attempt (more info ...)attempted-admin  2008-4250      URL
14896NETBIOS-DG SMB v4 srvsvc NetrpPathCononicalize unicode path cononicalization stack overflow attempt (more info ...)attempted-admin  2008-4250      URL
14897WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX function call access (more info ...)attempted-user  2007-6506  26950    
14898WEB-ACTIVEX HP Software Update RulesEngine.dll ActiveX function call unicode access (more info ...)attempted-user  2007-6506  26950    
14900NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum overflow attempt (more info ...)attempted-admin  2007-2446  24198    
14988NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum overflow attempt (more info ...)attempted-admin  2007-2446  24198    
14993WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX clsid access (more info ...)attempted-user  2008-4919  31984    
14994WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX clsid unicode access (more info ...)attempted-user  2008-4919  31984    
14995WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX function call access (more info ...)attempted-user  2008-4919  31984    
14996WEB-ACTIVEX Visagesoft eXPert PDF Viewer ActiveX function call unicode access (more info ...)attempted-user  2008-4919  31984    
14999WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX clsid access (more info ...)attempted-user  2008-4800  31996    
15000WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX clsid unicode access (more info ...)attempted-user  2008-4800  31996    
15001WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX function call access (more info ...)attempted-user  2008-4800  31996    
15002WEB-ACTIVEX Microsoft Debug Diagnostic Tool ActiveX function call unicode access (more info ...)attempted-user  2008-4800  31996    
15003WEB-ACTIVEX Chilkat Crypt 2 ActiveX clsid access (more info ...)attempted-user    32073    
15004WEB-ACTIVEX Chilkat Crypt 2 ActiveX clsid unicode access (more info ...)attempted-user    32073    
15005WEB-ACTIVEX Chilkat Crypt 2 ActiveX function call access (more info ...)attempted-user    32073    
15006WEB-ACTIVEX Chilkat Crypt 2 ActiveX function call unicode access (more info ...)attempted-user    32073    
15009NETBIOS possible SMB replay attempt - overlapping encryption keys detected (more info ...)attempted-user  2000-0834      URL
15011WEB-CLIENT Microsoft XML core services cross-domain information disclosure attempt (more info ...)misc-attack  2008-4033      URL
15015NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrUseAdd/NetrUseGetInfo/NetrUseDel overflow attempt (more info ...)attempted-admin  2008-4250      URL
15069WEB-ACTIVEX SAP AG SAPgui mdrmsap ActiveX clsid access (more info ...)attempted-user  2008-4387  32186    
15070WEB-ACTIVEX SAP AG SAPgui mdrmsap ActiveX clsid unicode access (more info ...)attempted-user  2008-4387  32186    
15084WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX clsid access (more info ...)attempted-user  2008-4255      URL
15086WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX function call access (more info ...)attempted-user  2008-4255      URL
15124NETBIOS Web-based NTLM replay attack attempt (more info ...)attempted-user  2000-0834      URL
15127NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15128NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX attempt (more info ...)attempted-admin  2008-5416  32710    URL
15129NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX unicode andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15130NETBIOS SMB sp_replwritetovarbin vulnerable function WriteAndX unicode attempt (more info ...)attempted-admin  2008-5416  32710    URL
15131NETBIOS SMB sp_replwritetovarbin vulnerable function andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15132NETBIOS SMB sp_replwritetovarbin vulnerable function attempt (more info ...)attempted-admin  2008-5416  32710    URL
15133NETBIOS SMB sp_replwritetovarbin vulnerable function unicode andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15134NETBIOS SMB sp_replwritetovarbin vulnerable function unicode attempt (more info ...)attempted-admin  2008-5416  32710    URL
15135NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15136NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX attempt (more info ...)attempted-admin  2008-5416  32710    URL
15137NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX unicode andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15138NETBIOS-DG SMB sp_replwritetovarbin vulnerable function WriteAndX unicode attempt (more info ...)attempted-admin  2008-5416  32710    URL
15139NETBIOS-DG SMB sp_replwritetovarbin vulnerable function andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15140NETBIOS-DG SMB sp_replwritetovarbin vulnerable function attempt (more info ...)attempted-admin  2008-5416  32710    URL
15141NETBIOS-DG SMB sp_replwritetovarbin vulnerable function unicode andx attempt (more info ...)attempted-admin  2008-5416  32710    URL
15142NETBIOS-DG SMB sp_replwritetovarbin vulnerable function unicode attempt (more info ...)attempted-admin  2008-5416  32710    URL
15147WEB-CLIENT Microsoft IE malformed iframe buffer overflow attempt (more info ...)attempted-user  2004-1050      
15148DOS Microsoft SMS remote control client message length denial of service attempt (more info ...)attempted-dos  2004-0728  10726    
15173WEB-ACTIVEX Phoenician Casino ActiveX clsid access (more info ...)attempted-user  2008-5691  32901    
15174WEB-ACTIVEX Phoenician Casino ActiveX clsid unicode access (more info ...)attempted-user  2008-5691  32901    
15175WEB-ACTIVEX Phoenician Casino ActiveX function call access (more info ...)attempted-user  2008-5691  32901    
15176WEB-ACTIVEX Phoenician Casino ActiveX function call unicode access (more info ...)attempted-user  2008-5691  32901    
15177WEB-ACTIVEX Trend Micro HouseCall ActiveX clsid access (more info ...)attempted-user  2008-2435  32965    
15178WEB-ACTIVEX Trend Micro HouseCall ActiveX clsid unicode access (more info ...)attempted-user  2008-2435  32965    
15179WEB-ACTIVEX Trend Micro HouseCall ActiveX function call access (more info ...)attempted-user  2008-2435  32965    
15180WEB-ACTIVEX Trend Micro HouseCall ActiveX function call unicode access (more info ...)attempted-user  2008-2435  32965    
15181WEB-ACTIVEX SaschArt SasCam Webcam Server ActiveX clsid access (more info ...)attempted-user    33053    
15182WEB-ACTIVEX SaschArt SasCam Webcam Server ActiveX clsid unicode access (more info ...)attempted-user    33053    
15192WEB-ACTIVEX SizerOne ActiveX clsid access (more info ...)attempted-user  2008-4827  33148    
15193WEB-ACTIVEX SizerOne ActiveX clsid unicode access (more info ...)attempted-user  2008-4827  33148    
15194WEB-ACTIVEX SizerOne ActiveX function call access (more info ...)attempted-user  2008-4827  33148    
15195WEB-ACTIVEX SizerOne ActiveX function call unicode access (more info ...)attempted-user  2008-4827  33148    
15196NETBIOS SMB NT Trans NT CREATE unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15197NETBIOS-DG SMB NT Trans NT CREATE param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15198NETBIOS-DG SMB NT Trans NT CREATE unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15199NETBIOS SMB NT Trans NT CREATE param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15200NETBIOS SMB NT Trans NT CREATE unicode andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15201NETBIOS-DG SMB NT Trans NT CREATE andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15202NETBIOS-DG SMB NT Trans NT CREATE unicode andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15203NETBIOS SMB NT Trans NT CREATE andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15204NETBIOS-DG SMB NT Trans NT CREATE unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15205NETBIOS SMB NT Trans NT CREATE unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15206NETBIOS SMB NT Trans NT CREATE max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15207NETBIOS-DG SMB NT Trans NT CREATE max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15208NETBIOS-DG SMB NT Trans NT CREATE unicode andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15209NETBIOS SMB NT Trans NT CREATE unicode andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15210NETBIOS SMB NT Trans NT CREATE andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15211NETBIOS-DG SMB NT Trans NT CREATE andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4834      URL
15212NETBIOS-DG SMB Trans2 OPEN2 max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15213NETBIOS SMB Trans2 OPEN2 unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15214NETBIOS SMB Trans2 OPEN2 max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15215NETBIOS-DG SMB Trans2 OPEN2 unicode max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15216NETBIOS-DG SMB Trans2 OPEN2 andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15217NETBIOS SMB Trans2 OPEN2 unicode andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15218NETBIOS SMB Trans2 OPEN2 andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15219NETBIOS-DG SMB Trans2 OPEN2 unicode andx max_param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15220NETBIOS SMB Trans2 OPEN2 unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15221NETBIOS SMB Trans2 OPEN2 param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15222NETBIOS-DG SMB Trans2 OPEN2 param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15223NETBIOS-DG SMB Trans2 OPEN2 unicode param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15224NETBIOS SMB Trans2 OPEN2 unicode andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15225NETBIOS SMB Trans2 OPEN2 andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15226NETBIOS-DG SMB Trans2 OPEN2 andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15227NETBIOS-DG SMB Trans2 OPEN2 unicode andx param_count underflow attempt (more info ...)protocol-command-decode  2008-4835      URL
15228WEB-ACTIVEX Ciansoft PDFBuilderX ActiveX clsid access (more info ...)attempted-user    33233    
15229WEB-ACTIVEX Ciansoft PDFBuilderX ActiveX clsid unicode access (more info ...)attempted-user    33233    
15232WEB-ACTIVEX Easy Grid ActiveX clsid access (more info ...)attempted-user    33272    
15233WEB-ACTIVEX Easy Grid ActiveX clsid unicode access (more info ...)attempted-user    33272    
15234WEB-ACTIVEX Easy Grid ActiveX function call access (more info ...)attempted-user    33272    
15235WEB-ACTIVEX Easy Grid ActiveX function call unicode access (more info ...)attempted-user    33272    
15243WEB-ACTIVEX AXIS Camera ActiveX clsid access (more info ...)attempted-user  2008-5260  33408    
15244WEB-ACTIVEX AXIS Camera ActiveX clsid unicode access (more info ...)attempted-user  2008-5260  33408    
15245WEB-ACTIVEX AXIS Camera ActiveX function call access (more info ...)attempted-user  2008-5260  33408    
15246WEB-ACTIVEX AXIS Camera ActiveX function call unicode access (more info ...)attempted-user  2008-5260  33408    
15247WEB-ACTIVEX JamDTA ActiveX clsid access (more info ...)attempted-user    33345    
15248WEB-ACTIVEX JamDTA ActiveX clsid unicode access (more info ...)attempted-user    33345    
15249WEB-ACTIVEX SmartVMD ActiveX clsid access (more info ...)attempted-user    33349    
15250WEB-ACTIVEX SmartVMD ActiveX clsid unicode access (more info ...)attempted-user    33349    
15251WEB-ACTIVEX MetaProducts MetaTreeX ActiveX clsid access (more info ...)attempted-user    33318    
15252WEB-ACTIVEX MetaProducts MetaTreeX ActiveX clsid unicode access (more info ...)attempted-user    33318    
15253WEB-ACTIVEX MetaProducts MetaTreeX ActiveX function call access (more info ...)attempted-user    33318    
15254WEB-ACTIVEX MetaProducts MetaTreeX ActiveX function call unicode access (more info ...)attempted-user    33318    
15265WEB-ACTIVEX NCTAudioFile2 ActiveX function call unicode access (more info ...)attempted-user  2007-0018  33469    URL
15266WEB-ACTIVEX MW6 Technologies Barcode ActiveX clsid access (more info ...)attempted-user  2009-0298  33451    
15267WEB-ACTIVEX MW6 Technologies Barcode ActiveX clsid unicode access (more info ...)attempted-user  2009-0298  33451    
15268WEB-ACTIVEX MW6 Technologies Barcode ActiveX function call access (more info ...)attempted-user  2009-0298  33451    
15269WEB-ACTIVEX MW6 Technologies Barcode ActiveX function call unicode access (more info ...)attempted-user  2009-0298  33451    
15270WEB-ACTIVEX MW6 Technologies PDF417 ActiveX clsid access (more info ...)attempted-user  2008-4926      
15271WEB-ACTIVEX MW6 Technologies PDF417 ActiveX clsid unicode access (more info ...)attempted-user  2008-4926      
15272WEB-ACTIVEX MW6 Technologies PDF417 ActiveX function call access (more info ...)attempted-user  2008-4926      
15273WEB-ACTIVEX MW6 Technologies PDF417 ActiveX function call unicode access (more info ...)attempted-user  2008-4926      
15274WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX clsid access (more info ...)attempted-user  2008-4925      
15275WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX clsid unicode access (more info ...)attempted-user  2008-4925      
15276WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX function call access (more info ...)attempted-user  2008-4925      
15277WEB-ACTIVEX MW6 Technologies DataMatrix ActiveX function call unicode access (more info ...)attempted-user  2008-4925      
15278WEB-ACTIVEX MW6 Technologies Aztec ActiveX clsid access (more info ...)attempted-user  2008-4923      
15279WEB-ACTIVEX MW6 Technologies Aztec ActiveX clsid unicode access (more info ...)attempted-user  2008-4923      
15280WEB-ACTIVEX MW6 Technologies Aztec ActiveX function call access (more info ...)attempted-user  2008-4923      
15281WEB-ACTIVEX MW6 Technologies Aztec ActiveX function call unicode access (more info ...)attempted-user  2008-4923      
15284WEB-ACTIVEX NCTAudioGrabber2 ActiveX clsid access (more info ...)attempted-user  2008-0958      URL
15285WEB-ACTIVEX NCTAudioGrabber2 ActiveX clsid unicode access (more info ...)attempted-user  2008-0958      URL
15286WEB-ACTIVEX NCTAudioGrabber2 ActiveX function call access (more info ...)attempted-user  2008-0958      URL
15287WEB-ACTIVEX NCTAudioGrabber2 ActiveX function call unicode access (more info ...)attempted-user  2008-0958      URL
15288WEB-ACTIVEX NCTAudioInformation2 ActiveX clsid access (more info ...)attempted-user  2008-0959      URL
15289WEB-ACTIVEX NCTAudioInformation2 ActiveX clsid unicode access (more info ...)attempted-user  2008-0959      URL
15290WEB-ACTIVEX NCTAudioInformation2 ActiveX function call access (more info ...)attempted-user  2008-0959      URL
15291WEB-ACTIVEX NCTAudioInformation2 ActiveX function call unicode access (more info ...)attempted-user  2008-0959      URL
15307WEB-ACTIVEX Microsoft Animation Control ActiveX clsid access (more info ...)attempted-user        URL
15308WEB-ACTIVEX Microsoft Animation Control ActiveX clsid unicode access (more info ...)attempted-user        URL
15309WEB-ACTIVEX Microsoft Animation Control ActiveX function call access (more info ...)attempted-user        URL
15310WEB-ACTIVEX Microsoft Animation Control ActiveX function call unicode access (more info ...)attempted-user        URL
15311WEB-ACTIVEX Research In Motion AxLoader ActiveX clsid access (more info ...)attempted-user  2009-0305  33663    URL
15312WEB-ACTIVEX Research In Motion AxLoader ActiveX clsid unicode access (more info ...)attempted-user  2009-0305  33663    URL
15313WEB-ACTIVEX Research In Motion AxLoader ActiveX function call access (more info ...)attempted-user  2009-0305  33663    URL
15314WEB-ACTIVEX Research In Motion AxLoader ActiveX function call unicode access (more info ...)attempted-user  2009-0305  33663    URL
15315WEB-ACTIVEX Akamai DownloadManager ActiveX clsid access (more info ...)attempted-user        URL
15316WEB-ACTIVEX Akamai DownloadManager ActiveX clsid unicode access (more info ...)attempted-user        URL
15317WEB-ACTIVEX Akamai DownloadManager ActiveX function call access (more info ...)attempted-user        URL
15318WEB-ACTIVEX Akamai DownloadManager ActiveX function call unicode access (more info ...)attempted-user        URL
15330WEB-ACTIVEX Nokia Phoenix Service 1 ActiveX clsid access (more info ...)attempted-user    33726    
15331WEB-ACTIVEX Nokia Phoenix Service 1 ActiveX clsid unicode access (more info ...)attempted-user    33726    
15332WEB-ACTIVEX Nokia Phoenix Service 2 ActiveX clsid access (more info ...)attempted-user    33726    
15333WEB-ACTIVEX Nokia Phoenix Service 2 ActiveX clsid unicode access (more info ...)attempted-user    33726    
15346WEB-ACTIVEX Synactis ALL In-The-Box ActiveX clsid access (more info ...)attempted-user  2009-0465  33535    
15347WEB-ACTIVEX Synactis ALL In-The-Box ActiveX clsid unicode access (more info ...)attempted-user  2009-0465  33535    
15348WEB-ACTIVEX Synactis ALL In-The-Box ActiveX function call access (more info ...)attempted-user  2009-0465  33535    
15349WEB-ACTIVEX Synactis ALL In-The-Box ActiveX function call unicode access (more info ...)attempted-user  2009-0465  33535    
15350WEB-ACTIVEX Web on Windows ActiveX clsid access (more info ...)attempted-user  2009-0389  33515    
15351WEB-ACTIVEX Web on Windows ActiveX clsid unicode access (more info ...)attempted-user  2009-0389  33515    
15352WEB-ACTIVEX Web on Windows ActiveX function call access (more info ...)attempted-user  2009-0389  33515    
15353WEB-ACTIVEX Web on Windows ActiveX function call unicode access (more info ...)attempted-user  2009-0389  33515    
15372WEB-ACTIVEX iDefense COMRaider ActiveX clsid access (more info ...)attempted-user    33867    
15373WEB-ACTIVEX iDefense COMRaider ActiveX clsid unicode access (more info ...)attempted-user    33867    
15374WEB-ACTIVEX iDefense COMRaider ActiveX function call access (more info ...)attempted-user    33867    
15375WEB-ACTIVEX iDefense COMRaider ActiveX function call unicode access (more info ...)attempted-user    33867    
15376WEB-ACTIVEX Sopcast SopCore ActiveX clsid access (more info ...)attempted-user    33920    
15377WEB-ACTIVEX Sopcast SopCore ActiveX clsid unicode access (more info ...)attempted-user    33920    
15378WEB-ACTIVEX Sopcast SopCore ActiveX function call access (more info ...)attempted-user    33920    
15379WEB-ACTIVEX Sopcast SopCore ActiveX function call unicode access (more info ...)attempted-user    33920    
15380WEB-ACTIVEX HP Virtual Rooms v7 ActiveX clsid access (more info ...)attempted-user  2009-0208  33918    
15381WEB-ACTIVEX HP Virtual Rooms v7 ActiveX clsid unicode access (more info ...)attempted-user  2009-0208  33918    
15387NETBIOS udp WINS WPAD registration attempt (more info ...)misc-attack  2009-0094      URL
15430WEB-CLIENT Microsoft EMF+ GpFont.SetData buffer overflow attempt (more info ...)attempted-user  2009-1217  34250    
15453NETBIOS SMB replay attempt via NTLMSSP - overlapping encryption keys detected (more info ...)attempted-user  2000-0834      URL
15498WEB-CLIENT Microsoft PowerPoint CString atom overflow attempt (more info ...)attempted-admin  2009-1128      URL
15500WEB-CLIENT Microsoft PowerPoint LinkedSlide memory corruption (more info ...)attempted-user  2009-0221      URL
15501WEB-CLIENT Microsoft Powerpoint ParaBuildAtom memory corruption attempt (more info ...)attempted-user  2009-0224      URL
15502WEB-CLIENT Microsoft Powerpoint DiagramBuildContainer memory corruption attempt (more info ...)attempted-user  2009-0224      URL
15505WEB-CLIENT Microsoft PowerPoint HashCode10Atom memory corruption attempt (more info ...)attempted-user  2009-1130      URL
15506WEB-CLIENT Microsoft PowerPoint CurrentUserAtom remote code execution attempt (more info ...)attempted-user  2009-1131      URL
15512NETBIOS DCERPC NCACN-IP-TCP rpcss2 _RemoteGetClassObject attempt (more info ...)protocol-command-decode  2003-0605      URL
15513NETBIOS DCERPC NCADG-IP-UDP rpcss2 _RemoteGetClassObject attempt (more info ...)protocol-command-decode  2003-0605      URL
15526EXPLOIT Microsoft Works 4.x converter font name buffer overflow attempt (more info ...)attempted-user  2009-1533      URL
15527EXPLOIT Microsoft Active Directory LDAP denial of service attempt (more info ...)attempted-admin  2009-1138      URL
15528NETBIOS DCERPC NCACN-IP-TCP spoolss RpcSetPrinterDataEx attempt (more info ...)protocol-command-decode  2009-0230      URL
15540WEB-CLIENT Microsoft IE DOM memory corruption attempt (more info ...)attempted-admin  2009-1532      URL
15543WEB-ACTIVEX Microsoft Communications Control v6 ActiveX clsid access (more info ...)attempted-user        URL
15544WEB-ACTIVEX Microsoft Communications Control v6 ActiveX clsid unicode access (more info ...)attempted-user        URL
15545WEB-ACTIVEX Microsoft Communications Control v6 ActiveX function call access (more info ...)attempted-user        URL
15546WEB-ACTIVEX Microsoft Communications Control v6 ActiveX function call unicode access (more info ...)attempted-user        URL
15547WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX clsid access (more info ...)attempted-user        URL
15548WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX clsid unicode access (more info ...)attempted-user        URL
15549WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX function call access (more info ...)attempted-user        URL
15550WEB-ACTIVEX eBay Picture Uploads control 1 ActiveX function call unicode access (more info ...)attempted-user        URL
15551WEB-ACTIVEX eBay Picture Uploads control 2 ActiveX clsid access (more info ...)attempted-user        URL
15552WEB-ACTIVEX eBay Picture Uploads control 2 ActiveX clsid unicode access (more info ...)attempted-user        URL
15557WEB-ACTIVEX SAP AG SAPgui EnjoySAP ActiveX clsid access (more info ...)attempted-user    35256    
15558WEB-ACTIVEX SAP AG SAPgui EnjoySAP ActiveX clsid unicode access (more info ...)attempted-user    35256    
15588WEB-ACTIVEX Microsoft Video 1 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15589WEB-ACTIVEX Microsoft Video 1 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15590WEB-ACTIVEX Microsoft Video 10 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15591WEB-ACTIVEX Microsoft Video 10 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15592WEB-ACTIVEX Microsoft Video 11 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15593WEB-ACTIVEX Microsoft Video 11 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15594WEB-ACTIVEX Microsoft Video 12 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15595WEB-ACTIVEX Microsoft Video 12 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15596WEB-ACTIVEX Microsoft Video 13 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15597WEB-ACTIVEX Microsoft Video 13 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15598WEB-ACTIVEX Microsoft Video 14 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15599WEB-ACTIVEX Microsoft Video 14 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15600WEB-ACTIVEX Microsoft Video 15 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15601WEB-ACTIVEX Microsoft Video 15 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15602WEB-ACTIVEX Microsoft Video 16 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15603WEB-ACTIVEX Microsoft Video 16 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15604WEB-ACTIVEX Microsoft Video 17 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15605WEB-ACTIVEX Microsoft Video 17 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15606WEB-ACTIVEX Microsoft Video 18 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15607WEB-ACTIVEX Microsoft Video 18 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15608WEB-ACTIVEX Microsoft Video 19 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15609WEB-ACTIVEX Microsoft Video 19 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15610WEB-ACTIVEX Microsoft Video 2 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15611WEB-ACTIVEX Microsoft Video 2 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15612WEB-ACTIVEX Microsoft Video 20 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15613WEB-ACTIVEX Microsoft Video 20 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15614WEB-ACTIVEX Microsoft Video 21 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15615WEB-ACTIVEX Microsoft Video 21 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15616WEB-ACTIVEX Microsoft Video 22 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15617WEB-ACTIVEX Microsoft Video 22 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15618WEB-ACTIVEX Microsoft Video 23 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15619WEB-ACTIVEX Microsoft Video 23 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15620WEB-ACTIVEX Microsoft Video 24 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15621WEB-ACTIVEX Microsoft Video 24 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15622WEB-ACTIVEX Microsoft Video 25 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15623WEB-ACTIVEX Microsoft Video 25 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15624WEB-ACTIVEX Microsoft Video 26 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15625WEB-ACTIVEX Microsoft Video 26 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15626WEB-ACTIVEX Microsoft Video 27 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15627WEB-ACTIVEX Microsoft Video 27 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15628WEB-ACTIVEX Microsoft Video 28 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15629WEB-ACTIVEX Microsoft Video 28 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15630WEB-ACTIVEX Microsoft Video 29 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15631WEB-ACTIVEX Microsoft Video 29 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15632WEB-ACTIVEX Microsoft Video 3 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15633WEB-ACTIVEX Microsoft Video 3 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15634WEB-ACTIVEX Microsoft Video 30 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15635WEB-ACTIVEX Microsoft Video 30 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15636WEB-ACTIVEX Microsoft Video 31 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15637WEB-ACTIVEX Microsoft Video 31 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15638WEB-ACTIVEX Microsoft Video 32 ActiveX clsid access (more info ...)attempted-user  2009-2494      URL
15639WEB-ACTIVEX Microsoft Video 32 ActiveX clsid unicode access (more info ...)attempted-user  2009-2494      URL
15640WEB-ACTIVEX Microsoft Video 33 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15641WEB-ACTIVEX Microsoft Video 33 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15642WEB-ACTIVEX Microsoft Video 34 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15643WEB-ACTIVEX Microsoft Video 34 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15644WEB-ACTIVEX Microsoft Video 35 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15645WEB-ACTIVEX Microsoft Video 35 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15646WEB-ACTIVEX Microsoft Video 36 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15647WEB-ACTIVEX Microsoft Video 36 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15648WEB-ACTIVEX Microsoft Video 37 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15649WEB-ACTIVEX Microsoft Video 37 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15650WEB-ACTIVEX Microsoft Video 38 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15651WEB-ACTIVEX Microsoft Video 38 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15652WEB-ACTIVEX Microsoft Video 39 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15653WEB-ACTIVEX Microsoft Video 39 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15654WEB-ACTIVEX Microsoft Video 4 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15655WEB-ACTIVEX Microsoft Video 4 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15656WEB-ACTIVEX Microsoft Video 40 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15657WEB-ACTIVEX Microsoft Video 40 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15658WEB-ACTIVEX Microsoft Video 41 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15659WEB-ACTIVEX Microsoft Video 41 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15660WEB-ACTIVEX Microsoft Video 42 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15661WEB-ACTIVEX Microsoft Video 42 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15662WEB-ACTIVEX Microsoft Video 43 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15663WEB-ACTIVEX Microsoft Video 43 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15664WEB-ACTIVEX Microsoft Video 44 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15665WEB-ACTIVEX Microsoft Video 44 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15666WEB-ACTIVEX Microsoft Video 45 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15667WEB-ACTIVEX Microsoft Video 45 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15668WEB-ACTIVEX Microsoft Video 5 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15669WEB-ACTIVEX Microsoft Video 5 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15670WEB-ACTIVEX Microsoft Video 6 ActiveX clsid access (more info ...)attempted-user  2009-0901  35558    URL
15671WEB-ACTIVEX Microsoft Video 6 ActiveX clsid unicode access (more info ...)attempted-user  2009-0901  35558    URL
15672WEB-ACTIVEX Microsoft Video 7 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15674WEB-ACTIVEX Microsoft Video 8 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15675WEB-ACTIVEX Microsoft Video 8 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15676WEB-ACTIVEX Microsoft Video 9 ActiveX clsid access (more info ...)attempted-user  2008-0015      URL
15677WEB-ACTIVEX Microsoft Video 9 ActiveX clsid unicode access (more info ...)attempted-user  2008-0015      URL
15701SPECIFIC-THREATS Microsoft Windows 2000 domain authentication bypass attempt (more info ...)attempted-user  2004-0540      
15702NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x13 overflow attempt (more info ...)attempted-dos  2009-1761  35396    
15710NETBIOS DCERPC NCACN-IP-TCP brightstor opcode 0x3B null strings attempt (more info ...)attempted-dos  2009-1761  35396    
15847NETBIOS Telnet-based NTLM replay attack attempt (more info ...)attempted-user  2000-0834      URL
15848EXPLOIT WINS replication request memory corruption attempt (more info ...)attempted-admin  2009-1923      URL
15849EXPLOIT WINS replication inform2 request memory corruption attempt (more info ...)attempted-admin  2009-1924      URL
15851DOS Microsoft ASP.NET bad request denial of service attempt (more info ...)attempted-dos  2009-1536      URL
15854WEB-CLIENT Microsoft Windows AVIFile media file processing memory corruption attempt (more info ...)attempted-user  2009-1546  35970    URL
15857WEB-CLIENT Microsoft Windows AVIFile media file invalid header length (more info ...)attempted-user  2009-1546      URL
15860NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrGetJoinInformation attempt (more info ...)protocol-command-decode  2009-1544      URL
15861WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX clsid access (more info ...)attempted-user  2009-1929      URL
15863WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX function call access (more info ...)attempted-user  2009-1929      URL
15878WEB-ACTIVEX AcerCtrls.APlunch ActiveX clsid access (more info ...)attempted-user  2009-2627      URL
15879WEB-ACTIVEX AcerCtrls.APlunch ActiveX clsid unicode access (more info ...)attempted-user  2009-2627      URL
15894SPECIFIC-THREATS Microsoft Color Management Module remote code execution attempt (more info ...)attempted-admin  2005-1219      URL
15904WEB-ACTIVEX Microsoft Video 6 ActiveX function call access (more info ...)attempted-user  2009-0901  35558    URL
15905WEB-ACTIVEX Microsoft Video 6 ActiveX function call unicode access (more info ...)attempted-user  2009-0901  35558    URL
15920WEB-CLIENT Microsoft mp3 malformed APIC header RCE attempt (more info ...)attempted-user  2009-2499      URL
15921WEB-CLIENT Microsoft media format file download request (more info ...)misc-activity        
15923WEB-ACTIVEX DHTML Editing ActiveX clsid unicode access (more info ...)attempted-user  2009-2519  1474    URL
15924WEB-ACTIVEX DHTML Editing ActiveX function call access (more info ...)attempted-user  2009-2519  1474    URL
15925WEB-ACTIVEX DHTML Editing ActiveX function call unicode access (more info ...)attempted-user  2009-2519  1474    URL
15926WEB-ACTIVEX PPStream PPSMediaList ActiveX clsid access (more info ...)attempted-user    36234    
15927WEB-ACTIVEX PPStream PPSMediaList ActiveX clsid unicode access (more info ...)attempted-user    36234    
15928WEB-ACTIVEX PPStream PPSMediaList ActiveX function call access (more info ...)attempted-user    36234    
15929WEB-ACTIVEX PPStream PPSMediaList ActiveX function call unicode access (more info ...)attempted-user    36234    
15930NETBIOS Microsoft Windows SMB malformed process ID high field remote code execution attempt (more info ...)attempted-dos  2009-3103      URL
15944SPECIFIC-THREATS Microsoft Windows Active Directory crafted LDAP request denial of service attempt (more info ...)attempted-dos  2007-3028  24796    
15946WEB-CLIENT Microsoft Windows Vista Feed Headlines Gagdet code execution attempt (more info ...)attempted-user  2007-3033  25287    
15959DOS Microsoft ASP.NET viewstate DoS attempt (more info ...)attempted-dos  2005-1665      URL
15965SPECIFIC-THREATS Microsoft Explorer long share name buffer overflow attempt (more info ...)attempted-user  2004-0214  10213    
15985SPECIFIC-THREATS Microsoft ASP.NET canonicalization exploit attempt (more info ...)attempted-user  2004-0847  11342    
15996SPECIFIC-THREATS Microsoft Negotiate SSP buffer overflow attempt (more info ...)attempted-admin  2004-0119  10113    
16048WEB-CLIENT Microsoft ASP.NET application folder info disclosure attempt (more info ...)attempted-recon  2006-1300  18920    
16051SPECIFIC-THREATS Microsoft Publisher 2007 conversion library code execution attempt (more info ...)attempted-user  2007-1754  22702    
16068SPECIFIC-THREATS Yahoo Music Jukebox ActiveX exploit (more info ...)attempted-user  2008-0625  27579    
16089SPECIFIC-THREATS Microsoft Windows embedded web font handling buffer overflow attempt (more info ...)attempted-user  2006-0010  16194    
16090SPECIFIC-THREATS Microsoft Core XML core services XMLHTTP control open method code execution attempt (more info ...)attempted-user  2006-5745  20915    
16143WEB-CLIENT Microsoft asf file download (more info ...)misc-activity        
16167DOS Microsoft LSASS integer wrap denial of service attempt (more info ...)attempted-dos  2009-2524      URL
16168DOS Microsoft SMBv2 integer overflow denial of service attempt (more info ...)attempted-admin  2009-2526      URL
16179EXPLOIT Microsoft .NET MSIL CLR interface multiple instantiation attempt (more info ...)attempted-user  2009-2497      URL
16182EXPLOIT Microsoft .NET MSIL stack corruption attempt (more info ...)attempted-user  2009-0090      URL
16183WEB-CLIENT Microsoft .NET MSIL CombineImpl suspicious usage (more info ...)attempted-user  2009-0091      URL
16184EXPLOIT Microsoft GDI+ TIFF file parsing heap overflow attempt (more info ...)attempted-user  2009-2502      URL
16185EXPLOIT Microsoft GDI+ compressed TIFF file parsing remote code execution attempt (more info ...)attempted-user  2009-2503      URL
16186WEB-CLIENT Microsoft GDI+ interlaced PNG file parsing heap overflow attempt (more info ...)attempted-user  2009-3126      URL
16188WEB-CLIENT Microsoft Powerpoint bad text header txttype attempt (more info ...)attempted-user  2006-0022      URL
16237DOS Microsoft Active Directory NTDSA stack space exhaustion attempt (more info ...)attempted-dos  2009-1928      URL
16238NETBIOS DCERPC NCACN-IP-TCP llsrpc2 LlsrLicenseRequestW overflow attempt (more info ...)attempted-admin  2009-2523      URL
16239NETBIOS DCERPC NCADG-IP-UDP llsrpc2 LlsrLicenseRequestW overflow attempt (more info ...)attempted-admin  2009-2523      URL
16285RPC AIX ttdbserv function 15 buffer overflow attempt (more info ...)attempted-admin  2009-2727  35419    URL
16305WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX clsid access (more info ...)attempted-user  2009-3033  37092    
16306WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX clsid unicode access (more info ...)attempted-user  2009-3033  37092    
16307WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX function call access (more info ...)attempted-user  2009-3033  37092    
16308WEB-ACTIVEX Symantec Altiris Deployment Solution ActiveX function call unicode access (more info ...)attempted-user  2009-3033  37092    
16327EXPLOIT Microsoft Windows GDIplus TIFF RLE compressed data buffer overflow attempt (more info ...)attempted-user  2009-2503      URL
16329EXPLOIT Microsoft Internet Authentication Service EAP-MSCHAPv2 authentication bypass attempt (more info ...)attempted-user  2009-3677      URL
16340SPECIFIC-THREATS DHTML Editing ActiveX clsid access (more info ...)attempted-user  2003-0228  7517  11595  URL
16342WEB-CLIENT Microsoft Windows AVIFile truncated media file processing memory corruption attempt (more info ...)attempted-user  2009-1546  35970    URL
16366EXPLOIT Microsoft embedded OpenType font engine LZX decompression buffer overflow attempt (more info ...)attempted-admin  2010-0018      URL
16379WEB-ACTIVEX SAP AG SAPgui sapirrfc ActiveX clsid access (more info ...)attempted-user    35256    URL
16380WEB-ACTIVEX SAP AG SAPgui sapirrfc ActiveX clsid unicode access (more info ...)attempted-user    35256    URL
16395NETBIOS SMB COPY command oversized pathname attempt (more info ...)attempted-admin  2010-0020      URL
16396NETBIOS SMB server srvnet.sys driver race condition attempt (more info ...)attempted-dos  2010-0021      URL
16409WEB-CLIENT Microsoft PowerPoint improper filename remote code execution attempt (more info ...)attempted-user  2010-0029      URL
16410WEB-CLIENT Microsoft PowerPoint file LinkedSlide10Atom record parsing heap corruption attempt (more info ...)attempted-user  2010-0030      URL
16411WEB-CLIENT Microsoft PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user  2010-0031      URL
16412WEB-CLIENT Microsoft PowerPoint invalid TextByteAtom remote code execution attempt (more info ...)attempted-user  2010-0033      URL
16415WEB-CLIENT Microsoft DirectShow memory corruption attempt (more info ...)attempted-user  2010-0250      URL
16417NETBIOS SMB Negotiate Protocol Response overflow attempt (more info ...)attempted-admin  2010-0016      URL
16419WEB-ACTIVEX Microsoft Data Analyzer 3.5 ActiveX clsid access (more info ...)attempted-user  2010-0252      URL
16421EXPLOIT Microsoft PowerPoint out of bounds value remote code execution attempt (more info ...)attempted-user  2010-0032      URL
16424WEB-ACTIVEX Windows Script Host Shell Object ActiveX clsid access (more info ...)attempted-user        URL
16432WEB-ACTIVEX Trend Micro Web Deployment ActiveX clsid access (more info ...)attempted-user  2008-3364  30407    
16472WEB-CLIENT Microsoft Windows Movie Maker project file heap buffer overflow attempt (more info ...)attempted-user  2010-0265      URL
16473WEB-CLIENT Microsoft Windows Movie Maker project file download request (more info ...)misc-activity        
16474WEB-CLIENT Microsoft Compound File Binary v3 file download (more info ...)misc-activity        
16475WEB-CLIENT Microsoft Compound File Binary v4 file download (more info ...)misc-activity        
16476WEB-CLIENT Microsoft .MSProducer file download request (more info ...)misc-activity        
16477WEB-CLIENT Microsoft .MSProducerZ file download request (more info ...)misc-activity        
16478WEB-CLIENT Microsoft .MSProducerBF file download request (more info ...)misc-activity        
16505EXPLOIT Microsoft IE HTML parsing memory corruption attempt (more info ...)attempted-user  2010-0489      URL
16510WEB-ACTIVEX Microsoft Tabular Control ActiveX overflow by CLSID (more info ...)attempted-user  2010-0805      URL
16511WEB-ACTIVEX Microsoft Tabular Control ActiveX overflow by ProgID (more info ...)attempted-user  2010-0805      URL
16532NETBIOS SMB client TRANS response ring0 remote code execution attempt (more info ...)attempted-admin  2010-0476      URL
16535EXPLOIT Microsoft Viso improper attribute code execution attempt (more info ...)attempted-user  2010-0254      URL
16536EXPLOIT Microsoft Viso off-by-one in array index code execution attempt (more info ...)attempted-user  2010-0256      URL
16538NETBIOS NT QUERY SECURITY DESC flowbit (more info ...)misc-activity        
16539NETBIOS SMBv1 BytesNeeded ring0 buffer overflow attempt (more info ...)attempted-admin  2010-0269      URL
16542EXPLOIT Microsoft Publisher 2007 and earlier stack buffer overflow attempt (more info ...)attempted-user  2010-0479      URL
16559WEB-ACTIVEX Microsoft Tabular Control ActiveX overflow by CLSID / param tag (more info ...)attempted-user  2010-0805      URL
16560WEB-MISC Microsoft Sharepoint XSS attempt (more info ...)attempted-user  2010-0817      URL
16566WEB-ACTIVEX Tumbleweed SecureTransport ActiveX clsid access (more info ...)attempted-user        
16567WEB-ACTIVEX Tumbleweed SecureTransport ActiveX clsid unicode access (more info ...)attempted-user        
16568WEB-ACTIVEX Altnet Download Manager ADM4 ActiveX clsid access (more info ...)attempted-user  2007-5217  25903    
16569WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX clsid access (more info ...)attempted-user  2007-3605  24772    
16570WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX clsid unicode access (more info ...)attempted-user  2007-3605  24772    
16571WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX function call access (more info ...)attempted-user  2007-3605  24772    
16572WEB-ACTIVEX EnjoySAP kweditcontrol ActiveX function call unicode access (more info ...)attempted-user  2007-3605  24772    
16573WEB-ACTIVEX obfuscated ActiveX object instantiation via unescape (more info ...)attempted-user        URL
16574WEB-ACTIVEX obfuscated ActiveX object instantiation via fromCharCode (more info ...)attempted-user        URL
16575SPECIFIC-THREATS RKD Software BarCode ActiveX buffer overflow attempt (more info ...)attempted-user  2007-3435  24596    
16577NETBIOS Microsoft Windows SMBv2 compound request DoS attempt (more info ...)attempted-dos  2010-2552      URL
16580SPECIFIC-THREATS NCTAudioFile2 ActiveX clsid access via object tag (more info ...)attempted-user  2007-0018  33469    
16588SPECIFIC-THREATS iseemedia LPViewer ActiveX exploit attempt (more info ...)attempted-user  2008-4384  31604    
16589SPECIFIC-THREATS iseemedia LPViewer ActiveX buffer overflows attempt (more info ...)attempted-user  2008-4384  31604    
16590SPECIFIC-THREATS EasyMail Objects ActiveX exploit attempt - 1 (more info ...)attempted-user  2007-4607  25467    
16591SPECIFIC-THREATS EasyMail Objects ActiveX exploit attempt - 2 (more info ...)attempted-user  2007-4607  25467    
16593WEB-CLIENT Microsoft VBE6.dll stack corruption attempt (more info ...)attempted-user  2010-0815      URL
16599SPECIFIC-THREATS AtHocGov IWSAlerts ActiveX control buffer overflow attempt (more info ...)attempted-user        URL
16608SPECIFIC-THREATS HP Mercury Quality Center SPIDERLib ActiveX buffer overflow attempt (more info ...)attempted-user  2007-1819  23239    URL
16610SPECIFIC-THREATS IBM Access Support ActiveX GetXMLValue method buffer overflow attempt (more info ...)attempted-user  2009-0215  34228    
16665WEB-CLIENT Microsoft Windows Help Centre escape sequence XSS attempt (more info ...)attempted-user  2010-1885  40725    URL
16672SPECIFIC-THREATS Symantec Backup Exec ActiveX control buffer overflow attempt (more info ...)attempted-user  2007-6016  26904    
16675SPECIFIC-THREATS CA BrightStor ListCtrl ActiveX exploit attempt (more info ...)attempted-user  2008-1472  28268    
16679WEB-MISC Microsoft Windows GDIplus integer overflow attempt (more info ...)misc-activity  2009-1217  34250    
16687WEB-ACTIVEX Juniper Networks SSL-VPN Client JuniperSetup ActiveX control buffer overflow attempt (more info ...)attempted-user  2006-2086  17712    
16699RPC Linux Kernel nfsd v2 udp CAP_MKNOD security bypass attempt (more info ...)misc-attack  2009-1072  34205    
16700RPC Linux Kernel nfsd v2 tcp CAP_MKNOD security bypass attempt (more info ...)misc-attack  2009-1072  34205    
16701RPC Linux Kernel nfsd v3 udp CAP_MKNOD security bypass attempt (more info ...)misc-attack  2009-1072  34205    
16702RPC Linux Kernel nfsd v3 tcp CAP_MKNOD security bypass attempt (more info ...)misc-attack  2009-1072  34205    
16704SPECIFIC-THREATS CA eTrust PestPatrol 'ppctl.dll' ActiveX Initialize method overflow attempt (more info ...)attempted-user  2009-4225  37133    
16705RPC Sun Solaris sadmind UDP array size buffer overflow attempt (more info ...)attempted-admin  2008-3869  35083    
16706RPC Sun Solaris sadmind TCP array size buffer overflow attempt (more info ...)attempted-admin  2008-3869  35083    
16711SPECIFIC-THREATS E-Book Systems FlipViewer FlipViewerX.dll ActiveX multiple buffer overflow attempt (more info ...)attempted-user  2007-2919  24328    
16714SPECIFIC-THREATS SoftArtisans XFile FileManager ActiveX Control buffer overflow attempt (more info ...)attempted-user  2007-1682  30826    URL
16715SPECIFIC-THREATS SaschArt SasCam Webcam Server ActiveX control exploit attempt (more info ...)attempted-user  2008-6898  33053    
16728NETBIOS Samba SMB1 chain_reply function memory corruption attempt (more info ...)attempted-admin  2010-2063  40884    
16729SPECIFIC-THREATS McAfee Remediation client ActiveX control buffer overflow attempt (more info ...)attempted-user        URL
16740SPECIFIC-THREATS Microsoft Works WkImgSrv.dll ActiveX control code execution attempt (more info ...)attempted-user  2008-1898  28820    
16741SPECIFIC-THREATS Microsoft Works WkImgSrv.dll ActiveX control exploit attempt (more info ...)attempted-user  2008-1898  28820    
16745SPECIFIC-THREATS DjVu ActiveX control ImageURL property overflow attempt (more info ...)attempted-user  2008-4922  31987    
16746WEB-ACTIVEX IBM Access Support ActiveX clsid access (more info ...)attempted-user  2009-0215  34228    
16747WEB-ACTIVEX IBM Access Support ActiveX clsid unicode access (more info ...)attempted-user  2009-0215  34228    
16748WEB-ACTIVEX IBM Access Support ActiveX function call access (more info ...)attempted-user  2009-0215  34228    
16749WEB-ACTIVEX IBM Access Support ActiveX function call unicode access (more info ...)attempted-user  2009-0215  34228    
16754NETBIOS SMB /PlughNTCommand andx create tree attempt (more info ...)protocol-command-decode  2009-1394      
16755NETBIOS SMB /PlughNTCommand create tree attempt (more info ...)protocol-command-decode  2009-1394      
16756NETBIOS SMB /PlughNTCommand unicode andx create tree attempt (more info ...)protocol-command-decode  2009-1394      
16757NETBIOS SMB /PlughNTCommand unicode create tree attempt (more info ...)protocol-command-decode  2009-1394      
16758NETBIOS-DG SMB /PlughNTCommand andx create tree attempt (more info ...)protocol-command-decode  2009-1394      
16759NETBIOS-DG SMB /PlughNTCommand create tree attempt (more info ...)protocol-command-decode  2009-1394      
16760NETBIOS-DG SMB /PlughNTCommand unicode andx create tree attempt (more info ...)protocol-command-decode  2009-1394      
16761NETBIOS-DG SMB /PlughNTCommand unicode create tree attempt (more info ...)protocol-command-decode  2009-1394      
16762NETBIOS SMB Timbuktu Pro overflow WriteAndX andx attempt (more info ...)attempted-admin  2009-1394      
16763NETBIOS SMB Timbuktu Pro overflow WriteAndX attempt (more info ...)attempted-admin  2009-1394      
16764NETBIOS SMB Timbuktu Pro overflow WriteAndX unicode andx attempt (more info ...)attempted-admin  2009-1394      
16765NETBIOS SMB Timbuktu Pro overflow WriteAndX unicode attempt (more info ...)attempted-admin  2009-1394      
16766NETBIOS SMB Timbuktu Pro overflow andx attempt (more info ...)attempted-admin  2009-1394      
16767WEB-ACTIVEX AwingSoft Web3D Player ActiveX clsid access (more info ...)attempted-user  2009-4850      
16768WEB-ACTIVEX AwingSoft Web3D Player ActiveX clsid unicode access (more info ...)attempted-user  2009-4850      
16769WEB-ACTIVEX AwingSoft Web3D Player ActiveX function call access (more info ...)attempted-user  2009-4850      
16770WEB-ACTIVEX AwingSoft Web3D Player ActiveX function call unicode access (more info ...)attempted-user  2009-4850      
16771SPECIFIC-THREATS AwingSoft Web3D Player WindsPlayerIE.View.1 ActiveX SceneURL method overflow attempt (more info ...)attempted-user  2009-4588      
16772WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX clsid access (more info ...)attempted-user    36546    
16773WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX clsid unicode access (more info ...)attempted-user    36546    
16774WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX function call access (more info ...)attempted-user    36546    
16775WEB-ACTIVEX EMC Captiva QuickScan Pro ActiveX function call unicode access (more info ...)attempted-user    36546    
16776SPECIFIC-THREATS KeyWorks KeyHelp 'keyhelp.ocx' ActiveX control multiple method overflow attempt (more info ...)attempted-user    36546    URL
16783WEB-ACTIVEX Autodesk iDrop ActiveX clsid access (more info ...)attempted-user        URL
16784WEB-ACTIVEX Autodesk iDrop ActiveX function call access (more info ...)attempted-user        URL
16789SPECIFIC-THREATS Chilkat Crypt 2 ActiveX WriteFile method arbitrary file overwrite attempt - 1 (more info ...)attempted-user  2008-5002  32073    
16790SPECIFIC-THREATS Chilkat Crypt 2 ActiveX WriteFile method arbitrary file overwrite attempt - 2 (more info ...)attempted-user  2008-5002  32073    
16791WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX clsid access (more info ...)attempted-user  2007-4475  34310    
16792WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX clsid unicode access (more info ...)attempted-user  2007-4475  34310    
16793WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX function call access (more info ...)attempted-user  2007-4475  34310    
16794WEB-ACTIVEX SAP AG SAPgui EAI WebViewer3D ActiveX function call unicode access (more info ...)attempted-user  2007-4475  34310    
16796RPC Sun Solaris sadmind UDP data length integer overflow attempt (more info ...)attempted-admin  2008-3870  35083    
16797RPC Sun Solaris sadmind TCP data length integer overflow attempt (more info ...)attempted-admin  2008-3870  35083    
16802WEB-ACTIVEX WinDVD IASystemInfo.dll ActiveX clsid access (more info ...)attempted-user  2007-0348  23071    
16803WEB-ACTIVEX WinDVD IASystemInfo.dll ActiveX clsid unicode access (more info ...)attempted-user  2007-0348  23071    
17037WEB-ACTIVEX MS Access multiple control instantiation memory corruption attempt (more info ...)attempted-user  2010-0814      URL
17038EXPLOIT Microsoft Access ACCWIZ library release after free attempt - 1 (more info ...)attempted-user  2010-1881      URL
17039EXPLOIT Microsoft Access ACCWIZ library release after free attempt - 2 (more info ...)attempted-user  2010-1881      URL
17042WEB-CLIENT Microsoft LNK shortcut download attempt (more info ...)attempted-user  2010-2568      URL
17043WEB-CLIENT Microsoft PIF shortcut download attempt (more info ...)attempted-user  2010-2568      URL
17051WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX clsid access (more info ...)attempted-user  2008-4388  33247    
17052WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX clsid unicode access (more info ...)attempted-user  2008-4388  33247    
17053WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX function call access (more info ...)attempted-user  2008-4388  33247    
17054WEB-ACTIVEX Symantec AppStream Client LaunchObj ActiveX function call unicode access (more info ...)attempted-user  2008-4388  33247    
17056SPECIFIC-THREATS Novell NetIdentity Agent XTIERRPCPIPE remote code execution attempt (more info ...)attempted-admin  2009-1350  34400    
17060SPECIFIC-THREATS Roxio CinePlayer SonicDVDDashVRNav.dll ActiveX control buffer overflow attempt (more info ...)attempted-user  2007-1559  23412    
17061WEB-ACTIVEX Symantec Norton Personal Firewall 2004 ActiveX clsid access (more info ...)attempted-user  2007-1689  23936    
17062WEB-ACTIVEX Symantec Norton Personal Firewall 2004 ActiveX clsid unicode access (more info ...)attempted-user  2007-1689  23936    
17063WEB-ACTIVEX Logitech Video Call 1 ActiveX clsid access (more info ...)attempted-user  2007-2918  24254    
17064WEB-ACTIVEX Logitech Video Call 1 ActiveX clsid unicode access (more info ...)attempted-user  2007-2918  24254    
17065WEB-ACTIVEX Logitech Video Call 2 ActiveX clsid access (more info ...)attempted-user  2007-2918  24254    
17066WEB-ACTIVEX Logitech Video Call 2 ActiveX clsid unicode access (more info ...)attempted-user  2007-2918  24254    
17067WEB-ACTIVEX Logitech Video Call 3 ActiveX clsid access (more info ...)attempted-user  2007-2918  24254    
17068WEB-ACTIVEX Logitech Video Call 3 ActiveX clsid unicode access (more info ...)attempted-user  2007-2918  24254    
17069WEB-ACTIVEX Logitech Video Call 4 ActiveX clsid access (more info ...)attempted-user  2007-2918  24254    
17070WEB-ACTIVEX Logitech Video Call 4 ActiveX clsid unicode access (more info ...)attempted-user  2007-2918  24254    
17071WEB-ACTIVEX Logitech Video Call 5 ActiveX clsid access (more info ...)attempted-user  2007-2918  24254    
17072WEB-ACTIVEX Logitech Video Call 5 ActiveX clsid unicode access (more info ...)attempted-user  2007-2918  24254    
17073WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX clsid access (more info ...)attempted-user  2007-5107  25785    
17074WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX clsid unicode access (more info ...)attempted-user  2007-5107  25785    
17075WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX function call access (more info ...)attempted-user  2007-5107  25785    
17076WEB-ACTIVEX Ask Toolbar AskJeevesToolBar.SettingsPlugin ActiveX function call unicode access (more info ...)attempted-user  2007-5107  25785    
17077SPECIFIC-THREATS Ask Toolbar AskJeevesToolBar.SettingsPlugin.1 ActiveX control buffer overflow attempt (more info ...)attempted-user  2007-5107  25785    
17078WEB-ACTIVEX GOM Player GomWeb ActiveX clsid access (more info ...)attempted-user  2007-5779  26236    
17079WEB-ACTIVEX GOM Player GomWeb ActiveX clsid unicode access (more info ...)attempted-user  2007-5779  26236    
17080WEB-ACTIVEX GOM Player GomWeb ActiveX function call access (more info ...)attempted-user  2007-5779  26236    
17081WEB-ACTIVEX GOM Player GomWeb ActiveX function call unicode access (more info ...)attempted-user  2007-5779  26236    
17082WEB-ACTIVEX SonicWALL SSL-VPN NeLaunchCtrl ActiveX clsid access (more info ...)attempted-user  2007-5603  26288    
17083WEB-ACTIVEX SonicWALL SSL-VPN NeLaunchCtrl ActiveX clsid unicode access (more info ...)attempted-user  2007-5603  26288    
17084WEB-ACTIVEX Creative Software AutoUpdate Engine ActiveX clsid access (more info ...)attempted-user  2008-0955  29391    
17085WEB-ACTIVEX Creative Software AutoUpdate Engine ActiveX clsid unicode access (more info ...)attempted-user  2008-0955  29391    
17086SPECIFIC-THREATS Creative Software AutoUpdate Engine CTSUEng.ocx ActiveX control buffer overflow attempt (more info ...)attempted-user  2008-0955  29391    
17087WEB-ACTIVEX VeryDOC PDF Viewer ActiveX clsid access (more info ...)attempted-user  2008-5492  32313    
17088WEB-ACTIVEX VeryDOC PDF Viewer ActiveX clsid unicode access (more info ...)attempted-user  2008-5492  32313    
17089WEB-ACTIVEX VeryDOC PDF Viewer ActiveX function call access (more info ...)attempted-user  2008-5492  32313    
17090WEB-ACTIVEX VeryDOC PDF Viewer ActiveX function call unicode access (more info ...)attempted-user  2008-5492  32313    
17091SPECIFIC-THREATS VeryDOC PDF Viewer ActiveX control OpenPDF buffer overflow attempt (more info ...)attempted-user  2008-5492  32313    
17092WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX clsid access (more info ...)attempted-user  2009-3028  36346    
17093WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX clsid unicode access (more info ...)attempted-user  2009-3028  36346    
17094WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX function call access (more info ...)attempted-user  2009-3028  36346    
17095WEB-ACTIVEX Symantec Altirix Deployment Solution AeXNSPkgDLLib.dll ActiveX function call unicode access (more info ...)attempted-user  2009-3028  36346    
17113WEB-CLIENT Microsoft SilverLight ImageSource redefine flowbit (more info ...)misc-activity        
17117EXPLOIT Microsoft MPEG Layer-3 audio heap corruption attempt (more info ...)attempted-user  2010-1882      URL
17118EXPLOIT Microsoft .NET CreateDelegate method arbitrary code execution attempt (more info ...)attempted-user  2010-1898      URL
17125NETBIOS SMB Trans2 MaxDataCount overflow attempt (more info ...)attempted-admin  2010-2550      URL
17126NETBIOS SMB large session length with small packet (more info ...)protocol-command-decode  2010-2551      URL
17127NETBIOS BytesIndicated validation dos attempt (more info ...)attempted-dos  2010-2551      URL
17135EXPLOIT Microsoft Windows Movie Maker string size overflow attempt (more info ...)attempted-user  2010-2564      URL
17160SPECIFIC-THREATS Liquid XML Studio LtXmlComHelp8.dll ActiveX OpenFile buffer overflow attempt (more info ...)attempted-user        URL
17161WEB-ACTIVEX Liquid XML Studio ActiveX clsid access (more info ...)attempted-user        URL
17162WEB-ACTIVEX Liquid XML Studio ActiveX clsid unicode access (more info ...)attempted-user        URL
17163WEB-ACTIVEX Liquid XML Studio ActiveX function call access (more info ...)attempted-user        URL
17164WEB-ACTIVEX Liquid XML Studio ActiveX function call unicode access (more info ...)attempted-user        URL
17167WEB-ACTIVEX Oracle Siebel Option Pack 1 ActiveX clsid access (more info ...)attempted-user  2009-3737      URL
17168WEB-ACTIVEX Oracle Siebel Option Pack 1 ActiveX clsid unicode access (more info ...)attempted-user  2009-3737      URL
17169WEB-ACTIVEX Oracle Siebel Option Pack 2 ActiveX clsid access (more info ...)attempted-user  2009-3737      URL
17170WEB-ACTIVEX Oracle Siebel Option Pack 2 ActiveX clsid unicode access (more info ...)attempted-user  2009-3737      URL
17171WEB-ACTIVEX Oracle Siebel Option Pack 3 ActiveX clsid access (more info ...)attempted-user  2009-3737      URL
17172WEB-ACTIVEX Oracle Siebel Option Pack 3 ActiveX clsid unicode access (more info ...)attempted-user  2009-3737      URL
17173WEB-ACTIVEX Oracle Siebel Option Pack 4 ActiveX clsid access (more info ...)attempted-user  2009-3737      URL
17174WEB-ACTIVEX Oracle Siebel Option Pack 4 ActiveX clsid unicode access (more info ...)attempted-user  2009-3737      URL
17175WEB-ACTIVEX Oracle Siebel Option Pack 5 ActiveX clsid access (more info ...)attempted-user  2009-3737      URL
17176WEB-ACTIVEX Oracle Siebel Option Pack 5 ActiveX clsid unicode access (more info ...)attempted-user  2009-3737      URL
17177WEB-ACTIVEX Oracle Siebel Option Pack 6 ActiveX clsid access (more info ...)attempted-user  2009-3737      URL
17178WEB-ACTIVEX Oracle Siebel Option Pack 6 ActiveX clsid unicode access (more info ...)attempted-user  2009-3737      URL
17226WEB-ACTIVEX AXIS Camera ActiveX initialization via script (more info ...)attempted-user  2008-5260  33408    
17241WEB-CLIENT Microsoft wmv file download request (more info ...)misc-activity        
17249EXPLOIT Microsoft LSASS integer overflow attempt (more info ...)attempted-user  2010-0820      URL
17256WEB-CLIENT Microsoft Windows uniscribe fonts parsing memory corruption attempt (more info ...)attempted-user  2010-2738      URL
17271WEB-CLIENT Microsoft Windows Web View script injection attempt (more info ...)attempted-user  2005-1191  13248    
17285WEB-CLIENT Microsoft Powerpoint PPT file parsing memory corruption attempt (more info ...)attempted-user  2006-3656  18993    
17292WEB-CLIENT Microsoft Powerpoint malformed data record code execution attempt (more info ...)attempted-user  2006-3876  20322    
17304WEB-CLIENT Microsoft Works file converter file section header index table stack overflow attempt (more info ...)attempted-user  2008-0105  27658    
17306SPECIFIC-THREATS Microsoft Malware Protection Engine file processing denial of service attempt (more info ...)denial-of-service  2008-1437      URL
17310SPECIFIC-THREATS Microsoft Powerpoint Viewer Memory Allocation Code Execution (more info ...)attempted-user  2008-0120  30552    
17316WEB-CLIENT Microsoft Windows Folder GUID Code Execution attempt (more info ...)attempted-user  2006-3281  19389    
17318WEB-CLIENT Microsoft Powerpoint MCAtom remote code execution attempt (more info ...)attempted-user  2006-5296  20495    
17319WEB-CLIENT Microsoft Powerpoint MCAtom remote code execution attempt (more info ...)attempted-user  2006-5296  20495    
17320WEB-CLIENT Microsoft Powerpoint MCAtom remote code execution attempt (more info ...)attempted-user  2006-5296  20495    
17321NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters name overflow attempt (more info ...)attempted-admin  2007-6701  25092    URL
17330WEB-CLIENT Microsoft Windows GRE WMF Handling Memory Read Exception attempt (more info ...)attempted-user  2006-0143  16167    
17347WEB-CLIENT Microsoft Windows Color Management Module buffer overflow attempt (more info ...)attempted-user  2005-1219  14214    
17348WEB-CLIENT Microsoft Windows Color Management Module buffer overflow attempt (more info ...)attempted-user  2005-1219  14214    
17349WEB-CLIENT Microsoft Windows Color Management Module buffer overflow attempt (more info ...)attempted-user  2005-1219  14214    
17364WEB-CLIENT Microsoft Help Workshop CNT Help contents (more info ...)web-application-activity        
17365WEB-CLIENT Microsoft Help Workshop CNT Help contents buffer overflow attempt (more info ...)web-application-attack  2007-0352  22100    
17366WEB-CLIENT Microsoft Help Workshop HPJ OPTIONS section buffer overflow attempt (more info ...)attempted-user  2007-0427  22135    
17374SPECIFIC-THREATS Microsoft Windows HLP File Handling heap overflow attempt (more info ...)attempted-user  2007-1912  23382    
17382SPECIFIC-THREATS Microsoft Project Invalid Memory Pointer Code Execution attempt (more info ...)attempted-user  2008-1088  28607    
17383SPECIFIC-THREATS Microsoft Publisher Object Handler Validation Code Execution attempted (more info ...)attempted-user  2008-0119  29158    
17408WEB-CLIENT Microsoft DirectX Targa image file heap overflow attempt (more info ...)attempted-user  2006-4183  24963    
17413SPECIFIC-THREATS Microsoft Jet DB Engine Buffer Overflow attempt (more info ...)attempted-user  2005-0944  12960    
17421WEB-CLIENT Microsoft OLE automation string manipulation overflow attempt (more info ...)attempted-user  2007-2224  25282    
17428WEB-MISC Microsoft ASP.NET information disclosure attempt (more info ...)misc-activity  2010-3332      URL
17429WEB-MISC Microsoft ASP.NET information disclosure attempt (more info ...)misc-activity  2010-3332      URL
17436NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt (more info ...)protocol-command-decode  2005-2120  15065    URL
17438NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceListSize attempt (more info ...)protocol-command-decode  2005-2120  15065    URL
17443WEB-CLIENT Microsoft DirectShow AVI decoder buffer overflow attempt (more info ...)attempted-user  2005-2128  15063    
17464WEB-ACTIVEX AOL Radio AmpX ActiveX clsid access (more info ...)attempted-user  2007-5755  26396    
17465WEB-ACTIVEX AOL Radio AmpX ActiveX clsid unicode access (more info ...)attempted-user  2007-5755  26396    
17467WEB-CLIENT Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt (more info ...)attempted-user  2007-3896  25945    URL
17468WEB-CLIENT Microsoft Windows ShellExecute and IE7 snews url handling code execution attempt (more info ...)attempted-user  2007-3896  25945    URL
17489SPECIFIC-THREATS Microsoft Windows Help File Heap Buffer Overflow attempt (more info ...)attempted-user  2006-1591  17325    
17490SPECIFIC-THREATS Microsoft Windows itss.dll CHM File Handling Heap Corruption attempt (more info ...)attempted-admin  2006-2297  17926    
17496WEB-CLIENT Microsoft Powerpoint malformed NamedShows record code execution attempt (more info ...)attempted-user  2006-4694  20226    
17497WEB-CLIENT Microsoft Powerpoint malformed NamedShows record code execution attempt (more info ...)attempted-user  2006-4694  20226    
17508WEB-MISC Microsoft .NET Application download attempt (more info ...)suspicious-filename-detect  2006-6696  21688    
17509WEB-MISC Microsoft .NET Manifest download attempt (more info ...)suspicious-filename-detect  2006-6696  21688    
17510WEB-MISC Microsoft .NET Deploy download attempt (more info ...)suspicious-filename-detect  2006-6696  21688    
17571WEB-ACTIVEX obfuscated instantiation of ActiveX object - likely malicious (more info ...)attempted-user  2008-3558      
17572WEB-CLIENT Microsoft XML Core Services cross-site information disclosure attempt (more info ...)attempted-recon  2008-4029  32155    URL
17575WEB-ACTIVEX SizerOne 2 ActiveX clsid access (more info ...)attempted-user  2008-4827  33148    
17576WEB-ACTIVEX SizerOne 2 ActiveX clsid unicode access (more info ...)attempted-user  2008-4827  33148    
17582WEB-ACTIVEX Symantec Norton AntiVirus CcErrDisp ActiveX function call access (more info ...)attempted-user    12175    
17583WEB-ACTIVEX Symantec Norton AntiVirus CcErrDisp ActiveX function call unicode access (more info ...)attempted-user    12175    
17587SPECIFIC-THREATS AcroPDF.PDF ActiveX exploit attempt (more info ...)attempted-user  2006-6027  21155    URL
17592WEB-ACTIVEX Microsoft MyInfo.dll ActiveX clsid access (more info ...)attempted-user  2006-4495  19636    URL
17593WEB-ACTIVEX Microsoft msdxm.ocx ActiveX clsid access (more info ...)attempted-user  2006-4495  19636    URL
17594WEB-ACTIVEX Microsoft creator.dll 1 ActiveX clsid access (more info ...)attempted-user  2006-4495  19636    URL
17595WEB-ACTIVEX Microsoft creator.dll 2 ActiveX clsid access (more info ...)attempted-user  2006-4495  19636    URL
17596WEB-ACTIVEX Microsoft ciodm.dll ActiveX clsid access (more info ...)attempted-user  2006-4495  19636    URL
17614WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX clsid access (more info ...)attempted-user        URL
17615WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX clsid unicode access (more info ...)attempted-user        URL
17616WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX function call access (more info ...)attempted-user        URL
17617WEB-ACTIVEX SAP GUI SAPBExCommonResources ActiveX function call unicode access (more info ...)attempted-user        URL
17618SPECIFIC-THREATS Microsoft Windows hraphics engine EMF rendering vulnerability (more info ...)attempted-user  2005-2123  15352    
17626SPECIFIC-THREATS Microsoft Windows embedded web font handling buffer overflow attempt (more info ...)attempted-user  2006-0010  16194    
17639NETBIOS Samba Root File System access bypass attempt (more info ...)attempted-recon  2009-0022  33118    
17646WEB-CLIENT Microsoft Powerpoint Legacy file format picture object code execution attempt (more info ...)attempted-user  2009-0223  34834    
17654SPECIFIC-THREATS Facebook Photo Uploader ActiveX exploit attempt (more info ...)attempted-user  2008-5711  27756    URL
17694WEB-CLIENT Microsoft Windows AVI file chunk length integer overflow attempt (more info ...)attempted-user  2009-1546  35970    
17695WEB-CLIENT Microsoft PowerPoint paragraph format array inner header overflow attempt (more info ...)attempted-user  2009-0220  34833    
17702NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrDfsCreateExitPoint dos attempt (more info ...)attempted-dos  2005-3644  15460    URL
17711WEB-CLIENT Microsoft Windows ASF parsing memory corruption attempt (more info ...)attempted-user  2007-0064      URL
17721EXPLOIT WINS replication inform2 request memory corruption attempt (more info ...)attempted-admin  2009-1924      URL
17723NETBIOS possible SMB replay attempt - overlapping encryption keys detected (more info ...)attempted-user  2010-0231      URL
17730WEB-CLIENT Microsoft XML Core Services MIME Viewer memory corruption attempt (more info ...)attempted-user  2007-0099      URL
17737SPECIFIC-THREATS Microsoft collaboration data objects buffer overflow attempt (more info ...)attempted-user  2005-1987  15067    
17745NETBIOS SMB TRANS2 Find_First2 request attempt (more info ...)misc-activity        
17746NETBIOS SMB client TRANS response Find_First2 filesize overflow attempt (more info ...)attempted-admin  2005-0045      URL
17749RPC Linux Kernel nfsd v4 CAP_MKNOD security bypass attempt (more info ...)misc-attack  2009-1072  34205    
17770WEB-ACTIVEX Microsoft HtmlDlgHelper ActiveX clsid access (more info ...)attempted-user  2010-3329      URL
17772WEB-ACTIVEX Microsoft Scriptlet Component ActiveX clsid access (more info ...)attempted-user  2010-3331      URL
18064EXPLOIT Microsoft .NET framework EntityObject execution attempt (more info ...)attempted-user  2010-3228      URL
18065EXPLOIT Microsoft PowerPoint converter bad indirection remote code execution attempt (more info ...)attempted-user  2010-2572      URL
18066WEB-CLIENT Microsoft PowerPoint integer underflow heap corruption attempt (more info ...)attempted-user  2010-2573      URL
18070NETBIOS pptimpconv.dll access (more info ...)attempted-user  2010-3337      URL
18073WEB-MISC Microsoft Forefront UAG arbitrary embedded scripting attempt (more info ...)attempted-user  2010-2733      URL
18097WEB-ACTIVEX VMWare Remote Console Plug-In ActiveX clsid access (more info ...)attempted-user  2009-3732      
18169WEB-ACTIVEX WinZip FileView 6.1 ActiveX function call unicode access (more info ...)attempted-user  2006-5198  21108    URL
18189NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18190NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18191NETBIOS DCERPC NCACN-IP-TCP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18192NETBIOS DCERPC NCADG-IP-UDP netdfs NetrDfsEnum attempt (more info ...)protocol-command-decode  2007-2446  24198    
18197WEB-ACTIVEX Microsoft COleSite ActiveX memory corruption attempt (more info ...)attempted-user  2010-3340      URL
18198WEB-ACTIVEX Microsoft COleSite ActiveX memory corruption attempt (more info ...)attempted-user  2010-3340      URL
18199WEB-ACTIVEX Microsoft COleSite ActiveX memory corruption attempt (more info ...)attempted-user  2010-3340      URL
18203NETBIOS Windows Address Book smmscrpt.dll malicious DLL load (more info ...)attempted-user  2010-3144      URL
18206NETBIOS Windows Address Book wab32res.dll malicious DLL load (more info ...)attempted-user  2010-3147      URL
18207NETBIOS Windows Address Book msoeres32.dll malicious DLL load (more info ...)attempted-user  2010-3147      URL
18209NETBIOS Windows 7 Home peerdist.dll dll-load exploit attempt (more info ...)attempted-user  2010-3966      URL
18210WEB-CLIENT Microsoft Movie Maker hhctrl.ocx dll-load exploit attempt (more info ...)attempted-user  2010-3967      URL
18211NETBIOS Microsoft Movie Maker hhctrl.ocx dll-load exploit attempt (more info ...)attempted-user  2010-3967      URL
18215NETBIOS NETAPI RPC interface reboot attempt (more info ...)attempted-user  2010-2742      URL
18219WEB-CLIENT Microsoft Windows ATMFD font driver remote code execution attempt (more info ...)attempted-user  2010-3957      URL
18220WEB-CLIENT Microsoft Windows ATMFD font driver malformed character glyph remote code execution attempt (more info ...)attempted-user  2010-3959      URL
18230SPECIFIC-THREATS Microsoft Publisher memory corruption attempt (more info ...)attempted-user  2010-3954      URL
18231WEB-CLIENT Microsoft Publisher oversized oti length attempt (more info ...)attempted-user  2010-3955      URL
18238EXPLOIT Microsoft Sharepoint document conversion remote code excution attempt (more info ...)attempted-admin  2010-3964      URL
18241WEB-ACTIVEX Microsoft WMI Administrator Tools Object Viewer ActiveX clsid access (more info ...)attempted-user        URL
18242WEB-ACTIVEX Microsoft WMI Administrator Tools Object Viewer ActiveX function call access (more info ...)attempted-user        URL
18246WEB-CLIENT Microsoft Windows Fax Services Cover Page Editor overflow attempt (more info ...)attempted-user        URL


# of warning rules in this group: 709

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
529NETBIOS DCERPC NCACN-IP-TCP srvsvc NetrShareEnum null policy handle attempt (more info ...)protocol-command-decode    
530NETBIOS NT NULL session (more info ...)attempted-recon 2000-0347 1163  
532NETBIOS SMB ADMIN$ share access (more info ...)protocol-command-decode    
533NETBIOS SMB C$ share access (more info ...)protocol-command-decode    
534NETBIOS SMB CD.. (more info ...)attempted-recon    
535NETBIOS SMB CD... (more info ...)attempted-recon    
536NETBIOS SMB D$ share access (more info ...)protocol-command-decode    
572RPC DOS ttdbserv Solaris (more info ...)attempted-dos 1999-0003 122  
574RPC mountd TCP export request (more info ...)attempted-recon    
575RPC portmap admind request UDP (more info ...)rpc-portmap-decode    
576RPC portmap amountd request UDP (more info ...)rpc-portmap-decode 1999-0704 614  
577RPC portmap bootparam request UDP (more info ...)rpc-portmap-decode 1999-0647   
578RPC portmap cmsd request UDP (more info ...)rpc-portmap-decode    
579RPC portmap mountd request UDP (more info ...)rpc-portmap-decode    
580RPC portmap nisd request UDP (more info ...)rpc-portmap-decode 1999-0008   
581RPC portmap pcnfsd request UDP (more info ...)rpc-portmap-decode 2002-0910 4816  
582RPC portmap rexd request UDP (more info ...)rpc-portmap-decode    
583RPC portmap rstatd request UDP (more info ...)rpc-portmap-decode    
584RPC portmap rusers request UDP (more info ...)rpc-portmap-decode 1999-0626   
585RPC portmap sadmind request UDP (more info ...)rpc-portmap-decode    
586RPC portmap selection_svc request UDP (more info ...)rpc-portmap-decode 1999-0209 8  
587RPC portmap status request UDP (more info ...)rpc-portmap-decode    
588RPC portmap ttdbserv request UDP (more info ...)rpc-portmap-decode 2001-0717 3382  URL
589RPC portmap yppasswd request UDP (more info ...)rpc-portmap-decode    
590RPC portmap ypserv request UDP (more info ...)rpc-portmap-decode 2002-1232 6016  
591RPC portmap ypupdated request TCP (more info ...)rpc-portmap-decode 1999-0208 1749  
595RPC portmap espd request TCP (more info ...)rpc-portmap-decode 2001-0331 2714  
598RPC portmap listing TCP 111 (more info ...)rpc-portmap-decode    
599RPC portmap listing TCP 32771 (more info ...)rpc-portmap-decode    
612RPC rusers query UDP (more info ...)attempted-recon 1999-0626   
1262RPC portmap admind request TCP (more info ...)rpc-portmap-decode    
1263RPC portmap amountd request TCP (more info ...)rpc-portmap-decode 1999-0704 614  
1264RPC portmap bootparam request TCP (more info ...)rpc-portmap-decode 1999-0647   
1265RPC portmap cmsd request TCP (more info ...)rpc-portmap-decode    
1267RPC portmap nisd request TCP (more info ...)rpc-portmap-decode    
1268RPC portmap pcnfsd request TCP (more info ...)rpc-portmap-decode 2002-0910 4816  
1269RPC portmap rexd request TCP (more info ...)rpc-portmap-decode    
1270RPC portmap rstatd request TCP (more info ...)rpc-portmap-decode    
1271RPC portmap rusers request TCP (more info ...)rpc-portmap-decode 1999-0626   
1272RPC portmap sadmind request TCP (more info ...)rpc-portmap-decode    
1273RPC portmap selection_svc request TCP (more info ...)rpc-portmap-decode 1999-0209 205  
1274RPC portmap ttdbserv request TCP (more info ...)rpc-portmap-decode 2001-0717 3382  URL
1275RPC portmap yppasswd request TCP (more info ...)rpc-portmap-decode    
1276RPC portmap ypserv request TCP (more info ...)rpc-portmap-decode 2002-1232 6016  
1277RPC portmap ypupdated request UDP (more info ...)rpc-portmap-decode 1999-0208 28383  
1280RPC portmap listing UDP 111 (more info ...)rpc-portmap-decode    
1281RPC portmap listing UDP 32771 (more info ...)rpc-portmap-decode    
1295NETBIOS nimda RICHED20.DLL (more info ...)bad-unknown    URL
1447MISC MS Terminal server request RDP (more info ...)protocol-command-decode 2001-0540 3099 10940 URL
1732RPC portmap rwalld request UDP (more info ...)rpc-portmap-decode 1999-0181 205  
1733RPC portmap rwalld request TCP (more info ...)rpc-portmap-decode 1999-0181 205  
1746RPC portmap cachefsd request UDP (more info ...)rpc-portmap-decode 2002-0084 4674 10951 
1747RPC portmap cachefsd request TCP (more info ...)rpc-portmap-decode 2002-0084 4674 10951 
1890RPC status GHBN format string attack (more info ...)misc-attack 2000-0666 1480 10544 
1891RPC status GHBN format string attack (more info ...)misc-attack 2000-0666 1480 10544 
1905RPC AMD UDP amqproc_mount plog overflow attempt (more info ...)misc-attack 1999-0704 614  
1906RPC AMD TCP amqproc_mount plog overflow attempt (more info ...)misc-attack 1999-0704 614  
1907RPC CMSD UDP CMSD_CREATE buffer overflow attempt (more info ...)attempted-admin 1999-0696 524  
1908RPC CMSD TCP CMSD_CREATE buffer overflow attempt (more info ...)attempted-admin 1999-0696 524  
1909RPC CMSD TCP CMSD_INSERT buffer overflow attempt (more info ...)misc-attack 1999-0696 524  URL
1910RPC CMSD udp CMSD_INSERT buffer overflow attempt (more info ...)misc-attack 1999-0696   URL
1911RPC sadmind UDP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt (more info ...)attempted-admin 1999-0977 866  
1912RPC sadmind TCP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt (more info ...)attempted-admin 1999-0977 866  
1913RPC STATD UDP stat mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1914RPC STATD TCP stat mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1915RPC STATD UDP monitor mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1916RPC STATD TCP monitor mon_name format string exploit attempt (more info ...)attempted-admin 2000-0666 1480 10544 
1922RPC portmap proxy attempt TCP (more info ...)rpc-portmap-decode    
1923RPC portmap proxy attempt UDP (more info ...)rpc-portmap-decode    
1924RPC mountd UDP export request (more info ...)attempted-recon    
1925RPC mountd TCP exportall request (more info ...)attempted-recon    
1926RPC mountd UDP exportall request (more info ...)attempted-recon    
1949RPC portmap SET attempt TCP 111 (more info ...)rpc-portmap-decode    
1950RPC portmap SET attempt UDP 111 (more info ...)rpc-portmap-decode    
1951RPC mountd TCP mount request (more info ...)attempted-recon 1999-0210   
1952RPC mountd UDP mount request (more info ...)attempted-recon    
1953RPC AMD TCP pid request (more info ...)rpc-portmap-decode    
1954RPC AMD UDP pid request (more info ...)rpc-portmap-decode    
1955RPC AMD TCP version request (more info ...)rpc-portmap-decode    
1956RPC AMD UDP version request (more info ...)rpc-portmap-decode 2000-0696 1554  
1957RPC sadmind UDP PING (more info ...)protocol-command-decode 1999-0977 866 10229 
1958RPC sadmind TCP PING (more info ...)protocol-command-decode 1999-0977 866 10229 
1959RPC portmap NFS request UDP (more info ...)rpc-portmap-decode    
1960RPC portmap NFS request TCP (more info ...)rpc-portmap-decode    
1961RPC portmap RQUOTA request UDP (more info ...)rpc-portmap-decode    
1962RPC portmap RQUOTA request TCP (more info ...)rpc-portmap-decode    
1963RPC RQUOTA getquota overflow attempt UDP (more info ...)misc-attack 1999-0974 864  
1964RPC tooltalk UDP overflow attempt (more info ...)attempted-admin 1999-0003 122  
1965RPC tooltalk TCP overflow attempt (more info ...)attempted-admin 2001-0717 122  
2006RPC portmap kcms_server request TCP (more info ...)rpc-portmap-decode 2003-0027 6665  URL
2014RPC portmap UNSET attempt TCP 111 (more info ...)rpc-portmap-decode  1892  
2015RPC portmap UNSET attempt UDP 111 (more info ...)rpc-portmap-decode  1892  
2016RPC portmap status request TCP (more info ...)rpc-portmap-decode    
2017RPC portmap espd request UDP (more info ...)rpc-portmap-decode 2001-0331 2714  
2018RPC mountd TCP dump request (more info ...)attempted-recon    
2019RPC mountd UDP dump request (more info ...)attempted-recon    
2020RPC mountd TCP unmount request (more info ...)attempted-recon    
2021RPC mountd UDP unmount request (more info ...)attempted-recon    
2022RPC mountd TCP unmountall request (more info ...)attempted-recon    
2023RPC mountd UDP unmountall request (more info ...)attempted-recon    
2024RPC RQUOTA getquota overflow attempt TCP (more info ...)misc-attack 1999-0974 864  
2025RPC yppasswd username overflow attempt UDP (more info ...)rpc-portmap-decode 2001-0779 2763 10684 
2026RPC yppasswd username overflow attempt TCP (more info ...)rpc-portmap-decode 2001-0779 2763 10684 
2031RPC yppasswd user update UDP (more info ...)rpc-portmap-decode 2001-0779 2763  
2032RPC yppasswd user update TCP (more info ...)rpc-portmap-decode 2001-0779 2763  
2033RPC ypserv maplist request UDP (more info ...)rpc-portmap-decode 2002-1232 6016 13976 
2034RPC ypserv maplist request TCP (more info ...)rpc-portmap-decode 2002-1232 6016  
2035RPC portmap network-status-monitor request UDP (more info ...)rpc-portmap-decode    
2036RPC portmap network-status-monitor request TCP (more info ...)rpc-portmap-decode    
2037RPC network-status-monitor mon-callback request UDP (more info ...)rpc-portmap-decode    
2038RPC network-status-monitor mon-callback request TCP (more info ...)rpc-portmap-decode    
2079RPC portmap nlockmgr request UDP (more info ...)rpc-portmap-decode 2000-0508 1372 10220 
2080RPC portmap nlockmgr request TCP (more info ...)rpc-portmap-decode 2000-0508 1372 10220 
2081RPC portmap rpc.xfsmd request UDP (more info ...)rpc-portmap-decode 2002-0359 5075  
2082RPC portmap rpc.xfsmd request TCP (more info ...)rpc-portmap-decode 2002-0359 5075  
2083RPC rpc.xfsmd xfs_export attempt UDP (more info ...)rpc-portmap-decode 2002-0359 5075  
2084RPC rpc.xfsmd xfs_export attempt TCP (more info ...)rpc-portmap-decode 2002-0359 5075  
2088RPC ypupdated arbitrary command attempt UDP (more info ...)misc-attack 1999-0208 28383  
2089RPC ypupdated arbitrary command attempt TCP (more info ...)misc-attack 1999-0208 1749  
2092RPC portmap proxy integer overflow attempt UDP (more info ...)rpc-portmap-decode 2003-0028 7123 11420 
2093RPC portmap proxy integer overflow attempt TCP (more info ...)rpc-portmap-decode 2003-0028 7123 11420 
2094RPC CMSD UDP CMSD_CREATE array buffer overflow attempt (more info ...)attempted-admin 2002-0391 5356 11418 
2095RPC CMSD TCP CMSD_CREATE array buffer overflow attempt (more info ...)attempted-admin 2002-0391 5356 11418 
2101NETBIOS SMB Trans Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
2126MISC Microsoft PPTP Start Control Request buffer overflow attempt (more info ...)attempted-admin 2002-1214 5807 11178 URL
2177NETBIOS SMB startup folder unicode access (more info ...)attempted-recon    
2184RPC mountd TCP mount path overflow attempt (more info ...)misc-attack 2003-0252 8179 11800 
2185RPC mountd UDP mount path overflow attempt (more info ...)misc-attack 2003-0252 8179 11800 
2190NETBIOS DCERPC invalid bind attempt (more info ...)attempted-dos    
2191NETBIOS SMB DCERPC invalid bind attempt (more info ...)attempted-dos    
2382NETBIOS SMB Session Setup NTMLSSP asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
2383NETBIOS SMB-DS Session Setup NTMLSSP asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
2402NETBIOS SMB-DS Session Setup andx username overflow attempt (more info ...)protocol-command-decode  9752  URL
2404NETBIOS SMB-DS Session Setup unicode andx username overflow attempt (more info ...)protocol-command-decode  9752  URL
2467NETBIOS SMB D$ unicode share access (more info ...)protocol-command-decode    
2468NETBIOS SMB-DS D$ share access (more info ...)protocol-command-decode    
2470NETBIOS SMB C$ unicode share access (more info ...)protocol-command-decode    
2471NETBIOS SMB-DS C$ share access (more info ...)protocol-command-decode    
2473NETBIOS SMB ADMIN$ unicode share access (more info ...)protocol-command-decode    
2474NETBIOS SMB-DS ADMIN$ share access (more info ...)protocol-command-decode    
2475NETBIOS SMB-DS ADMIN$ unicode share access (more info ...)protocol-command-decode    
2563NETBIOS NS lookup response name overflow attempt (more info ...)attempted-admin 2004-0444 10333  URL
2564NETBIOS NS lookup short response attempt (more info ...)attempted-admin 2004-0444 10335  URL
2936NETBIOS DCERPC NCACN-IP-TCP nddeapi NDdeSetTrustedShareW overflow attempt (more info ...)attempted-admin 2004-0206 11372  URL
2973NETBIOS SMB D$ unicode andx share access (more info ...)protocol-command-decode    
2974NETBIOS SMB-DS D$ andx share access (more info ...)protocol-command-decode    
2975NETBIOS SMB-DS D$ unicode andx share access (more info ...)protocol-command-decode    
2976NETBIOS SMB C$ andx share access (more info ...)protocol-command-decode    
2977NETBIOS SMB C$ unicode andx share access (more info ...)protocol-command-decode    
2978NETBIOS SMB-DS C$ andx share access (more info ...)protocol-command-decode    
2979NETBIOS SMB-DS C$ unicode andx share access (more info ...)protocol-command-decode    
2980NETBIOS SMB ADMIN$ andx share access (more info ...)protocol-command-decode    
2981NETBIOS SMB ADMIN$ unicode andx share access (more info ...)protocol-command-decode    
2982NETBIOS SMB-DS ADMIN$ andx share access (more info ...)protocol-command-decode    
2983NETBIOS SMB-DS ADMIN$ unicode andx share access (more info ...)protocol-command-decode    
3001NETBIOS SMB Session Setup NTMLSSP andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3002NETBIOS SMB Session Setup NTMLSSP unicode andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3004NETBIOS SMB-DS Session Setup NTMLSSP andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3005NETBIOS SMB-DS Session Setup NTMLSSP unicode andx asn1 overflow attempt (more info ...)protocol-command-decode 2003-0818 9635 12065 URL
3017EXPLOIT WINS overflow attempt (more info ...)misc-attack 2004-1080 11763  URL
3040NETBIOS SMB-DS NT Trans NT CREATE unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3041NETBIOS SMB-DS NT Trans NT CREATE unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
3042NETBIOS SMB NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3043NETBIOS SMB NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3044NETBIOS SMB NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3045NETBIOS SMB NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3046NETBIOS SMB-DS NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3047NETBIOS SMB-DS NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3048NETBIOS SMB-DS NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3049NETBIOS SMB-DS NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3050NETBIOS SMB NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3051NETBIOS SMB NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3052NETBIOS SMB NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3053NETBIOS SMB NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3054NETBIOS SMB-DS NT Trans NT CREATE invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3055NETBIOS SMB-DS NT Trans NT CREATE andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3056NETBIOS SMB-DS NT Trans NT CREATE unicode invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3057NETBIOS SMB-DS NT Trans NT CREATE unicode andx invalid SACL ace size dos attempt (more info ...)protocol-command-decode    
3114NETBIOS DCERPC NCACN-IP-TCP llsrpc LlsrConnect overflow attempt (more info ...)attempted-admin 2005-0050 12481  URL
3195NETBIOS name query overflow attempt TCP (more info ...)attempted-admin 2003-0825 9624 15912 
3196NETBIOS name query overflow attempt UDP (more info ...)attempted-admin 2003-0825 9624 15912 
3199EXPLOIT WINS name query overflow attempt TCP (more info ...)attempted-admin 2003-0825 9624 15912 URL
3200EXPLOIT WINS name query overflow attempt UDP (more info ...)attempted-admin 2003-0825 9624 15912 URL
3234NETBIOS Messenger message little endian overflow attempt (more info ...)attempted-admin 2003-0717 8826  
3235NETBIOS Messenger message overflow attempt (more info ...)attempted-admin 2003-0717 8826  
3238NETBIOS DCERPC NCACN-IP-TCP irot IrotIsRunning/Revoke overflow attempt (more info ...)attempted-admin 2002-1561 6005  URL
3239NETBIOS DCERPC NCADG-IP-UDP irot IrotIsRunning/Revoke overflow attempt (more info ...)attempted-admin 2002-1561 6005  URL
3590NETBIOS DCERPC NCACN-IP-TCP mqqm QMDeleteObject overflow attempt (more info ...)attempted-admin 2005-0059  18027 URL
3591NETBIOS DCERPC NCADG-IP-UDP mqqm QMDeleteObject overflow attempt (more info ...)attempted-admin 2005-0059  18027 URL
3639NETBIOS SMB Trans andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3640NETBIOS SMB Trans data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3641NETBIOS SMB Trans unicode data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3642NETBIOS SMB Trans unicode andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3643NETBIOS SMB-DS Trans andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3644NETBIOS SMB-DS Trans data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3645NETBIOS SMB-DS Trans unicode data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3646NETBIOS SMB-DS Trans unicode andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3647NETBIOS-DG SMB Trans andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3648NETBIOS-DG SMB Trans data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3649NETBIOS-DG SMB Trans unicode data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3650NETBIOS-DG SMB Trans unicode andx data displacement null pointer DOS attempt (more info ...)protocol-command-decode  13504  URL
3673MISC Microsoft SMS remote control client DoS overly long length attempt (more info ...)attempted-user 2004-0728 10726  
4334NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
4413NETBIOS DCERPC NCACN-IP-TCP spoolss AddPrinterEx overflow attempt (more info ...)attempted-admin 2005-1984 14514  URL
4608NETBIOS DCERPC NCACN-IP-TCP netware_cs function 43 overflow attempt (more info ...)attempted-admin 2005-1985 15066  URL
4651NETBIOS SMB NT Trans NT SET SECURITY DESC SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4652NETBIOS SMB NT Trans NT SET SECURITY DESC andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4653NETBIOS SMB NT Trans NT SET SECURITY DESC unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4654NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4655NETBIOS SMB-DS NT Trans NT SET SECURITY DESC SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4656NETBIOS SMB-DS NT Trans NT SET SECURITY DESC andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4657NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4658NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4659NETBIOS-DG SMB NT Trans NT SET SECURITY DESC SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4660NETBIOS-DG SMB NT Trans NT SET SECURITY DESC andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4661NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4662NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode andx SACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4663NETBIOS SMB NT Trans NT SET SECURITY DESC DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4664NETBIOS SMB NT Trans NT SET SECURITY DESC andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4665NETBIOS SMB NT Trans NT SET SECURITY DESC unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4666NETBIOS SMB NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4667NETBIOS SMB-DS NT Trans NT SET SECURITY DESC DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4668NETBIOS SMB-DS NT Trans NT SET SECURITY DESC andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4669NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4670NETBIOS SMB-DS NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4671NETBIOS-DG SMB NT Trans NT SET SECURITY DESC DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4672NETBIOS-DG SMB NT Trans NT SET SECURITY DESC andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4673NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4674NETBIOS-DG SMB NT Trans NT SET SECURITY DESC unicode andx DACL overflow attempt (more info ...)protocol-command-decode 2004-1154   
4826NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetRootDeviceInstance attempt (more info ...)protocol-command-decode 2005-3644 15460  URL
4918NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList dos attempt (more info ...)protocol-command-decode 2005-3644 15460  URL
5096NETBIOS DCERPC NCADG-IP-UDP lsass DsRolerGetPrimaryDomainInformation attempt (more info ...)protocol-command-decode 2003-0533 10108 12205 URL
5678NETBIOS SMB-DS Session Setup username overflow attempt (more info ...)protocol-command-decode  9752  URL
5679NETBIOS SMB-DS Session Setup unicode username overflow attempt (more info ...)protocol-command-decode  9752  URL
5680NETBIOS-DG SMB Session Setup username overflow attempt (more info ...)protocol-command-decode  9752  URL
5681NETBIOS-DG SMB Session Setup unicode username overflow attempt (more info ...)protocol-command-decode  9752  URL
5683NETBIOS-DG SMB Session Setup andx username overflow attempt (more info ...)protocol-command-decode  9752  URL
5684NETBIOS-DG SMB Session Setup unicode andx username overflow attempt (more info ...)protocol-command-decode  9752  URL
5717NETBIOS SMB-DS Trans Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5719NETBIOS-DG SMB Trans Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5720NETBIOS-DG SMB Trans unicode Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5721NETBIOS SMB Trans andx Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5722NETBIOS SMB Trans unicode andx Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5723NETBIOS SMB-DS Trans andx Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5724NETBIOS SMB-DS Trans unicode andx Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5725NETBIOS-DG SMB Trans andx Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5726NETBIOS-DG SMB Trans unicode andx Max Param/Count DOS attempt (more info ...)protocol-command-decode 2002-0724 5556 11110 URL
5727NETBIOS SMB Trans unicode Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5728NETBIOS-DG SMB Trans Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5729NETBIOS SMB Trans Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5730NETBIOS SMB-DS Trans Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5731NETBIOS SMB-DS Trans unicode Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5732NETBIOS-DG SMB Trans unicode Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5733NETBIOS SMB Trans unicode andx Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5734NETBIOS-DG SMB Trans andx Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5735NETBIOS SMB Trans andx Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5736NETBIOS SMB-DS Trans andx Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5737NETBIOS SMB-DS Trans unicode andx Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
5738NETBIOS-DG SMB Trans unicode andx Max Param DOS attempt (more info ...)protocol-command-decode 2005-1206 13942 18483 URL
6584NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSubmitRequest overflow attempt (more info ...)attempted-admin 2006-2370 18325  URL
6702NETBIOS SMB NT Trans Secondary Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6703NETBIOS SMB NT Trans Secondary unicode Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6704NETBIOS SMB-DS NT Trans Secondary Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6705NETBIOS SMB-DS NT Trans Secondary unicode Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6706NETBIOS-DG SMB NT Trans Secondary Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6707NETBIOS-DG SMB NT Trans Secondary unicode Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6708NETBIOS SMB NT Trans Secondary andx Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6709NETBIOS SMB NT Trans Secondary unicode andx Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6710NETBIOS SMB-DS NT Trans Secondary andx Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6711NETBIOS SMB-DS NT Trans Secondary unicode andx Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6712NETBIOS-DG SMB NT Trans Secondary andx Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6713NETBIOS-DG SMB NT Trans Secondary unicode andx Param Count overflow attempt (more info ...)protocol-command-decode 2003-0085 7106  
6810NETBIOS DCERPC NCACN-IP-TCP rras RasRpcSetUserPreferences area/country overflow attempt (more info ...)attempted-admin 2006-2371 18358  URL
7037NETBIOS-DG SMB Trans mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7038NETBIOS-DG SMB Trans unicode mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7042NETBIOS-DG SMB Trans unicode andx mailslot heap overflow attempt (more info ...)protocol-command-decode 2006-3942 18864  URL
7196EXPLOIT Microsoft DHCP option overflow attempt (more info ...)attempted-admin 2006-2372   URL
7422EXPLOIT Microsoft MMC mmcndmgr.dll cross site scripting attempt (more info ...)attempted-user 2006-3643 19417  URL
7423EXPLOIT Microsoft MMC mmc.exe cross site scripting attempt (more info ...)attempted-user 2006-3643 19417  URL
7424EXPLOIT Microsoft MMC createcab.cmd cross site scripting attempt (more info ...)attempted-user 2006-3643 19417  URL
8157NETBIOS DCERPC NCACN-IP-TCP webdav DavrCreateConnection hostname overflow attempt (more info ...)attempted-admin 2006-0013 16636  URL
8449NETBIOS SMB Rename invalid buffer type andx attempt (more info ...)attempted-dos 2006-4696   URL
8450NETBIOS SMB Rename invalid buffer type attempt (more info ...)attempted-dos 2006-4696   URL
8451NETBIOS SMB Rename invalid buffer type unicode andx attempt (more info ...)attempted-dos 2006-4696   URL
8452NETBIOS SMB Rename invalid buffer type unicode attempt (more info ...)attempted-dos 2006-4696   URL
8453NETBIOS SMB-DS Rename invalid buffer type andx attempt (more info ...)attempted-dos 2006-4696   URL
8454NETBIOS SMB-DS Rename invalid buffer type attempt (more info ...)attempted-dos 2006-4696   URL
8455NETBIOS SMB-DS Rename invalid buffer type unicode andx attempt (more info ...)attempted-dos 2006-4696   URL
8456NETBIOS SMB-DS Rename invalid buffer type unicode attempt (more info ...)attempted-dos 2006-4696   URL
8457NETBIOS-DG SMB Rename invalid buffer type andx attempt (more info ...)attempted-dos 2006-4696   URL
8458NETBIOS-DG SMB Rename invalid buffer type attempt (more info ...)attempted-dos 2006-4696   URL
8459NETBIOS-DG SMB Rename invalid buffer type unicode andx attempt (more info ...)attempted-dos 2006-4696   URL
8460NETBIOS-DG SMB Rename invalid buffer type unicode attempt (more info ...)attempted-dos 2006-4696   URL
8925NETBIOS DCERPC NCACN-IP-TCP wkssvc NetrAddAlternateComputerName overflow attempt (more info ...)attempted-admin 2003-0812 9011 11921 URL
9132NETBIOS DCERPC NCACN-IP-TCP netware_cs NwrOpenEnumNdsStubTrees_Any overflow attempt (more info ...)attempted-admin 2006-4689   URL
9228NETBIOS DCERPC NCACN-IP-TCP netware_cs NwGetConnectionInformation overflow attempt (more info ...)attempted-admin 2006-4689   URL
9431EXPLOIT Microsoft NNTP response overflow attempt (more info ...)attempted-user 2005-1213 13951  URL
9432WEB-CLIENT Microsoft Agent buffer overflow attempt (more info ...)attempted-user 2006-3445 21034  URL
9441NETBIOS DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath overflow attempt (more info ...)attempted-admin 2006-5143 20365  URL
9623RPC UNIX authentication machinename string overflow attempt TCP (more info ...)attempted-user 2006-5780 20941  
9624RPC UNIX authentication machinename string overflow attempt UDP (more info ...)attempted-user 2006-5780 20941  
9772NETBIOS DCERPC NCACN-IP-TCP msqueue function 1 overflow attempt (more info ...)attempted-admin    
9773NETBIOS DCERPC NCADG-IP-UDP msqueue function 1 overflow attempt (more info ...)attempted-admin    
9914NETBIOS DCERPC NCACN-IP-TCP tapisrv ClientRequest LSetAppPriority overflow attempt (more info ...)attempted-admin 2005-0058 14518  URL
10024NETBIOS DCERPC NCACN-IP-TCP brightstor-arc ClientDBMiniAgentClose attempt (more info ...)protocol-command-decode 2007-0168 22010  URL
10030NETBIOS DCERPC NCACN-IP-TCP brightstor QSIGetQueuePath_Function_45 overflow attempt (more info ...)attempted-admin 2006-5143 20365  
10036NETBIOS DCERPC NCACN-IP-TCP brightstor ASRemotePFC overflow attempt (more info ...)attempted-admin 2007-0169 22005  URL
10117NETBIOS DCERPC NCACN-IP-TCP brightstor-arc GetGCBHandleFromGroupName overflow attempt (more info ...)attempted-admin 2007-0169 22005  
10202NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect _SetRealTimeScanConfigInfo attempt (more info ...)protocol-command-decode 2007-1070 22639  URL
10208NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect COMN_NetTestConnection attempt (more info ...)protocol-command-decode 2007-1070 22639  URL
10285NETBIOS DCERPC NCACN-IP-TCP svcctl ChangeServiceConfig2A attempt (more info ...)protocol-command-decode    
10393WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX clsid access (more info ...)attempted-user 2006-6490 22564  URL
10394WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX clsid unicode access (more info ...)attempted-user 2006-6490 22564  URL
10395WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX function call access (more info ...)attempted-user 2006-6490 22564  URL
10408RPC portmap HP-UX Single Logical Screen SLSD tcp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10409RPC portmap HP-UX Single Logical Screen SLSD udp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10410RPC portmap HP-UX Single Logical Screen SLSD tcp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10411RPC portmap HP-UX Single Logical Screen SLSD udp request (more info ...)rpc-portmap-decode 2007-0915 22551  
10486NETBIOS DCERPC NCACN-IP-TCP brightstor-arc function 15,16,17 attempt (more info ...)protocol-command-decode 2007-1447 22994  URL
11073NETBIOS DCERPC NCACN-IP-TCP rpcss _RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
11074NETBIOS DCERPC NCADG-IP-UDP rpcss _RemoteGetClassObject attempt (more info ...)protocol-command-decode 2003-0605   URL
11288RPC portmap mountd tcp request (more info ...)rpc-portmap-decode 2006-0900 16838  
11289RPC portmap mountd tcp zero-length payload denial of service attempt (more info ...)rpc-portmap-decode 2006-0900 16838  
11442NETBIOS DCERPC NCACN-IP-TCP lsarpc LsarAddPrivilegesToAccount overflow attempt (more info ...)attempted-admin 2007-2446   
11443NETBIOS DCERPC NCADG-IP-UDP lsarpc LsarAddPrivilegesToAccount overflow attempt (more info ...)attempted-admin 2007-2446   
11620WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX function call access (more info ...)attempted-user  24188  URL
11621WEB-ACTIVEX DXImageTransform.Microsoft.Chroma ActiveX function call unicode access (more info ...)attempted-user  24188  URL
11624WEB-ACTIVEX LeadTools ISIS ActiveX clsid access (more info ...)attempted-user  24094  URL
11625WEB-ACTIVEX LeadTools ISIS ActiveX clsid unicode access (more info ...)attempted-user  24094  URL
11626WEB-ACTIVEX LeadTools ISIS ActiveX function call access (more info ...)attempted-user  24094  URL
11627WEB-ACTIVEX LeadTools ISIS ActiveX function call unicode access (more info ...)attempted-user  24094  URL
11628WEB-ACTIVEX LeadTools JPEG 2000 COM Object ActiveX function call access (more info ...)attempted-user  24040  URL
11629WEB-ACTIVEX LeadTools JPEG 2000 COM Object ActiveX function call unicode access (more info ...)attempted-user  24040  URL
11630WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX clsid access (more info ...)attempted-user  24133  URL
11631WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX clsid unicode access (more info ...)attempted-user  24133  URL
11632WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX function call access (more info ...)attempted-user  24133  URL
11633WEB-ACTIVEX LeadTools Raster Dialog File Object ActiveX function call unicode access (more info ...)attempted-user  24133  URL
11634WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX clsid access (more info ...)attempted-user  24153  URL
11635WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX clsid unicode access (more info ...)attempted-user  24153  URL
11636WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX function call access (more info ...)attempted-user  24153  URL
11637WEB-ACTIVEX LeadTools Raster Dialog File_D Object ActiveX function call unicode access (more info ...)attempted-user  24153  URL
11638WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX clsid access (more info ...)attempted-user  24179  URL
11639WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX clsid unicode access (more info ...)attempted-user  24179  URL
11640WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX function call access (more info ...)attempted-user  24179  URL
11641WEB-ACTIVEX LeadTools Raster Document Object Library ActiveX function call unicode access (more info ...)attempted-user  24179  URL
11642WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX clsid access (more info ...)attempted-user  24193  URL
11643WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX clsid unicode access (more info ...)attempted-user  24193  URL
11644WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX function call access (more info ...)attempted-user  24193  URL
11645WEB-ACTIVEX LeadTools Raster ISIS Object ActiveX function call unicode access (more info ...)attempted-user  24193  URL
11646WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX clsid access (more info ...)attempted-user  24057  URL
11647WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX clsid unicode access (more info ...)attempted-user  24057  URL
11648WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX function call access (more info ...)attempted-user  24057  URL
11649WEB-ACTIVEX LeadTools Raster Thumbnail Object Library ActiveX function call unicode access (more info ...)attempted-user  24057  URL
11650WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX clsid access (more info ...)attempted-user  24075  URL
11651WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX clsid unicode access (more info ...)attempted-user  24075  URL
11652WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX function call access (more info ...)attempted-user  24075  URL
11653WEB-ACTIVEX LeadTools Raster Variant Object Library ActiveX function call unicode access (more info ...)attempted-user  24075  URL
11654WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX clsid access (more info ...)attempted-user  24053  URL
11655WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX clsid unicode access (more info ...)attempted-user  24053  URL
11656WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX function call access (more info ...)attempted-user  24053  URL
11657WEB-ACTIVEX LeadTools Thumbnail Browser Control ActiveX function call unicode access (more info ...)attempted-user  24053  URL
11658WEB-ACTIVEX Dart ZipLite Compression ActiveX clsid access (more info ...)attempted-user  24099  URL
11659WEB-ACTIVEX Dart ZipLite Compression ActiveX clsid unicode access (more info ...)attempted-user  24099  URL
11673WEB-ACTIVEX Zenturi ProgramChecker ActiveX clsid access (more info ...)attempted-user 2007-3703 24883  
11674WEB-ACTIVEX Zenturi ProgramChecker ActiveX clsid unicode access (more info ...)attempted-user 2007-3703 24883  
11675WEB-ACTIVEX Zenturi ProgramChecker ActiveX function call access (more info ...)attempted-user 2007-3703 24883  
11676WEB-ACTIVEX Zenturi ProgramChecker ActiveX function call unicode access (more info ...)attempted-user 2007-3703 24883  
11677WEB-ACTIVEX Provideo Camimage Class ISSCamControl ActiveX clsid access (more info ...)attempted-user  24279  
11678WEB-ACTIVEX Provideo Camimage Class ISSCamControl ActiveX clsid unicode access (more info ...)attempted-user  24279  
11684EXPLOIT WINS overflow attempt (more info ...)misc-attack 2004-0567 11922  URL
11816NETBIOS Session Service NetDDE attack (more info ...)attempted-admin 2004-0206 11372  
11818WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX clsid access (more info ...)attempted-user 2007-3148 24341  URL
11819WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX clsid unicode access (more info ...)attempted-user 2007-3148 24341  URL
11820WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX function call access (more info ...)attempted-user 2007-3148 24341  URL
11821WEB-ACTIVEX Yahoo Webcam Viewer Wrapper ActiveX function call unicode access (more info ...)attempted-user 2007-3148 24341  URL
11826WEB-ACTIVEX Microsoft Voice Control ActiveX clsid access (more info ...)attempted-user 2007-2222   URL
11827WEB-ACTIVEX Microsoft Voice Control ActiveX clsid unicode access (more info ...)attempted-user 2007-2222   URL
11828WEB-ACTIVEX Microsoft Voice Control ActiveX function call access (more info ...)attempted-user 2007-2222   URL
11829WEB-ACTIVEX Microsoft Voice Control ActiveX function call unicode access (more info ...)attempted-user 2007-2222   URL
11830WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX clsid access (more info ...)attempted-user 2007-2222   URL
11831WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX clsid unicode access (more info ...)attempted-user 2007-2222   URL
11832WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX function call access (more info ...)attempted-user 2007-2222   URL
11833WEB-ACTIVEX Microsoft Direct Speech Recognition ActiveX function call unicode access (more info ...)attempted-user 2007-2222   URL
11839WEB-ACTIVEX TEC-IT TBarCode ActiveX clsid access (more info ...)attempted-user  24440  
11840WEB-ACTIVEX TEC-IT TBarCode ActiveX clsid unicode access (more info ...)attempted-user  24440  
11841WEB-ACTIVEX TEC-IT TBarCode ActiveX function call access (more info ...)attempted-user  24440  
11842WEB-ACTIVEX TEC-IT TBarCode ActiveX function call unicode access (more info ...)attempted-user  24440  
11843NETBIOS DCERPC NCACN-IP-TCP spoolss AddPrinter overflow attempt (more info ...)attempted-admin 2005-1984 14514  URL
11939WEB-ACTIVEX Westbyte Internet Download Accelerator ActiveX clsid unicode access (more info ...)attempted-user  24400  
11940WEB-ACTIVEX Westbyte Internet Download Accelerator ActiveX function call access (more info ...)attempted-user  24400  
11941WEB-ACTIVEX Westbyte Internet Download Accelerator ActiveX function call unicode access (more info ...)attempted-user  24400  
11942WEB-ACTIVEX Westbyte internet download accelerator ActiveX clsid access (more info ...)attempted-user  24400  
11943WEB-ACTIVEX HP ModemUtil ActiveX clsid access (more info ...)attempted-user    
11944WEB-ACTIVEX HP ModemUtil ActiveX clsid unicode access (more info ...)attempted-user    
11945NETBIOS SMB Trans2 OPEN2 maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11946NETBIOS Datagram Service NetDDE attack (more info ...)attempted-admin 2004-0206 11372  
11951BACKDOOR winshadow runtime detection - init connection request (more info ...)trojan-activity    URL
11952BACKDOOR winshadow runtime detection - udp response (more info ...)trojan-activity    URL
11955NETBIOS SMB-DS Trans2 OPEN2 maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11956NETBIOS SMB-DS Trans2 OPEN2 unicode maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11957NETBIOS-DG SMB Trans2 OPEN2 maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11958NETBIOS-DG SMB Trans2 OPEN2 unicode maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11959NETBIOS SMB Trans2 OPEN2 andx maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11960NETBIOS SMB Trans2 OPEN2 unicode andx maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11961NETBIOS SMB-DS Trans2 OPEN2 andx maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11962NETBIOS SMB-DS Trans2 OPEN2 unicode andx maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11963NETBIOS-DG SMB Trans2 OPEN2 andx maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
11964NETBIOS-DG SMB Trans2 OPEN2 unicode andx maximum param count overflow attempt (more info ...)protocol-command-decode 2003-0201   
12015WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX clsid access (more info ...)attempted-user  24656  URL
12016WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX clsid unicode access (more info ...)attempted-user  24656  URL
12017WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX function call access (more info ...)attempted-user  24656  URL
12018WEB-ACTIVEX NCTAudioStudio2 NCT WavChunksEditor ActiveX function call unicode access (more info ...)attempted-user  24656  URL
12019WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX clsid access (more info ...)attempted-user  24613  URL
12020WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX clsid unicode access (more info ...)attempted-user  24613  URL
12021WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX function call access (more info ...)attempted-user  24613  URL
12022WEB-ACTIVEX NCTsoft NCTAudioFile2 NCTWMAFile ActiveX function call unicode access (more info ...)attempted-user  24613  URL
12029WEB-ACTIVEX HP Digital Imaging hpqxml.dll ActiveX clsid access (more info ...)attempted-user 2007-3487 24678  URL
12030WEB-ACTIVEX HP Digital Imaging hpqxml.dll ActiveX clsid unicode access (more info ...)attempted-user 2007-3487 24678  URL
12058SPECIFIC-THREATS Microsoft SPNEGO ASN.1 library heap corruption overflow attempt (more info ...)attempted-admin 2003-0818 9633  URL
12062WEB-ACTIVEX HP Instant Support ActiveX clsid access (more info ...)attempted-user 2007-3554 24730  URL
12063WEB-ACTIVEX HP Instant Support ActiveX clsid unicode access (more info ...)attempted-user 2007-3554 24730  URL
12083WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX clsid access (more info ...)attempted-user 2007-3883 24959  
12084WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX clsid unicode access (more info ...)attempted-user 2007-3883 24959  
12085WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX function call access (more info ...)attempted-user 2007-3883 24959  
12086WEB-ACTIVEX Data Dynamics ActiveBar Actbar3 ActiveX function call unicode access (more info ...)attempted-user 2007-3883 24959  
12087WEB-ACTIVEX McAfee NeoTrace ActiveX clsid access (more info ...)attempted-user 2006-6707 21697  
12088WEB-ACTIVEX McAfee NeoTrace ActiveX clsid unicode access (more info ...)attempted-user 2006-6707 21697  
12089WEB-ACTIVEX McAfee NeoTrace ActiveX function call access (more info ...)attempted-user 2006-6707 21697  
12090WEB-ACTIVEX McAfee NeoTrace ActiveX function call unicode access (more info ...)attempted-user 2006-6707 21697  
12091WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX clsid access (more info ...)attempted-user 2007-3785 24882  
12092WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX clsid unicode access (more info ...)attempted-user 2007-3785 24882  
12093WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX function call access (more info ...)attempted-user 2007-3785 24882  
12094WEB-ACTIVEX EldoS SecureBlackbox PGPBBox ActiveX function call unicode access (more info ...)attempted-user 2007-3785 24882  
12100NETBIOS DCERPC NCACN-IP-TCP ca-alert function 16,23 overflow attempt (more info ...)attempted-admin 2007-3825 24947  URL
12116WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX clsid access (more info ...)attempted-user 2007-3984 25025  
12117WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX clsid unicode access (more info ...)attempted-user 2007-3984 25025  
12118WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX function call access (more info ...)attempted-user 2007-3984 25025  
12119WEB-ACTIVEX Zenturi ProgramChecker SASATL ActiveX function call unicode access (more info ...)attempted-user 2007-3984 25025  
12145BACKDOOR access remote pc runtime detection - rpc setup (more info ...)trojan-activity    URL
12168WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX clsid access (more info ...)attempted-user 2007-3302 25050  URL
12169WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX clsid unicode access (more info ...)attempted-user 2007-3302 25050  URL
12185RPC portmap 2112 tcp request (more info ...)rpc-portmap-decode 2007-2798 24653  URL
12186RPC portmap 2112 udp request (more info ...)rpc-portmap-decode 2007-2798 24653  URL
12189WEB-ACTIVEX Clever Internet Suite ActiveX clsid access (more info ...)attempted-user 2007-4067 25063  
12190WEB-ACTIVEX Clever Internet Suite ActiveX clsid unicode access (more info ...)attempted-user 2007-4067 25063  
12191WEB-ACTIVEX Clever Internet Suite ActiveX function call access (more info ...)attempted-user 2007-4067 25063  
12192WEB-ACTIVEX Clever Internet Suite ActiveX function call unicode access (more info ...)attempted-user 2007-4067 25063  
12193WEB-ACTIVEX Yahoo Widgets Engine ActiveX clsid access (more info ...)attempted-user 2007-4034 25086  URL
12194WEB-ACTIVEX Yahoo Widgets Engine ActiveX clsid unicode access (more info ...)attempted-user 2007-4034 25086  URL
12195WEB-ACTIVEX Yahoo Widgets Engine ActiveX function call access (more info ...)attempted-user 2007-4034 25086  URL
12196WEB-ACTIVEX Yahoo Widgets Engine ActiveX function call unicode access (more info ...)attempted-user 2007-4034 25086  URL
12200WEB-ACTIVEX VMWare IntraProcessLogging ActiveX clsid access (more info ...)attempted-user 2007-4059 25110  
12201WEB-ACTIVEX VMWare IntraProcessLogging ActiveX clsid unicode access (more info ...)attempted-user 2007-4059 25110  
12203WEB-ACTIVEX VMWare Vielib.dll ActiveX clsid access (more info ...)attempted-user 2007-4058 25118  
12204WEB-ACTIVEX VMWare Vielib.dll ActiveX clsid unicode access (more info ...)attempted-user 2007-4058 25118  
12205WEB-ACTIVEX VMWare Vielib.dll ActiveX function call access (more info ...)attempted-user 2007-4058 25118  
12206WEB-ACTIVEX VMWare Vielib.dll ActiveX function call unicode access (more info ...)attempted-user 2007-4058 25118  
12207WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX function call access (more info ...)attempted-user 2007-3302 25050  URL
12208WEB-ACTIVEX Computer Associates ETrust Intrusion Detection Caller.DLL ActiveX function call unicode access (more info ...)attempted-user 2007-3302 25050  URL
12246WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX clsid access (more info ...)attempted-user 2007-2955 24983  URL
12247WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX clsid unicode access (more info ...)attempted-user 2007-2955 24983  URL
12248WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX function call access (more info ...)attempted-user 2007-2955 24983  URL
12249WEB-ACTIVEX Symantec NavComUI AxSysListView32 ActiveX function call unicode access (more info ...)attempted-user 2007-2955 24983  URL
12250WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX clsid access (more info ...)attempted-user 2007-2955 24983  URL
12251WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX clsid unicode access (more info ...)attempted-user 2007-2955 24983  URL
12252WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX function call access (more info ...)attempted-user 2007-2955 24983  URL
12253WEB-ACTIVEX Symantec NavComUI AxSysListView32OAA ActiveX function call unicode access (more info ...)attempted-user 2007-2955 24983  URL
12257WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX clsid access (more info ...)attempted-user 2007-4336 25279  
12258WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX clsid unicode access (more info ...)attempted-user 2007-4336 25279  
12259WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX function call access (more info ...)attempted-user 2007-4336 25279  
12260WEB-ACTIVEX Microsoft DirectX Media SDK ActiveX function call unicode access (more info ...)attempted-user 2007-4336 25279  
12277EXPLOIT Microsoft IE CSS memory corruption exploit (more info ...)attempted-user 2007-0943   URL
12301WEB-ACTIVEX eCentrex VOIP Client Module ActiveX clsid access (more info ...)attempted-user 2007-4489 25383  URL
12302WEB-ACTIVEX eCentrex VOIP Client Module ActiveX clsid unicode access (more info ...)attempted-user 2007-4489 25383  URL
12380WEB-ACTIVEX Oracle JInitiator ActiveX clsid access (more info ...)attempted-user 2007-4467 25473  
12381WEB-ACTIVEX Oracle JInitiator ActiveX clsid unicode access (more info ...)attempted-user 2007-4467 25473  
12382WEB-ACTIVEX EasyMail Objects ActiveX clsid access (more info ...)attempted-user 2007-4607 25467  
12383WEB-ACTIVEX EasyMail Objects ActiveX clsid unicode access (more info ...)attempted-user 2007-4607 25467  
12384WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX clsid access (more info ...)attempted-user 2007-4515 25494  URL
12385WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX clsid unicode access (more info ...)attempted-user 2007-4515 25494  URL
12386WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX function call access (more info ...)attempted-user 2007-4515 25494  URL
12387WEB-ACTIVEX Yahoo Messenger YVerInfo ActiveX function call unicode access (more info ...)attempted-user 2007-4515 25494  URL
12388WEB-ACTIVEX PPStream PowerPlayer ActiveX clsid access (more info ...)attempted-user 2007-4748 25502  
12389WEB-ACTIVEX PPStream PowerPlayer ActiveX clsid unicode access (more info ...)attempted-user 2007-4748 25502  
12413WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX clsid access (more info ...)attempted-user 2007-4470 25584  
12414WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX clsid unicode access (more info ...)attempted-user 2007-4470 25584  
12415WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX function call access (more info ...)attempted-user 2007-4470 25584  
12416WEB-ACTIVEX Earth Resource Mapper NCSView ActiveX function call unicode access (more info ...)attempted-user 2007-4470 25584  
12428WEB-ACTIVEX GlobalLink glitemflat.dll ActiveX clsid access (more info ...)attempted-user  25586  
12429WEB-ACTIVEX GlobalLink glitemflat.dll ActiveX clsid unicode access (more info ...)attempted-user  25586  
12434WEB-ACTIVEX BaoFeng Storm MPS.dll ActiveX clsid access (more info ...)attempted-user 2009-1612 25601  
12435WEB-ACTIVEX BaoFeng Storm MPS.dll ActiveX clsid unicode access (more info ...)attempted-user 2009-1612 25601  
12438WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX clsid access (more info ...)attempted-user  25609  URL
12439WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX clsid unicode access (more info ...)attempted-user  25609  URL
12440WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX function call access (more info ...)attempted-user  25609  URL
12441WEB-ACTIVEX Ultra Crypto Component CryptoX.dll ActiveX function call unicode access (more info ...)attempted-user  25609  URL
12442WEB-ACTIVEX Ultra Crypto Component CryptoX.dll 2 ActiveX clsid access (more info ...)attempted-user  25611  URL
12443WEB-ACTIVEX Ultra Crypto Component CryptoX.dll 2 ActiveX clsid unicode access (more info ...)attempted-user  25611  URL
12448WEB-ACTIVEX Microsoft Agent Control ActiveX clsid access (more info ...)attempted-user 2007-3040 25566  URL
12449WEB-ACTIVEX Microsoft Agent Control ActiveX clsid unicode access (more info ...)attempted-user 2007-3040 25566  URL
12450WEB-ACTIVEX Microsoft Agent Control ActiveX function call access (more info ...)attempted-user 2007-3040 25566  URL
12451WEB-ACTIVEX Microsoft Agent Control ActiveX function call unicode access (more info ...)attempted-user 2007-3040 25566  URL
12452WEB-ACTIVEX MS Agent File Provider ActiveX clsid access (more info ...)attempted-user 2007-3040 25566  URL
12453WEB-ACTIVEX MS Agent File Provider ActiveX clsid unicode access (more info ...)attempted-user 2007-3040 25566  URL
12458RPC portmap Solaris sadmin port query tcp request (more info ...)rpc-portmap-decode 2003-0722 8615  
12459WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX clsid access (more info ...)attempted-user 2007-4891 25638  
12460WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX clsid unicode access (more info ...)attempted-user 2007-4891 25638  
12461WEB-ACTIVEX Microsoft Visual Studio 6 VBTOVSI.dll ActiveX clsid access (more info ...)attempted-user 2007-4890 25635  
12462WEB-ACTIVEX Microsoft Visual Studio 6 VBTOVSI.dll ActiveX clsid unicode access (more info ...)attempted-user 2007-4890 25635  
12468WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX clsid access (more info ...)attempted-user 2007-4983 25723  
12469WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX clsid unicode access (more info ...)attempted-user 2007-4983 25723  
12470WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX function call access (more info ...)attempted-user 2007-4983 25723  
12471WEB-ACTIVEX COWON America JetAudio JetFlExt.dll ActiveX function call unicode access (more info ...)attempted-user 2007-4983 25723  
12476WEB-ACTIVEX Yahoo Messenger CYFT ActiveX clsid access (more info ...)attempted-user 2007-5017 25727  
12477WEB-ACTIVEX Yahoo Messenger CYFT ActiveX clsid unicode access (more info ...)attempted-user 2007-5017 25727  
12478WEB-ACTIVEX Yahoo Messenger CYFT ActiveX function call access (more info ...)attempted-user 2007-5017 25727  
12479WEB-ACTIVEX Yahoo Messenger CYFT ActiveX function call unicode access (more info ...)attempted-user 2007-5017 25727  
12598WEB-ACTIVEX Xunlei Web Thunder ActiveX clsid access (more info ...)attempted-user 2007-5064 25751  
12599WEB-ACTIVEX Xunlei Web Thunder ActiveX clsid unicode access (more info ...)attempted-user 2007-5064 25751  
12600WEB-ACTIVEX ebCrypt IncrementalHash ActiveX clsid access (more info ...)attempted-user 2007-5111 25789  
12601WEB-ACTIVEX ebCrypt IncrementalHash ActiveX clsid unicode access (more info ...)attempted-user 2007-5111 25789  
12602WEB-ACTIVEX ebCrypt IncrementalHash ActiveX function call access (more info ...)attempted-user 2007-5111 25789  
12603WEB-ACTIVEX ebCrypt IncrementalHash ActiveX function call unicode access (more info ...)attempted-user 2007-5111 25789  
12604WEB-ACTIVEX ebCrypt PRNGenerator ActiveX clsid access (more info ...)attempted-user 2007-5110 25787  
12605WEB-ACTIVEX ebCrypt PRNGenerator ActiveX clsid unicode access (more info ...)attempted-user 2007-5110 25787  
12606WEB-ACTIVEX ebCrypt PRNGenerator ActiveX function call access (more info ...)attempted-user 2007-5110 25787  
12607WEB-ACTIVEX ebCrypt PRNGenerator ActiveX function call unicode access (more info ...)attempted-user 2007-5110 25787  
12608RPC portmap walld udp request (more info ...)rpc-portmap-decode 2002-0573 4639  
12609RPC portmap walld udp format string attack attempt (more info ...)rpc-portmap-decode 2002-0573 4639  
12616WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX function call access (more info ...)attempted-user 2007-4891 25638  
12617WEB-ACTIVEX Microsoft Visual Studio 6 PDWizard.ocx ActiveX function call unicode access (more info ...)attempted-user 2007-4891 25638  
12626RPC portmap Solaris sadmin port query udp request (more info ...)rpc-portmap-decode 2003-0722 8615  
12627RPC portmap Solaris sadmin port query tcp portmapper sadmin port query attempt (more info ...)rpc-portmap-decode 2003-0722 8615  
12628RPC portmap Solaris sadmin port query udp portmapper sadmin port query attempt (more info ...)rpc-portmap-decode 2003-0722 8615  
12631EXPLOIT Microsoft Kodak Imaging small offset malformed jpeg tables (more info ...)attempted-user 2007-2217   URL
12632EXPLOIT Microsoft Kodak Imaging large offset malformed jpeg tables (more info ...)attempted-user 2007-2217   URL
12635DOS RPC NTLMSSP malformed credentials (more info ...)denial-of-service 2007-2228   URL
12637WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX clsid access (more info ...)attempted-user 2007-3675 26004  
12638WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX clsid unicode access (more info ...)attempted-user 2007-3675 26004  
12639WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX function call access (more info ...)attempted-user 2007-3675 26004  
12640WEB-ACTIVEX Kaspersky Online Scanner KAVWebScan.dll ActiveX function call unicode access (more info ...)attempted-user 2007-3675 26004  
12642DOS RPC NTLMSSP malformed credentials (more info ...)denial-of-service 2007-2228   URL
12644WEB-ACTIVEX PBEmail7 ActiveX clsid access (more info ...)attempted-user 2007-5446 26058  
12645WEB-ACTIVEX PBEmail7 ActiveX clsid unicode access (more info ...)attempted-user 2007-5446 26058  
12646WEB-ACTIVEX PBEmail7 ActiveX function call access (more info ...)attempted-user 2007-5446 26058  
12647WEB-ACTIVEX PBEmail7 ActiveX function call unicode access (more info ...)attempted-user 2007-5446 26058  
12648WEB-ACTIVEX DB Software Laboratory VImpX ActiveX clsid access (more info ...)attempted-user 2007-5445 26064  
12649WEB-ACTIVEX DB Software Laboratory VImpX ActiveX clsid unicode access (more info ...)attempted-user 2007-5445 26064  
12650WEB-ACTIVEX DB Software Laboratory VImpX ActiveX function call access (more info ...)attempted-user 2007-5445 26064  
12651WEB-ACTIVEX DB Software Laboratory VImpX ActiveX function call unicode access (more info ...)attempted-user 2007-5445 26064  
12689WEB-ACTIVEX GlobalLink ConnectAndEnterRoom ActiveX clsid access (more info ...)attempted-user 2007-5722 26244  
12690WEB-ACTIVEX GlobalLink ConnectAndEnterRoom ActiveX clsid unicode access (more info ...)attempted-user 2007-5722 26244  
12714WEB-ACTIVEX WebEx GPCContainer ActiveX clsid access (more info ...)attempted-user 2007-6005 26430  
12715WEB-ACTIVEX WebEx GPCContainer ActiveX clsid unicode access (more info ...)attempted-user 2007-6005 26430  
12716WEB-ACTIVEX WebEx GPCContainer ActiveX function call access (more info ...)attempted-user 2007-6005 26430  
12717WEB-ACTIVEX WebEx GPCContainer ActiveX function call unicode access (more info ...)attempted-user 2007-6005 26430  
12729WEB-ACTIVEX AOL Radio AmpX ActiveX clsid access (more info ...)attempted-user 2007-5755 26396  
12730WEB-ACTIVEX AOL Radio AmpX ActiveX clsid unicode access (more info ...)attempted-user 2007-5755 26396  
12731WEB-ACTIVEX AOL Radio AmpX ActiveX function call access (more info ...)attempted-user 2007-5755 35028  
12732WEB-ACTIVEX AOL Radio AmpX ActiveX function call unicode access (more info ...)attempted-user 2007-5755 26396  
12733WEB-ACTIVEX ComponentOne FlexGrid ActiveX clsid access (more info ...)attempted-user 2007-6028 26467  
12734WEB-ACTIVEX ComponentOne FlexGrid ActiveX clsid unicode access (more info ...)attempted-user 2007-6028 26467  
12735WEB-ACTIVEX ComponentOne FlexGrid ActiveX function call access (more info ...)attempted-user 2007-6028 26467  
12736WEB-ACTIVEX ComponentOne FlexGrid ActiveX function call unicode access (more info ...)attempted-user 2007-6028 26467  
12737WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX clsid access (more info ...)attempted-user 2007-6144 26536  
12738WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX clsid unicode access (more info ...)attempted-user 2007-6144 26536  
12739WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX function call access (more info ...)attempted-user 2007-6144 26536  
12740WEB-ACTIVEX Xunlei Thunder PPLAYER.DLL ActiveX function call unicode access (more info ...)attempted-user 2007-6144 26536  
12747WEB-ACTIVEX BitDefender Online Scanner ActiveX clsid access (more info ...)attempted-user 2007-5775 26210  
12748WEB-ACTIVEX BitDefender Online Scanner ActiveX clsid unicode access (more info ...)attempted-user 2007-5775 26210  
12749WEB-ACTIVEX BitDefender Online Scanner ActiveX function call access (more info ...)attempted-user 2007-5775 26210  
12750WEB-ACTIVEX BitDefender Online Scanner ActiveX function call unicode access (more info ...)attempted-user 2007-5775 26210  
12780WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX clsid access (more info ...)attempted-user  27577  URL
12781WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX clsid unicode access (more info ...)attempted-user  27577  URL
12782WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX function call access (more info ...)attempted-user  27577  URL
12783WEB-ACTIVEX Aurigma Image Uploader 4 Vulnerable Methods ActiveX function call unicode access (more info ...)attempted-user  27577  URL
12905SPECIFIC-THREATS Microsoft SPNEGO ASN.1 library heap corruption overflow attempt (more info ...)attempted-admin 2003-0818 9633  URL
12940NETBIOS DCERPC NCACN-IP-TCP brightstor-arc2 CA call 269 overflow attempt (more info ...)attempted-admin 2007-5327 26015  
12977NETBIOS DCERPC NCACN-IP-TCP mqqm QMCreateObjectInternal overflow attempt (more info ...)attempted-admin 2007-3039   URL
12978NETBIOS DCERPC NCADG-IP-UDP mqqm QMCreateObjectInternal overflow attempt (more info ...)attempted-admin 2007-3039   URL
12984NETBIOS DCERPC NCACN-IP-TCP srvsvc NetSetFileSecurity integer overflow attempt (more info ...)protocol-command-decode 2007-2446 24196  
12985NETBIOS DCERPC NCADG-IP-UDP srvsvc NetSetFileSecurity integer overflow attempt (more info ...)protocol-command-decode 2007-2446 24196  
13210NETBIOS DCERPC NCACN-IP-TCP mqqm QMObjectPathToObjectFormat overflow attempt (more info ...)attempted-admin 2007-3039   URL
13211NETBIOS DCERPC NCADG-IP-UDP mqqm QMObjectPathToObjectFormat overflow attempt (more info ...)attempted-admin 2007-3039   URL
13228WEB-ACTIVEX HP eSupportDiagnostics 1 ActiveX clsid access (more info ...)attempted-user  26967  URL
13229WEB-ACTIVEX HP eSupportDiagnostics 1 ActiveX clsid unicode access (more info ...)attempted-user  26967  URL
13230WEB-ACTIVEX HP eSupportDiagnostics 2 ActiveX clsid access (more info ...)attempted-user  26967  URL
13231WEB-ACTIVEX HP eSupportDiagnostics 2 ActiveX clsid unicode access (more info ...)attempted-user  26967  URL
13232WEB-ACTIVEX Persits Software XUpload ActiveX clsid access (more info ...)attempted-user 2009-3693 36550  
13233WEB-ACTIVEX Persits Software XUpload ActiveX clsid unicode access (more info ...)attempted-user 2009-3693 36550  
13234WEB-ACTIVEX Persits Software XUpload ActiveX function call access (more info ...)attempted-user 2009-3693 36550  
13235WEB-ACTIVEX Persits Software XUpload ActiveX function call unicode access (more info ...)attempted-user 2009-3693 36550  
13434WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX clsid access (more info ...)attempted-user  27577  URL
13435WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX clsid unicode access (more info ...)attempted-user  27577  URL
13436WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX function call access (more info ...)attempted-user  27577  URL
13437WEB-ACTIVEX Aurigma Image Uploader 4 Property Overflows ActiveX function call unicode access (more info ...)attempted-user  27577  URL
13438WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX clsid access (more info ...)attempted-user  27577  URL
13439WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX clsid unicode access (more info ...)attempted-user  27577  URL
13440WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX function call access (more info ...)attempted-user  27577  URL
13441WEB-ACTIVEX Aurigma Image Uploader 5 Vulnerable Methods ActiveX function call unicode access (more info ...)attempted-user  27577  URL
13442WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX clsid access (more info ...)attempted-user  27577  URL
13443WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX clsid unicode access (more info ...)attempted-user  27577  URL
13444WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX function call access (more info ...)attempted-user  27577  URL
13445WEB-ACTIVEX Aurigma Image Uploader 5 Property Overflows ActiveX function call unicode access (more info ...)attempted-user  27577  URL
13451WEB-ACTIVEX Microsoft Visual FoxPro foxtlib ActiveX clsid access (more info ...)attempted-user 2007-5322 25977  URL
13452WEB-ACTIVEX Microsoft Visual FoxPro foxtlib ActiveX clsid unicode access (more info ...)attempted-user 2007-5322 25977  URL
13454WEB-CLIENT Microsoft DXLUTBuilder ActiveX clsid unicode access (more info ...)attempted-user 2008-0078   URL
13456WEB-CLIENT Microsoft DXLUTBuilder ActiveX function call unicode access (more info ...)attempted-user 2008-0078   URL
13458WEB-ACTIVEX Microsoft Forms 2.0 ActiveX clsid unicode access (more info ...)attempted-user 2007-0065   URL
13460WEB-ACTIVEX Microsoft Forms 2.0 ActiveX function call unicode access (more info ...)attempted-user 2007-0065   URL
13472EXPLOIT Microsoft Works invalid chunk size (more info ...)attempted-user 2008-0108   URL
13475DOS Microsoft Active Directory LDAP denial of service attempt (more info ...)attempted-dos 2008-0088   URL
13594SPECIFIC-THREATS Microsoft Windows print spooler little endian DoS attempt (more info ...)protocol-command-decode 2006-6296 21401  
13669WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX clsid unicode access (more info ...)attempted-user 2008-1086   URL
13671WEB-ACTIVEX Microsoft Help 2.0 Contents Control ActiveX function call unicode access (more info ...)attempted-user 2008-1086   URL
13673WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX clsid unicode access (more info ...)attempted-user 2008-1086   URL
13675WEB-ACTIVEX Microsoft Help 2.0 Contents Control 2 ActiveX function call unicode access (more info ...)attempted-user 2008-1086   URL
13828WEB-ACTIVEX sapi.dll ActiveX clsid access (more info ...)attempted-user 2007-0675   URL
13829WEB-ACTIVEX sapi.dll ActiveX clsid unicode access (more info ...)attempted-user 2007-0675   URL
13830WEB-ACTIVEX sapi.dll alternate killbit ActiveX clsid access (more info ...)attempted-user 2007-0675   URL
13831WEB-ACTIVEX sapi.dll alternate killbit ActiveX clsid unicode access (more info ...)attempted-user 2007-0675   URL
13832WEB-ACTIVEX backweb ActiveX clsid access (more info ...)attempted-user 2007-0675   URL
13833WEB-ACTIVEX backweb ActiveX clsid unicode access (more info ...)attempted-user 2007-0675   URL
13835DOS Microsoft Active Directory LDAP cookie denial of service attempt (more info ...)attempted-dos 2008-1445   URL
13966WEB-ACTIVEX Microsoft Message System ActiveX clsid unicode access (more info ...)attempted-user 2008-0082   URL
13968WEB-ACTIVEX Microsoft Message System ActiveX function call unicode access (more info ...)attempted-user 2008-0082   URL
13976WEB-CLIENT Microsoft Windows Event System ActiveX clsid unicode access (more info ...)attempted-user 2008-1457   URL
13978WEB-CLIENT Microsoft Windows Event System ActiveX function call unicode access (more info ...)attempted-user 2008-1457   URL
14033WEB-ACTIVEX Orbit Downloader ActiveX clsid access (more info ...)attempted-user 2008-1602   
14034WEB-ACTIVEX Orbit Downloader ActiveX clsid unicode access (more info ...)attempted-user 2008-1602   
14035WEB-ACTIVEX Orbit Downloader ActiveX function call access (more info ...)attempted-user 2008-1602   
14036WEB-ACTIVEX Orbit Downloader ActiveX function call unicode access (more info ...)attempted-user 2008-1602   
14038WEB-ACTIVEX Novell iPrint ActiveX target-frame parameter overflow attempt (more info ...)attempted-user 2008-2908 29736  
14066SPYWARE-PUT Adware winsecuredisc runtime detection (more info ...)misc-activity    URL
14078SPYWARE-PUT Adware winspywareprotect runtime detection - download malicous code (more info ...)misc-activity    URL
14079SPYWARE-PUT Adware winspywareprotect runtime detection - connection to malicious sites (more info ...)misc-activity    URL
14080SPYWARE-PUT Adware winspywareprotect runtime detection - connection to malicious server (more info ...)misc-activity    URL
14232WEB-ACTIVEX SoftArtisans XFile FileManager ActiveX clsid unicode access (more info ...)attempted-user 2007-1682 30826  URL
15085WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX clsid unicode access (more info ...)attempted-user 2008-4255   URL
15087WEB-ACTIVEX Microsoft Common Controls Animation Object ActiveX function call unicode access (more info ...)attempted-user 2008-4255   URL
15109WEB-ACTIVEX Shell.Explorer 1 ActiveX clsid access (more info ...)attempted-user 2008-4258   URL
15110WEB-ACTIVEX Shell.Explorer 1 ActiveX clsid unicode access (more info ...)attempted-user 2008-4258   URL
15111WEB-ACTIVEX Shell.Explorer 2 ActiveX clsid unicode access (more info ...)attempted-user 2008-4258 11466  URL
15112WEB-ACTIVEX Shell.Explorer 2 ActiveX function call access (more info ...)attempted-user 2008-4258 11466  URL
15113WEB-ACTIVEX Shell.Explorer 2 ActiveX function call unicode access (more info ...)attempted-user 2008-4258 11466  URL
15122WEB-ACTIVEX Shell.Explorer 2 ActiveX clsid access (more info ...)attempted-user 2008-4258 11466  URL
15448NETBIOS DCERPC NCADG-IP-UDP srvsvc NetrShareEnum null policy handle attempt (more info ...)protocol-command-decode    
15507SPECIFIC-THREATS DCERPC NCACN-IP-TCP lsarpc LsarLookupSids translated_names overflow attempt (more info ...)protocol-command-decode 2007-2446 24196  
15508SPECIFIC-THREATS DCERPC NCADG-IP-UDP lsarpc LsarLookupSids translated_names overflow attempt (more info ...)protocol-command-decode 2007-2446 24196  
15862WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX clsid unicode access (more info ...)attempted-user 2009-1929   URL
15864WEB-ACTIVEX Microsoft Remote Desktop Client ActiveX function call unicode access (more info ...)attempted-user 2009-1929   URL
15881NETBIOS DCERPC NCACN-IP-TCP spoolss EnumPrinters Name Field attempt (more info ...)protocol-command-decode 2008-0639   
15911NETBIOS DCERPC NCACN-IP-TCP spoolss RouteRefreshPrinterChangeNotification attempt (more info ...)protocol-command-decode 2007-2446   
16012WEB-ACTIVEX Symantec SupportSoft SmartIssue ActiveX function call unicode access (more info ...)attempted-user 2006-6490 22564  URL
16016SPECIFIC-THREATS Microsoft client for netware overflow attempt (more info ...)attempted-admin 2006-4688   URL
16034SPECIFIC-THREATS Samba spools RPC smb_io_notify_option_type_data request handling buffer overflow attempt (more info ...)attempted-user 2007-2446   
16058SPECIFIC-THREATS Samba WINS Server Name Registration handling stack buffer overflow attempt (more info ...)attempted-user 2007-5398 26455  
16066EXPLOIT Microsoft Windows Server driver crafted SMB data denial of service (more info ...)attempted-dos 2006-3942   URL
16081RPC portmap 395650 tcp XDR SString buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242 29283  URL
16082RPC portmap 395650 udp XDR SString buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242 29283  URL
16083RPC portmap 395650 tcp request (more info ...)rpc-portmap-decode 2008-2242   URL
16084RPC portmap 395650 udp request (more info ...)rpc-portmap-decode 2008-2242   URL
16085RPC portmap 395650 tcp xml buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242   URL
16086RPC portmap 395650 udp xml buffer overflow attempt (more info ...)rpc-portmap-decode 2008-2242   URL
16221EXPLOIT Microsoft ISA and Forefront Threat Management Web Proxy TCP Listener denial of service attempt (more info ...)attempted-dos 2009-0077 34414  URL
16294EXPLOIT Microsoft Windows TCP stack zero window size exploit attempt (more info ...)attempted-dos 2008-4609 31545  URL
16386WEB-ACTIVEX AcroPDF.PDF ActiveX clsid access (more info ...)attempted-user 2009-2987   
16387WEB-ACTIVEX AcroPDF.PDF ActiveX clsid unicode access (more info ...)attempted-user 2009-2987   
16388WEB-ACTIVEX AcroPDF.PDF ActiveX function call access (more info ...)attempted-user 2009-2987   
16389WEB-ACTIVEX AcroPDF.PDF ActiveX function call unicode access (more info ...)attempted-user 2009-2987   
16397NETBIOS SMB andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16398NETBIOS SMB invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16399NETBIOS SMB unicode andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16400NETBIOS SMB unicode invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16401NETBIOS-DG SMB andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16402NETBIOS-DG SMB invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16403NETBIOS-DG SMB unicode andx invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16404NETBIOS-DG SMB unicode invalid server name share access (more info ...)protocol-command-decode 2010-0022   URL
16413WEB-CLIENT Microsoft PowerPoint invalid TextCharsAtom remote code execution attempt (more info ...)attempted-user 2010-0034   URL
16420WEB-ACTIVEX Microsoft Data Analyzer 3.5 ActiveX clsid unicode access (more info ...)attempted-user 2010-0252   URL
16446RPC portmap Solaris sadmin tcp request (more info ...)rpc-portmap-decode 2008-4556 31751  
16447RPC portmap Solaris sadmin udp request (more info ...)rpc-portmap-decode 2008-4556 31751  
16448RPC portmap Solaris sadmin tcp adm_build_path overflow attempt (more info ...)rpc-portmap-decode 2008-4556 31751  
16449RPC portmap Solaris sadmin udp adm_build_path overflow attempt (more info ...)rpc-portmap-decode 2008-4556 31751  
16533BAD-TRAFFIC Microsoft Windows ISATAP-addressed IPv6 traffic spoofing attempt (more info ...)misc-attack 2010-0812   URL
16540NETBIOS SMB2 client NetBufferList NULL entry remote code execution attempt (more info ...)attempted-admin 2010-0477   URL
16581SPECIFIC-THREATS Persits Software XUpload ActiveX clsid unsafe function access attempt (more info ...)attempted-user 2009-3693 36550  
16926BLACKLIST URI request for known malicious URI - strMode=setup&strID=pcvaccine&strPC= (more info ...)trojan-activity    URL
17111SPECIFIC-THREATS Microsoft Video ActiveX Control stack buffer overflow attempt (more info ...)attempted-user 2008-0015 35558  
17112SPECIFIC-THREATS DCERPC rpcss2 _RemoteGetClassObject attempt (more info ...)attempted-user 2003-0715 8205  URL
17133WEB-CLIENT MSXML2 ActiveX malformed HTTP response (more info ...)attempted-dos 2010-2561   URL
17205RPC Multiple vendors librpc.dll stack buffer overflow attempt - udp (more info ...)attempted-admin 2009-2754 38472  
17206RPC Multiple vendors librpc.dll stack buffer overflow attempt - tcp (more info ...)attempted-admin 2009-2754 38472  
17231WEB-CLIENT Microsoft Kodak Imaging small offset malformed tiff - little-endian (more info ...)attempted-user 2007-2217   URL
17232WEB-CLIENT Microsoft Kodak Imaging large offset malformed tiff - big-endian (more info ...)attempted-user 2007-2217   URL
17252NETBIOS Microsoft Windows Print Spooler arbitrary file write attempt (more info ...)attempted-user 2010-2729   URL
17253NETBIOS Microsoft Windows Print Spooler arbitrary file write attempt (more info ...)attempted-user 2010-2729   URL
17435NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
17437NETBIOS DCERPC NCACN-IP-TCP umpnpmgr PNP_GetDeviceList attempt (more info ...)protocol-command-decode 2005-2120 15065  URL
17439EXPLOIT Microsoft Distributed Transaction Controller TIP DoS attempt (more info ...)attempted-dos 2005-1979 15058  
17634NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 little endian object call overflow attempt (more info ...)attempted-admin 2008-4398   URL
17635NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 little endian overflow attempt (more info ...)attempted-admin 2008-4398   URL
17636NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 object call overflow attempt (more info ...)attempted-admin 2008-4398   URL
17637NETBIOS DCERPC NCACN-IP-TCPbrightstor-arc function 0 overflow attempt (more info ...)attempted-admin 2008-4398   URL
17640NETBIOS DCERPC NCACN-IP-TCP brightstor opnum 43 overflow attempt (more info ...)attempted-admin 2007-0169 22005  URL
17707NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect trend_req_num buffer overflow attempt (more info ...)protocol-command-decode 2007-1070 22639  URL
17714NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt (more info ...)protocol-command-decode 2007-1070 22639  URL
17715NETBIOS DCERPC NCACN-IP-TCP trend-serverprotect CMON_ActiveUpdate attempt (more info ...)protocol-command-decode 2007-1070 22639  URL
18072WEB-MISC Microsoft Forefront UAG external redirect attempt (more info ...)policy-violation 2010-2732   URL

 goto Top

Group: OS / Linux

# of attack rules in this group: 4

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
15490EXPLOIT Linux SCTP malformed forward-tsn chunk arbitrary code execution attempt (more info ...)attempted-admin  2009-0065  33113    
16352EXPLOIT Linux Kernel NFSD Subsystem overflow attempt (more info ...)attempted-dos  2008-3915  31133    
17324SHELLCODE x86 Linux reverse connect shellcode (more info ...)shellcode-detect        
17738SPECIFIC-THREATS Linux Kernel SNMP Netfilter Memory Corruption attempt (more info ...)attempted-dos  2006-2444  18081    


# of warning rules in this group: 19

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
213BACKDOOR MISC Linux rootkit attempt (more info ...)attempted-admin    
214BACKDOOR MISC Linux rootkit attempt lrkr0x (more info ...)attempted-admin    
215BACKDOOR MISC Linux rootkit attempt (more info ...)attempted-admin    
216BACKDOOR MISC Linux rootkit satori attempt (more info ...)attempted-admin    
292EXPLOIT x86 Linux samba overflow (more info ...)attempted-admin 1999-0811 536  
302EXPLOIT Redhat 7.0 lprd overflow (more info ...)attempted-admin 2000-0917 1712  
313EXPLOIT ntalkd x86 Linux overflow (more info ...)attempted-admin  210  
315EXPLOIT x86 Linux mountd overflow (more info ...)attempted-admin 1999-0002 121  
316EXPLOIT x86 Linux mountd overflow (more info ...)attempted-admin 1999-0002 121  
317EXPLOIT x86 Linux mountd overflow (more info ...)attempted-admin 1999-0002 121  
601RSERVICES rlogin LinuxNIS (more info ...)bad-unknown    
652SHELLCODE Linux shellcode (more info ...)shellcode-detect    
1225X11 MIT Magic Cookie detected (more info ...)attempted-user    
1226X11 xopen (more info ...)unknown    
7021DOS linux kernel SCTP chunkless packet denial of service attempt (more info ...)attempted-dos 2006-2934 18755  
15906EXPLOIT Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt (more info ...)denial-of-service 2008-3276 30704  
15907EXPLOIT Linux Kernel DCCP Protocol Handler dccp_setsockopt_change integer overflow attempt (more info ...)denial-of-service 2008-3276 30704  
16724EXPLOIT Linux kernel sctp_process_unk_param SCTPChunkInit buffer overflow attempt (more info ...)attempted-admin 2010-1173 39794  
17302DOS Linux kernel SCTP Unknown Chunk Types denial of service attempt (more info ...)attempted-dos 2007-2876 24376  

 goto Top

Group: OS / Other

# of attack rules in this group: 30

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
5760SPYWARE-PUT Hijacker marketscore runtime detection (more info ...)misc-activity        URL
5798SPYWARE-PUT Adware mydailyhoroscope runtime detection (more info ...)misc-activity        URL
5799SPYWARE-PUT mydailyhoroscope update or installation in progress (more info ...)misc-activity        URL
5834SPYWARE-PUT Trickler conscorr runtime detection (more info ...)misc-activity        URL
6017BACKDOOR dsk lite 1.0 runtime detection - disconnect (more info ...)trojan-activity        URL
6384SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - agent discover broadcast (more info ...)successful-recon-limited        URL
7020WEB-CLIENT isComponentInstalled function buffer overflow (more info ...)attempted-user  2006-1016  16870    
7720BACKDOOR desktop scout runtime detection (more info ...)trojan-activity        URL
8090WEB-MISC HP Openview NNM freeIPaddrs.ovpl Unix command execution attempt (more info ...)web-application-attack  2005-2773  14662    
9635EXPLOIT Computer Associates Product Discovery Service type 9B remote buffer overflow attempt UDP (more info ...)attempted-admin  2006-6379  21502    
10134SPECIFIC-THREATS CA Brightstor discovery service buffer overflow attempt (more info ...)attempted-admin  2005-0260  12491    
10998EXPLOIT Novell GroupWise WebAccess authentication overflow (more info ...)attempted-admin  2007-2171  23556    
11970VOIP-SIP Cisco 7940/7960 INVITE Remote-Party-ID denial of service attempt (more info ...)attempted-dos  2007-1542  23047    URL
13363EXPLOIT Cisco Unified Communications Manager heap overflow attempt (more info ...)attempted-admin  2008-0027  27313    
13613SPECIFIC-THREATS Solaris username overflow authentication bypass attempt (more info ...)attempted-admin  2001-0797      
13912SPECIFIC-THREATS isComponentInstalled Metasploit attack attempt (more info ...)attempted-user    16870    
14989WEB-MISC Novell eDirectory SOAP Accept Language header overflow attempt (more info ...)attempted-user  2008-4479      
15446WEB-MISC Novell eDirectory management console Accept-Language buffer overflow attempt (more info ...)attempted-admin  2008-5094  31553    URL
15958WEB-MISC Novell ZENworks Remote Management overflow attempt (more info ...)attempted-admin  2005-1543  13678    
16019SPECIFIC-THREATS Novell Distributed Print Services integer overflow attempt (more info ...)attempted-user  2006-2327      
16194WEB-MISC Novell eDirectory HTTP request content-length heap buffer overflow attempt (more info ...)attempted-user  2008-4478      
16195WEB-MISC Novell eDirectory HTTP request content-length heap buffer overflow attempt (more info ...)attempted-user  2008-4478      
16429WEB-MISC Novell iManager eDirectory plugin schema buffer overflow attempt - GET request (more info ...)attempted-admin  2009-4486  37672    
16430WEB-MISC Novell iManager eDirectory plugin schema buffer overflow attempt - POST request (more info ...)attempted-admin  2009-4486  37672    
16522WEB-CLIENT Novell QuickFinder server cross-site-scripting attempt (more info ...)web-application-attack  2009-0611      
16587SPECIFIC-THREATS Symantec multiple products AeXNSConsoleUtilities buffer overflow attempt (more info ...)attempted-user  2009-3031  36698    
16787SPECIFIC-THREATS Symantec multiple products AeXNSConsoleUtilities RunCMD buffer overflow attempt (more info ...)attempted-user  2009-3033  37092    
17057SPECIFIC-THREATS Novell Client NetIdentity Agent remote arbitrary pointer dereference code execution attempt (more info ...)attempted-admin  2009-1350  34400    
17620SPECIFIC-THREATS Products Discovery Service Buffer Overflow (more info ...)attempted-user  2006-5143  20364    
17621SPECIFIC-THREATS Products Discovery Service Buffer Overflow (more info ...)attempted-user  2006-5143  20364    


# of warning rules in this group: 53

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
218BACKDOOR MISC Solaris 2.5 attempt (more info ...)attempted-user    
300EXPLOIT nlps x86 Solaris overflow (more info ...)attempted-admin  2319  
304EXPLOIT SCO calserver overflow (more info ...)attempted-admin 2000-0306 2353  
640SHELLCODE AIX NOOP (more info ...)shellcode-detect    
641SHELLCODE Digital UNIX NOOP (more info ...)shellcode-detect    
1132WEB-MISC Netscape Unixware overflow (more info ...)attempted-recon 1999-0744 908  
1165WEB-MISC Novell Groupwise gwweb.exe access (more info ...)attempted-recon 1999-1006 879 10877 
1209WEB-MISC .nsconfig access (more info ...)attempted-recon    URL
1250WEB-MISC Cisco IOS HTTP configuration attempt (more info ...)web-application-attack 2001-0537 2936 10700 
1499WEB-MISC SiteScope Service access (more info ...)web-application-activity   10778 
1544WEB-MISC Cisco Catalyst command execution attempt (more info ...)web-application-activity 2000-0945 1846 10545 
1545DOS Cisco attempt (more info ...)web-application-attack    
1614WEB-MISC Novell Groupwise gwweb.exe attempt (more info ...)attempted-recon 1999-1006 879 10877 
1814WEB-MISC CISCO VoIP DOS ATTEMPT (more info ...)misc-attack 2002-0882 4794 11013 
1858WEB-MISC CISCO PIX Firewall Manager directory traversal attempt (more info ...)misc-attack 1999-0158 691 10819 
3467WEB-MISC CISCO VoIP Portinformation access (more info ...)web-application-activity 2002-0882 4798  
3527EXPLOIT Solaris LPD overflow attempt (more info ...)attempted-admin  3274  
4127EXPLOIT Novell eDirectory Server iMonitor overflow attempt (more info ...)attempted-admin 2005-2551 14548  
4129EXPLOIT Novell ZenWorks Remote Management Agent large login packet DoS attempt (more info ...)attempted-dos 2005-1543 13678  
4130EXPLOIT Novell ZenWorks Remote Management Agent buffer overflow Attempt (more info ...)attempted-dos 2005-1543 13678  
4144EXPLOIT lpd Solaris control file upload attempt (more info ...)misc-attack    
6414WEB-MISC Novell GroupWise Messenger Accept-Language header buffer overflow attempt (more info ...)attempted-admin 2006-0992 17503  
6507WEB-MISC novell edirectory imonitor overflow attempt (more info ...)attempted-admin 2006-2496 18026  
8081SCAN UPnP service discover attempt (more info ...)network-scan    
8085WEB-MISC HP Openview NNM connectedNodes.ovpl port 3443 Unix command execution attempt (more info ...)web-application-attack 2005-2773 14662  
8086WEB-MISC HP Openview NNM cdpView.ovpl port 3443 Unix command execution attempt (more info ...)web-application-attack 2005-2773 14662  
8087WEB-MISC HP Openview NNM freeIPaddrs.ovpl port 3443 Unix command execution attempt (more info ...)web-application-attack 2005-2773 14662  
8088WEB-MISC HP Openview NNM connectedNodes.ovpl Unix command execution attempt (more info ...)web-application-attack 2005-2773 14662  
8089WEB-MISC HP Openview NNM cdpView.ovpl Unix command execution attempt (more info ...)web-application-attack 2005-2773 14662  
8711WEB-MISC Novell eDirectory HTTP redirection buffer overflow attempt (more info ...)attempted-admin 2006-5478 20655  
9633EXPLOIT Computer Associates Product Discovery Service type 9B remote buffer overflow attempt TCP (more info ...)attempted-admin 2006-6379 21502  
9634EXPLOIT Computer Associates Product Discovery Service type 9C remote buffer overflow attempt TCP (more info ...)attempted-admin 2006-6379 21502  
9636EXPLOIT Computer Associates Product Discovery Service type 9C remote buffer overflow attempt UDP (more info ...)attempted-admin 2006-6379 21502  
10418EXPLOIT lpd Solaris unlink file attempt (more info ...)misc-attack 2005-4797 14510  
11670EXPLOIT Symantec Discovery logging buffer overflow (more info ...)attempted-admin 2007-1173 24002  
12080EXPLOIT Sun Solaris printd arbitrary file deletion vulnerability (more info ...)misc-attack 2005-4797 14510  
12223EXPLOIT Novell WebAdmin long user name (more info ...)attempted-admin 2007-1350 22857  
12299EXPLOIT Cisco NHRP incorrect packet size (more info ...)attempted-user 2007-4286 25238  
12300EXPLOIT Cisco NHRP incorrect packet size (more info ...)attempted-user 2007-4286 25238  
13510EXPLOIT Novell eDirectory EventsRequest heap overflow attempt (more info ...)attempted-admin 2006-4509 20663  URL
13511EXPLOIT Novell eDirectory EventsRequest invalid event count exploit attempt (more info ...)attempted-admin 2006-4510 20663  URL
13620SPECIFIC-THREATS CA Brightstor discovery service alternate buffer overflow attempt (more info ...)attempted-admin 2005-0260   
14990WEB-MISC Novell eDirectory SOAP Accept Charset header overflow attempt (more info ...)attempted-user 2008-4479   
15960SPECIFIC-THREATS Novell eDirectory MS-DOS device name DoS attempt (more info ...)attempted-dos 2005-1729   
15973EXPLOIT Novell eDirectory LDAP null search parameter buffer overflow attempt (more info ...)attempted-admin 2008-1809 30175  URL
16014DOS Novell eDirectory HTTP headers denial of service attempt (more info ...)attempted-dos 2008-0927 28757  
16950PHISHING-SPAM tabscotti71i.ru known spam email attempt (more info ...)policy-violation    
17027PHISHING-SPAM scoreenjoy.ru known spam email attempt (more info ...)policy-violation    
17287WEB-MISC Cisco IOS HTTP service HTML injection attempt (more info ...)attempted-dos 2005-3921 15602  
17353EXPLOIT Sun Solaris printd Daemon Arbitrary File Deletion attempt (more info ...)misc-attack 2005-4797 14510  
17433EXPLOIT Sun Solaris DHCP Client Arbitrary Code Execution attempt (more info ...)attempted-user 2005-2870 14687  
17504EXPLOIT Novell ZENworks Asset Management buffer overflow attempt (more info ...)attempted-admin 2006-6299 21395  
17713EXPLOIT Novell NetMail NMAP STOR buffer overflow attempt (more info ...)attempted-admin 2006-6424 21725  

 goto Top

Group: Server

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP / Common

# of attack rules in this group: 22

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
13258WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX clsid access (more info ...)attempted-user  2010-0919  26972    
13259WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX clsid unicode access (more info ...)attempted-user  2010-0919  26972    
13260WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX function call access (more info ...)attempted-user  2010-0919  26972    
13261WEB-ACTIVEX IBM Lotus Domino Web Access 6 ActiveX function call unicode access (more info ...)attempted-user  2010-0919  26972    
13262WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX clsid access (more info ...)attempted-user  2010-0919  26972    
13263WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX clsid unicode access (more info ...)attempted-user  2010-0919  26972    
13264WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX function call access (more info ...)attempted-user  2010-0919  26972    
13265WEB-ACTIVEX IBM Lotus Domino Web Access 7 ActiveX function call unicode access (more info ...)attempted-user  2010-0919  26972    
15956ORACLE http Server mod_access restriction bypass attempt (more info ...)attempted-user  2005-1383  13418    
16017SPECIFIC-THREATS IBM Lotus Domino LDAP server invalid DN message buffer overflow attempt (more info ...)attempted-user  2007-1739  23174    
16052WEB-CLIENT Novell iManager Tomcat http post handling DoS attempt (more info ...)attempted-dos  2006-4517  20841    
16060SPECIFIC-THREATS IBM Lotus Domino LDAP server memory exception attempt (more info ...)attempted-dos  2006-0580  16523    
16216SPECIFIC-THREATS IBM Tivoli Provisioning Manager for OS deployment HTTP server buffer attempt (more info ...)attempted-user  2008-0401  27387    
16671SPECIFIC-THREATS IBM Lotus Domino Web Access ActiveX exploit attempt (more info ...)attempted-user  2010-0919  26972    
17391WEB-MISC Tomcat UNIX platform directory traversal (more info ...)web-application-attack  2007-0450  22960    URL
17466SPECIFIC-THREATS IBM Lotus Domino Web Access 7 ActiveX exploit attempt (more info ...)attempted-user  2010-0919  26972    
17498WEB-MISC Tomcat UNIX platform directory traversal (more info ...)web-application-attack  2007-0450  22960    URL
17499WEB-MISC Tomcat UNIX platform directory traversal (more info ...)web-application-attack  2007-0450  22960    URL
17500WEB-MISC Tomcat UNIX platform directory traversal (more info ...)web-application-attack  2007-0450  22960    URL
17501WEB-MISC Tomcat UNIX platform directory traversal (more info ...)web-application-attack  2007-0450  22960    URL
17502WEB-MISC Tomcat UNIX platform directory traversal (more info ...)web-application-attack  2007-0450  22960    URL
17545WEB-ACTIVEX Lotus Domino Web Access ActiveX Controls buffer overflow attempt (more info ...)attempted-user  2010-0919  38457    URL


# of warning rules in this group: 70

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
903WEB-COLDFUSION cfcache.map access (more info ...)attempted-recon 2000-0057 917  
904WEB-COLDFUSION exampleapp application.cfm (more info ...)attempted-recon 2001-0535 1021  
905WEB-COLDFUSION application.cfm access (more info ...)attempted-recon 2001-0535 1021  
906WEB-COLDFUSION getfile.cfm access (more info ...)attempted-recon 2001-0535 229  
907WEB-COLDFUSION addcontent.cfm access (more info ...)attempted-recon 2001-0535   
908WEB-COLDFUSION administrator access (more info ...)attempted-recon 2000-0538 1314 10581 
909WEB-COLDFUSION datasource username attempt (more info ...)web-application-attack 1999-0760 550  
910WEB-COLDFUSION fileexists.cfm access (more info ...)attempted-recon 1999-0760 550  
911WEB-COLDFUSION exprcalc access (more info ...)attempted-recon 1999-0760 550  
912WEB-COLDFUSION parks access (more info ...)attempted-recon 1999-0760 550  
913WEB-COLDFUSION cfappman access (more info ...)attempted-recon 1999-0760 550  
914WEB-COLDFUSION beaninfo access (more info ...)attempted-recon 1999-0760 550  
915WEB-COLDFUSION evaluate.cfm access (more info ...)attempted-recon 1999-0760 550  
916WEB-COLDFUSION getodbcdsn access (more info ...)web-application-attack 1999-0760 550  
917WEB-COLDFUSION db connections flush attempt (more info ...)web-application-attack 1999-0760 550  
918WEB-COLDFUSION expeval access (more info ...)attempted-user 1999-0760 550  
919WEB-COLDFUSION datasource passwordattempt (more info ...)web-application-attack 1999-0760 550  
920WEB-COLDFUSION datasource attempt (more info ...)web-application-attack 1999-0760 550  
921WEB-COLDFUSION admin encrypt attempt (more info ...)web-application-attack 1999-0760 550  
922WEB-COLDFUSION displayfile access (more info ...)web-application-attack 1999-0760 550  
923WEB-COLDFUSION getodbcin attempt (more info ...)web-application-attack 1999-0760 550  
924WEB-COLDFUSION admin decrypt attempt (more info ...)web-application-attack 1999-0760 550  
925WEB-COLDFUSION mainframeset access (more info ...)attempted-recon 1999-0760 550  
926WEB-COLDFUSION set odbc ini attempt (more info ...)web-application-attack 1999-0760 550  
927WEB-COLDFUSION settings refresh attempt (more info ...)web-application-attack 1999-0760 550  
928WEB-COLDFUSION exampleapp access (more info ...)attempted-recon 2001-0535   
929WEB-COLDFUSION CFUSION_VERIFYMAIL access (more info ...)attempted-user 1999-0760 550  
930WEB-COLDFUSION snippets attempt (more info ...)attempted-recon 1999-0760 550  
931WEB-COLDFUSION cfmlsyntaxcheck.cfm access (more info ...)attempted-recon 1999-0760 550  
932WEB-COLDFUSION application.cfm access (more info ...)attempted-recon 2000-0189 550  
933WEB-COLDFUSION onrequestend.cfm access (more info ...)attempted-recon 2000-0189 550  
935WEB-COLDFUSION startstop DOS access (more info ...)web-application-attack 1999-0756 247  
936WEB-COLDFUSION gettempdirectory.cfm access (more info ...)attempted-recon 1999-0760 550  
1056WEB-MISC Tomcat view source attempt (more info ...)web-application-attack 2001-0590 2527  
1072WEB-MISC Lotus Domino directory traversal (more info ...)web-application-attack 2001-0009 2173 12248 
1108WEB-MISC Tomcat server snoop access (more info ...)attempted-recon 2000-0760 1532 10478 
1111WEB-MISC Tomcat server exploit access (more info ...)attempted-recon 2000-0672 1548 10477 
1115WEB-MISC ICQ webserver DOS (more info ...)attempted-dos 1999-0474   URL
1150WEB-MISC Domino catalog.nsf access (more info ...)attempted-recon   10629 
1151WEB-MISC Domino domcfg.nsf access (more info ...)attempted-recon   10629 
1152WEB-MISC Domino domlog.nsf access (more info ...)attempted-recon   10629 
1153WEB-MISC Domino log.nsf access (more info ...)attempted-recon   10629 
1154WEB-MISC Domino names.nsf access (more info ...)attempted-recon   10629 
1540WEB-COLDFUSION ?Mode=debug attempt (more info ...)web-application-activity 1999-0760  10797 
1575WEB-MISC Domino mab.nsf access (more info ...)attempted-recon  4022 10953 
1576WEB-MISC Domino cersvr.nsf access (more info ...)attempted-recon   10629 
1577WEB-MISC Domino setup.nsf access (more info ...)attempted-recon   10629 
1578WEB-MISC Domino statrep.nsf access (more info ...)attempted-recon   10629 
1579WEB-MISC Domino webadmin.nsf access (more info ...)attempted-recon  9901 10629 
1580WEB-MISC Domino events4.nsf access (more info ...)attempted-recon   10629 
1581WEB-MISC Domino ntsync4.nsf access (more info ...)attempted-recon   10629 
1582WEB-MISC Domino collect4.nsf access (more info ...)attempted-recon   10629 
1583WEB-MISC Domino mailw46.nsf access (more info ...)attempted-recon   10629 
1584WEB-MISC Domino bookmark.nsf access (more info ...)attempted-recon   10629 
1585WEB-MISC Domino agentrunner.nsf access (more info ...)attempted-recon   10629 
1586WEB-MISC Domino mail.box access (more info ...)attempted-recon  881 10629 
1659WEB-COLDFUSION sendmail.cfm access (more info ...)attempted-recon 2001-0535   
1827WEB-MISC Tomcat servlet mapping cross site scripting attempt (more info ...)web-application-attack 2002-0682 5193 11041 
1829WEB-MISC Tomcat TroubleShooter servlet access (more info ...)web-application-activity  4575 11046 
1830WEB-MISC Tomcat SnoopServlet servlet access (more info ...)web-application-activity  4575 11046 
2061WEB-MISC Tomcat null byte directory listing attempt (more info ...)web-application-attack 2003-0042 6721 11438 
8485WEB-COLDFUSION CFNEWINTERNALADMINSECURITY access (more info ...)attempted-user 1999-0760 550  
8486WEB-COLDFUSION CFNEWINTERNALREGISTRY access (more info ...)attempted-user 1999-0760 550  
8487WEB-COLDFUSION CFADMIN_REGISTRY_SET access (more info ...)attempted-user 1999-0760 550  
8488WEB-COLDFUSION CFADMIN_REGISTRY_GET access (more info ...)attempted-user 1999-0760 550  
8489WEB-COLDFUSION CFADMIN_REGISTRY_DELETE access (more info ...)attempted-user 1999-0760 550  
8490WEB-COLDFUSION viewexample.cfm access (more info ...)attempted-recon 1999-0760 550  
8491WEB-COLDFUSION eval.cfm access (more info ...)attempted-recon 1999-0760 550  
8492WEB-COLDFUSION openfile.cfm access (more info ...)attempted-recon 1999-0760 550  
8493WEB-COLDFUSION sourcewindow.cfm access (more info ...)attempted-recon 1999-0922 550  

 goto Top

Group: Server / HTTP / Apache

# of attack rules in this group: 10

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
14771WEB-MISC BEA WebLogic Apache Oracle connector Transfer-Encoding buffer overflow (more info ...)attempted-admin  2008-4008      URL
16198SPECIFIC-THREATS Apache mod_auth_pgsql module logging facility format string exploit attempt (more info ...)attempted-user  2005-3656  16153    
16479SPECIFIC-THREATS Apache mod_isapi dangling pointer exploit attempt - public shell code (more info ...)attempted-admin  2010-0425  38494    
16480SPECIFIC-THREATS Apache mod_isapi dangling pointer exploit attempt (more info ...)attempted-admin  2010-0425  38494    
16611WEB-MISC Apache 413 error HTTP request method cross-site scripting attack (more info ...)web-application-attack  2007-6203  26663    
17156EXPLOIT HP Performance Manager Apache Tomcat policy bypass attempt (more info ...)attempted-admin  2009-3548  36954    
17387WEB-MISC Apache Tomcat allowLinking URIencoding directory traversal attempt (more info ...)suspicious-filename-detect  2008-2938  30633    
17533WEB-MISC Apache Struts Information Disclosure Attempt (more info ...)attempted-recon  2008-6505  32104    
17656WEB-MISC Apache HTTP server mod_rewrite module LDAP scheme handling buffer overflow attempt (more info ...)attempted-user  2006-3747      
18096WEB-MISC Apache Tomcat username enumeration attempt (more info ...)attempted-recon  2009-0580  35196    


# of warning rules in this group: 18

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1110WEB-MISC apache source.asp file access (more info ...)attempted-recon 2000-0628 1457 10480 
1519WEB-MISC apache ?M=D directory list attempt (more info ...)web-application-activity 2001-0731 3009 10704 
1808WEB-MISC apache chunked encoding memory corruption exploit attempt (more info ...)web-application-activity 2002-0392 5033  
1809WEB-MISC Apache Chunked-Encoding worm attempt (more info ...)web-application-attack 2002-0392 5033 10932 
11272WEB-MISC Apache newline exploit attempt (more info ...)web-application-attack 2003-0132 7254  
11273WEB-MISC Apache header parsing space saturation denial of service attempt (more info ...)attempted-dos 2004-0942   
11679WEB-MISC Apache mod_rewrite buffer overflow attempt (more info ...)attempted-admin 2006-3747   
12465EXPLOIT Apache APR memory corruption attempt (more info ...)attempted-user 2003-0245 7723  
12591DOS Apache mod_cache denial of service attempt (more info ...)denial-of-service 2007-1863 24649  
12711WEB-MISC Apache Tomcat WebDAV system tag remote file disclosure attempt (more info ...)successful-recon-limited 2007-5461 26070  URL
13302WEB-CLIENT Apache mod_imagemap cross site scripting attempt (more info ...)web-application-attack 2007-5000 26838  
15511SPECIFIC-THREATS Oracle WebLogic Apache Connector buffer overflow attempt (more info ...)attempted-admin 2008-3257 30273  URL
15578SPECIFIC-THREATS Slowloris http DoS tool (more info ...)attempted-dos 2007-0086   
15980WEB-MISC Apache mod_ssl hook functions format string attempt (more info ...)attempted-user 2004-0700 10736  
16021SPECIFIC-THREATS Apache http Server mod_tcl format string attempt (more info ...)attempted-user 2006-4154 20527  
17107SPECIFIC-THREATS Apache Tomcat JK Web Server Connector long URL stack overflow attempt - 1 (more info ...)attempted-admin 2007-0774 22791  
17108SPECIFIC-THREATS Apache Tomcat JK Web Server Connector long URL stack overflow attempt - 2 (more info ...)attempted-admin 2007-0774 22791  
17354SPECIFIC-THREATS Apache Byte-Range Filter denial of service attempt (more info ...)attempted-dos 2005-2728 14660  

 goto Top

Group: Server / HTTP / Microsoft IIS

# of attack rules in this group: 17

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1002WEB-IIS cmd.exe access (more info ...)web-application-attack        
1661WEB-IIS cmd32.exe access (more info ...)web-application-attack        
2091WEB-IIS WEBDAV nessus safe scan attempt (more info ...)attempted-admin  2003-0109  7116  11413  URL
15470WEB-MISC IIS ASP/ASP.NET potentially malicious file upload attempt (more info ...)attempted-user  2009-0080      URL
15974EXPLOIT Microsoft IIS ASP handling buffer overflow (more info ...)web-application-attack  2008-0075  27676    URL
16147SPECIFIC-THREATS Microsoft IIS malformed URL .dll denial of service attempt (more info ...)attempted-dos  2005-4360  15921    URL
16312WEB-IIS ADFS custom header arbitrary code execution attempt (more info ...)attempted-admin  2009-2509      URL
16356WEB-IIS multiple extension code execution attempt (more info ...)web-application-attack  2009-4444      
17103WEB-IIS IIS 5.1 alternate data stream authentication bypass attempt (more info ...)web-application-attack  2010-2731      URL
17254WEB-MISC Microsoft IIS stack exhaustion DoS attempt (more info ...)attempted-dos  2010-1899      URL
17255EXPLOIT Microsoft IIS FastCGI heap overflow attempt (more info ...)attempted-admin  2010-2730      URL
17431EXPLOIT Microsoft IIS SChannel improper certificate verification (more info ...)misc-activity  2009-0085      URL
17525SPECIFIC-THREATS Microsoft IIS 5.0 WebDav Request Directory Security Bypass (more info ...)attempted-admin  2009-1122  35232    
17564WEB-IIS WebDAV Request Directory Security Bypass attempt (more info ...)attempted-admin  2009-1535  34993    
17652WEB-MISC Microsoft IIS source code disclosure attempt (more info ...)misc-attack  2005-2678      URL
17653WEB-MISC Microsoft IIS source code disclosure attempt (more info ...)misc-attack  2005-2678      URL
18243SPECIFIC-THREATS Microsoft Windows 7 IIS7.5 FTPSVC buffer overflow attempt (more info ...)attempted-admin    45542    


# of warning rules in this group: 138

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
971WEB-IIS ISAPI .printer access (more info ...)web-application-activity 2001-0241 2674 10661 URL
973WEB-IIS *.idc attempt (more info ...)web-application-attack 2000-0661 1448  
974WEB-IIS Directory transversal attempt (more info ...)web-application-attack 1999-0229 2218  
975WEB-IIS Alternate Data streams ASP file access attempt (more info ...)web-application-attack 1999-0278 149 10362 URL
977WEB-IIS .cnf access (more info ...)web-application-activity 2002-1717 4078 10575 
978WEB-IIS ASP contents view (more info ...)web-application-attack 2000-0302 1084 10356 URL
979WEB-IIS ASP contents view (more info ...)web-application-attack 2000-0942 1861  URL
980WEB-IIS CGImail.exe access (more info ...)web-application-activity 2000-0726 1623 11721 
984WEB-IIS JET VBA access (more info ...)web-application-activity 1999-0874 307 10116 
985WEB-IIS JET VBA access (more info ...)web-application-activity 1999-0874 286  
986WEB-IIS MSProxy access (more info ...)web-application-activity    URL
987WEB-IIS .htr access (more info ...)web-application-activity 2000-0630 1488 10680 
991WEB-IIS achg.htr access (more info ...)web-application-activity 1999-0407 2110  
992WEB-IIS adctest.asp access (more info ...)web-application-activity    
993WEB-IIS iisadmin access (more info ...)web-application-attack 1999-1538 189 11032 
994WEB-IIS /scripts/iisadmin/default.htm access (more info ...)web-application-attack    
995WEB-IIS ism.dll access (more info ...)web-application-attack 2000-0630 189  
996WEB-IIS anot.htr access (more info ...)web-application-activity 1999-0407 2110  
997WEB-IIS asp-dot attempt (more info ...)web-application-attack  1814 10363 
998WEB-IIS asp-srch attempt (more info ...)web-application-attack    
999WEB-IIS bdir access (more info ...)web-application-activity  2280  
1000WEB-IIS bdir.htr access (more info ...)web-application-activity  2280 10577 
1003WEB-IIS cmd? access (more info ...)web-application-attack    
1004WEB-IIS codebrowser Exair access (more info ...)web-application-activity 1999-0815   
1005WEB-IIS codebrowser SDK access (more info ...)web-application-activity 1999-0736 167  
1007WEB-IIS Form_JScript.asp access (more info ...)web-application-attack 2000-1104 1595 10572 URL
1008WEB-IIS del attempt (more info ...)web-application-attack    
1009WEB-IIS directory listing (more info ...)web-application-attack   10573 
1011WEB-IIS exec-src access (more info ...)web-application-activity    
1012WEB-IIS fpcount attempt (more info ...)web-application-attack 1999-1376 2252  
1013WEB-IIS fpcount access (more info ...)web-application-activity 1999-1376 2252  
1015WEB-IIS getdrvs.exe access (more info ...)web-application-activity    
1016WEB-IIS global.asa access (more info ...)web-application-activity 2000-0778  10991 
1017WEB-IIS idc-srch attempt (more info ...)web-application-attack 1999-0874   
1018WEB-IIS iisadmpwd attempt (more info ...)web-application-attack 1999-0407 2110 10371 
1019WEB-IIS Malformed Hit-Highlighting Argument File Access Attempt (more info ...)web-application-attack 2000-0097 950  URL
1020WEB-IIS isc$data attempt (more info ...)web-application-attack 1999-0874 307 10116 
1021WEB-IIS ism.dll attempt (more info ...)web-application-attack 2000-0457 1193 10680 URL
1022WEB-IIS jet vba access (more info ...)web-application-activity 1999-0874 286  URL
1023WEB-IIS msadcs.dll access (more info ...)web-application-activity 1999-1011 529 10357 URL
1024WEB-IIS newdsn.exe access (more info ...)web-application-activity 1999-0191 1818 10360 
1025WEB-IIS perl access (more info ...)web-application-activity    
1026WEB-IIS perl-browse newline attempt (more info ...)web-application-attack  6833  
1027WEB-IIS perl-browse space attempt (more info ...)web-application-attack  6833  
1028WEB-IIS query.asp access (more info ...)web-application-activity 1999-0449 193  
1029WEB-IIS scripts-browse access (more info ...)web-application-attack   11032 
1030WEB-IIS search97.vts access (more info ...)web-application-activity  162  
1031WEB-IIS /SiteServer/Publishing/viewcode.asp access (more info ...)web-application-activity   10576 
1032WEB-IIS showcode access (more info ...)web-application-activity 1999-0737  10576 URL
1033WEB-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1034WEB-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1035WEB-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1036WEB-IIS viewcode access (more info ...)web-application-activity 1999-0737  10576 URL
1037WEB-IIS showcode.asp access (more info ...)web-application-activity 1999-0736 167 10007 URL
1038WEB-IIS site server config access (more info ...)web-application-activity 1999-1520 256  
1039WEB-IIS srch.htm access (more info ...)web-application-activity    
1040WEB-IIS srchadm access (more info ...)web-application-activity   11032 
1041WEB-IIS uploadn.asp access (more info ...)web-application-activity 1999-0360 1811  
1043WEB-IIS viewcode.asp access (more info ...)web-application-activity 1999-0737  10576 
1044WEB-IIS webhits access (more info ...)web-application-activity 2000-0097 950  
1045WEB-IIS Unauthorized IP Access Attempt (more info ...)web-application-attack    
1046WEB-IIS site/iisamples access (more info ...)web-application-activity   10370 
1075WEB-IIS postinfo.asp access (more info ...)web-application-activity 1999-0360 1811  
1076WEB-IIS repost.asp access (more info ...)web-application-activity   10372 
1242WEB-IIS ISAPI .ida access (more info ...)web-application-activity 2000-0071 1065  
1243WEB-IIS ISAPI .ida attempt (more info ...)web-application-attack 2001-0500 1065  
1244WEB-IIS ISAPI .idq attempt (more info ...)web-application-attack 2001-0500 968 10115 
1245WEB-IIS ISAPI .idq access (more info ...)web-application-activity 2000-0071 1065  
1256WEB-IIS CodeRed v2 root.exe access (more info ...)web-application-attack    URL
1283WEB-IIS outlook web dos (more info ...)web-application-attack  3223  
1285WEB-IIS msdac access (more info ...)web-application-activity   11032 
1286WEB-IIS _mem_bin access (more info ...)web-application-activity   11032 
1380WEB-IIS Form_VBScript.asp access (more info ...)web-application-attack 2000-1104 1595 10572 URL
1400WEB-IIS /scripts/samples/ access (more info ...)web-application-attack   10370 
1401WEB-IIS /msadc/samples/ access (more info ...)web-application-attack 1999-0736 167 1007 
1402WEB-IIS iissamples access (more info ...)web-application-attack   11032 
1485WEB-IIS mkilog.exe access (more info ...)web-application-activity   10359 URL
1486WEB-IIS ctss.idc access (more info ...)web-application-activity   10359 
1487WEB-IIS /iisadmpwd/aexp2.htr access (more info ...)web-application-activity 2002-0421 4236 10371 
1567WEB-IIS /exchange/root.asp attempt (more info ...)web-application-attack 2001-0660 3301 10781 URL
1568WEB-IIS /exchange/root.asp access (more info ...)web-application-activity 2001-0660 3301 10781 
1595WEB-IIS htimage.exe access (more info ...)web-application-activity 2000-0256 964 10376 
1618WEB-IIS .asp chunked Transfer-Encoding (more info ...)web-application-attack 2002-0079 4485 10932 
1626WEB-IIS /StoreCSVS/InstantOrder.asmx request (more info ...)web-application-activity    
1660WEB-IIS trace.axd access (more info ...)web-application-activity   10993 
1725WEB-IIS +.htr code fragment attempt (more info ...)web-application-attack 2000-0630 1488 10680 URL
1726WEB-IIS doctodep.btr access (more info ...)web-application-activity    
1750WEB-IIS users.xml access (more info ...)web-application-activity    
1753WEB-IIS as_web.exe access (more info ...)web-application-activity  4670  
1754WEB-IIS as_web4.exe access (more info ...)web-application-activity  4670  
1756WEB-IIS NewsPro administration authentication attempt (more info ...)web-application-activity 2002-1734 4672  
1772WEB-IIS pbserver access (more info ...)web-application-activity 2000-1089   URL
1802WEB-IIS .asa HTTP header buffer overflow attempt (more info ...)web-application-attack 2002-0150 4476 10936 URL
1803WEB-IIS .cer HTTP header buffer overflow attempt (more info ...)web-application-attack 2002-0150 4476 10936 URL
1804WEB-IIS .cdx HTTP header buffer overflow attempt (more info ...)web-application-attack 2002-0150 4476 10936 URL
1806WEB-IIS .htr chunked Transfer-Encoding (more info ...)web-application-attack 2002-0364 5003 11028 
1817WEB-IIS MS Site Server default login attempt (more info ...)web-application-attack   11018 
1818WEB-IIS MS Site Server admin attempt (more info ...)web-application-attack   11018 
1970WEB-IIS MDAC Content-Type overflow attempt (more info ...)web-application-attack 2002-1142 6214 11161 URL
2090WEB-IIS WEBDAV exploit attempt (more info ...)attempted-admin 2003-0109 7716 11413 URL
2117WEB-IIS Battleaxe Forum login.asp access (more info ...)web-application-activity 2003-0215 7416 11548 
2129WEB-IIS nsiislog.dll access (more info ...)web-application-activity 2003-0349 8035 11664 URL
2130WEB-IIS IISProtect siteadmin.asp access (more info ...)web-application-activity 2003-0377 7675 11662 
2131WEB-IIS IISProtect access (more info ...)web-application-activity   11661 
2132WEB-IIS Synchrologic Email Accelerator userid list access attempt (more info ...)web-application-activity   11657 
2133WEB-IIS MS BizTalk server access (more info ...)web-application-activity 2003-0118 7470 11638 URL
2157WEB-IIS IISProtect globaladmin.asp access (more info ...)web-application-activity   11661 
2247WEB-IIS UploadScript11.asp access (more info ...)web-application-activity 2001-0938 3608 11746 
2248WEB-IIS DirectoryListing.asp access (more info ...)web-application-activity 2001-0938   
2249WEB-IIS /pcadmin/login.asp access (more info ...)web-application-activity  8103 11785 
2321WEB-IIS foxweb.exe access (more info ...)web-application-activity   11939 
2322WEB-IIS foxweb.dll access (more info ...)web-application-activity   11939 
2324WEB-IIS VP-ASP shopsearch.asp access (more info ...)web-application-activity  9134 11942 
2325WEB-IIS VP-ASP ShopDisplayProducts.asp access (more info ...)web-application-activity  9134 11942 
2326WEB-IIS sgdynamo.exe access (more info ...)web-application-activity 2002-0375 4720 11955 
2386WEB-IIS NTLM ASN1 vulnerability scan attempt (more info ...)attempted-dos 2003-0818 9635 12065 URL
2571WEB-IIS SmarterTools SmarterMail frmGetAttachment.aspx access (more info ...)web-application-activity  9805  
2572WEB-IIS SmarterTools SmarterMail login.aspx buffer overflow attempt (more info ...)web-application-attack  9805  
2573WEB-IIS SmarterTools SmarterMail frmCompose.asp access (more info ...)web-application-activity  9805  
2667WEB-IIS ping.asp access (more info ...)web-application-activity   10968 
3087WEB-IIS w3who.dll buffer overflow attempt (more info ...)attempted-admin 2004-1134 11820  
3150WEB-IIS SQLXML content type overflow (more info ...)attempted-admin 2002-0186 5004 11304 URL
3193WEB-IIS .cmd executable file parsing attack (more info ...)web-application-attack 2000-0886 1912  
3194WEB-IIS .bat executable file parsing attack (more info ...)web-application-attack 2000-0886 1912  
3201WEB-IIS httpodbc.dll access - nimda (more info ...)web-application-activity 2001-0333 2708  
5695WEB-IIS web agent redirect overflow attempt (more info ...)web-application-attack 2005-1471 13524  
7027WEB-IIS frontpage server extensions 2002 cross site scripting attempt (more info ...)attempted-user 2006-0015 17452  URL
7028WEB-IIS frontpage server extensions 2002 cross site scripting attempt (more info ...)attempted-user 2006-0015 17452  URL
7029WEB-IIS frontpage server extensions 2002 cross site scripting attempt (more info ...)attempted-user 2006-0015 17452  URL
8349WEB-IIS Indexing Service ciRestriction cross-site scripting attempt (more info ...)misc-attack 2006-0032 19927  URL
8700WEB-IIS ASP.NET 2.0 cross-site scripting attempt (more info ...)attempted-user 2006-3436 20337  URL
11191WEB-IIS Microsoft Content Management Server memory corruption (more info ...)attempted-user 2007-0938 22861  URL
12043DOS Microsoft XML parser IIS WebDAV attack attempt (more info ...)denial-of-service 2003-0718 11384  
12064WEB-IIS w3svc _vti_bin null pointer dereference attempt (more info ...)attempted-dos 2005-4360 15921  URL
12595WEB-IIS malicious ASP file upload attempt (more info ...)attempted-user 2006-0026 18858  URL
13922WEB-IIS Microsoft IIS HTMLEncode Unicode string buffer overflow (more info ...)web-application-attack 2008-0075   URL
17648WEB-IIS source code disclosure attempt (more info ...)attempted-recon  14764  
17705WEB-IIS web agent chunked encoding overflow attempt (more info ...)web-application-attack 2005-1471 13524  

 goto Top

Group: Server / HTTP / Other

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP / Coldfusion

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / HTTP / Frontpage

# of attack rules in this group: 0

# of warning rules in this group: 38

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
937WEB-FRONTPAGE _vti_rpc access (more info ...)web-application-activity 2001-0096 2144 10585 
939WEB-FRONTPAGE posting (more info ...)web-application-activity 2001-0096 2144 10585 URL
940WEB-FRONTPAGE shtml.dll access (more info ...)web-application-activity 2000-0746 1595 11395 URL
941WEB-FRONTPAGE contents.htm access (more info ...)web-application-activity    
942WEB-FRONTPAGE orders.htm access (more info ...)web-application-activity    
943WEB-FRONTPAGE fpsrvadm.exe access (more info ...)web-application-activity    
944WEB-FRONTPAGE fpremadm.exe access (more info ...)web-application-activity    
945WEB-FRONTPAGE fpadmin.htm access (more info ...)web-application-activity    
946WEB-FRONTPAGE fpadmcgi.exe access (more info ...)web-application-activity    
947WEB-FRONTPAGE orders.txt access (more info ...)web-application-activity    
948WEB-FRONTPAGE form_results access (more info ...)web-application-activity 1999-1052   
949WEB-FRONTPAGE registrations.htm access (more info ...)web-application-activity    
950WEB-FRONTPAGE cfgwiz.exe access (more info ...)web-application-activity    
951WEB-FRONTPAGE authors.pwd access (more info ...)web-application-activity 1999-0386 989 10078 
952WEB-FRONTPAGE author.exe access (more info ...)web-application-activity    
953WEB-FRONTPAGE administrators.pwd access (more info ...)web-application-activity  1205  
954WEB-FRONTPAGE form_results.htm access (more info ...)web-application-activity 1999-1052   
955WEB-FRONTPAGE access.cnf access (more info ...)web-application-activity 2002-1717 4078 10575 
956WEB-FRONTPAGE register.txt access (more info ...)web-application-activity    
957WEB-FRONTPAGE registrations.txt access (more info ...)web-application-activity    
958WEB-FRONTPAGE service.cnf access (more info ...)web-application-activity 2002-1717 4078 10575 
959WEB-FRONTPAGE service.pwd (more info ...)web-application-activity  1205  
960WEB-FRONTPAGE service.stp access (more info ...)web-application-activity    
961WEB-FRONTPAGE services.cnf access (more info ...)web-application-activity 2002-1717 4078 10575 
962WEB-FRONTPAGE shtml.exe access (more info ...)web-application-activity 2002-0692 5804 11311 
963WEB-FRONTPAGE svcacl.cnf access (more info ...)web-application-activity 2002-1717 4078 10575 
964WEB-FRONTPAGE users.pwd access (more info ...)web-application-activity    
965WEB-FRONTPAGE writeto.cnf access (more info ...)web-application-activity 2002-1717 4078 10575 
966WEB-FRONTPAGE .... request (more info ...)web-application-attack 2000-0153 989 10142 
967WEB-FRONTPAGE dvwssr.dll access (more info ...)web-application-activity 2000-0260 1109 10369 URL
968WEB-FRONTPAGE register.htm access (more info ...)web-application-activity    
990WEB-FRONTPAGE _vti_inf.html access (more info ...)web-application-activity   11455 
1248WEB-FRONTPAGE rad fp30reg.dll access (more info ...)web-application-activity 2003-0822 2906 10699 URL
1249WEB-FRONTPAGE frontpage rad fp4areg.dll access (more info ...)web-application-activity 2001-0341 2906 10699 
1288WEB-FRONTPAGE /_vti_bin/ access (more info ...)web-application-activity   11032 
6409WEB-FRONTPAGE frontpage server extension long host string overflow attempt (more info ...)attempted-admin 2003-0824 9008  URL
6410WEB-FRONTPAGE frontpage server extension long host string overflow attempt (more info ...)attempted-admin 2003-0824 9008  URL
6411WEB-FRONTPAGE frontpage server extension long host string overflow attempt (more info ...)attempted-admin 2003-0824 9008  URL

 goto Top

Group: Server / HTTP / PHP

# of attack rules in this group: 25

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
5744SPYWARE-PUT Hijacker actualnames runtime detection - online.php request (more info ...)misc-activity        URL
5848SPYWARE-PUT Adware warez_p2p runtime detection - ip.php request (more info ...)misc-activity        URL
6020BACKDOOR dsk lite 1.0 runtime detection - php notification (more info ...)trojan-activity        URL
6042BACKDOOR fear 0.2 runtime detection - php notification (more info ...)trojan-activity        URL
6403WEB-PHP horde help module arbitrary command execution attempt (more info ...)web-application-attack  2006-1491  17292    
7149SPYWARE-PUT Hacker-Tool sars notifier runtime detection - php notification (more info ...)misc-activity        URL
7639BACKDOOR air runtime detection - php notification (more info ...)trojan-activity        URL
9653BACKDOOR apofis 1.0 runtime detection - php notification (more info ...)trojan-activity        URL
10196BACKDOOR Wordpress backdoor feed.php code execution attempt (more info ...)trojan-activity  2007-1277  22797    URL
10197BACKDOOR Wordpress backdoor theme.php code execution attempt (more info ...)trojan-activity  2007-1277  22797    URL
13816SPECIFIC-THREATS Metasploit Framework xmlrpc.php command injection attempt (more info ...)attempted-admin  2005-1921      
13817SPECIFIC-THREATS xmlrpc.php command injection attempt (more info ...)attempted-admin  2005-1921      
13818SPECIFIC-THREATS alternate xmlrpc.php command injection attempt (more info ...)attempted-admin  2005-1921      
14610WEB-PHP Joomla invalid token administrative password reset attempt (more info ...)attempted-admin  2008-3681  30667    URL
15257ORACLE Secure Backup common.php variable based command injection attempt (more info ...)attempted-admin  2008-4006      
15258ORACLE Secure Backup login.php variable based command injection attempt (more info ...)attempted-admin  2008-5449      
15424WEB-PHP phpBB mod shoutbox sql injection attempt (more info ...)web-application-attack  2008-6301  32123    
15425WEB-PHP phpBB mod tag board sql injection attempt (more info ...)web-application-attack  2008-6314  32701    
15432WEB-PHP wordpress cat parameter arbitrary file execution attempt (more info ...)web-application-attack  2008-4769  28845    
15977SPECIFIC-THREATS PHP strip_tags bypass vulnerability exploit attempt (more info ...)attempted-user  2004-0595  10724    
16190ORACLE Oracle Secure Backup Administration server property_box.php command injection attempt (more info ...)attempted-admin  2009-1978  35678    
16678WEB-PHP Tandberg VCS local file disclosure attempt (more info ...)web-application-attack  2009-4511      URL
16924BLACKLIST URI request for known malicious URI - /inst.php?fff= (more info ...)trojan-activity        URL
17597WEB-PHP TikiWiki jhot.php script file upload attempt (more info ...)attempted-user    19819    URL
17638Oracle Secure Backup Administration Server login.php Cookies Command Injection attempt (more info ...)attempted-admin  2008-4006  33177    


# of warning rules in this group: 165

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
824WEB-CGI php.cgi access (more info ...)attempted-recon 1999-0238 712 10178 
1085WEB-PHP strings overflow (more info ...)web-application-attack  802  
1086WEB-PHP strings overflow (more info ...)web-application-attack 2000-0967 1786  
1134WEB-PHP Phorum admin access (more info ...)attempted-recon  2271  
1137WEB-PHP Phorum authentication access (more info ...)attempted-recon  2274  
1161WEB-PHP piranha passwd.php3 access (more info ...)attempted-recon 2000-0322 1149  
1178WEB-PHP Phorum read access (more info ...)attempted-recon    
1179WEB-PHP Phorum violation access (more info ...)attempted-recon  2272  
1197WEB-PHP Phorum code access (more info ...)attempted-recon    
1254WEB-PHP PHPLIB remote command attempt (more info ...)attempted-user 2001-1370 3079 14910 
1255WEB-PHP PHPLIB remote command attempt (more info ...)attempted-user 2001-1370 3079  
1300WEB-PHP admin.php file upload attempt (more info ...)attempted-admin 2001-1032 3361  
1301WEB-PHP admin.php access (more info ...)attempted-recon 2001-1032 9270  
1399WEB-PHP PHP-Nuke remote file include attempt (more info ...)web-application-attack 2002-0206 3889  
1407WEB-PHP smssend.php access (more info ...)web-application-activity 2002-0220 3982  
1423WEB-PHP content-disposition memchr overflow (more info ...)web-application-attack 2002-0081 4183 10867 
1490WEB-PHP Phorum /support/common.php attempt (more info ...)web-application-attack  1997  
1491WEB-PHP Phorum /support/common.php access (more info ...)web-application-attack  9361  
1736WEB-PHP squirrel mail spell-check arbitrary command attempt (more info ...)web-application-attack  3952  
1737WEB-PHP squirrel mail theme arbitrary command attempt (more info ...)web-application-attack 2002-0516 4385  
1739WEB-PHP DNSTools administrator authentication bypass attempt (more info ...)web-application-attack 2002-0613 4617  
1740WEB-PHP DNSTools authentication bypass attempt (more info ...)web-application-attack 2002-0613 4617  
1741WEB-PHP DNSTools access (more info ...)web-application-activity 2002-0613 4617  
1742WEB-PHP Blahz-DNS dostuff.php modify user attempt (more info ...)web-application-attack 2002-0599 4618  
1743WEB-PHP Blahz-DNS dostuff.php access (more info ...)web-application-activity 2002-0599 4618  
1745WEB-PHP Messagerie supp_membre.php access (more info ...)web-application-activity  4635  
1773WEB-PHP php.exe access (more info ...)web-application-activity    URL
1774WEB-PHP bb_smilies.php access (more info ...)web-application-activity    URL
1815WEB-PHP directory.php arbitrary command attempt (more info ...)misc-attack 2002-0434 4278 11017 
1816WEB-PHP directory.php access (more info ...)misc-attack 2002-0434 4278  
1834WEB-PHP PHP-Wiki cross site scripting attempt (more info ...)web-application-attack 2002-1070 5254  
1967WEB-PHP phpbb quick-reply.php arbitrary command attempt (more info ...)web-application-attack  6173  
1968WEB-PHP phpbb quick-reply.php access (more info ...)web-application-activity  6173  
1999WEB-PHP edit_image.php access (more info ...)web-application-activity 2001-1020 3288 11104 
2000WEB-PHP readmsg.php access (more info ...)web-application-activity 2001-1408  11073 
2074WEB-PHP Mambo uploadimage.php upload php file attempt (more info ...)web-application-attack 2003-1204 6572 16315 
2075WEB-PHP Mambo upload.php upload php file attempt (more info ...)web-application-attack 2003-1204 6572 16315 
2076WEB-PHP Mambo uploadimage.php access (more info ...)web-application-activity 2003-1204 6572 16315 
2078WEB-PHP phpBB privmsg.php access (more info ...)web-application-activity  6634  
2140WEB-PHP p-news.php access (more info ...)web-application-activity   11669 
2141WEB-PHP shoutbox.php directory traversal attempt (more info ...)web-application-attack   11668 
2142WEB-PHP shoutbox.php access (more info ...)web-application-activity   11668 
2143WEB-PHP b2 cafelog gm-2-b2.php remote file include attempt (more info ...)web-application-attack   11667 
2144WEB-PHP b2 cafelog gm-2-b2.php access (more info ...)web-application-activity   11667 
2145WEB-PHP TextPortal admin.php default password admin attempt (more info ...)web-application-activity  7673 11660 
2146WEB-PHP TextPortal admin.php default password 12345 attempt (more info ...)web-application-activity  7673 11660 
2147WEB-PHP BLNews objects.inc.php4 remote file include attempt (more info ...)web-application-attack 2003-0394 7677 11647 
2148WEB-PHP BLNews objects.inc.php4 access (more info ...)web-application-activity 2003-0394 7677 11647 
2149WEB-PHP Turba status.php access (more info ...)web-application-activity   11646 
2150WEB-PHP ttCMS header.php remote file include attempt (more info ...)web-application-attack  7625 11636 
2151WEB-PHP ttCMS header.php access (more info ...)web-application-activity  7625 11636 
2152WEB-PHP test.php access (more info ...)web-application-activity   11617 
2153WEB-PHP autohtml.php directory traversal attempt (more info ...)web-application-attack   11630 
2154WEB-PHP autohtml.php access (more info ...)web-application-activity   11630 
2155WEB-PHP ttforum remote file include attempt (more info ...)web-application-attack  7543 11615 
2226WEB-PHP pmachine remote file include attempt (more info ...)web-application-attack  7919 11739 
2227WEB-PHP forum_details.php access (more info ...)web-application-attack  7933 11760 
2228WEB-PHP phpMyAdmin db_details_importdocsql.php access (more info ...)web-application-attack  7965 11761 
2229WEB-PHP viewtopic.php access (more info ...)web-application-attack 2003-0486 7979 11767 
2279WEB-PHP UpdateClasses.php access (more info ...)web-application-activity  9057  
2282WEB-PHP GlobalFunctions.php access (more info ...)web-application-activity  9057  
2283WEB-PHP DatabaseFunctions.php access (more info ...)web-application-activity  9057  
2284WEB-PHP rolis guestbook remote file include attempt (more info ...)web-application-attack  9057  
2285WEB-PHP rolis guestbook access (more info ...)web-application-activity  9057  
2287WEB-PHP Advanced Poll admin_comment.php access (more info ...)web-application-activity  8890 11487 
2288WEB-PHP Advanced Poll admin_edit.php access (more info ...)web-application-activity  8890 11487 
2289WEB-PHP Advanced Poll admin_embed.php access (more info ...)web-application-activity  8890 11487 
2290WEB-PHP Advanced Poll admin_help.php access (more info ...)web-application-activity  8890 11487 
2291WEB-PHP Advanced Poll admin_license.php access (more info ...)web-application-activity  8890 11487 
2292WEB-PHP Advanced Poll admin_logout.php access (more info ...)web-application-activity  8890 11487 
2293WEB-PHP Advanced Poll admin_password.php access (more info ...)web-application-activity  8890 11487 
2294WEB-PHP Advanced Poll admin_preview.php access (more info ...)web-application-activity  8890 11487 
2295WEB-PHP Advanced Poll admin_settings.php access (more info ...)web-application-activity  8890 11487 
2296WEB-PHP Advanced Poll admin_stats.php access (more info ...)web-application-activity  8890 11487 
2297WEB-PHP Advanced Poll admin_templates_misc.php access (more info ...)web-application-activity  8890 11487 
2298WEB-PHP Advanced Poll admin_templates.php access (more info ...)web-application-activity  8890 11487 
2299WEB-PHP Advanced Poll admin_tpl_misc_new.php access (more info ...)web-application-activity  8890 11487 
2300WEB-PHP Advanced Poll admin_tpl_new.php access (more info ...)web-application-activity  8890 11487 
2301WEB-PHP Advanced Poll booth.php access (more info ...)web-application-activity  8890 11487 
2302WEB-PHP Advanced Poll poll_ssi.php access (more info ...)web-application-activity  8890 11487 
2303WEB-PHP Advanced Poll popup.php access (more info ...)web-application-activity  8890 11487 
2304WEB-PHP files.inc.php access (more info ...)web-application-activity  8910  
2305WEB-PHP chatbox.php access (more info ...)web-application-activity  8930  
2306WEB-PHP gallery remote file include attempt (more info ...)web-application-attack  8814 11876 
2307WEB-PHP PayPal Storefront remote file include attempt (more info ...)web-application-attack  8791 11873 
2328WEB-PHP authentication_index.php access (more info ...)web-application-activity 2004-0032  11982 
2331WEB-PHP MatrikzGB privilege escalation attempt (more info ...)web-application-activity  8430  
2341WEB-PHP DCP-Portal remote file include editor script attempt (more info ...)web-application-attack  6525  
2342WEB-PHP DCP-Portal remote file include lib script attempt (more info ...)web-application-attack  6525  
2345WEB-PHP PhpGedView search.php access (more info ...)web-application-activity 2004-0032 9369  
2346WEB-PHP myPHPNuke chatheader.php access (more info ...)web-application-activity  6544  
2353WEB-PHP IdeaBox cord.php file include (more info ...)web-application-activity  7488  
2354WEB-PHP IdeaBox notification.php file include (more info ...)web-application-activity  7488  
2355WEB-PHP Invision Board emailer.php file include (more info ...)web-application-activity  7204  
2356WEB-PHP WebChat db_mysql.php file include (more info ...)web-application-attack  7000  
2357WEB-PHP WebChat english.php file include (more info ...)web-application-attack  7000  
2358WEB-PHP Typo3 translations.php file include (more info ...)web-application-attack  6984  
2359WEB-PHP Invision Board ipchat.php file include (more info ...)web-application-attack  6976  
2360WEB-PHP myphpPagetool pt_config.inc file include (more info ...)web-application-attack  6744  
2361WEB-PHP news.php file include (more info ...)web-application-attack  6674  
2362WEB-PHP YaBB SE packages.php file include (more info ...)web-application-attack  6663  
2363WEB-PHP Cyboards default_header.php access (more info ...)web-application-activity  6597  
2364WEB-PHP Cyboards options_form.php access (more info ...)web-application-activity  6597  
2365WEB-PHP newsPHP Language file include attempt (more info ...)web-application-activity  8488  
2366WEB-PHP PhpGedView PGV authentication_index.php base directory manipulation attempt (more info ...)web-application-attack 2004-0030 9368  
2367WEB-PHP PhpGedView PGV functions.php base directory manipulation attempt (more info ...)web-application-attack 2004-0030 9368  
2368WEB-PHP PhpGedView PGV config_gedcom.php base directory manipulation attempt (more info ...)web-application-attack 2004-0030 9368  
2372WEB-PHP Photopost PHP Pro showphoto.php access (more info ...)web-application-activity  9557  
2393WEB-PHP /_admin access (more info ...)web-application-activity  9537 12032 
2398WEB-PHP WAnewsletter newsletter.php file include attempt (more info ...)web-application-attack  6965  
2399WEB-PHP WAnewsletter db_type.php access (more info ...)web-application-activity  6964  
2405WEB-PHP phptest.php access (more info ...)web-application-activity  9737  
2410WEB-PHP IGeneric Free Shopping Cart page.php access (more info ...)web-application-activity  9773  
2566WEB-PHP PHPBB viewforum.php access (more info ...)web-application-activity  9866 12093 
2575WEB-PHP Opt-X header.php remote file include attempt (more info ...)web-application-attack  9732  
2588WEB-PHP TUTOS path disclosure attempt (more info ...)web-application-activity  10129  URL
2654WEB-PHP PHPNuke Forum viewtopic SQL insertion attempt (more info ...)web-application-attack  7193  
2926WEB-PHP PhpGedView PGV base directory manipulation (more info ...)web-application-attack  9368  
3544WEB-MISC TrackerCam ComGetLogFile.php3 directory traversal attempt (more info ...)web-application-attack 2005-0481 12592 17160 
3545WEB-MISC TrackerCam ComGetLogFile.php3 log information disclosure (more info ...)web-application-activity 2005-0481 12592 17160 
3547WEB-MISC TrackerCam overly long php parameter overflow attempt (more info ...)web-application-attack 2005-0481 12592  
3690WEB-CGI Nucleus CMS action.php itemid SQL injection (more info ...)web-application-activity 2004-2056 10798 14194 
3827WEB-PHP xmlrpc.php post attempt (more info ...)web-application-attack 2005-1921 14088  
4650WEB-MISC cacti graph_image.php access (more info ...)web-application-activity  14042  
5709WEB-PHP file upload directory traversal (more info ...)misc-attack    URL
8708WEB-PHP Wordpress cache_lastpostdate code injection attempt (more info ...)attempted-admin 2005-2612 14533  
8712WEB-PHP cacti graph_image arbitrary command execution attempt (more info ...)web-application-attack 2005-1524 14129  
8713WEB-PHP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
8714WEB-PHP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
8715WEB-PHP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
8716WEB-PHP cacti graph_image SQL injection attempt (more info ...)web-application-attack 2005-2148 14129  
11664WEB-PHP sphpblog password.txt access attempt (more info ...)attempted-user 2005-2733 14667  
11665WEB-PHP sphpblog install03_cgi access attempt (more info ...)attempted-user 2005-2733 14667  
11666WEB-PHP sphpblog upload_img_cgi access attempt (more info ...)attempted-user 2005-2733 14667  
11667WEB-PHP sphpblog arbitrary file delete attempt (more info ...)attempted-user 2005-2733 14667  
11668WEB-PHP vbulletin php code injection (more info ...)attempted-user 2005-0511   URL
12221WEB-PHP file upload GLOBAL variable overwrite attempt (more info ...)web-application-attack 2005-3390 15250  
12610WEB-PHP phpBB viewtopic double URL encoding attempt (more info ...)web-application-attack 2004-1315   
16078SPECIFIC-THREATS PHP memory_limit vulnerability exploit attempt (more info ...)attempted-user 2004-0594 10725  
16243BACKDOOR downloader-ash.gen.b runtime detection - 3264.php (more info ...)trojan-activity    URL
16613BACKDOOR c99shell.php command request - cmd (more info ...)policy-violation    URL
16614BACKDOOR c99shell.php command request - search (more info ...)policy-violation    URL
16615BACKDOOR c99shell.php command request - upload (more info ...)policy-violation    URL
16616BACKDOOR c99shell.php command request - about (more info ...)policy-violation    URL
16617BACKDOOR c99shell.php command request - encoder (more info ...)policy-violation    URL
16618BACKDOOR c99shell.php command request - bind (more info ...)policy-violation    URL
16619BACKDOOR c99shell.php command request - ps_aux (more info ...)policy-violation    URL
16620BACKDOOR c99shell.php command request - ftpquickbrute (more info ...)policy-violation    URL
16621BACKDOOR c99shell.php command request - security (more info ...)policy-violation    URL
16622BACKDOOR c99shell.php command request - sql (more info ...)policy-violation    URL
16623BACKDOOR c99shell.php command request - eval (more info ...)policy-violation    URL
16624BACKDOOR c99shell.php command request - feedback (more info ...)policy-violation    URL
16625BACKDOOR c99shell.php command request - selfremove (more info ...)policy-violation    URL
16626BACKDOOR c99shell.php command request - fsbuff (more info ...)policy-violation    URL
16627BACKDOOR c99shell.php command request - ls (more info ...)policy-violation    URL
16628BACKDOOR c99shell.php command request - phpinfo (more info ...)policy-violation    URL
16913BLACKLIST URI request for known malicious URI - count_log/log/boot.php?p= (more info ...)trojan-activity    URL
16923BLACKLIST URI request for known malicious URI - /search.php?username=coolweb07&keywords= (more info ...)trojan-activity    URL
16925BLACKLIST URI request for known malicious URI - /message.php?subid= (more info ...)trojan-activity    URL
16927BLACKLIST URI request for known malicious URI - MGWEB.php?c=TestUrl (more info ...)trojan-activity    URL
16929BLACKLIST URI request for known malicious URI - gate.php?guid= (more info ...)trojan-activity    URL
16931BLACKLIST URI request for known malicious URI - feedbigfoot.php?m= (more info ...)trojan-activity    URL
17898BLACKLIST URI request for known malicious URI - /get2.php?c=VTOXUGUI&d=26606B6739343F216560 (more info ...)trojan-activity    URL
17905BLACKLIST URI request for known malicious URI - 1de49069b6044785e9dfcd4c035cfd0c.php (more info ...)trojan-activity    URL
17906BLACKLIST URI request for known malicious URI - 2x/.*php (more info ...)trojan-activity    URL

 goto Top

Group: Server / HTTP / CGI

# of attack rules in this group: 21

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
5764SPYWARE-PUT Hijacker begin2search runtime detection - fcgi query (more info ...)misc-activity        URL
5945SPYWARE-PUT Adware weirdontheweb runtime detection - track.cgi request (more info ...)misc-activity        URL
6019BACKDOOR dsk lite 1.0 runtime detection - cgi notification (more info ...)trojan-activity        URL
6043BACKDOOR fear 0.2 runtime detection - cgi notification (more info ...)trojan-activity        URL
6059BACKDOOR neurotickat1.3 runtime detection - cgi notification (more info ...)trojan-activity        URL
7076BACKDOOR minimo v0.6 runtime detection - cgi notification (more info ...)trojan-activity        
7148SPYWARE-PUT Hacker-Tool sars notifier runtime detection - cgi notification (more info ...)misc-activity        URL
7524SPYWARE-PUT Hijacker moneybar runtime detection - cgispy counter (more info ...)misc-activity        URL
7540SPYWARE-PUT Hacker-Tool unify runtime detection - cgi notification (more info ...)misc-activity        URL
7722BACKDOOR prorat 1.9 cgi notification detection (more info ...)trojan-activity        URL
7742BACKDOOR nova 1.0 runtime detection - cgi notification client-to-server (more info ...)trojan-activity        URL
7743BACKDOOR nova 1.0 runtime detection - cgi notification server-to-client (more info ...)trojan-activity        URL
13161EXPLOIT HP OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2008-0067  26741    
13591WEB-CGI Trend Micro OfficeScan CGI password decryption buffer overflow attempt (more info ...)web-application-attack  2008-1365  28020    URL
13656WEB-MISC Cisco Secure Access Control Server UCP Application CSuserCGI.exe buffer overflow attempt (more info ...)attempted-admin  2008-0532  28222    URL
15264WEB-CGI Oracle TimesTen In-Memory Database evtdump CGI module format string exploit attempt (more info ...)attempted-admin  2008-5440  33177    
15510WEB-CLIENT Trend Micro OfficeScan Server cgiRecvFile overflow attempt (more info ...)attempted-admin  2008-2437  31139    
16079WEB-CGI uselang code injection (more info ...)web-application-attack  2005-4031  15703    
16674WEB-MISC HP OpenView CGI parameter buffer overflow attempt (more info ...)attempted-user  2010-1555      
17386SPECIFIC-THREATS Lighttpd mod_fastcgi Extension CGI Variable Overwriting Vulnerability attempt (more info ...)attempted-user  2007-4727  25622    
17605WEB-CGI Trend Micro OfficeScan CGI password decryption buffer overflow attempt (more info ...)web-application-attack  2008-1365  28020    URL


# of warning rules in this group: 365

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
803WEB-CGI HyperSeek hsx.cgi directory traversal attempt (more info ...)web-application-attack 2001-0253 2314 10602 
804WEB-CGI SWSoft ASPSeek Overflow attempt (more info ...)web-application-attack 2001-0476 2492  
805WEB-CGI webspeed access (more info ...)attempted-user 2000-0127 969 10304 
806WEB-CGI yabb directory traversal attempt (more info ...)attempted-recon 2000-0853 1668 10512 
807WEB-CGI /wwwboard/passwd.txt access (more info ...)attempted-recon 1999-0954 649 10321 
808WEB-CGI webdriver access (more info ...)attempted-recon  2166 10592 
809WEB-CGI whois_raw.cgi arbitrary command execution attempt (more info ...)web-application-attack 1999-1063 304 10306 
810WEB-CGI whois_raw.cgi access (more info ...)attempted-recon 1999-1063 304 10306 
811WEB-CGI websitepro path access (more info ...)attempted-recon 2000-0066 932 10303 
812WEB-CGI webplus version access (more info ...)attempted-recon 2000-0282 1102  
813WEB-CGI webplus directory traversal (more info ...)web-application-attack 2000-0282 1102 10367 
815WEB-CGI websendmail access (more info ...)attempted-recon 1999-0196 2077 10301 
817WEB-CGI dcboard.cgi invalid user addition attempt (more info ...)web-application-attack 2001-0527 2728 10583 
818WEB-CGI dcforum.cgi access (more info ...)attempted-recon 2001-0527 2728 10583 
819WEB-CGI mmstdod.cgi access (more info ...)attempted-recon 2001-0021 2063 10566 
820WEB-CGI anaconda directory transversal attempt (more info ...)web-application-attack 2001-0308 2388 10536 
821WEB-CGI imagemap.exe overflow attempt (more info ...)web-application-attack 1999-0951 739 10122 
823WEB-CGI cvsweb.cgi access (more info ...)attempted-recon 2000-0670 1469 10465 
825WEB-CGI glimpse access (more info ...)attempted-recon 1999-0147 2026 10095 
826WEB-CGI htmlscript access (more info ...)attempted-recon 1999-0264 2001 10106 
827WEB-CGI info2www access (more info ...)attempted-recon 1999-0266 1995 10127 
828WEB-CGI maillist.pl access (more info ...)attempted-recon    
829WEB-CGI nph-test-cgi access (more info ...)attempted-recon 1999-0045 686 10165 
832WEB-CGI perl.exe access (more info ...)attempted-recon 1999-0509  10173 URL
833WEB-CGI rguest.exe access (more info ...)attempted-recon 1999-0287 2024  
834WEB-CGI rwwwshell.pl access (more info ...)attempted-recon    URL
835WEB-CGI test-cgi access (more info ...)attempted-recon 1999-0070 2003 10282 
836WEB-CGI textcounter.pl access (more info ...)attempted-recon 1999-1479 2265 11451 
837WEB-CGI uploader.exe access (more info ...)attempted-recon 2000-0769 1611 10291 
838WEB-CGI webgais access (more info ...)attempted-recon 1999-0176 2058 10300 
839WEB-CGI finger access (more info ...)attempted-recon 1999-0612  10071 
840WEB-CGI perlshop.cgi access (more info ...)attempted-recon 1999-1374   
842WEB-CGI aglimpse access (more info ...)attempted-recon 1999-0147 2026 10095 
843WEB-CGI anform2 access (more info ...)attempted-recon 1999-0066 719  
844WEB-CGI args.bat access (more info ...)attempted-recon 1999-1180  11465 
845WEB-CGI AT-admin.cgi access (more info ...)attempted-recon 1999-1072   
846WEB-CGI bnbform.cgi access (more info ...)attempted-recon 1999-0937 2147  
847WEB-CGI campas access (more info ...)attempted-recon 1999-0146 1975 10035 
848WEB-CGI view-source directory traversal (more info ...)web-application-attack 1999-0174 8883  
849WEB-CGI view-source access (more info ...)attempted-recon 1999-0174 8883  
850WEB-CGI wais.pl access (more info ...)attempted-recon    
851WEB-CGI files.pl access (more info ...)attempted-recon 1999-1081   
852WEB-CGI wguest.exe access (more info ...)attempted-recon 1999-0467 2024  
854WEB-CGI classifieds.cgi access (more info ...)attempted-recon 1999-0934 2020  
856WEB-CGI environ.cgi access (more info ...)attempted-recon    
857WEB-CGI faxsurvey access (more info ...)web-application-activity 1999-0262 2056 10067 
858WEB-CGI filemail access (more info ...)attempted-recon 1999-1154   
859WEB-CGI man.sh access (more info ...)attempted-recon 1999-1179 2276  
860WEB-CGI snork.bat access (more info ...)attempted-recon 1999-0233 2023  
861WEB-CGI w3-msql access (more info ...)attempted-recon 2000-0012 898 10296 
863WEB-CGI day5datacopier.cgi access (more info ...)attempted-recon 1999-1232   
864WEB-CGI day5datanotifier.cgi access (more info ...)attempted-recon 1999-1232   
865WEB-CGI ksh access (more info ...)attempted-recon 1999-0509   URL
866WEB-CGI post-query access (more info ...)attempted-recon 2001-0291 6752  
867WEB-CGI visadmin.exe access (more info ...)attempted-recon 1999-0970 1808 10295 
868WEB-CGI rsh access (more info ...)attempted-recon 1999-0509   URL
869WEB-CGI dumpenv.pl access (more info ...)attempted-recon 1999-1178  10060 
870WEB-CGI snorkerz.cmd access (more info ...)attempted-recon    
871WEB-CGI survey.cgi access (more info ...)attempted-recon 1999-0936 1817  
872WEB-CGI tcsh access (more info ...)attempted-recon 1999-0509   URL
875WEB-CGI win-c-sample.exe access (more info ...)attempted-recon 1999-0178 2078 10008 
877WEB-CGI rksh access (more info ...)attempted-recon 1999-0509   URL
878WEB-CGI w3tvars.pm access (more info ...)attempted-recon    
879WEB-CGI admin.pl access (more info ...)attempted-recon 2002-1748 3839  URL
880WEB-CGI LWGate access (more info ...)attempted-recon    URL
881WEB-CGI archie access (more info ...)attempted-recon    
883WEB-CGI flexform access (more info ...)attempted-recon    URL
887WEB-CGI www-sql access (more info ...)attempted-recon    URL
888WEB-CGI wwwadmin.pl access (more info ...)attempted-recon    
889WEB-CGI ppdscgi.exe access (more info ...)attempted-recon  491 10187 URL
890WEB-CGI sendform.cgi access (more info ...)attempted-recon 2002-0710 5286  URL
892WEB-CGI AnyForm2 access (more info ...)attempted-recon 1999-0066 719 10277 
894WEB-CGI bb-hist.sh access (more info ...)attempted-recon 1999-1462 142 10025 
896WEB-CGI way-board access (more info ...)web-application-activity 2001-0214 2370 10610 
897WEB-CGI pals-cgi access (more info ...)attempted-recon 2001-0217 2372 10611 
898WEB-CGI commerce.cgi access (more info ...)attempted-recon 2001-0210 2361 10612 
899WEB-CGI Amaya templates sendtemp.pl directory traversal attempt (more info ...)web-application-attack 2001-0272 2504 10614 
900WEB-CGI webspirs.cgi directory traversal attempt (more info ...)web-application-attack 2001-0211 2362 10616 
901WEB-CGI webspirs.cgi access (more info ...)attempted-recon 2001-0211 2362 10616 
902WEB-CGI tstisapi.dll access (more info ...)attempted-recon 2001-0302 2381  
1051WEB-CGI technote main.cgi file directory traversal attempt (more info ...)web-application-attack 2001-0075 2156 10584 
1052WEB-CGI technote print.cgi directory traversal attempt (more info ...)web-application-attack 2001-0075 2156 10584 
1053WEB-CGI ads.cgi command execution attempt (more info ...)web-application-attack 2001-0025 2103 11464 
1088WEB-CGI eXtropia webstore directory traversal (more info ...)web-application-attack 2000-1005 1774 10532 
1089WEB-CGI shopping cart directory traversal (more info ...)web-application-attack 2000-0921 1777  
1090WEB-CGI Allaire Pro Web Shell attempt (more info ...)web-application-attack    
1092WEB-CGI Armada Style Master Index directory traversal (more info ...)web-application-attack 2000-0924 1772 10562 URL
1093WEB-CGI cached_feed.cgi moreover shopping cart directory traversal (more info ...)web-application-attack 2000-0906 1762  
1097WEB-CGI Talentsoft Web+ exploit attempt (more info ...)web-application-attack  1725  
1106WEB-CGI Poll-it access (more info ...)web-application-activity 2000-0590 1431 10459 
1149WEB-CGI count.cgi access (more info ...)web-application-activity 1999-0021 128 10049 
1163WEB-CGI webdist.cgi access (more info ...)web-application-activity 1999-0039 374 10299 
1172WEB-CGI bigconf.cgi access (more info ...)web-application-activity 1999-1550 778 10027 
1174WEB-CGI /cgi-bin/jj access (more info ...)web-application-activity 1999-0260 2002 10131 
1185WEB-CGI bizdbsearch attempt (more info ...)web-application-attack 2000-0287 1104 10383 
1194WEB-CGI sojourn.cgi File attempt (more info ...)web-application-attack 2000-0180 1052 10349 
1195WEB-CGI sojourn.cgi access (more info ...)web-application-activity 2000-0180 1052 10349 
1196WEB-CGI SGI InfoSearch fname attempt (more info ...)web-application-attack 2000-0207 1031 10128 
1204WEB-CGI ax-admin.cgi access (more info ...)web-application-activity    
1205WEB-CGI axs.cgi access (more info ...)web-application-activity    
1206WEB-CGI cachemgr.cgi access (more info ...)web-application-activity 1999-0710 2059 10034 
1208WEB-CGI responder.cgi access (more info ...)web-application-activity  3155  
1211WEB-CGI web-map.cgi access (more info ...)web-application-activity    
1215WEB-CGI ministats admin access (more info ...)web-application-activity    
1219WEB-CGI dfire.cgi access (more info ...)web-application-activity 1999-0913 564  
1221WEB-MISC Muscat Empower cgi access (more info ...)web-application-activity 2001-0224 2374 10609 
1222WEB-CGI pals-cgi arbitrary file access attempt (more info ...)web-application-attack 2001-0217 2372 10611 
1304WEB-CGI txt2html.cgi access (more info ...)web-application-activity    
1305WEB-CGI txt2html.cgi directory traversal attempt (more info ...)web-application-attack    
1306WEB-CGI store.cgi product directory traversal attempt (more info ...)web-application-attack 2001-0305 2385  
1307WEB-CGI store.cgi access (more info ...)web-application-activity 2001-0305 2385 10639 
1308WEB-CGI sendmessage.cgi access (more info ...)attempted-recon 2001-1100 3673  
1309WEB-CGI zsh access (more info ...)attempted-recon 1999-0509   URL
1392WEB-CGI lastlines.cgi access (more info ...)attempted-recon 2001-1206 3755  
1395WEB-CGI zml.cgi attempt (more info ...)web-application-activity 2001-1209 3759 10830 
1396WEB-CGI zml.cgi access (more info ...)web-application-activity 2001-1209 3759 10830 
1397WEB-CGI wayboard attempt (more info ...)web-application-attack 2001-0214 2370 10610 
1405WEB-CGI AHG search.cgi access (more info ...)web-application-activity  3985  
1406WEB-CGI agora.cgi access (more info ...)web-application-activity 2002-0215 3976 10836 
1410WEB-CGI dcboard.cgi access (more info ...)attempted-recon 2001-0527 2728 10583 
1451WEB-CGI NPH-maillist access (more info ...)attempted-recon 2001-0400 2563 10164 
1452WEB-CGI args.cmd access (more info ...)attempted-recon 1999-1180  11465 
1453WEB-CGI AT-generated.cgi access (more info ...)attempted-recon 1999-1072   
1454WEB-CGI wwwwais access (more info ...)attempted-recon 2001-0223  10597 
1455WEB-CGI calendar.pl access (more info ...)attempted-recon 2000-0432 1215  
1456WEB-CGI calender_admin.pl access (more info ...)attempted-recon 2000-0432  10506 
1457WEB-CGI user_update_admin.pl access (more info ...)attempted-recon 2000-0627 1486  
1458WEB-CGI user_update_passwd.pl access (more info ...)attempted-recon 2000-0627 1486  
1459WEB-CGI bb-histlog.sh access (more info ...)attempted-recon 1999-1462 142 10025 
1460WEB-CGI bb-histsvc.sh access (more info ...)attempted-recon 1999-1462 142  
1461WEB-CGI bb-rep.sh access (more info ...)attempted-recon 1999-1462 142  
1462WEB-CGI bb-replog.sh access (more info ...)attempted-recon 1999-1462 142  
1465WEB-CGI auktion.cgi access (more info ...)web-application-activity 2001-0212 2367 10638 
1466WEB-CGI cgiforum.pl access (more info ...)web-application-activity 2000-1171 1963 10552 
1467WEB-CGI directorypro.cgi access (more info ...)web-application-activity 2001-0780 2793 10679 
1468WEB-CGI Web Shopper shopper.cgi attempt (more info ...)web-application-attack 2000-0922 1776 10533 
1469WEB-CGI Web Shopper shopper.cgi access (more info ...)attempted-recon 2000-0922 1776  
1470WEB-CGI listrec.pl access (more info ...)attempted-recon 2001-0997 3328 10769 
1471WEB-CGI mailnews.cgi access (more info ...)attempted-recon 2001-0271 2391 10641 
1472WEB-CGI book.cgi access (more info ...)web-application-activity 2001-1114 3178 10721 
1473WEB-CGI newsdesk.cgi access (more info ...)attempted-recon 2001-0232 2172 10586 
1474WEB-CGI cal_make.pl access (more info ...)web-application-activity 2001-0463 2663 10664 
1475WEB-CGI mailit.pl access (more info ...)attempted-recon   10417 
1476WEB-CGI sdbsearch.cgi access (more info ...)attempted-recon 2001-1130 1658 10720 
1478WEB-CGI swc access (more info ...)attempted-recon   10493 
1479WEB-CGI ttawebtop.cgi arbitrary file attempt (more info ...)web-application-attack 2001-0805 2890 10696 
1480WEB-CGI ttawebtop.cgi access (more info ...)attempted-recon 2001-0805 2890 10696 
1481WEB-CGI upload.cgi access (more info ...)attempted-recon   10290 
1482WEB-CGI view_source access (more info ...)attempted-recon 1999-0174 2251 10294 
1483WEB-CGI ustorekeeper.pl access (more info ...)web-application-activity 2001-0466  10645 
1488WEB-CGI store.cgi directory traversal attempt (more info ...)web-application-attack 2001-0305 2385 10639 
1494WEB-CGI SIX webboard generate.cgi attempt (more info ...)web-application-attack 2001-1115 3175 10725 
1495WEB-CGI SIX webboard generate.cgi access (more info ...)web-application-activity 2001-1115 3175 10725 
1496WEB-CGI spin_client.cgi access (more info ...)web-application-activity   10393 
1501WEB-CGI a1stats a1disp3.cgi directory traversal attempt (more info ...)web-application-attack 2001-0561 2705 10669 
1502WEB-CGI a1stats a1disp3.cgi access (more info ...)web-application-activity 2001-0561 2705 10669 
1503WEB-CGI admentor admin.asp access (more info ...)web-application-activity 2002-0308 4152 10880 URL
1505WEB-CGI alchemy http server PRN arbitrary command execution attempt (more info ...)web-application-activity 2001-0871 3599 10818 
1506WEB-CGI alchemy http server NUL arbitrary command execution attempt (more info ...)web-application-activity 2001-0871 3599 10818 
1507WEB-CGI alibaba.pl arbitrary command execution attempt (more info ...)web-application-attack 1999-0885 770 10013 
1508WEB-CGI alibaba.pl access (more info ...)web-application-activity 1999-0885 770 10013 
1509WEB-CGI AltaVista Intranet Search directory traversal attempt (more info ...)web-application-attack 2000-0039 896 10015 
1510WEB-CGI test.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1511WEB-CGI test.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1512WEB-CGI input.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1513WEB-CGI input.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1514WEB-CGI input2.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1515WEB-CGI input2.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1516WEB-CGI envout.bat arbitrary command execution attempt (more info ...)web-application-attack 1999-0947 762 10016 
1517WEB-CGI envout.bat access (more info ...)web-application-activity 1999-0947 762 10016 
1531WEB-CGI bb-hist.sh attempt (more info ...)web-application-attack 1999-1462 142 10025 
1532WEB-CGI bb-hostscv.sh attempt (more info ...)web-application-attack 2000-0638 1455 10460 
1533WEB-CGI bb-hostscv.sh access (more info ...)web-application-activity 2000-0638 1455 10460 
1534WEB-CGI agora.cgi attempt (more info ...)web-application-attack 2002-0215 3976 10836 
1535WEB-CGI bizdbsearch access (more info ...)web-application-activity 2000-0287 1104 10383 
1536WEB-CGI calendar_admin.pl arbitrary command execution attempt (more info ...)web-application-attack 2000-0432 1215 10506 
1537WEB-CGI calendar_admin.pl access (more info ...)web-application-activity 2000-0432 1215 10506 
1539WEB-CGI /cgi-bin/ls access (more info ...)web-application-activity 2000-0079 936 10037 
1542WEB-CGI cgimail access (more info ...)web-application-activity 2000-0726 1623 11721 
1543WEB-CGI cgiwrap access (more info ...)web-application-activity 2001-0987 777 10041 
1547WEB-CGI csSearch.cgi arbitrary command execution attempt (more info ...)web-application-attack 2002-0495 4368 10924 
1548WEB-CGI csSearch.cgi access (more info ...)web-application-activity 2002-0495 4368 10924 
1554WEB-CGI dbman db.cgi access (more info ...)web-application-activity 2000-0381 1178 10403 
1555WEB-CGI DCShop access (more info ...)web-application-activity 2001-0821 2889  
1556WEB-CGI DCShop orders.txt access (more info ...)web-application-activity 2001-0821 2889  
1557WEB-CGI DCShop auth_user_file.txt access (more info ...)web-application-activity 2001-0821 2889  
1565WEB-CGI eshop.pl arbitrary command execution attempt (more info ...)web-application-attack 2001-1014 3340  
1566WEB-CGI eshop.pl access (more info ...)web-application-activity 2001-1014 3340  
1569WEB-CGI loadpage.cgi directory traversal attempt (more info ...)web-application-attack 2000-1092 2109 10065 
1570WEB-CGI loadpage.cgi access (more info ...)web-application-activity 2000-1092 2109 10065 
1571WEB-CGI dcforum.cgi directory traversal attempt (more info ...)web-application-attack 2001-0437 2611 10583 
1572WEB-CGI commerce.cgi arbitrary file access attempt (more info ...)attempted-recon 2001-0210 2361 10612 
1573WEB-CGI cgiforum.pl attempt (more info ...)web-application-attack 2000-1171 1963 10552 
1574WEB-CGI directorypro.cgi attempt (more info ...)web-application-attack 2001-0780 2793 10679 
1587WEB-MISC cgitest.exe access (more info ...)web-application-activity 2002-0128 3885 11131 
1590WEB-CGI faqmanager.cgi arbitrary file access attempt (more info ...)web-application-attack  3810 10837 
1591WEB-CGI faqmanager.cgi access (more info ...)web-application-activity  3810 10837 
1592WEB-CGI /fcgi-bin/echo.exe access (more info ...)web-application-activity   10838 
1593WEB-CGI FormHandler.cgi external site redirection attempt (more info ...)web-application-attack 1999-1050 799 10075 
1594WEB-CGI FormHandler.cgi access (more info ...)web-application-activity 1999-1050 799 10075 
1597WEB-CGI guestbook.cgi access (more info ...)web-application-activity 1999-0237  10098 
1598WEB-CGI Home Free search.cgi directory traversal attempt (more info ...)web-application-attack 2000-0054 921 10101 
1599WEB-CGI search.cgi access (more info ...)web-application-activity 2000-0054 921  
1600WEB-CGI htsearch arbitrary configuration file attempt (more info ...)web-application-attack 2001-0834 3410  
1601WEB-CGI htsearch arbitrary file read attempt (more info ...)web-application-attack 2000-0208 1026 10105 
1602WEB-CGI htsearch access (more info ...)web-application-activity 2000-0208 1026 10105 
1606WEB-CGI icat access (more info ...)web-application-activity 1999-1069   
1607WEB-CGI HyperSeek hsx.cgi access (more info ...)web-application-activity 2001-0253 2314 10602 
1608WEB-CGI htmlscript attempt (more info ...)web-application-attack 1999-0264 2001 10106 
1611WEB-CGI eXtropia webstore access (more info ...)web-application-activity 2000-1005 1774 10532 
1617WEB-CGI Bugzilla doeditvotes.cgi access (more info ...)web-application-activity 2002-0011 3800  
1628WEB-CGI FormHandler.cgi directory traversal attempt attempt (more info ...)web-application-attack 1999-1050 799 10075 
1637WEB-CGI yabb access (more info ...)attempted-recon 2000-0853 1668 10512 
1642WEB-CGI document.d2w access (more info ...)web-application-activity 2000-1110 2017  
1643WEB-CGI db2www access (more info ...)web-application-activity 2000-0677   
1644WEB-CGI test-cgi attempt (more info ...)web-application-attack 1999-0070 2003 10282 
1645WEB-CGI testcgi access (more info ...)web-application-activity  7214 11610 
1646WEB-CGI test.cgi access (more info ...)web-application-activity    
1648WEB-CGI perl.exe command attempt (more info ...)attempted-recon 1999-0509  10173 URL
1649WEB-CGI perl command attempt (more info ...)attempted-recon 1999-0509  10173 URL
1650WEB-CGI tst.bat access (more info ...)web-application-activity 1999-0885 770 10014 
1651WEB-CGI environ.pl access (more info ...)web-application-activity    
1652WEB-CGI campas attempt (more info ...)web-application-attack 1999-0146 1975 10035 
1654WEB-CGI cart32.exe access (more info ...)web-application-activity  1153 10389 
1655WEB-CGI pfdispaly.cgi arbitrary command execution attempt (more info ...)web-application-attack 1999-0270  10174 
1656WEB-CGI pfdispaly.cgi access (more info ...)web-application-activity 1999-0270 64 10174 
1657WEB-CGI pagelog.cgi directory traversal attempt (more info ...)web-application-activity 2000-0940 1864 10591 
1658WEB-CGI pagelog.cgi access (more info ...)web-application-activity 2000-0940 1864 10591 
1666ATTACK-RESPONSES index of /cgi-bin/ response (more info ...)bad-unknown   10039 
1668WEB-CGI /cgi-bin/ access (more info ...)web-application-attack    
1669WEB-CGI /cgi-dos/ access (more info ...)web-application-attack    
1700WEB-CGI imagemap.exe access (more info ...)web-application-activity 1999-0951 739 10122 
1701WEB-CGI calendar-admin.pl access (more info ...)web-application-activity 2000-0432 1215 10506 
1702WEB-CGI Amaya templates sendtemp.pl access (more info ...)web-application-activity 2001-0272 2504  
1703WEB-CGI auktion.cgi directory traversal attempt (more info ...)web-application-attack 2001-0212 2367 10638 
1704WEB-CGI cal_make.pl directory traversal attempt (more info ...)web-application-attack 2001-0463 2663 10664 
1705WEB-CGI echo.bat arbitrary command execution attempt (more info ...)web-application-attack 2000-0213 1002 10246 
1706WEB-CGI echo.bat access (more info ...)web-application-activity 2000-0213 1002 10246 
1707WEB-CGI hello.bat arbitrary command execution attempt (more info ...)web-application-attack 2000-0213 1002 10246 
1708WEB-CGI hello.bat access (more info ...)web-application-activity 2000-0213 1002 10246 
1709WEB-CGI ad.cgi access (more info ...)web-application-activity 2001-0025 2103 11464 
1710WEB-CGI bbs_forum.cgi access (more info ...)web-application-activity 2001-0123 2177  URL
1711WEB-CGI bsguest.cgi access (more info ...)web-application-activity 2001-0099 2159  
1712WEB-CGI bslist.cgi access (more info ...)web-application-activity 2001-0100 2160  
1713WEB-CGI cgforum.cgi access (more info ...)web-application-activity 2000-1132 1951  
1714WEB-CGI newdesk access (more info ...)web-application-activity    
1715WEB-CGI register.cgi access (more info ...)web-application-activity 2001-0076 2157  
1716WEB-CGI gbook.cgi access (more info ...)web-application-activity 2000-1131 1940  
1717WEB-CGI simplestguest.cgi access (more info ...)web-application-activity 2001-0022 2106  
1718WEB-CGI statsconfig.pl access (more info ...)web-application-activity 2001-0113 2211  
1719WEB-CGI talkback.cgi directory traversal attempt (more info ...)web-application-attack 2001-0420 2547  
1720WEB-CGI talkback.cgi access (more info ...)web-application-activity 2001-0420 2547  
1722WEB-CGI MachineInfo access (more info ...)web-application-activity 1999-1067   
1723WEB-CGI emumail.cgi NULL attempt (more info ...)web-application-activity 2002-1526 5824  
1724WEB-CGI emumail.cgi access (more info ...)web-application-activity 2002-1526 5824  
1727WEB-CGI SGI InfoSearch fname access (more info ...)web-application-activity 2000-0207 1031  
1730WEB-CGI ustorekeeper.pl directory traversal attempt (more info ...)web-application-attack 2001-0466 2536 10645 
1731WEB-CGI a1stats access (more info ...)web-application-activity 2001-0561 2705 10669 
1762WEB-CGI phf arbitrary command execution attempt (more info ...)web-application-attack 1999-0067 629  
1763WEB-CGI Nortel Contivity cgiproc DOS attempt (more info ...)web-application-attack 2000-0064 938 10160 
1764WEB-CGI Nortel Contivity cgiproc DOS attempt (more info ...)web-application-attack 2000-0064 938 10160 
1765WEB-CGI Nortel Contivity cgiproc access (more info ...)web-application-activity 2000-0064 938 10160 
1787WEB-CGI csPassword.cgi access (more info ...)web-application-activity 2002-0918 4889  
1788WEB-CGI csPassword password.cgi.tmp access (more info ...)web-application-activity 2002-0920 4889  
1805WEB-CGI Oracle reports CGI access (more info ...)web-application-activity 2002-0947 4848  
1822WEB-CGI alienform.cgi directory traversal attempt (more info ...)web-application-attack 2002-0934 4983 11027 
1823WEB-CGI AlienForm af.cgi directory traversal attempt (more info ...)web-application-attack 2002-0934 4983 11027 
1824WEB-CGI alienform.cgi access (more info ...)web-application-activity 2002-0934 4983 11027 
1825WEB-CGI AlienForm af.cgi access (more info ...)web-application-activity 2002-0934 4983 11027 
1850WEB-CGI way-board.cgi access (more info ...)web-application-activity   10610 
1862WEB-CGI mrtg.cgi directory traversal attempt (more info ...)web-application-attack 2002-0232 4017 11001 
1865WEB-CGI webdist.cgi arbitrary command attempt (more info ...)web-application-attack 1999-0039 374 10299 
1868WEB-CGI story.pl arbitrary file read attempt (more info ...)default-login-attempt 2001-0804 3028 10817 
1869WEB-CGI story.pl access (more info ...)default-login-attempt 2001-0804 3028 10817 
1870WEB-CGI siteUserMod.cgi access (more info ...)web-application-activity 2000-0117 951 10253 
1875WEB-CGI cgicso access (more info ...)web-application-activity 2002-1652 6141 10780 
1876WEB-CGI nph-publish.cgi access (more info ...)web-application-activity 1999-1177  10164 
1877WEB-CGI printenv access (more info ...)web-application-activity 2000-0868 1658 10503 
1878WEB-CGI sdbsearch.cgi access (more info ...)web-application-activity 2000-0868 1658 10503 
1879WEB-CGI book.cgi arbitrary command execution attempt (more info ...)web-application-attack 2001-1114 3178 10721 
1931WEB-CGI rpc-nlog.pl access (more info ...)web-application-activity 1999-1278   URL
1932WEB-CGI rpc-smb.pl access (more info ...)web-application-activity 1999-1278   
1933WEB-CGI cart.cgi access (more info ...)web-application-activity 2000-0252 1115 10368 
1994WEB-CGI vpasswd.cgi access (more info ...)web-application-activity  6038 11165 
1995WEB-CGI alya.cgi access (more info ...)web-application-activity   11118 
1996WEB-CGI viralator.cgi access (more info ...)web-application-activity 2001-0849 3495 11107 
2001WEB-CGI smartsearch.cgi access (more info ...)web-application-activity  7133  
2051WEB-CGI cached_feed.cgi moreover shopping cart access (more info ...)web-application-activity 2000-0906 1762  
2052WEB-CGI overflow.cgi access (more info ...)web-application-activity 2002-1361 6326 11190 URL
2053WEB-CGI process_bug.cgi access (more info ...)web-application-activity 2002-0008 3272  
2054WEB-CGI enter_bug.cgi arbitrary command attempt (more info ...)web-application-attack 2002-0008 3272  
2055WEB-CGI enter_bug.cgi access (more info ...)web-application-activity 2002-0008 3272  
2085WEB-CGI parse_xml.cgi access (more info ...)web-application-activity 2003-0054 6960  
2086WEB-CGI streaming server parse_xml.cgi access (more info ...)web-application-activity 2003-0054 6960 11278 
2115WEB-CGI album.pl access (more info ...)web-application-activity  7444 11581 
2116WEB-CGI chipcfg.cgi access (more info ...)web-application-activity 2001-1341 2767  URL
2127WEB-CGI ikonboard.cgi access (more info ...)web-application-activity  7361 11605 
2128WEB-CGI swsrv.cgi access (more info ...)web-application-activity 2003-0217 7510 11608 
2194WEB-CGI CSMailto.cgi access (more info ...)web-application-activity 2002-0749 6265 11748 
2195WEB-CGI alert.cgi access (more info ...)web-application-activity 2002-0346 4579 11748 
2196WEB-CGI catgy.cgi access (more info ...)web-application-activity 2001-1212 4579 11748 
2197WEB-CGI cvsview2.cgi access (more info ...)web-application-activity 2003-0153 5517 11748 
2198WEB-CGI cvslog.cgi access (more info ...)web-application-activity 2003-0153 5517 11748 
2199WEB-CGI multidiff.cgi access (more info ...)web-application-activity 2003-0153 5517 11748 
2200WEB-CGI dnewsweb.cgi access (more info ...)web-application-activity 2000-0423 4579 11748 
2202WEB-CGI edit_action.cgi access (more info ...)web-application-activity 2001-1196 4579 11748 
2203WEB-CGI everythingform.cgi access (more info ...)web-application-activity 2001-0023 4579 11748 
2204WEB-CGI ezadmin.cgi access (more info ...)web-application-activity 2002-0263 4579 11748 
2205WEB-CGI ezboard.cgi access (more info ...)web-application-activity 2002-0263 4579 11748 
2206WEB-CGI ezman.cgi access (more info ...)web-application-activity 2002-0263 4579 11748 
2207WEB-CGI fileseek.cgi access (more info ...)web-application-activity 2002-0611 6784 11748 
2208WEB-CGI fom.cgi access (more info ...)web-application-activity 2002-0230 4579 11748 
2209WEB-CGI getdoc.cgi access (more info ...)web-application-activity 2000-0288 4579 11748 
2210WEB-CGI global.cgi access (more info ...)web-application-activity 2000-0952 4579 11748 
2211WEB-CGI guestserver.cgi access (more info ...)web-application-activity 2001-0180 4579 11748 
2212WEB-CGI imageFolio.cgi access (more info ...)web-application-activity 2002-1334 6265 11748 
2213WEB-CGI mailfile.cgi access (more info ...)web-application-activity 2000-0977 4579 11748 
2214WEB-CGI mailview.cgi access (more info ...)web-application-activity 2000-0526 4579 11748 
2215WEB-CGI nsManager.cgi access (more info ...)web-application-activity 2000-1023 4579 11748 
2216WEB-CGI readmail.cgi access (more info ...)web-application-activity 2001-1283 4579 11748 
2217WEB-CGI printmail.cgi access (more info ...)web-application-activity 2001-1283 4579 11748 
2218WEB-CGI service.cgi access (more info ...)web-application-activity 2002-0346 4579 11748 
2219WEB-CGI setpasswd.cgi access (more info ...)web-application-activity 2001-0133 4579 11748 
2220WEB-CGI simplestmail.cgi access (more info ...)web-application-activity 2001-0022 4579 11748 
2221WEB-CGI ws_mail.cgi access (more info ...)web-application-activity 2001-1343 4579 11748 
2222WEB-CGI nph-exploitscanget.cgi access (more info ...)web-application-activity 2003-0434 7913 11740 
2223WEB-CGI csNews.cgi access (more info ...)web-application-activity 2002-0923 4994 11726 
2224WEB-CGI psunami.cgi access (more info ...)web-application-activity  6607 11750 
2225WEB-CGI gozila.cgi access (more info ...)web-application-activity 2002-1236 6086 11773 
2237WEB-MISC cgiWebupdate.exe access (more info ...)web-application-activity 2001-1150 3216 11722 
2242WEB-MISC ddicgi.exe access (more info ...)web-application-activity 2000-0826 1657 11728 
2243WEB-MISC ndcgi.exe access (more info ...)web-application-activity 2001-0922 3583 11730 
2277WEB-MISC PeopleSoft PeopleBooks psdoccgi access (more info ...)web-application-activity 2003-0627 9038  
2323WEB-CGI quickstore.cgi access (more info ...)web-application-activity  9282 11975 
2387WEB-CGI view_broadcast.cgi access (more info ...)web-application-activity 2003-0422 8257  
2388WEB-CGI streaming server view_broadcast.cgi access (more info ...)web-application-activity 2003-0422 8257  
2396WEB-CGI CCBill whereami.cgi arbitrary command execution attempt (more info ...)web-application-attack  8095  URL
2397WEB-CGI CCBill whereami.cgi access (more info ...)web-application-activity  8095  URL
2433WEB-CGI MDaemon form2raw.cgi overflow attempt (more info ...)web-application-attack 2003-1200 9317  URL
2434WEB-CGI MDaemon form2raw.cgi access (more info ...)web-application-activity 2003-1200 9317  URL
2567WEB-CGI Emumail init.emu access (more info ...)web-application-activity  9861 12095 
2568WEB-CGI Emumail emumail.fcgi access (more info ...)web-application-activity  9861 12095 
2663WEB-CGI WhatsUpGold instancename overflow attempt (more info ...)web-application-attack 2004-0798 11043  
2668WEB-CGI processit access (more info ...)web-application-activity   10649 
2669WEB-CGI ibillpm.pl access (more info ...)web-application-activity 2001-0839 3476 11083 
2670WEB-CGI pgpmail.pl access (more info ...)web-application-activity 2001-0937 3605 11070 
3062WEB-CGI NetScreen SA 5000 delhomepage.cgi access (more info ...)web-application-activity 2004-0347 9791  
3131WEB-CGI mailman directory traversal attempt (more info ...)web-application-attack 2005-0202   
3463WEB-CGI awstats access (more info ...)web-application-activity  12572 16456 
3464WEB-CGI awstats.pl command execution attempt (more info ...)web-application-attack  12572 16456 
3465WEB-CGI RiSearch show.pl proxy attempt (more info ...)web-application-activity  10812  
3468WEB-CGI math_sum.mscgi access (more info ...)web-application-activity  10831 14182 
3469WEB-CGI Ipswitch WhatsUp Gold dos attempt (more info ...)attempted-dos 2004-0799 11110  URL
3638WEB-CGI SoftCart.exe CGI buffer overflow attempt (more info ...)web-application-attack 2004-2221 10926  
3674WEB-CGI db4web_c directory traversal attempt (more info ...)web-application-attack 2002-1483 5723 11182 
3813WEB-CGI awstats.pl configdir command execution attempt (more info ...)attempted-user 2005-0116 12298 16189 
4128WEB-CGI 4DWebstar ShellExample.cgi information disclosure (more info ...)attempted-recon  10721  URL
8084WEB-CGI CVSTrac filediff function access (more info ...)web-application-activity 2004-1456 10878 14238 URL
10999WEB-CGI chetcpasswd access (more info ...)web-application-activity 2006-6679 6472  
11817WEB-CGI WhatsUpGold configuration access (more info ...)web-application-activity 2004-0798 11043  
12056WEB-CGI WhatsUpGold instancename overflow attempt (more info ...)web-application-attack 2004-0798 11043  
12057WEB-CGI WhatsUpGold configuration access (more info ...)web-application-activity 2004-0798 11043  
12255WEB-CGI CSGuestbook setup attempt (more info ...)web-application-activity 2002-1750 4448  
15908WEB-MISC Trend Micro OfficeScan multiple CGI modules HTTP form processing buffer overflow attempt (more info ...)attempted-admin 2008-3862   
16922BLACKLIST URI request for known malicious URI - /cgi-bin/rd.cgi?f=/vercfg.dat?AgentID= (more info ...)trojan-activity    URL

 goto Top

Group: Server / Mail

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Mail / Microsoft Exchange

# of attack rules in this group: 12

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
7165SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 1 (more info ...)successful-recon-limited        URL
7166SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 2 (more info ...)successful-recon-limited        URL
7167SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 3 (more info ...)successful-recon-limited        URL
7168SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 4 (more info ...)successful-recon-limited        URL
7169SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange (more info ...)successful-recon-limited        URL
11222SMTP Exchange MODPROPS denial of service attempt (more info ...)attempted-dos  2007-0039  23808    URL
12619EXPLOIT Microsoft Exchange ical/vcal malformed property (more info ...)attempted-admin  2006-0027  17908    URL
15301SMTP Exchange compressed RTF remote code execution attempt (more info ...)attempted-admin  2009-0098      URL
15302DOS Microsoft Exchange System Attendant denial of service attempt (more info ...)attempted-dos  2009-0099      URL
15329SMTP Microsoft Exchange MODPROPS memory corruption attempt (more info ...)attempted-admin  2006-0027  17908    URL
15964SPECIFIC-THREATS Microsoft Exchange OWA XSS and spoofing attempt (more info ...)misc-attack  2004-0203  10902    
17481SPECIFIC-THREATS Microsoft Exchange and Outlook TNEF Decoding Integer Overflow attempt (more info ...)attempted-admin  2006-0002  16197    


# of warning rules in this group: 5

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
658SMTP exchange mime DOS (more info ...)attempted-dos 2000-1006 1869 10558 URL
3815SMTP eXchange POP3 mail server overflow attempt (more info ...)misc-attack 2004-1945 10180  
10010EXPLOIT Putty Server key exchange buffer overflow attempt (more info ...)attempted-user 2002-1359 6407  URL
14742SPECIFIC-THREATS Exchange MODPROPS denial of service PoC attempt (more info ...)attempted-dos 2007-0039 23808  URL
16108BACKDOOR trojan downloader exchanger.gen2 runtime detection (more info ...)trojan-activity    URL

 goto Top

Group: Server / Mail / Sendmail

# of attack rules in this group: 0

# of warning rules in this group: 21

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
655SMTP sendmail 8.6.9 exploit (more info ...)attempted-admin 1999-0204 2311  
662SMTP sendmail 5.5.5 exploit (more info ...)attempted-admin 1999-0203  10258 
665SMTP sendmail 5.6.5 exploit (more info ...)attempted-user 1999-0203 2308  
667SMTP sendmail 8.6.10 exploit (more info ...)attempted-user 1999-0204 2311  
668SMTP sendmail 8.6.10 exploit (more info ...)attempted-user 1999-0204 2311  
669SMTP sendmail 8.6.9 exploit (more info ...)attempted-user 1999-0204 2311  
670SMTP sendmail 8.6.9 exploit (more info ...)attempted-user 1999-0204 2311  
671SMTP sendmail 8.6.9c exploit (more info ...)attempted-user 1999-0204 2311  
1526WEB-MISC basilix sendmail.inc access (more info ...)web-application-activity 2001-1044 2198 10601 
2261SMTP SEND FROM sendmail prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991 11316 
2262SMTP SEND FROM sendmail prescan too long addresses overflow (more info ...)misc-attack 2003-0161 7230 11499 
2263SMTP SAML FROM sendmail prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2264SMTP SAML FROM sendmail prescan too long addresses overflow (more info ...)misc-attack 2003-0161 7230 11499 
2265SMTP SOML FROM sendmail prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2266SMTP SOML FROM sendmail prescan too long addresses overflow (more info ...)misc-attack 2003-0161 7230 11499 
2267SMTP MAIL FROM sendmail prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2268SMTP MAIL FROM sendmail prescan too long addresses overflow (more info ...)attempted-admin 2003-0161 7230 11499 
2269SMTP RCPT TO sendmail prescan too many addresses overflow (more info ...)attempted-admin 2002-1337 6991  
2270SMTP RCPT TO sendmail prescan too long addresses overflow (more info ...)attempted-admin 2003-0694 7230 11499 
15936SPECIFIC-THREATS Sendmail identd command parsing vulnerability (more info ...)attempted-admin 1999-0204 2311  
16057SPECIFIC-THREATS sendmail smtp timeout buffer overflow attempt (more info ...)attempted-admin 2006-0058 17192  

 goto Top

Group: Server / Mail / POP3

# of attack rules in this group: 11

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
2535POP3 SSLv3 Client_Hello request (more info ...)protocol-command-decode        
2536POP3 SSLv3 Server_Hello request (more info ...)protocol-command-decode        
3499POP3 SSLv2 Client_Hello request (more info ...)protocol-command-decode        
3500POP3 SSLv2 Client_Hello with pad request (more info ...)protocol-command-decode        
3501POP3 TLSv1 Client_Hello request (more info ...)protocol-command-decode        
3502POP3 TLSv1 Client_Hello via SSLv2 handshake request (more info ...)protocol-command-decode        
3503POP3 SSLv2 Server_Hello request (more info ...)protocol-command-decode        
3504POP3 TLSv1 Server_Hello request (more info ...)protocol-command-decode        
16594POP3 STAT command (more info ...)protocol-command-decode        
16799POP3 Eureka Mail 2.2q server error response overflow attempt (more info ...)misc-attack  2009-3837      URL
17331POP3 Lotus Notes HTML Speed Reader Long URL buffer overflow attempt (more info ...)attempted-user  2005-2618  16576    


# of warning rules in this group: 29

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
286POP3 EXPLOIT x86 BSD overflow (more info ...)attempted-admin 1999-0006 133 10196 
287POP3 EXPLOIT x86 BSD overflow (more info ...)attempted-admin    
288POP3 EXPLOIT x86 Linux overflow (more info ...)attempted-admin    
289POP3 EXPLOIT x86 SCO overflow (more info ...)attempted-admin 1999-0006 156  
290POP3 EXPLOIT qpopper overflow (more info ...)attempted-admin 1999-0822 830 10184 
1634POP3 PASS overflow attempt (more info ...)attempted-admin 2006-6605 791 10325 
1635POP3 APOP overflow attempt (more info ...)attempted-admin 2000-0841 1652 10559 
1866POP3 USER overflow attempt (more info ...)attempted-admin 2006-4364 789 10311 
1936POP3 AUTH overflow attempt (more info ...)attempted-admin 1999-0822 830 10184 
1937POP3 LIST overflow attempt (more info ...)attempted-admin 2000-0096 948 10197 
1938POP3 XTND overflow attempt (more info ...)attempted-admin    
2108POP3 CAPA overflow attempt (more info ...)attempted-admin    
2109POP3 TOP overflow attempt (more info ...)attempted-admin    
2110POP3 STAT overflow attempt (more info ...)attempted-admin    
2111POP3 DELE overflow attempt (more info ...)attempted-admin    
2112POP3 RSET overflow attempt (more info ...)attempted-admin    
2121POP3 DELE negative argument attempt (more info ...)misc-attack 2002-1539 7445 11570 
2122POP3 UIDL negative argument attempt (more info ...)misc-attack 2002-1539 6053 11570 
2250POP3 USER format string attempt (more info ...)attempted-admin 2003-0391 7667 11742 
2274POP3 login brute force attempt (more info ...)suspicious-login    
2409POP3 APOP USER overflow attempt (more info ...)attempted-admin  9794  
2502POP3 SSLv3 invalid data version attempt (more info ...)attempted-dos 2004-0120 10115 12204 URL
2518POP3 PCT Client_Hello overflow attempt (more info ...)attempted-admin 2003-0719 10116 12205 URL
2537POP3 SSLv3 invalid Client_Hello attempt (more info ...)attempted-dos 2004-0120  12204 URL
2666POP3 PASS format string attempt (more info ...)attempted-admin  10976  
8429POP3 SSLv2 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 22083  URL
8430POP3 SSLv3 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 25831  URL
8431POP3 SSLv2 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 22083  URL
16595POP3 Windows Mail remote code execution attempt (more info ...)attempted-user 2010-0816   URL

 goto Top

Group: Server / Mail / IMAP

# of attack rules in this group: 34

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1844IMAP authenticate overflow attempt (more info ...)misc-attack  1999-0042  130  10292  
1930IMAP auth literal overflow attempt (more info ...)misc-attack  2006-6424  21724    
2330IMAP auth overflow attempt (more info ...)misc-attack  2003-1177  8861  11910  
2529IMAP SSLv3 Client_Hello request (more info ...)protocol-command-decode        
2530IMAP SSLv3 Server_Hello request (more info ...)protocol-command-decode        
2665IMAP login literal format string attempt (more info ...)attempted-admin  2007-0221  10976    URL
3067IMAP examine literal overflow attempt (more info ...)misc-attack  2004-1211  11775  15867  
3068IMAP examine overflow attempt (more info ...)misc-attack  2005-3155  15006  15867  
3069IMAP fetch literal overflow attempt (more info ...)misc-attack  2004-1211  11775  15867  
3073IMAP SUBSCRIBE literal overflow attempt (more info ...)attempted-admin  2007-3510  26219  15867  
3074IMAP SUBSCRIBE overflow attempt (more info ...)attempted-admin  2007-3510  26219  15867  
3487IMAP SSLv2 Client_Hello request (more info ...)protocol-command-decode        
3488IMAP SSLv2 Client_Hello with pad request (more info ...)protocol-command-decode        
3489IMAP TLSv1 Client_Hello request (more info ...)protocol-command-decode        
3490IMAP TLSv1 Client_Hello via SSLv2 handshake request (more info ...)protocol-command-decode        
3491IMAP SSLv2 Server_Hello request (more info ...)protocol-command-decode        
3492IMAP TLSv1 Server_Hello request (more info ...)protocol-command-decode        
10011IMAP Novell NetMail APPEND command buffer overflow attempt (more info ...)misc-attack  2006-6425  21723    
11004IMAP CRAM-MD5 authentication method buffer overflow (more info ...)attempted-admin  2007-1675  23172    
12114IMAP Ipswitch IMail search command buffer overflow attempt (more info ...)attempted-admin  2007-3925  24962    URL
12115IMAP Ipswitch IMail search command buffer overflow attempt (more info ...)attempted-admin  2007-3925  24962    URL
12212IMAP Ipswitch IMail literal search date command buffer overflow attempt (more info ...)attempted-admin  2007-3925  24962    URL
12213IMAP Ipswitch IMail search date command buffer overflow attempt (more info ...)attempted-admin  2007-3925  24962    URL
13663IMAP Alt-N MDaemon IMAP Server FETCH command buffer overflow attempt (more info ...)attempted-admin  2008-1358  28245    URL
15484IMAP CRAM-MD5 authentication method buffer overflow (more info ...)attempted-admin  2007-1675  23172    
16779WEB-ACTIVEX EasyMail IMAP4 ActiveX clsid access (more info ...)attempted-user  2007-4607  25467    
16780WEB-ACTIVEX EasyMail IMAP4 ActiveX clsid unicode access (more info ...)attempted-user  2007-4607  25467    
16781WEB-ACTIVEX EasyMail IMAP4 ActiveX function call access (more info ...)attempted-user  2007-4607  25467    
16782WEB-ACTIVEX EasyMail IMAP4 ActiveX function call unicode access (more info ...)attempted-user  2007-4607  25467    
17239IMAP Alt-N MDaemon IMAP server CREATE command buffer overflow attempt (more info ...)attempted-dos    14315    
17240IMAP Alt-N MDaemon IMAP server literal CREATE command buffer overflow attempt (more info ...)attempted-dos    14315    
17327IMAP Qualcomm WorldMail Server Response (more info ...)protocol-command-decode        
17328IMAP Qualcomm WorldMail IMAP Literal Token Parsing Buffer Overflow (more info ...)attempted-admin  2005-4267  15980    
17503IMAP MailEnable IMAP Service Invalid Command Buffer Overlow LOGIN (more info ...)attempted-admin    21252    


# of warning rules in this group: 44

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1755IMAP partial body buffer overflow attempt (more info ...)misc-attack 2002-0379 4713 10966 
1842IMAP login buffer overflow attempt (more info ...)attempted-user 2007-2795 502 10125 
1845IMAP list literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1902IMAP lsub literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1903IMAP rename overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1904IMAP find overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
1993IMAP login literal buffer overflow attempt (more info ...)misc-attack 2006-6424 6298 12532 
2046IMAP partial body.peek buffer overflow attempt (more info ...)misc-attack 2002-0379 4713 10966 
2105IMAP authenticate literal overflow attempt (more info ...)misc-attack 2006-6424 21724 10292 
2106IMAP lsub overflow attempt (more info ...)misc-attack 2005-3155 15006 10374 
2107IMAP create buffer overflow attempt (more info ...)misc-attack  7446  
2118IMAP list overflow attempt (more info ...)misc-attack 2005-3155 15006 10374 
2119IMAP rename literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
2120IMAP create literal buffer overflow attempt (more info ...)misc-attack  7446  
2273IMAP login brute force attempt (more info ...)suspicious-login    
2497IMAP SSLv3 invalid data version attempt (more info ...)attempted-dos 2004-0120 10115 12204 URL
2531IMAP SSLv3 invalid Client_Hello attempt (more info ...)attempted-dos 2004-0120  12204 URL
2664IMAP login format string attempt (more info ...)attempted-admin  10976  
3007IMAP delete overflow attempt (more info ...)misc-attack 2005-3155 15006 15771 
3008IMAP delete literal overflow attempt (more info ...)misc-attack 2004-1520 11675 15771 
3058IMAP copy literal overflow attempt (more info ...)misc-attack 2000-0284 1110 10374 
3066IMAP append overflow attempt (more info ...)misc-attack 2006-6425 21729 15867 
3070IMAP fetch overflow attempt (more info ...)misc-attack 2004-1211 11775 15867 
3071IMAP status literal overflow attempt (more info ...)misc-attack 2004-1211 15491 15867 
3072IMAP status overflow attempt (more info ...)misc-attack 2005-3314 15491 15867 
3075IMAP unsubscribe literal overflow attempt (more info ...)misc-attack 2004-1211 11775 15867 
3076IMAP UNSUBSCRIBE overflow attempt (more info ...)attempted-admin 2005-3189 15488 15867 
4645IMAP search format string attempt (more info ...)attempted-admin  10976  
4646IMAP search literal format string attempt (more info ...)attempted-admin  10976  
5696IMAP delete directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5697IMAP examine directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5698IMAP list directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5699IMAP lsub directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5700IMAP rename directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5701IMAP status directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5702IMAP SUBSCRIBE directory traversal attempt (more info ...)attempted-admin 2007-3510 26219 15867 
5703IMAP unsubscribe directory traversal attempt (more info ...)misc-attack 2005-3189 15488  
5704IMAP SELECT overflow attempt (more info ...)misc-attack 2006-1255 15006  
5705IMAP CAPABILITY overflow attempt (more info ...)misc-attack 2005-3155 15006  
8438IMAP SSLv2 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 22083  URL
8439IMAP SSLv3 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 25831  URL
12392IMAP GNU Mailutils request tag format string vulnerability (more info ...)attempted-admin 2005-1523 13764  
13921IMAP Altrium Software MERCUR IMAPD NTLMSSP command handling memory corruption attempt (more info ...)attempted-admin 2007-1578 23058  URL
17369IMAP MailEnable Service APPEND Command Handling Buffer Overflow (more info ...)attempted-admin 2007-0494 22792  

 goto Top

Group: Server / Mail / SMTP

# of attack rules in this group: 165

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
654SMTP RCPT TO overflow (more info ...)attempted-admin  2009-0410  9696    
1549SMTP HELO overflow attempt (more info ...)attempted-admin  2000-0042  895  11674  
2183SMTP Content-Transfer-Encoding overflow attempt (more info ...)attempted-admin  2003-0161      URL
2253SMTP XEXCH50 overflow attempt (more info ...)attempted-admin  2003-0714  8838  11889  URL
2259SMTP EXPN overflow attempt (more info ...)attempted-admin  2003-0161  7230    
2260SMTP VRFY overflow attempt (more info ...)attempted-admin  2003-0161  7230    
2527SMTP STARTTLS attempt (more info ...)protocol-command-decode        
2542SMTP SSLv3 Client_Hello request (more info ...)protocol-command-decode        
2543SMTP SSLv3 Server_Hello request (more info ...)protocol-command-decode        
3461SMTP Content-Type overflow attempt (more info ...)attempted-admin  2003-0113  7419    URL
3462SMTP Content-Encoding overflow attempt (more info ...)attempted-admin  2003-0113  7419    URL
3493SMTP SSLv2 Client_Hello request (more info ...)protocol-command-decode        
3494SMTP SSLv2 Client_Hello with pad request (more info ...)protocol-command-decode        
3495SMTP TLSv1 Client_Hello request (more info ...)protocol-command-decode        
3496SMTP TLSv1 Client_Hello via SSLv2 handshake request (more info ...)protocol-command-decode        
3497SMTP SSLv2 Server_Hello request (more info ...)protocol-command-decode        
3498SMTP TLSv1 Server_Hello request (more info ...)protocol-command-decode        
5685SMTP TLSv1 Client_Hello via SSLv2 handshake request (more info ...)protocol-command-decode        
5686SMTP TLSv1 Server_Hello request (more info ...)protocol-command-decode        
5687SMTP SSLv2 Client_Hello request (more info ...)protocol-command-decode        
5688SMTP SSLv2 Client_Hello with pad request (more info ...)protocol-command-decode        
5689SMTP TLSv1 Client_Hello request (more info ...)protocol-command-decode        
5690SMTP SSLv3 Client_Hello request (more info ...)protocol-command-decode        
5691SMTP SSLv2 Server_Hello request (more info ...)protocol-command-decode        
5790SPYWARE-PUT Keylogger pc actmon pro runtime detection - smtp (more info ...)successful-recon-limited        URL
5880SPYWARE-PUT Keylogger spyagent runtime detect - smtp delivery (more info ...)successful-recon-limited        URL
6125BACKDOOR dkangel runtime detection - smtp (more info ...)trojan-activity        URL
6126BACKDOOR dkangel runtime detection - smtp (more info ...)trojan-activity        URL
6207SPYWARE-PUT Keylogger winsession runtime detection - smtp (more info ...)successful-recon-limited        URL
6301BACKDOOR cia 1.3 runtime detection - smtp notification (more info ...)trojan-activity        URL
6397BACKDOOR http rat runtime detection - smtp (more info ...)trojan-activity        URL
6477SPYWARE-PUT Hacker-Tool beee runtime detection - smtp (more info ...)misc-activity        URL
7184SPYWARE-PUT Keylogger 007 spy software runtime detection - smtp (more info ...)successful-recon-limited        URL
7505SPYWARE-PUT Keylogger actualspy runtime detection - smtp (more info ...)successful-recon-limited        URL
7551SPYWARE-PUT Keylogger ardamax keylogger runtime detection - smtp (more info ...)successful-recon-limited        URL
8544SPYWARE-PUT Keylogger nicespy runtime detection - smtp (more info ...)successful-recon-limited        URL
8704SMTP YPOPS Banner (more info ...)not-suspicious        
9326SPECIFIC-THREATS netsky.p smtp propagation detection (more info ...)trojan-activity        URL
9327SPECIFIC-THREATS netsky.af smtp propagation detection (more info ...)trojan-activity        URL
9328SPECIFIC-THREATS zhangpo smtp propagation detection (more info ...)trojan-activity        URL
9329SPECIFIC-THREATS yarner.b smtp propagation detection (more info ...)trojan-activity        URL
9330SPECIFIC-THREATS mydoom.e smtp propagation detection (more info ...)trojan-activity        URL
9331SPECIFIC-THREATS mydoom.m smtp propagation detection (more info ...)trojan-activity        URL
9332SPECIFIC-THREATS mimail.a smtp propagation detection (more info ...)trojan-activity        URL
9333SPECIFIC-THREATS mimail.e smtp propagation detection (more info ...)trojan-activity        URL
9334SPECIFIC-THREATS lovgate.c smtp propagation detection (more info ...)trojan-activity        URL
9335SPECIFIC-THREATS netsky.b smtp propagation detection (more info ...)trojan-activity        URL
9336SPECIFIC-THREATS netsky.t smtp propagation detection (more info ...)trojan-activity        URL
9337SPECIFIC-THREATS netsky.x smtp propagation detection (more info ...)trojan-activity        URL
9338SPECIFIC-THREATS mydoom.i smtp propagation detection (more info ...)trojan-activity        URL
9342SPECIFIC-THREATS paroc.a smtp propagation detection (more info ...)trojan-activity        URL
9343SPECIFIC-THREATS kadra smtp propagation detection (more info ...)trojan-activity        URL
9344SPECIFIC-THREATS kindal smtp propagation detection (more info ...)trojan-activity        URL
9345SPECIFIC-THREATS kipis.a smtp propagation detection (more info ...)trojan-activity        URL
9348SPECIFIC-THREATS morbex smtp propagation detection (more info ...)trojan-activity        URL
9349SPECIFIC-THREATS plemood smtp propagation detection (more info ...)trojan-activity        URL
9350SPECIFIC-THREATS mimail.k smtp propagation detection (more info ...)trojan-activity        URL
9352SPECIFIC-THREATS lovgate.a smtp propagation detection (more info ...)trojan-activity        URL
9358SPECIFIC-THREATS fizzer smtp propagation detection (more info ...)trojan-activity        URL
9359SPECIFIC-THREATS zafi.b smtp propagation detection (more info ...)trojan-activity        URL
9360SPECIFIC-THREATS cult.b smtp propagation detection (more info ...)trojan-activity        URL
9361SPECIFIC-THREATS mimail.l smtp propagation detection (more info ...)trojan-activity        URL
9362SPECIFIC-THREATS mimail.m smtp propagation detection (more info ...)trojan-activity        URL
9365SPECIFIC-THREATS cult.c smtp propagation detection (more info ...)trojan-activity        URL
9366SPECIFIC-THREATS mimail.s smtp propagation detection (more info ...)trojan-activity        URL
9367SPECIFIC-THREATS anset.b smtp propagation detection (more info ...)trojan-activity        URL
9368SPECIFIC-THREATS agist.a smtp propagation detection (more info ...)trojan-activity        URL
9369SPECIFIC-THREATS atak.a smtp propagation detection (more info ...)trojan-activity        URL
9370SPECIFIC-THREATS bagle.b smtp propagation detection (more info ...)trojan-activity        URL
9371SPECIFIC-THREATS bagle.e smtp propagation detection (more info ...)trojan-activity        URL
9372SPECIFIC-THREATS blebla.a smtp propagation detection (more info ...)trojan-activity        URL
9373SPECIFIC-THREATS clepa smtp propagation detection (more info ...)trojan-activity        URL
9374SPECIFIC-THREATS creepy.b smtp propagation detection (more info ...)trojan-activity        URL
9375SPECIFIC-THREATS duksten.c smtp propagation detection (more info ...)trojan-activity        URL
9376SPECIFIC-THREATS fishlet.a smtp propagation detection (more info ...)trojan-activity        URL
9377SPECIFIC-THREATS mydoom.g smtp propagation detection (more info ...)trojan-activity        URL
9378SPECIFIC-THREATS netsky.q smtp propagation detection (more info ...)trojan-activity        URL
9379SPECIFIC-THREATS netsky.s smtp propagation detection (more info ...)trojan-activity        URL
9381SPECIFIC-THREATS lara smtp propagation detection (more info ...)trojan-activity        URL
9382SPECIFIC-THREATS fearso.c smtp propagation detection (more info ...)trojan-activity        URL
9383SPECIFIC-THREATS netsky.y smtp propagation detection (more info ...)trojan-activity        URL
9384SPECIFIC-THREATS beglur.a smtp propagation detection (more info ...)trojan-activity        URL
9385SPECIFIC-THREATS collo.a smtp propagation detection (more info ...)trojan-activity        URL
9386SPECIFIC-THREATS bagle.f smtp propagation detection (more info ...)trojan-activity        URL
9388SPECIFIC-THREATS mimail.g smtp propagation detection (more info ...)trojan-activity        URL
9389SPECIFIC-THREATS bagle.i smtp propagation detection (more info ...)trojan-activity        URL
9391SPECIFIC-THREATS mimail.i smtp propagation detection (more info ...)trojan-activity        URL
9392SPECIFIC-THREATS bagle.j smtp propagation detection (more info ...)trojan-activity        URL
9393SPECIFIC-THREATS bagle.k smtp propagation detection (more info ...)trojan-activity        URL
9394SPECIFIC-THREATS bagle.n smtp propagation detection (more info ...)trojan-activity        URL
9397SPECIFIC-THREATS neysid smtp propagation detection (more info ...)trojan-activity        URL
9398SPECIFIC-THREATS totilix.a smtp propagation detection (more info ...)trojan-activity        URL
9399SPECIFIC-THREATS hanged smtp propagation detection (more info ...)trojan-activity        URL
9400SPECIFIC-THREATS abotus smtp propagation detection (more info ...)trojan-activity        URL
9403SPECIFIC-THREATS netsky.aa smtp propagation detection (more info ...)trojan-activity        URL
9404SPECIFIC-THREATS netsky.ac smtp propagation detection (more info ...)trojan-activity        URL
9405SPECIFIC-THREATS netsky.af smtp propagation detection (more info ...)trojan-activity        URL
9406SPECIFIC-THREATS lovgate.e smtp propagation detection (more info ...)trojan-activity        URL
9408SPECIFIC-THREATS lacrow smtp propagation detection (more info ...)trojan-activity        URL
9409SPECIFIC-THREATS atak.b smtp propagation detection (more info ...)trojan-activity        URL
9410SPECIFIC-THREATS netsky.z smtp propagation detection (more info ...)trojan-activity        URL
9411SPECIFIC-THREATS mimail.f smtp propagation detection (more info ...)trojan-activity        URL
9413SPECIFIC-THREATS ganda smtp propagation detection (more info ...)trojan-activity        URL
9414SPECIFIC-THREATS lovelorn.a smtp propagation detection (more info ...)trojan-activity        URL
9415SPECIFIC-THREATS plexus.a smtp propagation detection (more info ...)trojan-activity        URL
9416SPECIFIC-THREATS bagle.at smtp propagation detection (more info ...)trojan-activity        URL
9417SPECIFIC-THREATS bagle.a smtp propagation detection (more info ...)trojan-activity        URL
9827SPYWARE-PUT Keylogger paq keylog runtime detection - smtp (more info ...)successful-recon-limited        URL
9841SMTP Microsoft Outlook VEVENT overflow attempt (more info ...)attempted-user  2007-0033  21931    URL
10012SMTP Microsoft Outlook VEVENT non-TZID overflow attempt (more info ...)attempted-user  2007-0033  21931    URL
10065SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10066SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10067SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10068SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10069SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10070SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10071SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10072SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10073SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10074SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10075SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10076SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10077SPECIFIC-THREATS Trojan Peacomm smtp propagation detection (more info ...)trojan-activity        
10078SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity        
10079SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity        
10080SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity        
10081SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity        
10082SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity        
10083SPECIFIC-THREATS W32.Nuwar.AY smtp propagation detection (more info ...)trojan-activity        
10088SPYWARE-PUT Keylogger beyond Keylogger runtime detection - log sent by smtp (more info ...)successful-recon-limited        URL
10453BACKDOOR zalivator 1.4.2 pro runtime detection - smtp notification (more info ...)trojan-activity        URL
11305SPYWARE-PUT Snoopware childwebguardian runtime detection - send log through smtp (more info ...)successful-recon-limited        URL
12807SMTP Lotus 123 file attachment (more info ...)suspicious-filename-detect  2007-6593  27835    URL
13718SMTP BDAT buffer overflow attempt (more info ...)attempted-admin  2002-0055  4204    URL
13894SMTP Microsoft Outlook Web Access From field cross-site scripting attempt (more info ...)misc-attack  2008-2247      URL
13895SMTP Microsoft Outlook Web Access invalid CSS escape sequence script execution attempt (more info ...)misc-attack  2008-2248      URL
13923SMTP MailEnable SMTP HELO command denial of service attempt (more info ...)attempted-dos  2006-3277  18630    
15358SMTP Adobe PDF JBIG2 remote code execution attempt (more info ...)attempted-user  2009-0658  33751    
15359SMTP Suspicious JBIG2 pdf file sent via email (more info ...)attempted-user  2009-0658  33751    
15360SMTP Suspicious JBIG2 pdf file sent in email (more info ...)attempted-user  2009-0658  33751    
15367SMTP outlook web access script injection attempt (more info ...)attempted-user  2006-1193  18381    
15494SMTP Suspicious JBIG2 pdf file sent from email (more info ...)attempted-user  2009-0658  33751    
15495SMTP Suspicious JBIG2 pdf file sent by email (more info ...)attempted-user  2009-0658  33751    
15496SMTP Suspicious JBIG2 pdf file sent through email (more info ...)attempted-user  2009-0658  33751    
15497SMTP Suspicious JBIG2 pdf file sent with email (more info ...)attempted-user  2009-0658  33751    
15574SMTP MAIL FROM command overflow attempt (more info ...)attempted-admin  2004-0399  7506    URL
16025SPECIFIC-THREATS MailEnable SMTP service SPF lookup buffer overflow attempt (more info ...)attempted-admin  2006-4616  20091    
16193SMTP Novell GroupWise Internet Agent SMTP AUTH LOGIN command buffer overflow attempt (more info ...)attempted-admin  2009-1636  35065    
16201SPECIFIC-THREATS Ipswitch Collaboration Suite SMTP format string exploit attempt (more info ...)attempted-admin  2005-2931  15752    
16515SMTP Novell Groupwise Internet Agent RCPT command overflow attempt (more info ...)attempted-user  2009-0410  33560    
16534DOS Windows Server2000/2003/2008 SMTP service DNS MX lookup denial of service attempt (more info ...)attempted-dos  2010-0024      URL
16597SMTP Novell GroupWise Internet Agent Email address processing buffer overflow attempt (more info ...)attempted-admin  2009-1636  35064    
17034SMTP Outlook AttachMethods local file execution attempt (more info ...)attempted-user  2010-0266      URL
17035SMTP Outlook AttachMethods local file execution attempt (more info ...)attempted-user  2010-0266      URL
17036SMTP Outlook AttachMethods local file execution attempt (more info ...)attempted-user  2010-0266      URL
17099WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX clsid access (more info ...)attempted-user        URL
17100WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX clsid unicode access (more info ...)attempted-user        URL
17101WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX function call access (more info ...)attempted-user        URL
17102WEB-ACTIVEX CommuniCrypt Mail ANSMTP.dll/AOSMTP.dll ActiveX function call unicode access (more info ...)attempted-user        URL
17251SMTP Outlook RTF remote code execution attempt (more info ...)attempted-admin  2010-2728      URL
17332SMTP Content-Disposition attachment (more info ...)protocol-command-decode        
17333SMTP Lotus Notes Attachment Viewer UUE file buffer overflow attempt (more info ...)attempted-user  2005-2618  16576    
17693SMTP MailEnable NTLM Authentication buffer overflow attempt (more info ...)attempted-admin  2006-5176  20290    URL
17697SMTP GnuPG Message Packet Length overflow attempt (more info ...)attempted-user  2006-3746      URL
17717SMTP IBM Lotus Notes HTML input tag buffer overflow attempt (more info ...)attempted-user  2007-4222  26200    URL


# of warning rules in this group: 45

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
631SMTP ehlo cybercop attempt (more info ...)protocol-command-decode 1999-0531   
632SMTP expn cybercop attempt (more info ...)protocol-command-decode 1999-0531   
657SMTP chameleon overflow (more info ...)attempted-admin 1999-0261 2387  
659SMTP expn decode (more info ...)attempted-recon 1999-0096  10248 
660SMTP expn root (more info ...)attempted-recon 1999-0531  10249 
661SMTP majordomo ifs (more info ...)attempted-admin 1999-0207 2310  
663SMTP rcpt to command attempt (more info ...)attempted-admin 1999-0095 1  
664SMTP RCPT TO decode attempt (more info ...)attempted-admin 1999-0203 2308  
672SMTP vrfy decode (more info ...)attempted-recon 1999-0096   
1446SMTP vrfy root (more info ...)attempted-recon 1999-0531   
1450SMTP expn *@ (more info ...)misc-attack 1999-1200   
1550SMTP ETRN overflow attempt (more info ...)attempted-admin 2000-0490 7515 10438 
2087SMTP From comment overflow attempt (more info ...)attempted-admin 2002-1337 6991  URL
2275SMTP AUTH LOGON brute force attempt (more info ...)suspicious-login    
2487SMTP WinZip MIME content-type buffer overflow (more info ...)attempted-user 2004-0333 9758 12621 
2488SMTP WinZip MIME content-disposition buffer overflow (more info ...)attempted-user 2004-0333 9758 12621 
2504SMTP SSLv3 invalid data version attempt (more info ...)attempted-dos 2004-0120 10115 12204 URL
2528SMTP PCT Client_Hello overflow attempt (more info ...)attempted-admin 2003-0719 10116 12205 URL
2541SMTP TLS SSLv3 invalid data version attempt (more info ...)attempted-dos 2004-0120 10115 12204 URL
2544SMTP SSLv3 invalid Client_Hello attempt (more info ...)attempted-dos 2004-0120  12204 URL
3511SMTP PCT Client_Hello overflow attempt (more info ...)attempted-admin 2003-0719 10116  URL
3653SMTP SAML overflow attempt (more info ...)attempted-user 2004-1546 11238  
3654SMTP SOML overflow attempt (more info ...)attempted-user 2004-1546 11238  
3655SMTP SEND overflow attempt (more info ...)attempted-user 2004-1546 11238  
3656SMTP MDaemon 6.5.1 and prior versions MAIL overflow attempt (more info ...)attempted-user 2004-1546 11238  
3682SMTP spoofed MIME-Type auto-execution attempt (more info ...)attempted-admin 2001-0154 2524  URL
3824SMTP AUTH user overflow attempt (more info ...)attempted-admin 2007-4440 13772  
5739SMTP headers too long server response (more info ...)bad-unknown 2006-0058 17192  
6412SMTP Windows Address Book attachment detected (more info ...)misc-activity 2006-2386 17459  URL
6413SMTP Base64 encoded Windows Address Book attachment detected (more info ...)misc-activity 2006-2386 17459  URL
8432SMTP SSLv2 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 22083  URL
8433SMTP SSLv2 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 22083  URL
8434SMTP SSLv3 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 25831  URL
8435SMTP SSLv3 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 25831  URL
8436SMTP SSLv2 openssl get shared ciphers overflow attempt (more info ...)attempted-admin 2007-5135 22083  URL
8705SMTP YPOPS buffer overflow attempt (more info ...)attempted-admin 2004-1558 11256  
10186SMTP ClamAV mime parsing directory traversal (more info ...)attempted-user 2007-0898 22581  URL
12423SMTP Microsoft CDO long header name (more info ...)attempted-admin 2005-1987 15067  URL
12692SMTP RCPT TO IPSwitch proxy overflow attempt (more info ...)attempted-admin 2006-4379   URL
12704SMTP Lotus Notes MIF viewer MIFFILE comment overflow (more info ...)attempted-user 2007-5910 26175  
12705SMTP Lotus Notes MIF viewer statement overflow (more info ...)attempted-user 2007-5910 26175  
12706SMTP Lotus Notes MIF viewer statement data overflow (more info ...)attempted-user 2007-5910 26175  
13651SPYWARE-PUT Keylogger family cyber alert runtime detection - smtp traffic for recorded activities (more info ...)successful-recon-limited    URL
17224SMTP McAfee WebShield SMTP bounce message format string attempt (more info ...)attempted-admin 2006-0559 16742  
17283SMTP Mercury Mail Transport System Buffer Overflow attempt (more info ...)attempted-user 2005-4411 16396  

 goto Top

Group: Server / Database

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Database / Microsoft

# of attack rules in this group: 10

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
13888SQL Microsoft SQL Server Backup Database File integer overflow attempt (more info ...)attempted-admin  2008-0107      URL
13889SQL Microsoft SQL Server Backup Database File integer overflow attempt (more info ...)attempted-admin  2008-0107      URL
13890SQL Microsoft SQL Server Backup Database File integer overflow attempt (more info ...)attempted-admin  2008-0107      URL
14756WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX clsid access (more info ...)attempted-user  2008-4110  31129    
14757WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX clsid unicode access (more info ...)attempted-user  2008-4110  31129    
14758WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX function call access (more info ...)attempted-user  2008-4110  31129    
14759WEB-ACTIVEX Microsoft SQL Server 2000 Client Components ActiveX function call unicode access (more info ...)attempted-user  2008-4110  31129    
16073SPECIFIC-THREATS MS-SQL convert function unicode overflow (more info ...)attempted-admin  2008-0086      URL
16074MS-SQL Suspicious SQL ansi_padding option (more info ...)policy-violation  2008-0106      URL
16208WEB-CLIENT Microsoft SQL Server Distributed Management Objects overflow attempt (more info ...)attempted-user  2007-4814  25594    


# of warning rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
11264SQL Microsoft SQL Server 2000 Server hello buffer overflow attempt (more info ...)attempted-admin 2002-1123 5411  URL
11683SPECIFIC-THREATS CA BrightStor Agent for Microsoft SQL overflow attempt (more info ...)attempted-admin 2005-1272 14453  
12444WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX clsid access (more info ...)attempted-user 2007-4814 25594  
12445WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX clsid unicode access (more info ...)attempted-user 2007-4814 25594  
12446WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX function call access (more info ...)attempted-user 2007-4814 25594  
12447WEB-ACTIVEX Microsoft SQL Server Distributed Management Objects ActiveX function call unicode access (more info ...)attempted-user 2007-4814 25594  
13896SQL Microsoft SQL server MTF file download (more info ...)misc-activity 2008-0085   URL
17307SPECIFIC-THREATS MS SQL Server INSERT Statement Buffer Overflow attempt (more info ...)policy-violation 2008-0106   

 goto Top

Group: Server / Database / Oracle

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Database / MySQL

# of attack rules in this group: 16

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3665MYSQL server greeting (more info ...)attempted-user  2004-0627  10655  12639  URL
13593SQL MySQL yaSSL SSL Hello Message Buffer Overflow attempt (more info ...)attempted-admin  2008-0226  27140    URL
13709MYSQL yaSSL SSLv2 Server_Hello request (more info ...)protocol-command-decode        
13710MYSQL yaSSL TLSv1 Server_Hello request (more info ...)protocol-command-decode        
13711MYSQL yaSSL SSLv2 Client Hello Message Cipher Length Buffer Overflow attempt (more info ...)attempted-user  2008-0226  27140    URL
13712MYSQL yaSSL SSLv2 Client Hello Message Session ID Buffer Overflow attempt (more info ...)attempted-user  2008-0226  27140    URL
13713MYSQL yaSSL SSLv2 Client Hello Message Challenge Buffer Overflow attempt (more info ...)attempted-user  2008-0226  27140    URL
13714MYSQL yaSSL SSLv3 Client Hello Message Cipher Specs Buffer Overflow attempt (more info ...)attempted-user  2008-0226  27140    URL
15442MYSQL XML Functions ExtractValue Scalar XPath denial of service attempt (more info ...)attempted-dos  2009-0819  33972    URL
15443MYSQL XML Functions UpdateXML Scalar XPath denial of service attempt (more info ...)attempted-dos  2009-0819  33972    URL
15952MYSQL create function libc arbitrary code execution attempt (more info ...)attempted-user  2005-0709  12781    
16020SPECIFIC-THREATS MySQL login handshake information disclosure attempt (more info ...)misc-activity  2006-1516  17780    
16348SPECIFIC-THREATS Sun MySQL database PROCEDURE ANALYSE denial of service attempt - 1 (more info ...)attempted-dos  2009-4019      URL
16349SPECIFIC-THREATS Sun MySQL database Procedure Analyse denial of service attempt - 2 (more info ...)attempted-dos  2009-4019      URL
16385MYSQL yaSSL library cert parsing stack overflow attempt (more info ...)attempted-user  2009-4484  37640    
17412MYSQL CREATE FUNCTION mysql.func Arbitrary Library Injection attempt (more info ...)attempted-user  2005-0710  12781    


# of warning rules in this group: 19

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
509WEB-MISC PCCS mysql database admin tool access (more info ...)web-application-attack 2000-0707 1557 10783 
1527WEB-MISC basilix mysql.class access (more info ...)web-application-activity 2001-1044 2198 10601 
1775MYSQL root login attempt (more info ...)protocol-command-decode    
1776MYSQL show databases attempt (more info ...)protocol-command-decode    
3456MYSQL 4.0 root login attempt (more info ...)protocol-command-decode    
3518WEB-MISC MySQL MaxDB WebSQL wppassword buffer overflow (more info ...)web-application-attack 2005-0111 12265  URL
3519WEB-MISC MySQL MaxDB WebSQL wppassword buffer overflow default port (more info ...)web-application-attack 2005-0111 12265  URL
3528MYSQL create function access attempt (more info ...)misc-activity 2005-0709 12781  
3666MYSQL server greeting finished (more info ...)attempted-user 2004-0627 10655 12639 URL
3667MYSQL protocol 41 client authentication bypass attempt (more info ...)misc-attack 2004-0627 10655 12639 URL
3668MYSQL client authentication bypass attempt (more info ...)misc-attack 2004-0627 10655 12639 URL
3669MYSQL protocol 41 secure client overflow attempt (more info ...)misc-attack 2004-0627 10655 12639 URL
3670MYSQL secure client overflow attempt (more info ...)misc-attack 2004-0627 10655 12639 URL
3671MYSQL protocol 41 client overflow attempt (more info ...)misc-attack 2004-0627 10655 12639 URL
3672MYSQL client overflow attempt (more info ...)misc-attack 2004-0627 10655 12639 URL
4649MYSQL create function buffer overflow attempt (more info ...)misc-activity 2005-2558 14509  
8057MYSQL Date_Format denial of service attempt (more info ...)attempted-dos 2006-3469 19032  URL
11619MISC MySQL COM_TABLE_DUMP Function Stack Overflow attempt (more info ...)attempted-admin 2006-1517 17780  URL
15951SPECIFIC-THREATS MySQL MaxDB Webtool GET command overflow attempt (more info ...)attempted-user 2005-0684 13368  

 goto Top

Group: Server / Database / Common SQL

# of attack rules in this group: 60

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
688SQL sa login failed (more info ...)unsuccessful-user  2000-1209  4797  10673  
11204ORACLE Oracle Database DBMS_AQADM_SYS package GRANT_TYPE_ACCESS procedure SQL injection attempt (more info ...)attempted-admin  2009-0977  34461    URL
12027SQL Ingres Database uuid_from_char buffer overflow attempt (more info ...)attempted-admin  2007-3338  24585    URL
13356SQL SAP MaxDB shell command injection attempt (more info ...)attempted-admin  2008-0244  27206    
13366ORACLE Oracle database SYS.LT.FINDRICSET SQL injection attempt (more info ...)attempted-admin  2007-5511  26098    URL
13512SQL generic sql exec injection attempt - GET parameter (more info ...)web-application-attack        URL
13513SQL generic sql insert injection atttempt - GET parameter (more info ...)web-application-attack        URL
13551ORACLE Oracle XDB.XDB_PITRIG_PKG sql injection attempt (more info ...)attempted-admin  2008-0339  27229    URL
13791SQL oversized cast statement - possible sql injection obfuscation (more info ...)web-application-attack        URL
13928SPECIFIC-THREATS Adobe RoboHelp r0 SQL injection attempt (more info ...)web-application-attack  2008-2991      
13929WEB-MISC Adobe RoboHelp rx SQL injection attempt (more info ...)web-application-attack  2008-2991      
13987SQL oversized convert statement - possible sql injection obfuscation (more info ...)web-application-attack        URL
13988SQL large number of calls to ascii function - possible sql injection obfuscation (more info ...)web-application-attack        URL
13990SQL union select - possible sql injection attempt - GET parameter (more info ...)misc-attack        
14008SQL large number of calls to concat function - possible sql injection obfuscation (more info ...)web-application-attack        URL
14991SQL IBM DB2 Universal Database xmlquery buffer overflow attempt (more info ...)attempted-user  2008-3854  29601    
15143SQL sp_replwritetovarbin unicode vulnerable function attempt (more info ...)attempted-admin  2008-5416  32710    URL
15144SQL sp_replwritetovarbin vulnerable function attempt (more info ...)attempted-admin  2008-5416  32710    URL
15319NETBIOS-DG SMB /sql/query create tree attempt (more info ...)protocol-command-decode        
15320NETBIOS-DG SMB /sql/query unicode create tree attempt (more info ...)protocol-command-decode        
15321NETBIOS SMB /sql/query create tree attempt (more info ...)protocol-command-decode        
15322NETBIOS SMB /sql/query unicode create tree attempt (more info ...)protocol-command-decode        
15323NETBIOS-DG SMB /sql/query andx create tree attempt (more info ...)protocol-command-decode        
15324NETBIOS-DG SMB /sql/query unicode andx create tree attempt (more info ...)protocol-command-decode        
15325NETBIOS SMB /sql/query andx create tree attempt (more info ...)protocol-command-decode        
15326NETBIOS SMB /sql/query unicode andx create tree attempt (more info ...)protocol-command-decode        
15515ORACLE Oracle Database Server RollbackWorkspace SQL injection attempt (more info ...)attempted-admin  2009-0978  34461    URL
15584SQL char and sysobjects - possible sql injection recon attempt (more info ...)web-application-attack        URL
15722SPECIFIC-THREATS Oracle database server Workspace Manager multiple SQL injection attempt (more info ...)attempted-admin  2008-3982  31683    URL
15723ORACLE Oracle database server CompressWorkspaceTree SQL injection attempt (more info ...)attempted-admin  2008-3982  31683    URL
15724ORACLE Oracle database server MergeWorkspace SQL injection attempt (more info ...)attempted-admin  2008-3982  31683    URL
15725ORACLE Oracle database server RemoveWorkspace SQL injection attempt (more info ...)attempted-admin  2008-3982  31683    URL
15868SQL Borland InterBase username buffer overflow (more info ...)attempted-user  2008-2559  29302    
15874SQL union select - possible sql injection attempt - POST parameter (more info ...)misc-attack        
15875SQL generic sql insert injection atttempt - POST parameter (more info ...)web-application-attack        URL
15876SQL generic sql update injection attempt - POST parameter (more info ...)web-application-attack        URL
15877SQL generic sql exec injection attempt - POST parameter (more info ...)web-application-attack        URL
15896DOS Firebird SQL op_connect_request denial of service attempt (more info ...)attempted-dos  2009-2620  35842    
16049SPECIFIC-THREATS GNU Radius SQL accounting format string exploit attempt (more info ...)attempted-admin  2006-4181  21303    
16159WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 1 ActiveX clsid access (more info ...)attempted-user  2009-2493      URL
16160WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 1 ActiveX clsid unicode access (more info ...)attempted-user  2009-2493      URL
16161WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 2 ActiveX clsid access (more info ...)attempted-user  2009-2493      URL
16162WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 2 ActiveX clsid unicode access (more info ...)attempted-user  2009-2493      URL
16163WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 3 ActiveX clsid access (more info ...)attempted-user  2009-2493      URL
16164WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 3 ActiveX clsid unicode access (more info ...)attempted-user  2009-2493      URL
16165WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 4 ActiveX clsid access (more info ...)attempted-user  2009-2493      URL
16166WEB-ACTIVEX Microsoft Excel Add-in for SQL Analysis Services 4 ActiveX clsid unicode access (more info ...)attempted-user  2009-2493      URL
16189ORACLE Oracle Database REPCAT_RPC.VALIDATE_REMOTE_RC SQL injection attempt (more info ...)attempted-admin  2009-1021  35685    URL
16290ORACLE Oracle database server CREATE_TABLES SQL injection attempt (more info ...)attempted-admin  2009-1991  36748    URL
16364DOS IBM DB2 database server SQLSTT denial of service attempt (more info ...)denial-of-service  2009-0173      
16513SQL Jive Software Openfire Jabber Server SQL injection attempt (more info ...)attempted-user  2008-6510  32189    
16524FTP ProFTPD username sql injection attempt (more info ...)attempted-admin  2009-0542  33722    
16722ORACLE Oracle Database Server DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE procedure SQL injection attempt (more info ...)attempted-user  2010-0870  39422    
16723ORACLE Oracle Database Server DBMS_CDC_PUBLISH.ALTER_CHANGE_SOURCE procedure SQL injection attempt (more info ...)attempted-user  2010-0870  39422    
17044SQL WinCC DB default password security bypass attempt (more info ...)attempted-user  2010-2772      URL
17209SQL IBM DB2 DATABASE SERVER SQL REPEAT Buffer Overflow (more info ...)attempted-admin  2010-0462  37976    
17270ORACLE DBMS_METADATA Package SQL Injection attempt (more info ...)attempted-user  2005-1197      
17419ORACLE Oracle database SQL compiler read-only join auth bypass attempt (more info ...)attempted-user  2007-3855      
17449WEB-MISC Novell ZENworks patch management SQL injection attempt (more info ...)web-application-attack  2005-3315  15220    
17590ORACLE DBMS_ASSERT.simple_sql_name double quote SQL injection attempt (more info ...)misc-attack    19203    


# of warning rules in this group: 113

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
673SQL sp_start_job - program execution (more info ...)attempted-user    
676SQL sp_start_job - program execution (more info ...)attempted-user    
677SQL sp_password password change (more info ...)attempted-user    
678SQL sp_delete_alert log file deletion (more info ...)attempted-user    
679SQL sp_adduser database user creation (more info ...)attempted-user    
681SQL xp_cmdshell program execution (more info ...)attempted-user  5309  
683SQL sp_password - password change (more info ...)attempted-user    
684SQL sp_delete_alert log file deletion (more info ...)attempted-user    
685SQL sp_adduser - database user creation (more info ...)attempted-user    
686SQL xp_reg* - registry access (more info ...)attempted-user 2002-0642 5205 10642 URL
687SQL xp_cmdshell - program execution (more info ...)attempted-user  5309  
689SQL xp_reg* registry access (more info ...)attempted-user 2002-0642 5205 10642 URL
691SQL shellcode attempt (more info ...)shellcode-detect    
692SQL shellcode attempt (more info ...)shellcode-detect    
693SQL shellcode attempt (more info ...)shellcode-detect    
694SQL shellcode attempt (more info ...)attempted-user    
695SQL xp_sprintf possible buffer overflow (more info ...)attempted-user  1204  URL
704SQL xp_sprintf possible buffer overflow (more info ...)attempted-user 2001-0542 3733  URL
1057SQL ftp attempt (more info ...)web-application-activity    
1058SQL xp_enumdsn attempt (more info ...)web-application-attack    
1059SQL xp_filelist attempt (more info ...)web-application-attack    
1060SQL xp_availablemedia attempt (more info ...)web-application-attack    
1061SQL xp_cmdshell attempt (more info ...)web-application-attack  5309  
1069SQL xp_regread attempt (more info ...)web-application-activity    
1077SQL queryhit.htm access (more info ...)web-application-activity   10370 
1078SQL counter.exe access (more info ...)web-application-activity 1999-1030 267  
1385WEB-MISC mod-plsql administration access (more info ...)web-application-activity 2001-1217 3727 10849 
1386SQL raiserror possible buffer overflow (more info ...)attempted-user 2001-0542 3733  URL
1387SQL raiserror possible buffer overflow (more info ...)attempted-user 2001-0542 3733 11217 
1759SQL xp_cmdshell program execution 445 (more info ...)attempted-user  5309  
1871WEB-MISC Oracle XSQLConfig.xml access (more info ...)web-application-activity 2002-0568 4290 10855 
2049SQL ping attempt (more info ...)misc-activity   10674 
2063WEB-MISC Demarc SQL injection attempt (more info ...)web-application-activity 2002-0539 4520  
2701WEB-MISC Oracle iSQLPlus sid overflow attempt (more info ...)web-application-attack  10871  URL
2702WEB-MISC Oracle iSQLPlus username overflow attempt (more info ...)web-application-attack  10871  URL
2703WEB-MISC Oracle iSQLPlus login.uix username overflow attempt (more info ...)web-application-attack  10871  URL
2704WEB-MISC Oracle 10g iSQLPlus login.unix connectID overflow attempt (more info ...)web-application-attack  10871  URL
3152SQL sa brute force failed login attempt (more info ...)unsuccessful-user 2000-1209 4797 10673 
3273SQL sa brute force failed login unicode attempt (more info ...)unsuccessful-user 2000-1209 4797 10673 
3542SQL SA brute force login attempt (more info ...)suspicious-login 2000-1209 4797 10673 
4984SQL sa brute force failed login unicode attempt (more info ...)unsuccessful-user 2000-1209 4797 10673 
4989SQL heap-based overflow attempt (more info ...)attempted-admin 2002-0649 5310 11214 URL
7207ORACLE DBMS_EXPORT_EXTENSION SQL injection attempt (more info ...)attempted-user 2006-3702 19054  
8059ORACLE SYS.KUPW-WORKER sql injection attempt (more info ...)attempted-admin 2006-3698 19054  URL
8494SQL formatmessage possible buffer overflow (more info ...)attempted-admin 2001-0542 3733  
8495SQL formatmessage possible buffer overflow (more info ...)attempted-admin 2001-0542 3733  
8496SQL sp_oacreate unicode vulnerable function attempt (more info ...)attempted-admin    URL
8497SQL sp_oacreate vulnerable function attempt (more info ...)attempted-admin    URL
8498SQL sp_oacreate unicode vulnerable function attempt (more info ...)attempted-admin    URL
8499SQL xp_displayparamstmt unicode vulnerable function attempt (more info ...)attempted-admin 2000-1081 2030  URL
8500SQL xp_displayparamstmt unicode vulnerable function attempt (more info ...)attempted-admin 2000-1081 2030  URL
8501SQL xp_displayparamstmt vulnerable function attempt (more info ...)attempted-admin 2000-1081 2030  URL
8502SQL xp_enumresultset unicode vulnerable function attempt (more info ...)attempted-admin 2000-1082 2031  URL
8503SQL xp_enumresultset unicode vulnerable function attempt (more info ...)attempted-admin 2000-1082 2031  URL
8504SQL xp_enumresultset vulnerable function attempt (more info ...)attempted-admin 2000-1082 2031  URL
8505SQL xp_oadestroy unicode vulnerable function attempt (more info ...)attempted-admin    URL
8506SQL xp_oadestroy unicode vulnerable function attempt (more info ...)attempted-admin    URL
8507SQL xp_oadestroy vulnerable function attempt (more info ...)attempted-admin    URL
8508SQL xp_oagetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8509SQL xp_oagetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8510SQL xp_oagetproperty vulnerable function attempt (more info ...)attempted-admin    URL
8511SQL xp_oamethod unicode vulnerable function attempt (more info ...)attempted-admin    URL
8512SQL xp_oamethod vulnerable function attempt (more info ...)attempted-admin    URL
8513SQL xp_oamethod unicode vulnerable function attempt (more info ...)attempted-admin    URL
8514SQL xp_oasetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8515SQL xp_oasetproperty unicode vulnerable function attempt (more info ...)attempted-admin    URL
8516SQL xp_oasetproperty vulnerable function attempt (more info ...)attempted-admin    URL
8517SQL xp_peekqueue unicode vulnerable function attempt (more info ...)attempted-admin 2000-1085 2041  URL
8518SQL xp_peekqueue unicode vulnerable function attempt (more info ...)attempted-admin 2000-1085 2041  URL
8519SQL xp_peekqueue vulnerable function attempt (more info ...)attempted-admin 2000-1085 2041  URL
8520SQL xp_printstatements unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2041  URL
8521SQL xp_printstatements unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2041  URL
8522SQL xp_printstatements vulnerable function attempt (more info ...)attempted-admin 2000-1086 2041  URL
8523SQL xp_proxiedmetadata unicode vulnerable function attempt (more info ...)attempted-admin 2000-1087 2024  URL
8524SQL xp_proxiedmetadata unicode vulnerable function attempt (more info ...)attempted-admin 2000-1087 2024  URL
8525SQL xp_proxiedmetadata vulnerable function attempt (more info ...)attempted-admin 2000-1087 2024  URL
8526SQL xp_SetSQLSecurity unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2043  URL
8527SQL xp_SetSQLSecurity unicode vulnerable function attempt (more info ...)attempted-admin 2000-1086 2043  URL
8528SQL xp_SetSQLSecurity vulnerable function attempt (more info ...)attempted-admin 2000-1086 2043  URL
8529SQL xp_showcolv unicode vulnerable function attempt (more info ...)attempted-admin 2000-1083 2038  URL
8530SQL xp_showcolv unicode vulnerable function attempt (more info ...)attempted-admin 2000-1083 2038  URL
8531SQL xp_showcolv vulnerable function attempt (more info ...)attempted-admin 2000-1083 2038  URL
8532SQL xp_sqlagent_monitor unicode vulnerable function attempt (more info ...)attempted-admin    URL
8533SQL xp_sqlagent_monitor vulnerable function attempt (more info ...)attempted-admin    URL
8534SQL xp_sqlagent_monitor unicode vulnerable function attempt (more info ...)attempted-admin    URL
8535SQL xp_sqlinventory unicode vulnerable function attempt (more info ...)attempted-admin    URL
8536SQL xp_sqlinventory vulnerable function attempt (more info ...)attempted-admin    URL
8537SQL xp_sqlinventory unicode vulnerable function attempt (more info ...)attempted-admin    URL
8538SQL xp_updatecolvbm unicode vulnerable function attempt (more info ...)attempted-admin 2000-1084 2039  URL
8539SQL xp_updatecolvbm unicode vulnerable function attempt (more info ...)attempted-admin 2000-1084 2039  URL
8540SQL xp_updatecolvbm vulnerable function attempt (more info ...)attempted-admin 2000-1084 2039  URL
11193WEB-MISC Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
11194WEB-MISC Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
11616WEB-MISC Symantec Sygate Policy Manager SQL injection (more info ...)attempted-admin 2006-0522 16452  
11685WEB-MISC Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
12009SQL Firebird SQL Fbserver buffer overflow attempt (more info ...)attempted-user 2007-3181   
12059WEB-MISC Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
12060WEB-MISC Oracle iSQL Plus cross site scripting attempt (more info ...)web-application-attack 2004-2115 9484  
13553EXPLOIT Sybase SQL Anywhere Mobilink username string buffer overflow (more info ...)attempted-admin 2008-0912 27914  URL
13554EXPLOIT Sybase SQL Anywhere Mobilink version string buffer overflow (more info ...)attempted-admin 2008-0912 27914  URL
13555EXPLOIT Sybase SQL Anywhere Mobilink remoteID string buffer overflow (more info ...)attempted-admin 2008-0912 27914  URL
13891SQL Memory page overwrite attempt (more info ...)attempted-admin 2008-0106   URL
13892SQL Convert function style overwrite (more info ...)attempted-admin 2008-0086   URL
13991SQL xp_regaddmultistring attempt (more info ...)web-application-activity    
13992SQL xp_regdeletevalue attempt (more info ...)web-application-activity    
13993SQL xp_regenumkeys attempt (more info ...)web-application-activity    
13994SQL xp_regenumvalues attempt (more info ...)web-application-activity    
13995SQL xp_regremovemultistring attempt (more info ...)web-application-activity    
13996SQL xp_servicecontrol attempt (more info ...)web-application-activity    
13997SQL xp_loginconfig attempt (more info ...)web-application-activity    
13998SQL xp_terminate_process attempt (more info ...)web-application-activity    
16393EXPLOIT Postgresql bit substring buffer overflow (more info ...)attempted-admin 2010-0442 37973  
16431SQL generic sql with comments injection attempt - GET parameter (more info ...)web-application-attack    URL

 goto Top

Group: Server / Database / Common SQL

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Misc

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Misc / DNS

# of attack rules in this group: 24

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
253DNS SPOOF query response PTR with TTL of 1 min. and no authority (more info ...)bad-unknown        
1948DNS zone transfer UDP (more info ...)attempted-recon  1999-0532    10595  
2921DNS UDP inverse query (more info ...)attempted-recon  2001-0010  2302  10605  
8709DNS Windows NAT helper components tcp denial of service attempt (more info ...)misc-attack  2006-5614      
8710DNS Windows NAT helper components udp denial of service attempt (more info ...)misc-attack  2006-5614      
15327BAD-TRAFFIC libspf2 DNS TXT record parsing buffer overflow attempt (more info ...)attempted-user  2008-2469  31881    
15991DOS Multiple vendor DNS message decompression denial of service attempt (more info ...)attempted-dos  2005-0036  13729    
16029SPECIFIC-THREATS Microsoft Windows DNS client ATMA buffer overrun attempt (more info ...)attempted-admin  2006-3441  19404    
16030SPECIFIC-THREATS Microsoft Windows DNS client TXT buffer overrun attempt (more info ...)attempted-admin  2006-3441  19404    
16206SPECIFIC-THREATS Microsoft Windows DNS server spoofing attempt (more info ...)misc-attack  2007-3898  25919    URL
16297BOTNET-CNC Palevo bot DNS request for C&C attempt (more info ...)trojan-activity        URL
16298BOTNET-CNC Palevo bot DNS request attempt (more info ...)misc-activity        URL
16299BOTNET-CNC Palevo bot DNS request attempt (more info ...)misc-activity        URL
16302BOTNET-CNC Virut DNS request for C&C attempt (more info ...)trojan-activity        URL
16303BOTNET-CNC Virut DNS request attempt (more info ...)trojan-activity        URL
16304BOTNET-CNC Virut DNS request attempt (more info ...)trojan-activity        URL
16693SPYWARE-PUT Torpig bot sinkhole server DNS lookup attempt (more info ...)trojan-activity        URL
17294DOS Microsoft Windows NAT Helper DNS query denial of service attempt (more info ...)attempted-dos  2006-5614  20804    
17483DNS squid proxy dns A record response denial of service attempt (more info ...)attempted-dos  2005-0446  12551    
17484DNS squid proxy dns PTR record response denial of service attempt (more info ...)attempted-dos  2005-0446  12551    
17485DNS Symantec Gateway products DNS cache poisoning attempt (more info ...)misc-attack  2005-0817      
17495SPECIFIC-THREATS Squid proxy DNS response spoofing attempt (more info ...)attempted-dos  2005-1519  13592    
17680SPECIFIC-THREATS ISC BIND DNSSEC Validation Multiple RRsets DoS (more info ...)attempted-dos  2007-0494  22231    
17696EXPLOIT Microsoft DNS Server ANY query cache weakness (more info ...)misc-activity  2009-0234      URL


# of warning rules in this group: 265

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
256DNS named authors attempt (more info ...)attempted-recon   10728 
257DNS named version attempt (more info ...)attempted-recon   10028 
258DNS EXPLOIT named 8.2->8.2.1 (more info ...)attempted-admin 1999-0833 788  
259DNS EXPLOIT named overflow ADM (more info ...)attempted-admin 1999-0833 788  
260DNS EXPLOIT named overflow ADMROCKS (more info ...)attempted-admin 1999-0833 788  URL
261DNS EXPLOIT named overflow attempt (more info ...)attempted-admin    URL
262DNS EXPLOIT x86 Linux overflow attempt (more info ...)attempted-admin    
264DNS EXPLOIT x86 Linux overflow attempt (more info ...)attempted-admin    
265DNS EXPLOIT x86 Linux overflow attempt ADMv2 (more info ...)attempted-admin    
266DNS EXPLOIT x86 FreeBSD overflow attempt (more info ...)attempted-admin    
267DNS EXPLOIT sparc overflow attempt (more info ...)attempted-admin    
303DNS EXPLOIT named tsig overflow attempt (more info ...)attempted-admin 2001-0010 2302 10605 
314DNS EXPLOIT named tsig overflow attempt (more info ...)attempted-admin 2001-0010 2302  
1261EXPLOIT AIX pdnsd overflow (more info ...)attempted-user 1999-0745 590  
1435DNS named authors attempt (more info ...)attempted-recon   10728 
1616DNS named version attempt (more info ...)attempted-recon   10028 
3154DNS UDP inverse query overflow (more info ...)attempted-admin 1999-0009 134  
10603NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvUpdateRecord2 overflow attempt (more info ...)attempted-admin 2007-1748 23470  URL
10900NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvEnumRecords overflow attempt (more info ...)attempted-admin 2007-1748 23470  URL
12357EXPLOIT Apple mDNSresponder excessive HTTP headers (more info ...)attempted-admin 2007-3744 25159  
15963SPECIFIC-THREATS Red Hat Enterprise Linux DNS resolver buffer overflow attempt (more info ...)attempted-admin 2002-0029 6186  
15988SPECIFIC-THREATS Microsoft ISA Server DNS spoofing attempt (more info ...)misc-attack 2004-0892 11605  
16499NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvUpdateRecord2 overflow attempt (more info ...)attempted-admin 2007-1748 23470  URL
16500NETBIOS DCERPC NCACN-IP-TCP dns R_DnssrvEnumRecords overflow attempt (more info ...)attempted-admin 2007-1748 23470  URL
16612WEB-CLIENT Firefox oversized SOCKS5 DNS reply memory corruption attempt (more info ...)attempted-user 2009-2470 35925  
16834BLACKLIST DNS request for known malware domain qd.netkill.com.cn - Trojan-Downloader.Win32.Adload.rzx (more info ...)trojan-activity    URL
16835BLACKLIST DNS request for known malware domain exe.146843.com - Trojan.Win32.Opeg.a (more info ...)trojan-activity    URL
16836BLACKLIST DNS request for known malware domain ra03.e5732.com - Trojan-Clicker.Win32.Small.afg (more info ...)trojan-activity    URL
16837BLACKLIST DNS request for known malware domain dangercheats.com.br - Trojan.Win32.Refroso.arnq (more info ...)trojan-activity    URL
16838BLACKLIST DNS request for known malware domain xlm.ppvsr.com - Trojan-GameThief.Win32.OnLineGames.wwcf (more info ...)trojan-activity    URL
16839BLACKLIST DNS request for known malware domain sh16.e8753.com - Trojan.Win32.Scar.ccqb (more info ...)trojan-activity    URL
16840BLACKLIST DNS request for known malware domain rx11.e6532.com - Trojan.Win32.Opeg.a (more info ...)trojan-activity    URL
16841BLACKLIST DNS request for known malware domain podgorz.org - Trojan-Spy.Win32.Zbot.gen (more info ...)trojan-activity    URL
16842BLACKLIST DNS request for known malware domain sp19.e4578.com - Trojan-Downloader.Win32.Genome.njz (more info ...)trojan-activity    URL
16843BLACKLIST DNS request for known malware domain 1.7zsm.com - Trojan-Downloader.Win32.Agent.dtuo (more info ...)trojan-activity    URL
16844BLACKLIST DNS request for known malware domain rm08.e4562.com - Trojan-Downloader.Win32.Agent.dngx (more info ...)trojan-activity    URL
16845BLACKLIST DNS request for known malware domain rc04.e6532.com - Trojan-Downloader.Win32.Genome.awld (more info ...)trojan-activity    URL
16846BLACKLIST DNS request for known malware domain bedayton.com - Trojan-Downloader.Win32.Agent.dlhe (more info ...)trojan-activity    URL
16847BLACKLIST DNS request for known malware domain rz12.e6805.com - Trojan-Downloader.Win32.Genome.awld (more info ...)trojan-activity    URL
16848BLACKLIST DNS request for known malware domain in.chinaitlm.cn - Trojan.VBS.HideIcon.d (more info ...)trojan-activity    URL
16849BLACKLIST DNS request for known malware domain re05.e6532.com - Trojan-Downloader.Win32.Genome.awld (more info ...)trojan-activity    URL
16850BLACKLIST DNS request for known malware domain kldmten.net - Trojan-Spy.Win32.Zbot.akra (more info ...)trojan-activity    URL
16851BLACKLIST DNS request for known malware domain forelc.cc - Trojan-Ransom.Win32.XBlocker.ahe (more info ...)trojan-activity    URL
16852BLACKLIST DNS request for known malware domain v.yao63.com - Trojan-Downloader.Win32.Agent.dqns (more info ...)trojan-activity    URL
16853BLACKLIST DNS request for known malware domain vh26.e4578.com - Trojan.Win32.Opeg.a (more info ...)trojan-activity    URL
16854BLACKLIST DNS request for known malware domain up1.give2sms.com - Trojan-Downloader.Win32.Genome.est (more info ...)trojan-activity    URL
16855BLACKLIST DNS request for known malware domain d.123kuaihuo.com - Trojan.Win32.Scar.clbx (more info ...)trojan-activity    URL
16856BLACKLIST DNS request for known malware domain andy.cd - Backdoor.Win32.Agent.auto (more info ...)trojan-activity    URL
16857BLACKLIST DNS request for known malware domain site.mynet.com - Trojan.Win32.Buzus.dxsr (more info ...)trojan-activity    URL
16858BLACKLIST DNS request for known malware domain charter-x.biz - Packed.Win32.Krap.ae (more info ...)trojan-activity    URL
16859BLACKLIST DNS request for known malware domain gerherber.com - Trojan-Spy.Win32.Zbot.akdw (more info ...)trojan-activity    URL
16860BLACKLIST DNS request for known malware domain urodinam.net - Trojan.Win32.TDSS.azsj (more info ...)trojan-activity    URL
16861BLACKLIST DNS request for known malware domain gite-eguisheim.com - Trojan-Downloader.Win32.Piker.clp (more info ...)trojan-activity    URL
16862BLACKLIST DNS request for known malware domain phaizeipeu.ru - Packed.Win32.Krap.gx (more info ...)trojan-activity    URL
16863BLACKLIST DNS request for known malware domain teendx.com - Trojan-Spy.Win32.Zbot.gen (more info ...)trojan-activity    URL
16864BLACKLIST DNS request for known malware domain taiping2033.2288.org - Trojan-Downloader.Win32.Selvice.afy (more info ...)trojan-activity    URL
16865BLACKLIST DNS request for known malware domain cnfg.maxsitesrevenues.net - Trojan.Win32.BHO.afke (more info ...)trojan-activity    URL
16866BLACKLIST DNS request for known malware domain members.multimania.co.uk - Trojan.Win32.Inject.ahqv (more info ...)trojan-activity    URL
16867BLACKLIST DNS request for known malware domain down.toopc.com - Trojan-Dropper.Win32.Clons.hai (more info ...)trojan-activity    URL
16868BLACKLIST DNS request for known malware domain hostshack.net - Trojan.Win32.Buzus.empl (more info ...)trojan-activity    URL
16869BLACKLIST DNS request for known malware domain tt.vv49.com - Trojan-GameThief.Win32.OnLineGames.bnkb (more info ...)trojan-activity    URL
16870BLACKLIST DNS request for known malware domain search.sidegreen.com - Backdoor.Win32.Agent.arqi (more info ...)trojan-activity    URL
16871BLACKLIST DNS request for known malware domain parfaitpournous.com - Trojan-Spy.Win32.Zbot.gen (more info ...)trojan-activity    URL
16872BLACKLIST DNS request for known malware domain postmetoday.ru - Packed.Win32.Katusha.j (more info ...)trojan-activity    URL
16873BLACKLIST DNS request for known malware domain youword.cn - Trojan.Win32.Scar.bvgu (more info ...)trojan-activity    URL
16874BLACKLIST DNS request for known malware domain ophaeghaev.ru - Trojan-Spy.Win32.Zbot.akmi (more info ...)trojan-activity    URL
16875BLACKLIST DNS request for known malware domain up1.free-sms.co.kr - Trojan.Win32.Vilsel.akp (more info ...)trojan-activity    URL
16876BLACKLIST DNS request for known malware domain c.softdowns.info - Trojan.BAT.Agent.yn (more info ...)trojan-activity    URL
16877BLACKLIST DNS request for known malware domain ddkom.biz - Trojan.Win32.Scar.ckhr (more info ...)trojan-activity    URL
16878BLACKLIST DNS request for known malware domain vopret.ru - Trojan.Win32.FraudPack.axwn (more info ...)trojan-activity    URL
16879BLACKLIST DNS request for known malware domain dnfpomo.dnfranran.com - Trojan-GameThief.Win32.OnLineGames.bnkx (more info ...)trojan-activity    URL
16880BLACKLIST DNS request for known malware domain dnfuu.3322.org - Trojan-Downloader.Win32.Genome.asrx (more info ...)trojan-activity    URL
16881BLACKLIST DNS request for known malware domain sex-gifts.ru - Trojan-Spy.Win32.Zbot.gen (more info ...)trojan-activity    URL
16882BLACKLIST DNS request for known malware domain 111.168lala.com - Backdoor.Win32.Popwin.cyn (more info ...)trojan-activity    URL
16883BLACKLIST DNS request for known malware domain mcafee-registry.ru - Trojan-Spy.Win32.Zbot.akgb (more info ...)trojan-activity    URL
16884BLACKLIST DNS request for known malware domain bits4ever.ru - Trojan-Spy.Win32.Zbot.aknt (more info ...)trojan-activity    URL
16885BLACKLIST DNS request for known malware domain monicaecarlos.com - Trojan-Downloader.Win32.Genome.awxv (more info ...)trojan-activity    URL
16886BLACKLIST DNS request for known malware domain d.trymedia.com - Trojan-Dropper.Win32.Delf.fkk (more info ...)trojan-activity    URL
16888BLACKLIST DNS request for known malware domain dbtte.com - Trojan-Banker.Win32.Banz.crk (more info ...)trojan-activity    URL
16889BLACKLIST DNS request for known malware domain h1.ripway.com - Trojan.Win32.Refroso.bcdq (more info ...)trojan-activity    URL
16890BLACKLIST DNS request for known malware domain in6cs.com - Trojan.Win32.Tdss.beea (more info ...)trojan-activity    URL
16891BLACKLIST DNS request for known malware domain solo1928.ru - Trojan-Spy.Win32.Zbot.gen (more info ...)trojan-activity    URL
16892BLACKLIST DNS request for known malware domain fg545633.host.zgridc.com - Trojan.Win32.Pincav.abub (more info ...)trojan-activity    URL
16893BLACKLIST DNS request for known malware domain primusdns.ru - Backdoor.Win32.Havar.eh (more info ...)trojan-activity    URL
16894BLACKLIST DNS request for known malware domain eq.pccppc.com - Trojan-Downloader.Win32.Pher.fkl (more info ...)trojan-activity    URL
16895BLACKLIST DNS request for known malware domain alodh.in - Backdoor.Win32.Delf.vde (more info ...)trojan-activity    URL
16896BLACKLIST DNS request for known malware domain reward.pnshop.co.kr - Backdoor.Win32.Agent.ahra (more info ...)trojan-activity    URL
16897BLACKLIST DNS request for known malware domain sympathy.hdnews.net - Trojan-Spy.Win32.Zbot.gen (more info ...)trojan-activity    URL
16898BLACKLIST DNS request for known malware domain sx21.e4578.com - Trojan.Win32.Scar.ccqb (more info ...)trojan-activity    URL
16899BLACKLIST DNS request for known malware domain downloadering.9966.org - Trojan.Win32.Vilsel.adxv (more info ...)trojan-activity    URL
16900BLACKLIST DNS request for known malware domain reportes201.com - Trojan-Downloader.Win32.Genome.ashe (more info ...)trojan-activity    URL
16901BLACKLIST DNS request for known malware domain local.1140.co.kr - Trojan-Downloader.Win32.Genome.aobm (more info ...)trojan-activity    URL
16902BLACKLIST DNS request for known malware domain promojoy.net - Packed.Win32.Krap.gx (more info ...)trojan-activity    URL
16903BLACKLIST DNS request for known malware domain gpwg.ws - Worm.Win32.AutoRun.bjca (more info ...)trojan-activity    URL
16904BLACKLIST DNS request for known malware domain xoomer.alice.it - Trojan-Downloader.Win32.Banload.kdu (more info ...)trojan-activity    URL
16905BLACKLIST DNS request for known malware domain xoomer.virgilio.it - Backdoor.Win32.Clar.d (more info ...)trojan-activity    URL
16906BLACKLIST DNS request for known malware domain down.p2pplay.com - Trojan-GameThief.Win32.OnLineGames.wgkv (more info ...)trojan-activity    URL
16907BLACKLIST DNS request for known malware domain livetrust.info - Trojan-Spy.Win32.Zbot.akku (more info ...)trojan-activity    URL
16908BLACKLIST DNS request for known malware domain ootaivilei.ru - Trojan-Spy.Win32.Zbot.akme (more info ...)trojan-activity    URL
16909BLACKLIST DNS request for known malware domain babah20122012.com - Trojan-Spy.Win32.Zbot.akbb (more info ...)trojan-activity    URL
16910BLACKLIST DNS request for known malware domain pattern - 0-0-0-0-0-0-0.info (more info ...)trojan-activity    URL
17047NETBIOS Microsoft Windows DNS Server RPC management interface buffer overflow attempt (more info ...)attempted-admin 2007-1748 23470  URL
17818BLACKLIST DNS request for known malware domain ktr.t134.net (more info ...)trojan-activity    URL
17819BLACKLIST DNS request for known malware domain motuh.com (more info ...)trojan-activity    URL
17820BLACKLIST DNS request for known malware domain myanimalclips.com (more info ...)trojan-activity    URL
17821BLACKLIST DNS request for known malware domain ketsymbol.com (more info ...)trojan-activity    URL
17822BLACKLIST DNS request for known malware domain ics.hotbar.com (more info ...)trojan-activity    URL
17823BLACKLIST DNS request for known malware domain www.myroitracking.com (more info ...)trojan-activity    URL
17824BLACKLIST DNS request for known malware domain teenxmovs.net (more info ...)trojan-activity    URL
17825BLACKLIST DNS request for known malware domain px.smowtion.com (more info ...)trojan-activity    URL
17826BLACKLIST DNS request for known malware domain cheaps1.info (more info ...)trojan-activity    URL
17827BLACKLIST DNS request for known malware domain sexmoviesland.net (more info ...)trojan-activity    URL
17828BLACKLIST DNS request for known malware domain 67.201.36.16 (more info ...)trojan-activity    URL
17829BLACKLIST DNS request for known malware domain c7.zxxds.net (more info ...)trojan-activity    URL
17830BLACKLIST DNS request for known malware domain dickvsclit.net (more info ...)trojan-activity    URL
17831BLACKLIST DNS request for known malware domain edrichfinearts.com (more info ...)trojan-activity    URL
17832BLACKLIST DNS request for known malware domain img100.xvideos.com (more info ...)trojan-activity    URL
17833BLACKLIST DNS request for known malware domain www.dsnextgen.com (more info ...)trojan-activity    URL
17834BLACKLIST DNS request for known malware domain 343.boolans.com (more info ...)trojan-activity    URL
17835BLACKLIST DNS request for known malware domain xpresdnet.com (more info ...)trojan-activity    URL
17836BLACKLIST DNS request for known malware domain gbsup.com (more info ...)trojan-activity    URL
17837BLACKLIST DNS request for known malware domain xxsmovies.com (more info ...)trojan-activity    URL
17838BLACKLIST DNS request for known malware domain vc.iwriteweb.com (more info ...)trojan-activity    URL
17839BLACKLIST DNS request for known malware domain js.222233.com (more info ...)trojan-activity    URL
17840BLACKLIST DNS request for known malware domain www.grannyplanet.com (more info ...)trojan-activity    URL
17841BLACKLIST DNS request for known malware domain coop.crwdcntrl.net (more info ...)trojan-activity    URL
17842BLACKLIST DNS request for known malware domain extrahotx.net (more info ...)trojan-activity    URL
17843BLACKLIST DNS request for known malware domain extralargevideos.com (more info ...)trojan-activity    URL
17844BLACKLIST DNS request for known malware domain www.derquda.com (more info ...)trojan-activity    URL
17845BLACKLIST DNS request for known malware domain aahydrogen.com (more info ...)trojan-activity    URL
17846BLACKLIST DNS request for known malware domain trumpetlicks.com (more info ...)trojan-activity    URL
17847BLACKLIST DNS request for known malware domain mskla.com (more info ...)trojan-activity    URL
17848BLACKLIST DNS request for known malware domain play.unionsky.cn (more info ...)trojan-activity    URL
17849BLACKLIST DNS request for known malware domain fuckersucker.com (more info ...)trojan-activity    URL
17850BLACKLIST DNS request for known malware domain pornfucklist.com (more info ...)trojan-activity    URL
17851BLACKLIST DNS request for known malware domain game.685faiudeme.com (more info ...)trojan-activity    URL
17852BLACKLIST DNS request for known malware domain 447.cc (more info ...)trojan-activity    URL
17853BLACKLIST DNS request for known malware domain dommonview.com (more info ...)trojan-activity    URL
17854BLACKLIST DNS request for known malware domain www.lamiaexragazza.com (more info ...)trojan-activity    URL
17855BLACKLIST DNS request for known malware domain acofinder.com (more info ...)trojan-activity    URL
17856BLACKLIST DNS request for known malware domain fuckfuckvids.com (more info ...)trojan-activity    URL
17857BLACKLIST DNS request for known malware domain www.cnhack.cn (more info ...)trojan-activity    URL
17858BLACKLIST DNS request for known malware domain kingsizematures.com (more info ...)trojan-activity    URL
17859BLACKLIST DNS request for known malware domain promotds.com (more info ...)trojan-activity    URL
17860BLACKLIST DNS request for known malware domain mejac.com (more info ...)trojan-activity    URL
17861BLACKLIST DNS request for known malware domain zq2.9wee.com (more info ...)trojan-activity    URL
17862BLACKLIST DNS request for known malware domain 122.770304123.cn (more info ...)trojan-activity    URL
17863BLACKLIST DNS request for known malware domain rpt2.21civ.com (more info ...)trojan-activity    URL
17864BLACKLIST DNS request for known malware domain tubexxxmatures.com (more info ...)trojan-activity    URL
17865BLACKLIST DNS request for known malware domain 110.770304123.cn (more info ...)trojan-activity    URL
17866BLACKLIST DNS request for known malware domain aebankonline.com (more info ...)trojan-activity    URL
17867BLACKLIST DNS request for known malware domain utm.trk.myfuncards.com (more info ...)trojan-activity    URL
17868BLACKLIST DNS request for known malware domain a.qq2233.com (more info ...)trojan-activity    URL
17869BLACKLIST DNS request for known malware domain px.mgplatform.com (more info ...)trojan-activity    URL
17870BLACKLIST DNS request for known malware domain trojan8.com (more info ...)trojan-activity    URL
17871BLACKLIST DNS request for known malware domain brutalxvideos.com (more info ...)trojan-activity    URL
17872BLACKLIST DNS request for known malware domain www3.sexown.com (more info ...)trojan-activity    URL
17873BLACKLIST DNS request for known malware domain mummimpegs.com (more info ...)trojan-activity    URL
17874BLACKLIST DNS request for known malware domain f19dd4abb8b8bdf2.cn (more info ...)trojan-activity    URL
17875BLACKLIST DNS request for known malware domain www.very-young-boys.com (more info ...)trojan-activity    URL
17876BLACKLIST DNS request for known malware domain 91629.com (more info ...)trojan-activity    URL
17877BLACKLIST DNS request for known malware domain animal36.com (more info ...)trojan-activity    URL
17878BLACKLIST DNS request for known malware domain ayb.host127-0-0-1.com (more info ...)trojan-activity    URL
17879BLACKLIST DNS request for known malware domain cfg.353wanwan.com (more info ...)trojan-activity    URL
17880BLACKLIST DNS request for known malware domain www.027dj.com (more info ...)trojan-activity    URL
17881BLACKLIST DNS request for known malware domain fucktosky.com (more info ...)trojan-activity    URL
17882BLACKLIST DNS request for known malware domain procca.com (more info ...)trojan-activity    URL
17883BLACKLIST DNS request for known malware domain autouploaders.net (more info ...)trojan-activity    URL
17884BLACKLIST DNS request for known malware domain gimmemyporn.com (more info ...)trojan-activity    URL
17885BLACKLIST DNS request for known malware domain waytoall.com (more info ...)trojan-activity    URL
17886BLACKLIST DNS request for known malware domain www.spamature.com (more info ...)trojan-activity    URL
17887BLACKLIST DNS request for known malware domain info.collectionerrorreport.com (more info ...)trojan-activity    URL
17888BLACKLIST DNS request for known malware domain bn.xp1.ru4.com (more info ...)trojan-activity    URL
17889BLACKLIST DNS request for known malware domain www.ajie520.com (more info ...)trojan-activity    URL
17890BLACKLIST DNS request for known malware domain 114search1.118114.cn (more info ...)trojan-activity    URL
17891BLACKLIST DNS request for known malware domain bestkind.ru (more info ...)trojan-activity    URL
17892BLACKLIST DNS request for known malware domain clickpotato.tv (more info ...)trojan-activity    URL
17893BLACKLIST DNS request for known malware domain www.zxc0001.com (more info ...)trojan-activity    URL
17894BLACKLIST DNS request for known malware domain streq.cn (more info ...)trojan-activity    URL
17895BLACKLIST DNS request for known malware domain pyow.prixi-soft.ir (more info ...)trojan-activity    URL
17896BLACKLIST DNS request for known malware domain 113552url.cptgt.com (more info ...)trojan-activity    URL
17897BLACKLIST DNS request for known malware domain www.moneytw8.com (more info ...)trojan-activity    URL
18079BLACKLIST DNS request for known malware domain jsshmz.gotoip4.com (more info ...)trojan-activity    
18080BLACKLIST DNS request for known malware domain netrand.house.sina.com.cn (more info ...)trojan-activity    
18081BLACKLIST DNS request for known malware domain wenyixuan.3322.org (more info ...)trojan-activity    
18082BLACKLIST DNS request for known malware domain 3q.sbwanwan.com (more info ...)trojan-activity    
18083BLACKLIST DNS request for known malware domain 863.dclsba.com (more info ...)trojan-activity    
18084BLACKLIST DNS request for known malware domain drs317a.gotoip4.com (more info ...)trojan-activity    
18085BLACKLIST DNS request for known malware domain jsshmz.gotoip4.com (more info ...)trojan-activity    
18086BLACKLIST DNS request for known malware domain qq.sbwanwan.com (more info ...)trojan-activity    
18087BLACKLIST DNS request for known malware domain tiantianzaixian.gotoip1.com (more info ...)trojan-activity    
18088BLACKLIST DNS request for known malware domain wenyixuan.3322.org (more info ...)trojan-activity    
18089BLACKLIST DNS request for known malware domain www.auto328.com (more info ...)trojan-activity    
18090BLACKLIST DNS request for known malware domain www.comstelecom.com (more info ...)trojan-activity    
18091BLACKLIST DNS request for known malware domain www.goodfriends.or.kr (more info ...)trojan-activity    
18092BLACKLIST DNS request for known malware domain www.hao1345.com (more info ...)trojan-activity    
18093BLACKLIST DNS request for known malware domain www.opusgame.com (more info ...)trojan-activity    
18094BLACKLIST DNS request for known malware domain www.theoffstage.com (more info ...)trojan-activity    
18095BLACKLIST DNS request for known malware domain www.wwmei.com (more info ...)trojan-activity    
18103BLACKLIST DNS request for known malware domain 5yvod.net (more info ...)trojan-activity 2010-3962   
18104BLACKLIST DNS request for known malware domain b.9s3.info (more info ...)trojan-activity 2010-3962   
18105BLACKLIST DNS request for known malware domain baidutaobao.gotoip55.com (more info ...)trojan-activity 2010-3962   
18106BLACKLIST DNS request for known malware domain e.msssm.com (more info ...)trojan-activity 2010-3962   
18107BLACKLIST DNS request for known malware domain jsshmz.gotoip4.com (more info ...)trojan-activity 2010-3962   
18108BLACKLIST DNS request for known malware domain phoroshop.es (more info ...)trojan-activity 2010-3962   
18109BLACKLIST DNS request for known malware domain talk.cetizen.com (more info ...)trojan-activity 2010-3962   
18110BLACKLIST DNS request for known malware domain tiantianzaixian.gotoip1.com (more info ...)trojan-activity 2010-3962   
18111BLACKLIST DNS request for known malware domain v.9y9c.co.cc (more info ...)trojan-activity 2010-3962   
18112BLACKLIST DNS request for known malware domain wenyixuan.3322.org. (more info ...)trojan-activity 2010-3962   
18113BLACKLIST DNS request for known malware domain wusheng03.3322.org (more info ...)trojan-activity 2010-3962   
18114BLACKLIST DNS request for known malware domain www.5fqq.com (more info ...)trojan-activity 2010-3962   
18115BLACKLIST DNS request for known malware domain www.ajs2002.com (more info ...)trojan-activity 2010-3962   
18116BLACKLIST DNS request for known malware domain www.bnbsoft.co.kr (more info ...)trojan-activity 2010-3962   
18117BLACKLIST DNS request for known malware domain www.cineseoul.com (more info ...)trojan-activity 2010-3962   
18118BLACKLIST DNS request for known malware domain www.hao1345.com (more info ...)trojan-activity 2010-3962   
18119BLACKLIST DNS request for known malware domain www.ilbondrama.net (more info ...)trojan-activity 2010-3962   
18120BLACKLIST DNS request for known malware domain www.iwebdy.net (more info ...)trojan-activity 2010-3962   
18121BLACKLIST DNS request for known malware domain www.linzhiling123.com (more info ...)trojan-activity 2010-3962   
18122BLACKLIST DNS request for known malware domain www.opusgame.com (more info ...)trojan-activity 2010-3962   
18123BLACKLIST DNS request for known malware domain www.phoroshop.es (more info ...)trojan-activity 2010-3962   
18124BLACKLIST DNS request for known malware domain www.sijianfeng.com (more info ...)trojan-activity 2010-3962   
18125BLACKLIST DNS request for known malware domain www.tpydb.com (more info ...)trojan-activity 2010-3962   
18126BLACKLIST DNS request for known malware domain www.tpydb.com (more info ...)trojan-activity 2010-3962   
18127BLACKLIST DNS request for known malware domain www.univus.co.kr (more info ...)trojan-activity 2010-3962   
18128BLACKLIST DNS request for known malware domain www.uwonderfull.com (more info ...)trojan-activity 2010-3962   
18129BLACKLIST DNS request for known malware domain www.w22rt.com (more info ...)trojan-activity 2010-3962   
18130BLACKLIST DNS request for known malware domain www.wwmei.com (more info ...)trojan-activity 2010-3962   
18131BLACKLIST DNS request for known malware domain www.ybtour.co.kr (more info ...)trojan-activity 2010-3962   
18133BLACKLIST DNS request for known malware domain www.001zs.com (more info ...)trojan-activity 2010-3962   
18134BLACKLIST DNS request for known malware domain www.551sf.com (more info ...)trojan-activity 2010-3962   
18135BLACKLIST DNS request for known malware domain www.555hd.com (more info ...)trojan-activity 2010-3962   
18136BLACKLIST DNS request for known malware domain www.66xihu.com (more info ...)trojan-activity 2010-3962   
18137BLACKLIST DNS request for known malware domain www.9292cs.cn (more info ...)trojan-activity 2010-3962   
18138BLACKLIST DNS request for known malware domain www.chateaulegend.com (more info ...)trojan-activity 2010-3962   
18139BLACKLIST DNS request for known malware domain www.china-aoben.com (more info ...)trojan-activity 2010-3962   
18140BLACKLIST DNS request for known malware domain www.cqtjg.com (more info ...)trojan-activity 2010-3962   
18141BLACKLIST DNS request for known malware domain www.dspenter.com (more info ...)trojan-activity 2010-3962   
18142BLACKLIST DNS request for known malware domain www.eastadmin.com (more info ...)trojan-activity 2010-3962   
18143BLACKLIST DNS request for known malware domain www.fp0755.cn (more info ...)trojan-activity 2010-3962   
18144BLACKLIST DNS request for known malware domain www.fp0769.com (more info ...)trojan-activity 2010-3962   
18145BLACKLIST DNS request for known malware domain www.fp360.net (more info ...)trojan-activity 2010-3962   
18146BLACKLIST DNS request for known malware domain www.gdfp365.cn (more info ...)trojan-activity 2010-3962   
18147BLACKLIST DNS request for known malware domain www.gev.cn (more info ...)trojan-activity 2010-3962   
18148BLACKLIST DNS request for known malware domain www.haoleyou.com (more info ...)trojan-activity 2010-3962   
18149BLACKLIST DNS request for known malware domain www.haosf08.com (more info ...)trojan-activity 2010-3962   
18150BLACKLIST DNS request for known malware domain www.jxbaike.com (more info ...)trojan-activity 2010-3962   
18151BLACKLIST DNS request for known malware domain www.kingsoftduba2009.com (more info ...)trojan-activity 2010-3962   
18152BLACKLIST DNS request for known malware domain www.mainhu.com (more info ...)trojan-activity 2010-3962   
18153BLACKLIST DNS request for known malware domain www.maoyiren.com (more info ...)trojan-activity 2010-3962   
18154BLACKLIST DNS request for known malware domain www.nc57.com (more info ...)trojan-activity 2010-3962   
18155BLACKLIST DNS request for known malware domain www.pplog.cn (more info ...)trojan-activity 2010-3962   
18156BLACKLIST DNS request for known malware domain www.pxflm.com (more info ...)trojan-activity 2010-3962   
18157BLACKLIST DNS request for known malware domain www.quyou365.com (more info ...)trojan-activity 2010-3962   
18158BLACKLIST DNS request for known malware domain www.shzhaotian.cn (more info ...)trojan-activity 2010-3962   
18159BLACKLIST DNS request for known malware domain www.soanala.com (more info ...)trojan-activity 2010-3962   
18160BLACKLIST DNS request for known malware domain www.stony-skunk.com (more info ...)trojan-activity 2010-3962   
18161BLACKLIST DNS request for known malware domain www.street08.com (more info ...)trojan-activity 2010-3962   
18162BLACKLIST DNS request for known malware domain www.weilingcy.com (more info ...)trojan-activity 2010-3962   
18163BLACKLIST DNS request for known malware domain www.yisaa.com (more info ...)trojan-activity 2010-3962   
18164BLACKLIST DNS request for known malware domain www.yx240.com (more info ...)trojan-activity 2010-3962   
18165BLACKLIST DNS request for known malware domain e.mssm.com (more info ...)trojan-activity 2010-3962   
18166BLACKLIST DNS request for known malware domain dfgdd.9y6c.co.cc (more info ...)trojan-activity 2010-3962   
18183BLACKLIST DNS request for known malware domain mailzou.com (more info ...)trojan-activity 2010-3962   
18184BLACKLIST DNS request for known malware domain dnf.gametime.co.kr (more info ...)trojan-activity 2010-3962   
18185BLACKLIST DNS request for known malware domain www.dd0415.net (more info ...)trojan-activity 2010-3962   

 goto Top

Group: Server / Misc / FTP

# of attack rules in this group: 39

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1941TFTP GET filename overflow attempt (more info ...)attempted-admin  2009-2957  5328  18264  
2338FTP LIST buffer overflow attempt (more info ...)misc-attack  2009-0351  9675    URL
2374FTP NLST overflow attempt (more info ...)attempted-admin  2009-3023  7909    URL
5881SPYWARE-PUT Keylogger spyagent runtime detect - ftp delivery (more info ...)successful-recon-limited        URL
6142BACKDOOR hellzaddiction v1.0e runtime detection - ftp open (more info ...)trojan-activity        URL
6208SPYWARE-PUT Keylogger winsession runtime detection - ftp (more info ...)successful-recon-limited        URL
6288BACKDOOR fictional daemon 4.4 runtime detection - ftp (more info ...)trojan-activity        URL
6319BACKDOOR evilftp runtime detection - init connection (more info ...)trojan-activity        URL
7185SPYWARE-PUT Keylogger 007 spy software runtime detection - ftp (more info ...)successful-recon-limited        URL
7504SPYWARE-PUT Keylogger actualspy runtime detection - ftp-data (more info ...)successful-recon-limited        URL
7762BACKDOOR analftp 0.1 runtime detection - icq notification (more info ...)trojan-activity        URL
7934WEB-ACTIVEX ftp Asychronous Pluggable Protocol Handler ActiveX clsid access (more info ...)attempted-user  2007-0218      URL
7935WEB-ACTIVEX ftp Asychronous Pluggable Protocol Handler ActiveX clsid unicode access (more info ...)attempted-user  2007-0218      URL
9341SPECIFIC-THREATS sasser open ftp command shell (more info ...)trojan-activity        URL
9402SPECIFIC-THREATS welchia tftp propagation detection (more info ...)trojan-activity        URL
9828SPYWARE-PUT Keylogger paq keylog runtime detection - ftp (more info ...)successful-recon-limited        URL
10089SPYWARE-PUT Keylogger beyond Keylogger runtime detection - log sent by ftp (more info ...)successful-recon-limited        URL
10135DOS Squid proxy FTP denial of service attempt (more info ...)denial-of-service  2007-0247  22079    
10444BACKDOOR acidbattery 1.0 runtime detection - open ftp serice (more info ...)trojan-activity        URL
12237BACKDOOR theef 2.10 runtime detection - ftp (more info ...)trojan-activity        
13927TFTP Server log generation buffer overflow attempt (more info ...)attempted-admin  2008-2161      
14778WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX clsid access (more info ...)attempted-user    31814    
14779WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX clsid unicode access (more info ...)attempted-user    31814    
14780WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX function call access (more info ...)attempted-user    31814    
14781WEB-ACTIVEX Dart Communications PowerTCP FTP ActiveX function call unicode access (more info ...)attempted-user    31814    
15159WEB-ACTIVEX Evans FTP ActiveX clsid access (more info ...)attempted-user    32814    
15160WEB-ACTIVEX Evans FTP ActiveX clsid unicode access (more info ...)attempted-user    32814    
15161WEB-ACTIVEX Evans FTP ActiveX function call access (more info ...)attempted-user    32814    
15162WEB-ACTIVEX Evans FTP ActiveX function call unicode access (more info ...)attempted-user    32814    
15368WEB-ACTIVEX FathFTP ActiveX clsid access (more info ...)attempted-user    33842    
15369WEB-ACTIVEX FathFTP ActiveX clsid unicode access (more info ...)attempted-user    33842    
15370WEB-ACTIVEX FathFTP ActiveX function call access (more info ...)attempted-user    33842    
15371WEB-ACTIVEX FathFTP ActiveX function call unicode access (more info ...)attempted-user    33842    
15932FTP LIST globbing denial of service attack (more info ...)attempted-dos  2009-2521      URL
16077SPECIFIC-THREATS Tripwire format string vulnerability ftp exploit attempt (more info ...)attempted-admin  2004-0536  10454    
16357FTP multiple extension code execution attempt (more info ...)web-application-attack  2009-4444      
17059FTP Vermillion 1.31 vftpd port command memory corruption (more info ...)misc-attack        URL
17446SPECIFIC-THREATS Microsoft Internet Explorer FTP client directory traversal attempt (more info ...)misc-activity  2004-1376      
17521SPECIFIC-THREATS GoodTech SSH Server SFTP Processing Buffer Overflow (more info ...)attempted-user  2008-4726  31879    


# of warning rules in this group: 123

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
144FTP ADMw0rm ftp login attempt (more info ...)suspicious-login    
157BACKDOOR BackConstruction 2.1 Client FTP Open Request (more info ...)misc-activity    
158BACKDOOR BackConstruction 2.1 Server FTP Open Reply (more info ...)misc-activity    
308EXPLOIT NextFTP client overflow (more info ...)attempted-user 1999-0671 572  
334FTP .forward (more info ...)suspicious-filename-detect    
335FTP .rhosts (more info ...)suspicious-filename-detect    
336FTP CWD ~root attempt (more info ...)bad-unknown 1999-0082   
337FTP CEL overflow attempt (more info ...)attempted-admin 1999-0789 679 10009 
353FTP adm scan (more info ...)suspicious-login    
354FTP iss scan (more info ...)suspicious-login    
355FTP pass wh00t (more info ...)suspicious-login    
356FTP passwd retrieval attempt (more info ...)suspicious-filename-detect    
357FTP piss scan (more info ...)suspicious-login    URL
358FTP saint scan (more info ...)suspicious-login    
359FTP satan scan (more info ...)suspicious-login    
360FTP serv-u directory transversal (more info ...)bad-unknown 2001-0054 2052 10565 
361FTP SITE EXEC attempt (more info ...)bad-unknown 1999-0955 2241  
362FTP tar parameters (more info ...)bad-unknown 1999-0997 2240  
489FTP no password (more info ...)unknown    
491FTP Bad login (more info ...)bad-unknown    
518TFTP Put (more info ...)bad-unknown 1999-0183   
519TFTP parent directory (more info ...)bad-unknown 2002-1209   
520TFTP root directory (more info ...)bad-unknown 1999-0183   
1068WEB-MISC tftp attempt (more info ...)web-application-activity    
1107WEB-MISC ftp.pl access (more info ...)web-application-activity 2000-0674 1471 10467 
1166WEB-MISC ws_ftp.ini access (more info ...)attempted-recon 1999-1078 547  
1229FTP CWD ... (more info ...)bad-unknown  9237  
1230WEB-MISC VirusWall FtpSave access (more info ...)attempted-recon 2001-0432 2808 10733 
1234WEB-MISC VirusWall FtpSaveCSP access (more info ...)attempted-recon 2001-0432 2808 10733 
1235WEB-MISC VirusWall FtpSaveCVP access (more info ...)attempted-recon 2001-0432 2808 10733 
1289TFTP GET Admin.dll (more info ...)successful-admin    URL
1377FTP wu-ftp bad file completion attempt [ (more info ...)misc-attack 2001-0886 3707 10821 
1379FTP STAT overflow attempt (more info ...)attempted-admin 2003-0772 8542  URL
1441TFTP GET nc.exe (more info ...)successful-admin    
1442TFTP GET shadow (more info ...)successful-admin    
1443TFTP GET passwd (more info ...)successful-admin    
1444TFTP Get (more info ...)bad-unknown    
1529FTP SITE overflow attempt (more info ...)attempted-admin 2001-0770   
1562FTP SITE CHOWN overflow attempt (more info ...)attempted-admin 2001-0065 2120 10579 
1612WEB-MISC ftp.pl attempt (more info ...)web-application-attack 2000-0674 1471 10467 
1621FTP CMD overflow attempt (more info ...)attempted-admin    
1622FTP RNFR ././ attempt (more info ...)misc-attack 1999-0081   
1623FTP invalid MODE (more info ...)protocol-command-decode    URL
1624FTP PWD overflow attempt (more info ...)protocol-command-decode    
1625FTP SYST overflow attempt (more info ...)protocol-command-decode    URL
1662WEB-MISC /~ftp access (more info ...)attempted-recon    
1670WEB-MISC /home/ftp access (more info ...)web-application-activity   11032 
1672FTP CWD ~ attempt (more info ...)denial-of-service 2001-0421 9215  
1734FTP USER overflow attempt (more info ...)attempted-admin 2005-3683 8376  
1777FTP EXPLOIT STAT * dos attempt (more info ...)attempted-dos 2002-0073 4482 10934 URL
1778FTP EXPLOIT STAT ? dos attempt (more info ...)attempted-dos 2002-0073 4482 10934 URL
1864FTP SITE NEWER attempt (more info ...)attempted-dos 1999-0880  10319 
1888FTP SITE CPWD overflow attempt (more info ...)misc-attack 2002-0826 5427  
1919FTP CWD overflow attempt (more info ...)attempted-admin 2002-0405 7950  
1920FTP SITE NEWER overflow attempt (more info ...)attempted-admin 1999-0800 229  
1921FTP SITE ZIPCHK overflow attempt (more info ...)attempted-admin 2000-0040   
1927FTP authorized_keys (more info ...)suspicious-filename-detect    
1928FTP shadow retrieval attempt (more info ...)suspicious-filename-detect    
1942FTP RMDIR overflow attempt (more info ...)attempted-admin  819  
1971FTP SITE EXEC format string attempt (more info ...)bad-unknown  1505  
1972FTP PASS overflow attempt (more info ...)attempted-admin 2005-3683 9285  
1973FTP MKD overflow attempt (more info ...)attempted-admin 2010-0625 9872 12108 URL
1974FTP REST overflow attempt (more info ...)attempted-admin 2001-0826 2972 11755 
1976FTP RMD overflow attempt (more info ...)attempted-admin 2010-0625 39041  
1992FTP LIST directory traversal attempt (more info ...)protocol-command-decode 2002-1054 2618 11112 
2125FTP CWD Root directory transversal attempt (more info ...)protocol-command-decode 2003-0392 7674 11677 
2178FTP USER format string attempt (more info ...)misc-attack 2004-0277 9800 11687 
2179FTP PASS format string attempt (more info ...)misc-attack 2000-0699 9800 10490 
2272FTP LIST integer overflow attempt (more info ...)misc-attack 2003-0854 8875 11912 
2332FTP MKD format string attempt (more info ...)misc-attack  9262  
2333FTP RENAME format string attempt (more info ...)misc-attack  9262  
2334FTP Yak! FTP server default account login attempt (more info ...)suspicious-login  9072  
2335FTP RMD / attempt (more info ...)attempted-dos  9159  
2337TFTP PUT filename overflow attempt (more info ...)attempted-admin 2003-0380 8505 18264 
2339TFTP NULL command attempt (more info ...)bad-unknown  7575  
2340FTP SITE CHMOD overflow attempt (more info ...)attempted-admin 1999-0838 9675 12037 
2343FTP STOR overflow attempt (more info ...)attempted-admin 2000-0133 8668  
2344FTP XCWD overflow attempt (more info ...)attempted-admin  8704  
2373FTP XMKD overflow attempt (more info ...)attempted-admin 2001-1021 7909  
2389FTP RNTO overflow attempt (more info ...)attempted-admin 2005-3683 8315  
2390FTP STOU overflow attempt (more info ...)attempted-admin 2003-0466 8315  
2391FTP APPE overflow attempt (more info ...)attempted-admin 2003-0772 8542  
2392FTP RETR overflow attempt (more info ...)attempted-admin 2005-3683 8315  
2416FTP invalid MDTM command attempt (more info ...)attempted-admin 2004-0330 9751  
2417FTP format string attempt (more info ...)string-detect 2005-2123 9800  
2449FTP ALLO overflow attempt (more info ...)attempted-admin 2004-1883 9953 14598 
2546FTP MDTM overflow attempt (more info ...)attempted-admin 2004-0330 9751 12080 
2574FTP RETR format string attempt (more info ...)attempted-admin 2004-1883 9800  
3077FTP RNFR overflow attempt (more info ...)attempted-admin  14339  
3441FTP PORT bounce attempt (more info ...)misc-attack 1999-0017 126 10081 
3460FTP REST with numeric argument (more info ...)attempted-recon  7825  
3523FTP SITE INDEX format string attempt (more info ...)bad-unknown 2000-0573 1387  
3526ORACLE XDB FTP UNLOCK overflow attempt (more info ...)attempted-admin 2003-0727 8375  
3532ORACLE ftp password buffer overflow attempt (more info ...)attempted-user 2003-0727 8375  
3630ORACLE ftp TEST command buffer overflow attempt (more info ...)misc-attack 2003-0727 8375  
3631ORACLE ftp user name buffer overflow attempt (more info ...)attempted-user 2003-0727 8375  
3817TFTP GET transfer mode overflow attempt (more info ...)attempted-admin 2005-1812 13821  
3818TFTP PUT transfer mode overflow attempt (more info ...)attempted-admin 2006-6183 21301  
8415FTP SIZE overflow attempt (more info ...)attempted-admin 2006-4318 19617  
8479FTP HELP overflow attempt (more info ...)attempted-admin 2001-0826 2972  
8480FTP PORT overflow attempt (more info ...)attempted-admin 2006-2226 18711  
8481FTP Microsoft NLST * dos attempt (more info ...)attempted-dos 2001-0334 2717  URL
8707FTP WZD-FTPD SITE arbitrary command execution attempt (more info ...)attempted-admin 2005-3081 14935  
9621TFTP 3COM server transport mode buffer overflow attempt (more info ...)attempted-admin  21301  
9638TFTP PUT Microsoft RIS filename overwrite attempt (more info ...)policy-violation 2006-5584   URL
9792FTP PASV overflow attempt (more info ...)attempted-admin    URL
10188FTP Wsftp XMD5 overflow attempt (more info ...)attempted-admin 2006-5000 20076  
12076DOS Ipswitch WS_FTP log server long unicode string (more info ...)denial-of-service 2007-3823   URL
12238BACKDOOR theef 2.10 runtime detection - ftp (more info ...)trojan-activity    URL
12379SPYWARE-PUT Keylogger PaqKeylogger 5.1 runtime detection - ftp (more info ...)successful-recon-limited    URL
13925FTP Computer Associates eTrust Secure Content Manager PASV stack overflow attempt (more info ...)attempted-user 2008-2541   
14743FTP RNTO directory traversal attempt (more info ...)suspicious-filename-detect 2008-4501 31563  
16697FTP httpdx USER null byte denial of service (more info ...)attempted-dos    URL
16698FTP httpdx PASS null byte denial of service (more info ...)attempted-dos    URL
16795DOS Google Chrome FTP handling out-of-bounds array index denial of service attempt (more info ...)attempted-dos  39183  
16806BACKDOOR Backdoor.Win32.Qakbot.E - FTP upload seclog (more info ...)trojan-activity    URL
16807BACKDOOR Backdoor.Win32.Qakbot.E - FTP Upload ps_dump (more info ...)trojan-activity    URL
17329FTP EPRT overflow attempt (more info ...)attempted-admin 2005-4459 15998  
17367FTP Microsoft Internet Explorer FTP Response Parsing Memory Corruption (more info ...)web-application-attack 2007-0217 22489  
17518FTP FlashGet PWD command stack buffer overflow attempt (more info ...)attempted-user 2008-4321 30685  
17712SPECIFIC-THREATS TFTP PUT Microsoft RIS filename overwrite attempt (more info ...)policy-violation 2006-5584   URL
18181SPECIFIC-THREATS ProFTPd 1.3.3c backdoor activity (more info ...)trojan-activity    URL
18182SPECIFIC-THREATS ProFTPd 1.3.3c backdoor help access attempt (more info ...)trojan-activity    URL

 goto Top

Group: Server / Misc / SSH

# of attack rules in this group: 0

# of warning rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1326EXPLOIT ssh CRC32 overflow NOOP (more info ...)shellcode-detect 2001-0572 2347  
1638SCAN SSH Version map attempt (more info ...)network-scan    
1810SPECIFIC-THREATS successful gobbles ssh exploit GOBBLE (more info ...)successful-admin 2002-0640 5093  
1811SPECIFIC-THREATS successful gobbles ssh exploit uname (more info ...)misc-attack 2002-0640 5093 11031 
1812EXPLOIT gobbles SSH exploit attempt (more info ...)misc-attack 2002-0639 5093 11031 
1838EXPLOIT SSH server banner overflow (more info ...)misc-attack 2002-1059 5287 15822 
13814BACKDOOR passhax runtime detection - initial connection (more info ...)trojan-activity    URL
17317SPECIFIC-THREATS OpenSSH sshd Identical Blocks DOS attempt (more info ...)attempted-admin 2006-4924 20216  

 goto Top

Group: Server / Misc / Backup

# of attack rules in this group: 19

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
6010EXPLOIT VERITAS NetBackup vnetd connection attempt (more info ...)protocol-command-decode        
6404EXPLOIT Veritas NetBackup Volume Manager connection attempt (more info ...)protocol-command-decode        
12667EXPLOIT CA BrightStor ARCServer malicious fileupload attempt (more info ...)attempted-admin  2007-5005  24348    
12784EXPLOIT CA ARCserve Backup for Laptops rsxGetBackupLog second argument overflow (more info ...)attempted-admin  2007-3216  24348    
12785EXPLOIT CA ARCserve Backup for Laptops rsxGetBackupComplete overflow attemp (more info ...)attempted-admin  2007-3216  24348    
12786EXPLOIT CA ARCserve Backup for Laptops rxsSetDataGrowthScheduleAndFilter overflow attempt (more info ...)attempted-admin  2007-3216  24348    
12787EXPLOIT CA ARCserve Backup for Laptops rxsSetDefaultConfigName overflow attempt (more info ...)attempted-admin  2007-3216  24348    
12788EXPLOIT CA ARCserve Backup for Laptops rxsSetDefaultConfigName overflow attempt (more info ...)attempted-admin  2007-3216  24348    
12904EXPLOIT Veritas NetBackup vmd shared library buffer overflow attempt (more info ...)attempted-admin  2005-3116  15353    
13552EXPLOIT Symantec VERITAS Storage Foundation Suite buffer overflow attempt (more info ...)attempted-admin  2008-0638  25778    URL
13800EXPLOIT ARCServe LGServer service data overflow attempt (more info ...)attempted-admin  2008-1328  28616    
13846SPECIFIC-THREATS Veritas Backup Agent password overflow attempt (more info ...)attempted-admin  2005-0773      
14741EXPLOIT Symantec Veritas Foundation Service NULL service authentication attempt (more info ...)attempted-admin  2007-2279      
14768MISC Symantec Veritas Storage Scheduler Service NULL Session auth bypass attempt (more info ...)attempted-user  2008-3703  30596    
14773SPECIFIC-THREATS CA ARCserve LGServer handshake buffer overflow attempt (more info ...)attempted-admin  2008-3175  30472    
15931MISC Veritas NetBackup java user interface service format string attack attempt (more info ...)attempted-admin  2005-2715      
16071EXPLOIT CA ARCServe Backup Discovery Service denial of service attempt (more info ...)attempted-dos  2008-1979  28927    URL
17520EXPLOIT CA ARCserve Backup DB Engine Denial of Service (more info ...)protocol-command-decode  2008-4399  31684    
17706MISC Veritas NetBackup java user interface service format string attack attempt (more info ...)attempted-admin  2005-2715      


# of warning rules in this group: 46

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3084EXPLOIT Veritas backup overflow attempt (more info ...)attempted-admin 2004-1172 11974  
3453MISC Arkeia client backup system info probe (more info ...)attempted-recon 2005-0491 12594  
3454MISC Arkeia client backup generic info probe (more info ...)attempted-recon 2005-0491 12594  
3457EXPLOIT Arkeia backup client type 77 overflow attempt (more info ...)attempted-user 2005-0491 12594 17158 
3458EXPLOIT Arkeia backup client type 84 overflow attempt (more info ...)attempted-user 2005-0491 12594  
3472EXPLOIT ARCserve discovery service overflow (more info ...)attempted-admin 2005-0260 12491  
3474EXPLOIT ARCserve backup TCP slot info msg client name overflow (more info ...)attempted-admin  12536  
3475EXPLOIT ARCserve backup TCP slot info msg client domain overflow (more info ...)attempted-admin  12536  
3476EXPLOIT ARCserve backup TCP product info msg 0x9b client domain overflow (more info ...)attempted-admin  12536  
3477EXPLOIT ARCserve backup TCP product info msg 0x9b client name overflow (more info ...)attempted-admin  12536  
3478EXPLOIT ARCserve backup TCP product info msg 0x9c client domain overflow (more info ...)attempted-admin  12536  
3479EXPLOIT ARCserve backup TCP product info msg 0x9c client name overflow (more info ...)attempted-admin  12536  
3480EXPLOIT ARCserve backup UDP slot info msg client name overflow (more info ...)attempted-admin  12536  
3481EXPLOIT ARCserve backup UDP slot info msg client domain overflow (more info ...)attempted-admin  12536  
3482EXPLOIT ARCserve backup UDP product info msg 0x9b client name overflow (more info ...)attempted-admin  12536  
3483EXPLOIT ARCserve backup UDP product info msg 0x9b client domain overflow (more info ...)attempted-admin  12536  
3484EXPLOIT ARCserve backup UDP product info msg 0x9c client name overflow (more info ...)attempted-admin  12536  
3485EXPLOIT ARCserve backup UDP product info msg 0x9c client domain overflow (more info ...)attempted-admin  12536  
3530EXPLOIT ARCserve backup UDP msg 0x99 client name overflow (more info ...)attempted-admin  12536  
3531EXPLOIT ARCserve backup UDP msg 0x99 client domain overflow (more info ...)attempted-admin  12536  
3658EXPLOIT ARCserve universal backup agent option 1000 little endian buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3659EXPLOIT ARCserve universal backup agent option 1000 buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3660EXPLOIT ARCserve universal backup agent option 00 little endian buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3661EXPLOIT ARCserve universal backup agent option 00 buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3662EXPLOIT ARCserve universal backup agent option 03 little endian buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3663EXPLOIT ARCserve universal backup agent option 03 buffer overflow attempt (more info ...)attempted-admin 2005-1018 13102 18041 
3695EXPLOIT Veritas Backup Agent password overflow attempt (more info ...)attempted-admin 2005-0773   
3696EXPLOIT Veritas Backup Agent DoS attempt (more info ...)attempted-dos 2005-0772 14201  
3697NETBIOS DCERPC NCACN-IP-TCP veritas bind attempt (more info ...)protocol-command-decode 2005-0771 14020  URL
4126EXPLOIT Veritas Backup Exec root connection attempt using default password hash (more info ...)suspicious-login 2005-2611 14551  
6011EXPLOIT VERITAS NetBackup vnetd buffer overflow attempt (more info ...)attempted-admin 2006-0991 17264  
6405EXPLOIT Veritas NetBackup Volume Manager overflow attempt (more info ...)attempted-admin 2006-0989 17264  
10132RPC portmap BrightStor ARCserve denial of service attempt (more info ...)attempted-dos 2007-0816 22365  
10133RPC portmap BrightStor ARCserve denial of service attempt (more info ...)attempted-dos 2007-0816 22365  
10482RPC portmap CA BrightStor ARCserve tcp request (more info ...)rpc-portmap-decode 2007-1785 23209  
10483RPC portmap CA BrightStor ARCserve udp request (more info ...)rpc-portmap-decode 2007-1785 23209  
10484RPC portmap CA BrightStor ARCserve tcp procedure 191 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
10485RPC portmap CA BrightStor ARCserve udp procedure 191 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
13716RPC portmap CA BrightStor ARCserve tcp procedure 232 attempt (more info ...)rpc-portmap-decode  23209  
13717RPC portmap CA BrightStor ARCserve udp procedure 232 attempt (more info ...)rpc-portmap-decode  23209  
13805RPC portmap CA BrightStor ARCserve tcp procedure 234 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
13806RPC portmap CA BrightStor ARCserve udp procedure 234 attempt (more info ...)rpc-portmap-decode 2007-1785 23209  
17045EXPLOIT CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt (more info ...)attempted-admin 2008-3175 30472  
17046EXPLOIT CA ARCserve Backup for Laptops and Desktops LGServer handshake buffer overflow attempt (more info ...)attempted-admin 2008-3175 30472  
17643EXPLOIT CA BrightStor ARCServe logger servie null-pointer dereference attempt (more info ...)attempted-admin 2007-2772   
17710EXPLOIT Veritas NetBackup vmd shared library buffer overflow attempt (more info ...)attempted-admin 2005-3116 15353  

 goto Top

Group: Server / Misc / TFTP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Server / Misc / SNMP

# of attack rules in this group: 3

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
569RPC snmpXdmi overflow attempt TCP (more info ...)attempted-admin  2001-0236  2417  10659  URL
16712WEB-MISC HP OpenView Network Node Manager ovwebsnmpsrv.exe OVwSelection buffer overflow attempt - GET (more info ...)attempted-user  2009-4181  37343    
16713WEB-MISC HP OpenView Network Node Manager ovwebsnmpsrv.exe OVwSelection buffer overflow attempt - POST (more info ...)attempted-user  2009-4181  37343    


# of warning rules in this group: 4

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
593RPC portmap snmpXdmi request TCP (more info ...)rpc-portmap-decode 2001-0236 2417 10659 URL
1279RPC portmap snmpXdmi request UDP (more info ...)rpc-portmap-decode 2001-0236 2417 10659 URL
2045RPC snmpXdmi overflow attempt UDP (more info ...)attempted-admin 2001-0236 2417 10659 URL
13773DOS linux kernel snmp nat netfilter memory corruption attempt (more info ...)attempted-dos 2008-1673 18081  URL

 goto Top

Group: Server / Misc / Authentication

# of attack rules in this group: 7

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
13223RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin  2007-2442  24655    URL
13268RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin  2007-2442  24655    URL
16207WEB-MISC MIT Kerberos V% KAdminD klog_vsyslog server overflow attempt (more info ...)attempted-user  2007-0957  23285    
16209DOS FreeRADIUS RADIUS server rad_decode remote denial of service attempt (more info ...)attempted-dos  2009-3111  36263    
17273SPECIFIC-THREATS MIT Kerberos V5 KDC krb5_unparse_name overflow attempt (more info ...)attempted-admin  2005-1174      URL
17274SPECIFIC-THREATS MIT Kerberos V5 KDC krb5_unparse_name overflow attempt (more info ...)attempted-admin  2005-1175      URL
17741EXPLOIT MIT Kerberos ASN.1 asn1_decode_generaltime uninitialized pointer reference attempt (more info ...)attempted-admin  2009-0846  34409    


# of warning rules in this group: 12

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
2578EXPLOIT kerberos principal name overflow UDP (more info ...)attempted-admin 2003-0072  11512 URL
2579EXPLOIT kerberos principal name overflow TCP (more info ...)attempted-admin 2003-0072  11512 URL
3538EXPLOIT RADIUS registration MSID overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
3539EXPLOIT RADIUS MSID overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
3540EXPLOIT RADIUS registration vendor ATTR_TYPE_STR overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
3541EXPLOIT RADIUS ATTR_TYPE_STR overflow attempt (more info ...)attempted-admin 2005-0699 12759 19120 
12046RPC MIT Kerberos kadmind RPC Library unix authentication buffer overflow attempt (more info ...)attempted-admin 2007-2443 24657  URL
12075RPC MIT Kerberos kadmind rpc library uninitialized pointer arbitrary code execution attempt (more info ...)attempted-admin 2007-2442 24655  URL
12424RPC MIT Kerberos kadmind rpc RPCSEC_GSS buffer overflow attempt (more info ...)attempted-admin 2007-3999 25534  URL
12708RPC MIT Kerberos kadmind auth buffer overflow attempt (more info ...)rpc-portmap-decode 2007-2443 24657  
16394DOS Active Directory Kerberos referral TGT renewal DoS attempt (more info ...)attempted-dos 2010-0035   URL
17243EXPLOIT MIT Kerberos V5 krb5_recvauth double free attempt (more info ...)attempted-admin 2005-1689 14239  

 goto Top

Group: Server / Misc / CVS

# of attack rules in this group: 1

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
13616SPECIFIC-THREATS CVS Argument overflow (more info ...)attempted-admin  2004-0396      


# of warning rules in this group: 16

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1551WEB-MISC /CVS/Entries access (more info ...)web-application-activity   11032 
1552WEB-MISC cvsweb version access (more info ...)web-application-activity 2000-0670  10465 
2008MISC CVS invalid user authentication response (more info ...)misc-attack    
2009MISC CVS invalid repository response (more info ...)misc-attack    
2010MISC CVS double free exploit attempt response (more info ...)misc-attack 2003-0015 6650 11385 
2011MISC CVS invalid directory response (more info ...)misc-attack 2003-0015 6650 11385 
2012MISC CVS missing cvsroot response (more info ...)misc-attack    
2013MISC CVS invalid module response (more info ...)misc-attack    
2317MISC CVS non-relative path error response (more info ...)misc-attack 2003-0977 9178 11947 
2318MISC CVS non-relative path access attempt (more info ...)misc-attack 2003-0977 9178 11947 
2583MISC CVS Max-dotdot integer overflow attempt (more info ...)misc-attack 2004-0417 10499  
3651EXPLOIT CVS rsh annotate revision overflow attempt (more info ...)attempted-dos 2005-0753 13217 18097 URL
3652EXPLOIT CVS pserver annotate revision overflow attempt (more info ...)attempted-dos 2005-0753 13217 18097 URL
13614EXPLOIT CVS Argument overflow attempt (more info ...)attempted-admin 2004-0396   
13615EXPLOIT CVS Argument overflow attempt (more info ...)attempted-admin 2004-0396   
15971EXPLOIT CVS Argumentx command double free attempt (more info ...)attempted-admin 2004-0416 10499  

 goto Top

Group: Client

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Client / Office

# of attack rules in this group: 281

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
4170WEB-ACTIVEX Office 2000 and 2002 Web Components Data Source Control ActiveX clsid access (more info ...)attempted-user  2007-1201  4449    URL
4175WEB-ACTIVEX Office 2000/2002 Web Components PivotTable ActiveX Object Access (more info ...)attempted-user  2002-0727  4449    URL
4176WEB-ACTIVEX Office 2000 and 2002 Web Components Chart ActiveX Object Access (more info ...)attempted-user  2002-0727  4449    URL
4177WEB-ACTIVEX Office 2000 and 2002 Web Components Spreadsheet ActiveX clsid access (more info ...)attempted-user  2006-4695  4453    URL
4178WEB-ACTIVEX Office 2000 and 2002 Web Components Record Navigation Control ActiveX Object Access (more info ...)attempted-user  2002-0727  4449    URL
4217WEB-ACTIVEX Microsoft Office Services on the Web Free/Busy ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4218WEB-ACTIVEX Microsoft Visual Basic WebClass ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
5780SPYWARE-PUT Keylogger runtime detection - hwpe word filtered echelon log (more info ...)successful-recon-limited        URL
5782SPYWARE-PUT Keylogger runtime detection - hwae word filtered echelon log (more info ...)successful-recon-limited        URL
5892SPYWARE-PUT Trackware wordiq toolbar runtime detection - get link info (more info ...)successful-recon-limited        URL
5893SPYWARE-PUT Trackware wordiq toolbar runtime detection - search keyword (more info ...)successful-recon-limited        URL
5958SPYWARE-PUT Hacker-Tool ghostvoice 1.02 runtime detection - init connection with password requirement (more info ...)misc-activity        URL
5959SPYWARE-PUT Hijacker raxsearch detection - send search keywords to raxsearch (more info ...)misc-activity        URL
5962SPYWARE-PUT Hijacker searchfast detection - catch search keyword (more info ...)misc-activity        URL
5992SPYWARE-PUT Hijacker getmirar runtime detection - get keyword-related content (more info ...)misc-activity        URL
6185SPYWARE-PUT Adware 180Search assistant runtime detection - reporting keyword (more info ...)misc-activity        URL
6192SPYWARE-PUT Adware seekmo runtime detection - reporting keyword (more info ...)misc-activity        URL
6278SPYWARE-PUT Trickler navexcel search toolbar runtime detection - activate/update (more info ...)misc-activity        URL
6309BACKDOOR net demon runtime detection - initial connection - password request (more info ...)trojan-activity        URL
6310BACKDOOR net demon runtime detection - initial connection - password send (more info ...)trojan-activity        URL
6311BACKDOOR net demon runtime detection - initial connection - password accepted (more info ...)trojan-activity        URL
7002WEB-CLIENT excel url unicode overflow attempt (more info ...)attempted-user  2006-3086  18500    URL
7025WEB-CLIENT excel url unicode overflow attempt (more info ...)attempted-user  2006-3014  18583    URL
7047WEB-CLIENT excel object record overflow attempt (more info ...)attempted-user  2006-1306      URL
7048WEB-CLIENT excel object record overflow attempt (more info ...)attempted-user  2006-1306      URL
7087BACKDOOR sinique 1.0 runtime detection - initial connection with correct password client-to-server (more info ...)trojan-activity        URL
7089BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password -client-to-server (more info ...)trojan-activity        URL
7098BACKDOOR remote hack 1.5 runtime detection - get password (more info ...)trojan-activity        URL
7197WEB-CLIENT excel MSO.DLL malformed string parsing single byte buffer over attempt (more info ...)attempted-user  2006-1540  17252    URL
7198WEB-CLIENT excel MSO.DLL malformed string parsing multi byte buffer over attempt (more info ...)attempted-user  2006-1540  17252    URL
7199WEB-CLIENT excel label record overflow attempt (more info ...)attempted-user  2008-0114  28166    URL
7200WEB-CLIENT microsoft word document summary information null string overflow attempt (more info ...)attempted-user  2006-1540      URL
7201WEB-CLIENT microsoft word summary information null string overflow attempt (more info ...)attempted-user  2006-1540      URL
7202WEB-CLIENT microsoft word document summary information string overflow attempt (more info ...)attempted-user  2006-1540      URL
7203WEB-CLIENT microsoft word information string overflow attempt (more info ...)attempted-user  2006-1540      URL
7517SPYWARE-PUT Hijacker chinese keywords runtime detection (more info ...)misc-activity        URL
7616BACKDOOR theef 2.0 runtime detection - connection without password (more info ...)trojan-activity        URL
7617BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 1 (more info ...)trojan-activity        
7618BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 2 (more info ...)trojan-activity        
7619BACKDOOR theef 2.0 runtime detection - connection request with password (more info ...)trojan-activity        URL
7785BACKDOOR forced control uploader runtime detection - connection with password (more info ...)trojan-activity        
7832SPYWARE-PUT Hijacker navexcel helper runtime detection - active/update (more info ...)misc-activity        URL
7833SPYWARE-PUT Hijacker navexcel helper runtime detection - search (more info ...)misc-activity        URL
7870WEB-ACTIVEX Microsoft Office Data Source Control 9.0 ActiveX clsid access (more info ...)attempted-user  2007-1201  28136    URL
7871WEB-ACTIVEX Microsoft Office Data Source Control 9.0 ActiveX clsid unicode access (more info ...)attempted-user  2007-1201  28136    URL
7874WEB-ACTIVEX Microsoft Office PivotTable 10.0 ActiveX CLSID access (more info ...)attempted-user  2002-0861      URL
7875WEB-ACTIVEX Microsoft Office PivotTable 10.0 ActiveX CLSID unicode access (more info ...)attempted-user  2002-0861      URL
7876WEB-ACTIVEX Microsoft Office Data Source Control 10.0 ActiveX clsid access (more info ...)attempted-user  2009-0562  35990    URL
7877WEB-ACTIVEX Microsoft Office Data Source Control 10.0 ActiveX clsid unicode access (more info ...)attempted-user  2009-0562  35990    URL
8358SPYWARE-PUT Hijacker yok supersearch runtime detection - addressbar keyword search hijack (more info ...)misc-activity        URL
8397WEB-ACTIVEX Microsoft Office List 11.0 ActiveX CLSID access (more info ...)attempted-user        
8398WEB-ACTIVEX Microsoft Office List 11.0 ActiveX CLSID unicode access (more info ...)attempted-user        
8448WEB-CLIENT Excel colinfo XF record overflow attempt (more info ...)attempted-user  2006-3875      URL
8723WEB-ACTIVEX Microsoft Office Data Source Control 11.0 ActiveX clsid access (more info ...)attempted-user  2006-3729  24462    URL
8724WEB-ACTIVEX Microsoft Office Data Source Control 11.0 ActiveX clsid unicode access (more info ...)attempted-user  2006-3729  24462    URL
8738WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX clsid access (more info ...)attempted-user  2007-5660  31235    URL
8739WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX clsid unicode access (more info ...)attempted-user  2007-5660  31235    URL
8740WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX function call access (more info ...)attempted-user  2007-5660  31235    URL
9645SPYWARE-PUT Hijacker sogou runtime detection - keyword hijack (more info ...)misc-activity        URL
10123SPECIFIC-THREATS PA168 chipset based IP phone default password attempt (more info ...)attempted-admin        URL
10173WEB-ACTIVEX Trend Micro OfficeScan Client ActiveX clsid access (more info ...)attempted-user  2007-0325  22585    
10174WEB-ACTIVEX Trend Micro OfficeScan Client ActiveX clsid unicode access (more info ...)attempted-user  2007-0325  22585    
10175WEB-ACTIVEX Trend Micro OfficeScan Client ActiveX function call access (more info ...)attempted-user  2007-0325  22585    
10445BACKDOOR acidbattery 1.0 runtime detection - get password (more info ...)trojan-activity        URL
11181WEB-ACTIVEX Excel Viewer ActiveX clsid access (more info ...)attempted-user    33243    URL
11182WEB-ACTIVEX Excel Viewer ActiveX clsid unicode access (more info ...)attempted-user    33243    URL
11183WEB-ACTIVEX Excel Viewer ActiveX function call access (more info ...)attempted-user    33243    URL
11184WEB-ACTIVEX Excel Viewer ActiveX function call unicode access (more info ...)attempted-user    33243    URL
11186DOS CA eTrust key handling dos -- password (more info ...)denial-of-service  2007-1005  22743    
11187WEB-ACTIVEX Word Viewer ActiveX clsid access (more info ...)attempted-user    33243    URL
11188WEB-ACTIVEX Word Viewer ActiveX clsid unicode access (more info ...)attempted-user    33243    URL
11189WEB-ACTIVEX Word Viewer ActiveX function call access (more info ...)attempted-user    33243    URL
11190WEB-ACTIVEX Word Viewer ActiveX function call unicode access (more info ...)attempted-user    33243    URL
11258WEB-CLIENT Excel Malformed Named Graph Information unicode overflow (more info ...)attempted-user  2007-0215      URL
11290WEB-CLIENT Excel malformed named graph information ascii overflow (more info ...)attempted-user  2007-0215      URL
11836MISC Visio version number anomaly (more info ...)misc-activity  2007-0934      URL
12233BACKDOOR theef 2.10 runtime detection - connect with no password (more info ...)trojan-activity        
12235BACKDOOR theef 2.10 runtime detection - connect with password (more info ...)trojan-activity        
12256WEB-CLIENT Excel malformed FBI record (more info ...)attempted-user  2007-1747  23826    URL
12285WEB-CLIENT Excel Workspace file download (more info ...)misc-activity        URL
12703WEB-ACTIVEX Macrovision InstallShield Update Service ActiveX function call unicode access (more info ...)attempted-user  2007-5660  31235    URL
13325WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX clsid access (more info ...)attempted-user    27279    
13326WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX clsid unicode access (more info ...)attempted-user    27279    
13327WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX function call access (more info ...)attempted-user    27279    
13328WEB-ACTIVEX Macrovision FLEXnet Connect ActiveX function call unicode access (more info ...)attempted-user    27279    
13571WEB-CLIENT Microsoft Excel dval record arbitrary code excecution attempt (more info ...)attempted-user  2008-0111      URL
13665WEB-CLIENT Microsoft Visio DXF file invalid memory allocation exploit attempt (more info ...)attempted-user  2008-1090      URL
13790WEB-CLIENT Microsoft Word malformed css remote code execution attempt (more info ...)attempted-user  2008-1434      URL
13803WEB-CLIENT RTF control word overflow attempt (more info ...)attempted-user  2008-1091      URL
13973WEB-CLIENT Microsoft Excel format record code execution attempt (more info ...)attempted-user  2008-3005      URL
13983WEB-CLIENT Microsoft Office eps file download (more info ...)misc-activity        
14628WEB-ACTIVEX Office 2000 and 2002 Web Components Chart ActiveX clsid unicode access (more info ...)attempted-user  2002-0727  4449    URL
14629WEB-ACTIVEX Office 2000 and 2002 Web Components PivotTable ActiveX clsid unicode access (more info ...)attempted-user  2002-0727  4449    URL
14630WEB-ACTIVEX Office 2000 and 2002 Web Components Data Source Control ActiveX clsid unicode access (more info ...)attempted-user  2002-0727  4449    URL
14641WEB-CLIENT Microsoft Excel invalid FRTWrapper record buffer overflow attempt (more info ...)attempted-user  2008-3471      URL
14642WEB-CLIENT Microsoft Excel file with embedded ActiveX control (more info ...)attempted-user  2008-3477      URL
14764WEB-ACTIVEX Macrovision InstallShield Update Service Agent ActiveX clsid access (more info ...)attempted-user  2008-2470  31235    
14765WEB-ACTIVEX Macrovision InstallShield Update Service Agent ActiveX function call (more info ...)attempted-user  2008-2470  31235    
14997WEB-ACTIVEX DjVu MSOffice Converter ActiveX clsid access (more info ...)attempted-user  2008-4922  31987    
14998WEB-ACTIVEX DjVu MSOffice Converter ActiveX clsid unicode access (more info ...)attempted-user  2008-4922  31987    
15083EXPLOIT Microsoft Word .rtf file double free attempt (more info ...)attempted-user  2008-4027      URL
15088WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX clsid access (more info ...)attempted-user  2008-4256      URL
15090WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX function call access (more info ...)attempted-user  2008-4256      URL
15092WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX clsid access (more info ...)attempted-user  2008-4252      URL
15094WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX function call access (more info ...)attempted-user  2008-4252      URL
15096WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX clsid access (more info ...)attempted-user  2008-4253      URL
15098WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX function call access (more info ...)attempted-user  2008-4253      URL
15100WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX clsid access (more info ...)attempted-user  2008-4254      URL
15102WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX function call access (more info ...)attempted-user  2008-4254      URL
15104WEB-CLIENT Visual Basic 6.0 malformed AVI buffer overflow attempt (more info ...)attempted-user  2008-4255      URL
15106WEB-CLIENT Microsoft Word .rtf file integer overflow attempt (more info ...)misc-attack  2008-4025      URL
15107WEB-CLIENT Microsoft Word .rtf file stylesheet buffer overflow attempt (more info ...)attempted-user  2008-4031      URL
15108WEB-CLIENT Microsoft Office Sharepoint Server elevation of privilege exploit attempt (more info ...)attempted-admin  2008-4032      URL
15118WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX clsid access (more info ...)attempted-user  2008-4251      URL
15120WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX function call access (more info ...)attempted-user  2008-4251      URL
15163SPECIFIC-THREATS Microsoft Visio Object Header Buffer Overflow attempt (more info ...)attempted-user  2008-1089      
15230WEB-ACTIVEX Office Viewer 2 ActiveX clsid access (more info ...)attempted-user    33245    URL
15231WEB-ACTIVEX Office Viewer 2 ActiveX clsid unicode access (more info ...)attempted-user    33245    URL
15282WEB-ACTIVEX FlexCell Grid ActiveX clsid access (more info ...)attempted-user  2009-0301  33453    
15283WEB-ACTIVEX FlexCell Grid ActiveX clsid unicode access (more info ...)attempted-user  2009-0301  33453    
15294WEB-CLIENT Microsoft Visio file download request (more info ...)misc-activity        
15298WEB-CLIENT Microsoft Visio could allow remote code execution (more info ...)attempted-user  2009-0097      URL
15299WEB-CLIENT Microsoft Office Visio invalid ho tag attempt (more info ...)attempted-user  2009-0096  33660    URL
15303WEB-CLIENT Malformed Visio IconBitsComponent arbitrary code execution attempt (more info ...)attempted-user  2009-0095      URL
15334WEB-ACTIVEX GeoVision LiveX 7000 ActiveX clsid access (more info ...)attempted-user    33782    
15335WEB-ACTIVEX GeoVision LiveX 7000 ActiveX clsid unicode access (more info ...)attempted-user    33782    
15336WEB-ACTIVEX GeoVision LiveX 7000 ActiveX function call access (more info ...)attempted-user    33782    
15337WEB-ACTIVEX GeoVision LiveX 7000 ActiveX function call unicode access (more info ...)attempted-user    33782    
15338WEB-ACTIVEX GeoVision LiveX 8120 ActiveX clsid access (more info ...)attempted-user    33782    
15339WEB-ACTIVEX GeoVision LiveX 8120 ActiveX clsid unicode access (more info ...)attempted-user    33782    
15340WEB-ACTIVEX GeoVision LiveX 8120 ActiveX function call access (more info ...)attempted-user    33782    
15341WEB-ACTIVEX GeoVision LiveX 8120 ActiveX function call unicode access (more info ...)attempted-user    33782    
15342WEB-ACTIVEX GeoVision LiveX 8200 ActiveX clsid access (more info ...)attempted-user    33782    
15343WEB-ACTIVEX GeoVision LiveX 8200 ActiveX clsid unicode access (more info ...)attempted-user    33782    
15344WEB-ACTIVEX GeoVision LiveX 8200 ActiveX function call access (more info ...)attempted-user    33782    
15345WEB-ACTIVEX GeoVision LiveX 8200 ActiveX function call unicode access (more info ...)attempted-user    33782    
15365WEB-CLIENT Microsoft Excel extrst record arbitrary code excecution attempt (more info ...)attempted-user  2009-0238      URL
15454WEB-CLIENT Microsoft Office PowerPoint malformed msofbtTextbox exploit attempt (more info ...)attempted-user  2009-0556      URL
15455EXPLOIT WordPad and Office Text Converters XST parsing buffer overflow attempt (more info ...)attempted-user  2008-4841      URL
15463WEB-CLIENT Microsoft Excel file request (more info ...)protocol-command-decode        
15465WEB-CLIENT Microsoft Excel malformed object record remote code execution attempt (more info ...)attempted-user  2009-0100      URL
15466EXPLOIT WordPad WordPerfect 6.x converter buffer overflow attempt (more info ...)attempted-user  2009-0088      URL
15467EXPLOIT WordPad and Office Text Converters PlcPcd aCP buffer overflow attempt (more info ...)attempted-user  2009-0235      URL
15469WEB-CLIENT Microsoft WordPad and Office text converters integer underflow attempt (more info ...)attempted-user  2009-0087      URL
15488SPECIFIC-THREATS Oracle Database Application Express Component APEX password hash disclosure attempt (more info ...)misc-attack  2009-0981  34461    URL
15519WEB-CLIENT Microsoft Office Excel BRAI record remote code execution attempt (more info ...)attempted-user  2009-0549      URL
15520WEB-CLIENT Microsoft Office Excel FtCbls remote code execution attempt (more info ...)attempted-user  2009-0557      URL
15521WEB-CLIENT Microsoft Office Excel ExternSheet record remote code execution attempt (more info ...)attempted-user  2009-0558      URL
15524EXPLOIT Microsoft Word remote code execution attempt (more info ...)attempted-user  2009-0563      URL
15525EXPLOIT Microsoft Word remote code execution attempt (more info ...)attempted-user  2009-0565      URL
15537WEB-CLIENT Microsoft Office Excel MsoDrawingGroup record remote code execution attempt (more info ...)attempted-user  2009-0559      URL
15541WEB-CLIENT Excel SST record remote code execution attempt (more info ...)attempted-user  2009-3037  36042    URL
15542WEB-CLIENT Microsoft Office Excel Qsir and Qsif record remote code execution attempt (more info ...)attempted-user  2009-1134      URL
15587WEB-CLIENT Word file download request (more info ...)protocol-command-decode        
15685WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX clsid access (more info ...)attempted-user  2009-2496      URL
15687WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX function call access (more info ...)attempted-user  2009-2496      URL
15689WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX clsid access (more info ...)attempted-user  2009-1136      URL
15691WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX function call access (more info ...)attempted-user  2009-1136      URL
15852WEB-ACTIVEX Microsoft Office Web Components Datasource ActiveX clsid access (more info ...)attempted-user  2009-0562      URL
15853WEB-ACTIVEX Microsoft Office Web Components Datasource ActiveX clsid unicode access (more info ...)attempted-user  2009-0562      URL
15913WEB-CLIENT javascript arguments keyword override rce attempt (more info ...)attempted-user  2009-1920      URL
15975WEB-CLIENT OpenOffice TIFF file in little endian format parsing integer overflow attempt (more info ...)attempted-user  2007-2834  25690    
15976WEB-CLIENT OpenOffice TIFF file in big endian format parsing integer overflow attempt (more info ...)attempted-user  2007-2834  25690    
15987WEB-MISC Microsoft Visio DXF file download request (more info ...)misc-activity        
16177EXPLOIT Microsoft GDI+ Word file Office Art Property Table remote code execution attempt (more info ...)attempted-user  2009-2528      URL
16178EXPLOIT Microsoft GDI+ Excel file Office Art Property Table remote code execution attempt (more info ...)attempted-user  2009-2528      URL
16226EXPLOIT Microsoft Office Excel integer field in row record improper validation remote code execution attempt (more info ...)attempted-user  2009-3130      URL
16229WEB-CLIENT Microsoft Excel oversized ib memory corruption attempt (more info ...)attempted-user  2009-3131      URL
16230WEB-CLIENT Microsoft Excel oversized ib memory corruption attempt (more info ...)attempted-user  2009-3131      URL
16233EXPLOIT Microsoft Excel oversized ptgFuncVar cparams value buffer overflow attempt (more info ...)attempted-user  2009-3132      URL
16234WEB-CLIENT Microsoft Word Document remote code execution attempt (more info ...)attempted-user  2009-3135      URL
16235EXPLOIT Microsoft Excel file SXDB record exploit attempt (more info ...)attempted-user  2009-3127      URL
16236EXPLOIT Microsoft Excel file SxView record exploit attempt (more info ...)attempted-user  2009-3128      URL
16240EXPLOIT Microsoft Excel file Window/Pane record exploit attempt (more info ...)attempted-user  2009-3133      URL
16241WEB-CLIENT Microsoft Office Excel FeatHdr BIFF record remote code execution attempt (more info ...)attempted-user  2009-3129      URL
16314EXPLOIT Microsoft WordPad and Office text converter integer overflow attempt (more info ...)attempted-user  2009-2506      URL
16318WEB-CLIENT Microsoft Office Visio invalid ho tag attempt (more info ...)attempted-user  2009-0096  33660    URL
16328EXPLOIT Microsoft Office Project file parsing arbitrary memory access attempt (more info ...)attempted-user  2009-0102      URL
16361WEB-CLIENT Microsoft Office BMP header biClrUsed integer overflow attempt (more info ...)attempted-admin  2009-2518  36651    
16461EXPLOIT Microsoft Excel write access violation attempt (more info ...)misc-activity  2010-0257      URL
16462EXPLOIT Microsoft Excel BIFF8 formulas from records parsing code execution attempt (more info ...)attempted-user  2010-0258      URL
16463EXPLOIT Microsoft Excel BIFF5 formulas from records parsing code execution attempt (more info ...)attempted-user  2010-0258      URL
16464WEB-CLIENT Microsoft Excel ContinueFRT12 heap overflow attempt (more info ...)attempted-user  2010-0260      URL
16465WEB-CLIENT Microsoft Excel ContinueFRT12 and MDXSet heap overflow attempt (more info ...)attempted-user  2010-0261      URL
16466EXPLOIT Microsoft Excel uninitialized stack variable code execution attempt (more info ...)attempted-user  2010-0262      URL
16467EXPLOIT Microsoft Excel 2007 invalid comments.xml uninitialized pointer access attempt 1 (more info ...)attempted-user  2010-0263      URL
16468EXPLOIT Microsoft Excel 2007 invalid comments.xml uninitialized pointer access attempt 2 (more info ...)attempted-user  2010-0263      URL
16469WEB-CLIENT Microsoft Excel DbOrParamQry.fOdbcConn parsing remote code execution attempt (more info ...)attempted-user  2010-0264      URL
16470WEB-CLIENT Microsoft Excel DbOrParamQry.fWeb parsing remote code execution attempt (more info ...)attempted-user  2010-0264      URL
16471WEB-CLIENT Microsoft Excel DbOrParamQry.fWeb parsing remote code execution attempt (more info ...)attempted-user  2010-0264      URL
16553EXPLOIT Microsoft Office Excel ptg index parsing code execution attempt (more info ...)attempted-user  2009-3132      URL
16565WEB-ACTIVEX Ultra Shareware Office ActiveX clsid access (more info ...)attempted-user  2008-3878  30861    
16586WEB-CLIENT Microsoft Word Document remote code execution attempt (more info ...)attempted-user  2009-3135      URL
16638WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt (more info ...)attempted-user  2010-0822      URL
16639WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt - with macro (more info ...)attempted-user  2010-0822      URL
16640WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt - with linkFmla (more info ...)attempted-user  2010-0822      URL
16641WEB-CLIENT Microsoft Excel OBJ record stack buffer overflow attempt - with macro and linkFmla (more info ...)attempted-user  2010-0822      URL
16643WEB-CLIENT Microsoft Excel Chart Sheet Substream memory corruption attempt (more info ...)attempted-user  2010-0823      URL
16644EXPLOIT Microsoft Excel WOpt record memory corruption attempt (more info ...)attempted-user  2010-0824      URL
16645EXPLOIT Microsoft Excel SxView record memory pointer corruption attempt (more info ...)attempted-user  2010-1245      URL
16646EXPLOIT Microsoft Excel RealTimeData record stack buffer overflow attempt (more info ...)attempted-user  2010-1246      URL
16647WEB-CLIENT Microsoft Excel RealTimeData record heap memory corruption attempt - 2 (more info ...)attempted-user  2010-1247      URL
16648EXPLOIT Microsoft Excel RealTimeData record heap memory corruption attempt - 1 (more info ...)attempted-user  2010-1247      URL
16649WEB-CLIENT Microsoft Excel HFPicture record stack buffer overflow attempt (more info ...)attempted-user  2010-1248      URL
16662WEB-CLIENT Microsoft Excel SxView heap overflow attempt (more info ...)attempted-user  2010-0821      URL
16786SPECIFIC-THREATS Microsoft Office Web Components Spreadsheet ActiveX buffer overflow attempt (more info ...)attempted-user  2009-1534  35992    
16800EXPLOIT Microsoft Excel FRTWrapper record buffer overflow attempt (more info ...)attempted-user  2008-3471      URL
17119EXPLOIT Microsoft Word sprmCMajority SPRM overflow attempt (more info ...)attempted-user  2010-1900      URL
17124WEB-CLIENT Microsoft Word malformed table record memory corruption attempt (more info ...)attempted-user  2010-1903      URL
17227WEB-CLIENT Microsoft Excel sheet name memory corruption attempt (more info ...)attempted-user  2007-3490  24691    
17250EXPLOIT Microsoft WordPad sprmTSetBrc80 SPRM overflow attempt (more info ...)attempted-user  2010-2563      URL
17284WEB-CLIENT Microsoft Office malformed routing slip code execution attempt (more info ...)attempted-user  2006-0009  17000    
17286SPECIFIC-THREATS Microsoft Visual Basic for Applications document properties overflow attempt (more info ...)attempted-user  2006-3649  19414    
17295WEB-MISC Trend Micro OfficeScan Console authentication buffer overflow attempt (more info ...)attempted-admin  2007-3455  24935    
17301WEB-CLIENT Microsoft Word TextBox sub-document memory corruption attempt (more info ...)attempted-user  2007-1910  23380    
17308WEB-CLIENT Microsoft Word SmartTag record code execution attempt (more info ...)attempted-user  2008-2244  30124    
17315WEB-CLIENT OpenOffice OLE File Stream Buffer Overflow (more info ...)attempted-user  2008-0320  28819    
17322SHELLCODE x86 OS agnostic fnstenv geteip dword xor decoder (more info ...)shellcode-detect        
17344SHELLCODE x86 OS agnostic xor dword decoder (more info ...)shellcode-detect        
17345SHELLCODE x86 OS agnostic dword additive feedback decoder (more info ...)shellcode-detect        
17362WEB-CLIENT Microsoft Excel IMDATA buffer overflow attempt (more info ...)attempted-user  2007-0027  21856    
17368WEB-CLIENT Microsoft Word document stream handling code execution attempt (more info ...)attempted-user  2007-0870  25567    
17377SPECIFIC-THREATS Microsoft excel Malformed Filter Records Handling Code Execution attempt (more info ...)attempted-user  2007-1214  23780    
17403WEB-CLIENT OpenOffice RTF File parsing heap buffer overflow attempt (more info ...)attempted-user  2007-0245  24450    
17404EXPLOIT Microsoft Word Converter XST structure buffer overflow attempt (more info ...)attempted-user  2008-4841      URL
17405EXPLOIT Microsoft Word Converter XST structure buffer overflow attempt (more info ...)attempted-user  2008-4841      URL
17406EXPLOIT Microsoft Word Converter XST structure buffer overflow attempt (more info ...)attempted-user  2008-4841      URL
17488SPECIFIC-THREATS Excel Malformed Range Code Execution attempt (more info ...)attempted-user  2005-4131  15780    
17491SPECIFIC-THREATS Microsoft Word mso.dll LsCreateLine Memory Corruption (more info ...)attempted-user  2006-3493  18905    
17492SPECIFIC-THREATS Microsoft Excel Malformed SELECTION Record Code Execution attempt (more info ...)attempted-user  2006-1301  18853    
17505WEB-CLIENT Microsoft Word formatted disk pages table memory corruption attempt (more info ...)attempted-user  2006-6561  21589    
17506WEB-CLIENT Microsoft Word formatted disk pages table memory corruption attempt (more info ...)attempted-user  2006-6561  21589    
17507WEB-CLIENT Microsoft Word formatted disk pages table memory corruption attempt (more info ...)attempted-user  2006-6561  21589    
17511WEB-CLIENT Excel malformed Graphic Code Execution (more info ...)attempted-user  2006-0030  16181    
17517WEB-CLIENT excel Malformed Record Code Execution attempt (more info ...)attempted-user  2006-0031  17101    
17537SPECIFIC-THREATS Microsoft Excel Unspecified Null Page Name Memory Corruption Attempt (more info ...)attempted-user  2006-0031  15926    
17538SPECIFIC-THREATS Microsoft Excel Unspecified Page Name Memory Corruption Attempt (more info ...)attempted-user  2006-0031  15926    
17539SPECIFIC-THREATS Microsoft Excel Unspecified Grafic Pointer Memory Corruption Attempt (more info ...)attempted-user  2006-0030  15926    
17542SPECIFIC-THREATS Excel MalformedPalete Record Memory Corruption attempt (more info ...)attempted-user  2007-0031  21922    
17543WEB-CLIENT Excel Column Record Handling Memory Corruption attempt (more info ...)attempted-user  2007-0030  21925    
17550SPECIFIC-THREATS Microsoft Word Font Parsing Buffer Overflow attempt (more info ...)attempted-user  2005-0564  14216    
17555SPECIFIC-THREATS Macrovision InstallShield Update Service ActiveX exploit attempt (more info ...)attempted-user  2007-5660  31235    URL
17560SPECIFIC-THREATS Microsoft Word Global Array Index Heap Overflow attempt (more info ...)attempted-user  2008-4026  32583    
17565SPECIFIC-THREATS Microsoft Office PowerPoint PP7 File Handling Memory Corruption attempt (more info ...)attempted-user  2009-0225  34880    
17568WEB-MISC Microsoft Office XP URL Handling Buffer Overflow attempt (more info ...)attempted-admin  2004-0848  12480    
17574SPECIFIC-THREATS Sophos Anti-Virus Visio File Parsing Buffer Overflow attempt (more info ...)attempted-user  2005-2768  14362    
17578SPECIFIC-THREATS Microsoft Word Section Table Array Buffer Overflow attempt (more info ...)attempted-user  2007-0515  22225    
17579SPECIFIC-THREATS Microsoft Office Drawing Record msofbtOPT Code Execution attempt (more info ...)attempted-user  2007-0671  22383    
17591WEB-CLIENT Microsoft Word Crafted Sprm memory corruption attempt (more info ...)attempted-user  2008-4837  32584    
17649WEB-CLIENT Microsoft Word array data handling buffer overflow attempt (more info ...)attempted-user  2007-0035  23804    
17655WEB-CLIENT Microsoft Excel malformed formula parsing code execution attempt (more info ...)attempted-user  2008-0115  28167    URL
17665WEB-CLIENT OpenOffice Word document table parsing multiple heap based buffer overflow attempt (more info ...)attempted-user  2009-0201  36200    
17670WEB-ACTIVEX BigAnt Office Manager ActiveX clsid access (more info ...)attempted-user    39721    
17671WEB-ACTIVEX BigAnt Office Manager ActiveX clsid unicode access (more info ...)attempted-user    39721    
17672WEB-ACTIVEX BigAnt Office Manager ActiveX function call access (more info ...)attempted-user    39721    
17673WEB-ACTIVEX BigAnt Office Manager ActiveX function call unicode access (more info ...)attempted-user    39721    
17690EXPLOIT Microsoft Word remote code execution attempt (more info ...)attempted-user  2009-0565      URL
17691EXPLOIT Microsoft Word remote code execution attempt (more info ...)attempted-user  2009-0565      URL
17701SPECIFIC-THREATS Office Viewer ActiveX arbitrary command execution attempt (more info ...)attempted-user  2007-2588  33245    URL
17734WEB-MISC Excel REPT integer underflow attempt (more info ...)attempted-user  2008-4019  31706    
17742EXPLOIT Microsoft Word remote code execution attempt (more info ...)attempted-user  2009-0563      URL
17743EXPLOIT Microsoft Word RTF parsing memory corruption (more info ...)attempted-user  2008-1091  29104    URL
17754EXPLOIT Microsoft Word bookmark bound check remote code execution attempt (more info ...)attempted-user  2010-3216      URL
17755EXPLOIT Microsoft Word unchecked index value remote code execution attempt (more info ...)attempted-user  2010-3219      URL
17756WEB-CLIENT Microsoft Word XP PLFLSInTableStream heap overflow attempt (more info ...)attempted-user  2010-3220      URL
17757WEB-CLIENT Microsoft Excel CrErr record integer overflow attempt (more info ...)attempted-user  2010-3230      URL
17758EXPLOIT Microsoft Excel PtgExtraArray data parsing vulnerability exploit attempt (more info ...)attempted-user  2010-3231      URL
17759EXPLOIT Microsoft Excel invalid SerAr object exploit attempt (more info ...)attempted-user  2010-3239      URL
17760EXPLOIT Microsoft Excel RealTimeData record exploit attempt (more info ...)attempted-user  2010-3240      URL
17761WEB-CLIENT Microsoft Excel malformed MergeCells record exploit attempt (more info ...)attempted-user  2010-3237      URL
17762WEB-CLIENT Microsoft Excel corrupted TABLE record clean up exploit attempt (more info ...)attempted-user  2010-3232      URL
17763EXPLOIT Microsoft Excel GhostRw record exploit attempt (more info ...)attempted-user  2010-3242      URL
17764EXPLOIT Microsoft Excel PtgName invalid index exploit attempt (more info ...)attempted-user  2010-3235      URL
18063WEB-CLIENT Microsoft Office embedded Office Art drawings execution attempt (more info ...)attempted-user  2010-3334      URL
18067WEB-CLIENT Microsoft Office RTF parsing remote code execution attempt (more info ...)attempted-user  2010-3333      URL
18068EXPLOIT Microsoft Excel malformed MsoDrawingObject record attempt (more info ...)attempted-user  2010-3335      URL
18069WEB-CLIENT Microsoft Office Art drawing invalid shape identifier attempt (more info ...)attempted-user  2010-3336      URL
18200EXPLOIT Microsoft Office .CGM file cell array heap overflow attempt (more info ...)attempted-user  2010-3945      URL
18201EXPLOIT Microsoft Office TIFF filter remote code execution attempt (more info ...)attempted-user  2010-3947      URL
18235WEB-CLIENT Microsoft Office PICT graphics converter memory corruption attempt (more info ...)attempted-user  2010-3946      URL
18236SPECIFIC-THREATS Microsoft Office TIFFIM32.FLT filter memory corruption attempt (more info ...)attempted-user  2010-3949      URL


# of warning rules in this group: 112

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
233DDOS Trin00 Attacker to Master default startup password (more info ...)attempted-dos 2000-0138   
234DDOS Trin00 Attacker to Master default password (more info ...)attempted-dos 2000-0138   
235DDOS Trin00 Attacker to Master default mdie password (more info ...)bad-unknown 2000-0138   
237DDOS Trin00 Master to Daemon default password attempt (more info ...)attempted-dos 2000-0138   
505MISC Insecure TIMBUKTU Password (more info ...)bad-unknown    
1098WEB-MISC SmartWin CyberOffice Shopping Cart access (more info ...)web-application-attack 2000-0925 1734  
1192WEB-MISC Trend Micro OfficeScan access (more info ...)attempted-recon  1057  
1381WEB-MISC Trend Micro OfficeScan attempt (more info ...)attempted-recon  1057  
1859WEB-MISC Sun JavaServer default password login attempt (more info ...)default-login-attempt   10995 
1860WEB-MISC Linksys router default password login attempt (more info ...)default-login-attempt   10999 
1861WEB-MISC Linksys router default username and password login attempt (more info ...)default-login-attempt   10999 
2027RPC yppasswd old password overflow attempt UDP (more info ...)rpc-portmap-decode 2001-0779 2763  
2028RPC yppasswd old password overflow attempt TCP (more info ...)rpc-portmap-decode 2001-0779 2763  
2029RPC yppasswd new password overflow attempt UDP (more info ...)rpc-portmap-decode 2001-0779 2763  
2030RPC yppasswd new password overflow attempt TCP (more info ...)rpc-portmap-decode 2001-0779 2763  
2114RSERVICES rexec password overflow attempt (more info ...)attempted-admin    
2230WEB-MISC NetGear router default password login attempt admin/password (more info ...)default-login-attempt   11737 
2408WEB-MISC Invision Power Board search.pl access (more info ...)web-application-activity  9766  
6471EXPLOIT RealVNC password authentication bypass attempt (more info ...)attempted-admin 2006-2369 17978  
7024WEB-CLIENT excel style handling overflow attempt (more info ...)attempted-user 2006-3431 18872  URL
7088BACKDOOR sinique 1.0 runtime detection - initial connection with correct password server-to-client (more info ...)trojan-activity    URL
7090BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password server-to-client (more info ...)trojan-activity    URL
7204WEB-CLIENT excel object ftCmo overflow attempt (more info ...)attempted-user 2006-1306 18886  
7205WEB-CLIENT excel FngGroupCount record overflow attempt (more info ...)attempted-user 2006-1308 18890  
7872WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX clsid access (more info ...)attempted-user 2009-1136   URL
7873WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX clsid unicode access (more info ...)attempted-user 2009-1136   URL
10087EXPLOIT VNC password request buffer overflow attempt (more info ...)web-application-attack 2006-1652 2305  
10407EXPLOIT Helix Server LoadTestPassword buffer overflow attempt (more info ...)attempted-admin 2006-6026 23068  URL
11199WEB-ACTIVEX Office Viewer ActiveX clsid access (more info ...)attempted-user  33283  URL
11200WEB-ACTIVEX Office Viewer ActiveX clsid unicode access (more info ...)attempted-user  33283  URL
11201WEB-ACTIVEX Office Viewer ActiveX function call access (more info ...)attempted-user  33283  URL
11202WEB-ACTIVEX Office Viewer ActiveX function call unicode access (more info ...)attempted-user  33283  URL
11622WEB-ACTIVEX Microsoft Office 2000 OUACTR ActiveX clsid access (more info ...)attempted-user 2007-2903 24118  URL
11623WEB-ACTIVEX Microsoft Office 2000 OUACTR ActiveX clsid unicode access (more info ...)attempted-user 2007-2903 24118  URL
11660WEB-ACTIVEX EDraw Office Viewer ActiveX clsid access (more info ...)attempted-user  24230  URL
11661WEB-ACTIVEX EDraw Office Viewer ActiveX clsid unicode access (more info ...)attempted-user  24230  URL
11662WEB-ACTIVEX EDraw Office Viewer ActiveX function call access (more info ...)attempted-user  24230  URL
11663WEB-ACTIVEX EDraw Office Viewer ActiveX function call unicode access (more info ...)attempted-user  24230  URL
11967WEB-ACTIVEX Microsoft Office Data Source Control 11.0 ActiveX function call unicode access (more info ...)attempted-user 2006-3729 24462  URL
12070EXPLOIT Microsoft Excel malformed version field (more info ...)attempted-user 2007-1756 24801  URL
12099MISC Microsoft Excel rtWindow1 record handling arbitrary code execution attempt (more info ...)attempted-user 2007-3029 22555  URL
12184MISC Microsoft Excel workbook workspace designation handling arbitrary code execution attempt (more info ...)attempted-user 2007-3030 24803  URL
12234BACKDOOR theef 2.10 runtime detection - connect with no password (more info ...)trojan-activity    URL
12236BACKDOOR theef 2.10 runtime detection - connect with password (more info ...)trojan-activity    URL
12261WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX clsid access (more info ...)attempted-user 2007-3041   URL
12262WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX clsid unicode access (more info ...)attempted-user 2007-3041   URL
12263WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX function call access (more info ...)attempted-user 2007-3041   URL
12264WEB-ACTIVEX Microsoft Visual Basic 6 PDWizard.File ActiveX function call unicode access (more info ...)attempted-user 2007-3041   URL
12265WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX clsid access (more info ...)attempted-user 2007-2216   URL
12266WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX clsid unicode access (more info ...)attempted-user 2007-2216   URL
12267WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX function call access (more info ...)attempted-user 2007-2216   URL
12268WEB-ACTIVEX Microsoft Visual Basic 6 SearchHelper ActiveX function call unicode access (more info ...)attempted-user 2007-2216   URL
12269WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX clsid access (more info ...)attempted-user 2007-2216   URL
12270WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX clsid unicode access (more info ...)attempted-user 2007-2216   URL
12271WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX function call access (more info ...)attempted-user 2007-2216   URL
12272WEB-ACTIVEX Microsoft Visual Basic 6 TLIApplication ActiveX function call unicode access (more info ...)attempted-user 2007-2216   URL
12273WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid access (more info ...)attempted-user 2007-2216   URL
12274WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX clsid unicode access (more info ...)attempted-user 2007-2216   URL
12275WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX function call access (more info ...)attempted-user 2007-2216   URL
12276WEB-ACTIVEX Microsoft Visual Basic 6 TypeLibInfo ActiveX function call unicode access (more info ...)attempted-user 2007-2216   URL
12284WEB-CLIENT Excel rtWnDesk record memory corruption exploit attempt (more info ...)attempted-user 2007-3890   URL
12430WEB-ACTIVEX EDraw Office Viewer Component ActiveX clsid access (more info ...)attempted-user 2007-4821 25892  
12431WEB-ACTIVEX EDraw Office Viewer Component ActiveX clsid unicode access (more info ...)attempted-user 2007-4821 25892  
12432WEB-ACTIVEX EDraw Office Viewer Component ActiveX function call access (more info ...)attempted-user 2007-4821 25892  
12433WEB-ACTIVEX EDraw Office Viewer Component ActiveX function call unicode access (more info ...)attempted-user 2007-4821 25892  
12618WEB-CLIENT Microsoft Visual Basic VBP file reference overflow attempt (more info ...)attempted-user 2007-4776 25629  
13277SPYWARE-PUT Adware netword agent runtime detection (more info ...)misc-activity    URL
13467WEB-ACTIVEX Office 2000 and 2002 Web Components Spreadsheet ActiveX clsid unicode access (more info ...)attempted-user 2006-4695 4453  URL
13468WEB-ACTIVEX Office 2000 and 2002 Web Components Data Source Control ActiveX clsid unicode access (more info ...)attempted-user 2007-1201 4449  URL
13469WEB-CLIENT Microsoft Word ole stream memory corruption attempt (more info ...)attempted-user 2008-0109   URL
13556SPYWARE-PUT Hijacker kword interkey runtime detection - search traffic 1 (more info ...)misc-activity    URL
13557SPYWARE-PUT Hijacker kword interkey runtime detection - search traffic 2 (more info ...)misc-activity    URL
13558SPYWARE-PUT Hijacker kword interkey runtime detection - log user info (more info ...)misc-activity    URL
13569WEB-CLIENT Microsoft Excel macro validation arbitrary code execution attempt (more info ...)attempted-user 2008-0081   URL
13580WEB-ACTIVEX Microsoft Office Web Components remote code execution attempt ActiveX clsid access (more info ...)attempted-user 2006-4695   URL
13581WEB-ACTIVEX Microsoft Office Web Components remote code execution attempt ActiveX clsid unicode access (more info ...)attempted-user 2006-4695   URL
13958WEB-CLIENT WordPerfect Graphics file invalid RLE buffer overflow attempt (more info ...)attempted-user 2008-3460   URL
15089WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX clsid unicode access (more info ...)attempted-user 2008-4256   URL
15091WEB-ACTIVEX Microsoft Visual Basic Charts ActiveX function call unicode access (more info ...)attempted-user 2008-4256   URL
15093WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX clsid unicode access (more info ...)attempted-user 2008-4252   URL
15095WEB-ACTIVEX Microsoft Visual Basic DataGrid ActiveX function call unicode access (more info ...)attempted-user 2008-4252   URL
15097WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX clsid unicode access (more info ...)attempted-user 2008-4253   URL
15099WEB-ACTIVEX Microsoft Visual Basic FlexGrid ActiveX function call unicode access (more info ...)attempted-user 2008-4253   URL
15101WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX clsid unicode access (more info ...)attempted-user 2008-4254   URL
15103WEB-ACTIVEX Microsoft Visual Basic Hierarchical FlexGrid ActiveX function call unicode access (more info ...)attempted-user 2008-4254   URL
15119WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX clsid unicode access (more info ...)attempted-user 2008-4251   URL
15121WEB-ACTIVEX Microsoft Visual Basic Winsock ActiveX function call unicode access (more info ...)attempted-user 2008-4251   URL
15539WEB-CLIENT Microsoft Office Excel Formula record remote code execution attempt (more info ...)attempted-user 2009-0560   URL
15575WEB-CLIENT WordPerfect file download (more info ...)misc-activity    URL
15686WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX clsid unicode access (more info ...)attempted-user 2009-2496   URL
15688WEB-ACTIVEX Microsoft Office Web Components 10 Spreadsheet ActiveX function call unicode access (more info ...)attempted-user 2009-2496   URL
15690WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX clsid unicode access (more info ...)attempted-user 2009-1136   URL
15692WEB-ACTIVEX Microsoft Office Web Components 11 Spreadsheet ActiveX function call unicode access (more info ...)attempted-user 2009-1136   URL
15855WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX function call access (more info ...)attempted-user 2009-1136   URL
15856WEB-ACTIVEX Microsoft Office Spreadsheet 10.0 ActiveX function call unicode access (more info ...)attempted-user 2009-1136   URL
15858WEB-ACTIVEX Microsoft Office Web Components Spreadsheet ActiveX clsid access (more info ...)attempted-user 2009-1534   URL
15859WEB-ACTIVEX Microsoft Office Web Components Spreadsheet ActiveX clsid unicode access (more info ...)attempted-user 2009-1534   URL
16059EXPLOIT Microsoft Excel malformed file format parsing code execution attempt (more info ...)attempted-user 2006-0028   URL
16228WEB-CLIENT Microsoft Excel malformed StartObject record arbitrary code execution attempt (more info ...)attempted-admin 2009-3134   URL
16650WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 1 (more info ...)attempted-user 2010-1249   URL
16651WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 2 (more info ...)attempted-user 2010-1249   URL
16652WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 3 (more info ...)attempted-user 2010-1249   URL
16653WEB-CLIENT Microsoft Excel ExternName record stack buffer overflow attempt - 4 (more info ...)attempted-user 2010-1249   URL
16654WEB-CLIENT Microsoft Excel undocumented Publisher record heap buffer overflow attempt (more info ...)attempted-user 2010-1250   URL
16655WEB-CLIENT Microsoft Excel Lbl record stack overflow attempt (more info ...)attempted-user 2010-1251   URL
16656WEB-CLIENT Microsoft Excel BIFF5 ExternSheet record stack overflow attempt (more info ...)attempted-user 2010-1252   URL
16657WEB-CLIENT Microsoft Excel DBQueryExt record memory corruption attempt (more info ...)attempted-user 2010-1253   URL
17134WEB-CLIENT Microsoft Excel out-of-bounds structure read memory corruption attempt (more info ...)attempted-user 2010-2562   URL
17388WEB-CLIENT OpenOffice EMF file EMR record parsing integer overflow attempt (more info ...)attempted-user 2008-2238   URL
17532SPECIFIC-THREATS Microsoft Excel TXO and OBJ Records Parsing Stack Memory Corruption (more info ...)attempted-user 2008-4265 32618  
17708EXPLOIT VNC password request URL buffer overflow attempt (more info ...)web-application-attack 2006-1652 17378  
18049PHISHING-SPAM word.onlinephilbert42f.ru known spam email attempt (more info ...)policy-violation    

 goto Top

Group: Client / Browser

# of attack rules in this group: 246

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3686WEB-CLIENT Microsoft Internet Explorer Content Advisor memory corruption attempt (more info ...)attempted-user  2005-0555      URL
3814WEB-CLIENT IE javaprxy.dll COM access (more info ...)attempted-user  2005-2087  14087    URL
4169WEB-ACTIVEX Internet Explorer Active Setup ActiveX Object Access (more info ...)attempted-user    667    URL
4198WEB-ACTIVEX Internet Explorer Blnmgrps.dll ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4199WEB-ACTIVEX Internet Explorer Blnmgrps.dll ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4210WEB-ACTIVEX Internet Explorer Msb1geen.dll ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4222WEB-ACTIVEX Internet Explorer Outllib.dll ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4235WEB-ACTIVEX Helper Object for Java ActiveX Object Access (more info ...)attempted-user  2005-2127      URL
4647WEB-CLIENT internet explorer javascript onload overflow attempt (more info ...)attempted-user  2005-1790  13799    URL
4917WEB-CLIENT internet explorer javascript onload prompt obfuscation overflow attempt (more info ...)attempted-user  2005-1790  13799    URL
6509WEB-CLIENT Internet Explorer mhtml uri href buffer overflow attempt (more info ...)attempted-user  2006-2766  18198    URL
6510WEB-CLIENT Internet Explorer mhtml uri shortcut buffer overflow attempt (more info ...)attempted-user  2006-2766  18198    URL
8019WEB-ACTIVEX Internet Explorer Address Bar ActiveX CLSID access (more info ...)attempted-user  2005-1990  14511    URL
8020WEB-ACTIVEX Internet Explorer Address Bar ActiveX CLSID unicode access (more info ...)attempted-user  2005-1990  14511    URL
8058WEB-CLIENT Mozilla javascript navigator object access (more info ...)attempted-user  2006-3677  19181    URL
8443WEB-CLIENT Mozilla regular expression heap corruption attempt (more info ...)attempted-user  2006-4566  20042    
9628WEB-ACTIVEX javaprxy.dll ActiveX clsid unicode access (more info ...)attempted-user  2005-2087  14087    URL
9843WEB-CLIENT Adobe Acrobat Plugin JavaScript parameter double free attempt (more info ...)attempted-user  2007-0046      URL
10062WEB-CLIENT Java Virtual Machine malformed GIF buffer overflow attempt (more info ...)attempted-user  2007-0243  22085    
10131WEB-CLIENT mozilla compareTo arbitrary code execution attempt (more info ...)attempted-user  2005-2265  14242    URL
11257WEB-CLIENT Microsoft Internet Explorer colgroup tag uninitialized memory corruption vulnerability (more info ...)attempted-user  2007-0944  23771    URL
11680MISC Sun Java web proxy sockd buffer overflow attempt (more info ...)attempted-admin  2007-2881  24165    URL
11834WEB-MISC Internet Explorer navcancl.htm url spoofing attempt (more info ...)misc-attack  2007-1752  22966    URL
12472WEB-ACTIVEX Sun Java Web Start ActiveX clsid access (more info ...)attempted-user  2007-5019  25734    
12473WEB-ACTIVEX Sun Java Web Start ActiveX clsid unicode access (more info ...)attempted-user  2007-5019  25734    
12474WEB-ACTIVEX Sun Java Web Start ActiveX function call access (more info ...)attempted-user  2007-5019  25734    
12475WEB-ACTIVEX Sun Java Web Start ActiveX function call unicode access (more info ...)attempted-user  2007-5019  25734    
13834WEB-CLIENT Microsoft Internet Explorer request header overwrite (more info ...)misc-activity  2008-1544      URL
13838WEB-CLIENT Mozilla Firefox IFRAME style change handling code execution (more info ...)attempted-user  2008-1236  28448    URL
13960WEB-CLIENT Microsoft Internet Explorer static text range overflow attempt (more info ...)attempted-user  2008-2255      URL
13961WEB-CLIENT Internet Explorer table layout access violation vulnerability (more info ...)misc-attack  2008-2258      URL
13963WEB-CLIENT Internet Explorer argument validation in print preview handling vulnerability (more info ...)attempted-user  2008-2259      URL
14615EXPLOIT Sun Java web console format string attempt (more info ...)attempted-user  2007-1681      
15081WEB-CLIENT Sun Java Web Start xml encoding buffer overflow attempt (more info ...)attempted-admin  2008-1188  28083    URL
15114WEB-CLIENT Microsoft Internet Explorer embed src buffer overflow attempt (more info ...)attempted-user  2008-4261      URL
15126WEB-CLIENT Internet Explorer nested tag memory corruption attempt (more info ...)attempted-user  2008-4844  32721    URL
15164SPECIFIC-THREATS Mozilla Products SVG Layout Engine Index Parameter memory corruption attempt (more info ...)attempted-user  2007-2867  24242    
15191SPECIFIC-THREATS Mozilla Firefox animated PNG processing integer overflow (more info ...)attempted-user  2008-4064      
15237WEB-MISC Java .class file download attempt (more info ...)misc-activity        
15238SPECIFIC-THREATS Apple QuickTime for Java toQTPointer function memory corruption attempt (more info ...)attempted-user  2007-2175  23608    
15300WEB-CLIENT Microsoft Internet Explorer EMF polyline overflow attempt (more info ...)attempted-user  2009-0081      URL
15304WEB-CLIENT Internet Explorer object clone deletion memory corruption attempt (more info ...)attempted-user  2009-0075      URL
15305WEB-CLIENT Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user  2009-0076      URL
15362WEB-CLIENT obfuscated javascript excessive fromCharCode - potential attack (more info ...)misc-activity        URL
15363WEB-CLIENT Potential obfuscated javascript eval unescape attack attempt (more info ...)misc-activity        URL
15383SPECIFIC-THREATS Mozilla Firefox XBL Event Handler Tags Removal memory corruption attempt (more info ...)attempted-user  2007-5339  26132    
15428WEB-CLIENT Mozilla Firefox SVG data processing memory corruption attempt (more info ...)attempted-user  2009-0771  33990    URL
15458EXPLOIT Internet Explorer navigating between pages race condition attempt (more info ...)attempted-user  2009-0551      URL
15459EXPLOIT Internet Explorer deleted/unitialized object memory corruption attempt (more info ...)attempted-user  2009-0552      URL
15460EXPLOIT Internet Explorer ActiveX load/unload race condition attempt (more info ...)attempted-user  2009-0553      URL
15461WEB-CLIENT Microsoft Internet Explorer marquee tag onstart memory corruption (more info ...)attempted-user  2009-0554      URL
15482EXPLOIT Sun Java System sockd authentication buffer overflow attempt (more info ...)attempted-admin  2007-2881      
15529WEB-CLIENT Microsoft Internet Explorer cross-domain navigation cookie stealing attempt (more info ...)misc-attack  2007-3091      URL
15678SPECIFIC-THREATS Microsoft DirectShow ActiveX exploit via JavaScript (more info ...)attempted-user  2008-0015      URL
15679SPECIFIC-THREATS Microsoft DirectShow ActiveX exploit via JavaScript - unicode encoding (more info ...)attempted-user  2008-0015      URL
15697WEB-CLIENT Generic javascript obfuscation attempt (more info ...)attempted-user    35660    
15698WEB-CLIENT Possible generic javascript heap spray attempt (more info ...)attempted-user    35660    
15699SPECIFIC-THREATS Mozilla Firefox 3.5 unicode stack overflow attempt (more info ...)attempted-user  2009-2479  35707    
15731EXPLOIT javascript deleted reference arbitrary code execution attempt (more info ...)attempted-user  2009-1917      URL
15732EXPLOIT Microsoft Internet Explorer CSS handling memory corruption attempt (more info ...)attempted-user  2009-1919      URL
15733EXPLOIT Microsoft Internet Explorer empty table tag memory corruption attempt (more info ...)attempted-user  2009-1918      URL
15880SPECIFIC-THREATS Microsoft Internet Explorer popup window object tag code execution attempt (more info ...)attempted-user  2003-0838      
15910EXPLOIT Microsoft Internet Explorer getElementById object corruption (more info ...)attempted-user  2008-2254  30614    URL
15997SPECIFIC-THREATS Mozilla Firefox JIT escape function memory corruption attempt (more info ...)attempted-user  2009-2477  35660    URL
15999SPECIFIC-THREATS Mozilla products frame comment objects manipulation memory corruption attempt (more info ...)attempted-user  2006-6504  21668    
16000WEB-CLIENT Sun Microsystems Java gif handling memory corruption attempt (more info ...)attempted-user  2007-0243  22085    
16005SPECIFIC-THREATS Mozilla browsers JavaScript argument passing code execution attempt (more info ...)attempted-user  2007-0777  22694    
16007SPECIFIC-THREATS Microsoft Internet Explorer colgroup tag uninitialized memory exploit attempt (more info ...)attempted-user  2007-0944  23771    URL
16008WEB-MISC Microsoft Internet Explorer 7 html object memory corruption attempt (more info ...)misc-activity  2007-0947      
16009SPECIFIC-THREATS Mozilla products overflow event handling memory corruption attempt (more info ...)attempted-user  2007-2876  24376    
16024SPECIFIC-THREATS Mozilla Firefox Javascript Function focus overflow attempt (more info ...)attempted-user  2006-1993  17671    
16031WEB-CLIENT Microsoft Internet Explorer nested object tag memory corruption attempt (more info ...)attempted-user  2006-1992  17658    
16032WEB-CLIENT Microsoft Internet Explorer HTML Decoding memory corruption attempt (more info ...)attempted-user  2006-2382  18309    
16033SPECIFIC-THREATS Microsoft Internet Explorer compressed content attempt (more info ...)attempted-user  2006-3873  19987    
16035WEB-CLIENT Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user  2006-1359  17196    
16036WEB-CLIENT Mozilla Products QueryInterface method memory corruption attempt (more info ...)attempted-user  2006-0295  16476    
16037WEB-CLIENT Mozilla products graphics and XML features integer overflows attempt (more info ...)attempted-user  2006-0297  16476    
16038MISC Mozilla Thunderbird WYSIWIG engine filtering IFRAME JavaScript execution attempt (more info ...)attempted-user  2006-0884  16770    
16042SPECIFIC-THREATS Mozilla browsers CSS moz-binding cross domain scripting attempt (more info ...)attempted-user  2006-0496  16427    
16043WEB-CLIENT Microsoft Internet Explorer html tag memory corruption attempt (more info ...)attempted-dos  2006-1188  17468    
16044WEB-CLIENT Mozilla Firefox CSS Letter-Spacing overflow attempt (more info ...)attempted-user  2006-1730  17516    
16045SPECIFIC-THREATS Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user  2006-3280  18682    
16047SPECIFIC-THREATS Mozilla Firefox layout frame constructor memory corruption attempt (more info ...)attempted-user  2007-5959      
16050WEB-CLIENT Mozilla Firefox tag order memory corruption attempt (more info ...)attempted-user  2006-0749  17516    
16063WEB-CLIENT Internet Explorer isindex buffer overflow attempt (more info ...)attempted-user  2008-0076  27668    URL
16064SPECIFIC-THREATS internet explorer onBeforeUnload address bar spoofing attempt (more info ...)misc-activity  2007-3826  24911    URL
16065SPECIFIC-THREATS internet explorer location.replace memory corruption attempt (more info ...)attempted-user  2007-5347  26427    URL
16067SPECIFIC-THREATS Microsoft Internet Explorer DOM object cache management memory corruption attempt (more info ...)attempted-user  2007-5344      
16142SPECIFIC-THREATS Mozilla Firefox PKCS11 module installation code execution attempt (more info ...)attempted-user  2009-3076  36343    
16145SPECIFIC-THREATS Apple Safari Webkit floating point buffer overflow attempt (more info ...)attempted-user  2009-2195  36023    
16149EXPLOIT Microsoft Internet Explorer data stream header remote code execution attempt (more info ...)attempted-user  2009-1547      URL
16150EXPLOIT Internet Explorer variant argument validation remote code execution attempt (more info ...)misc-activity  2009-2529      URL
16151WEB-CLIENT Internet Explorer unitialized or deleted object access attempt (more info ...)misc-activity  2009-2530      URL
16152EXPLOIT Internet Explorer table layout unitialized or deleted object access attempt (more info ...)misc-activity  2009-2531      URL
16169WEB-CLIENT Microsoft Internet Explorer dynamic style update memory corruption attempt (more info ...)attempted-user  2009-0076      URL
16284SPECIFIC-THREATS Mozilla Firefox ClearTextRun exploit attempt (more info ...)attempted-user  2009-1313  34743    
16288SPECIFIC-THREATS Sun Java Runtime AWT setDiffICM stack buffer overflow attempt (more info ...)attempted-user  2009-3869  36881    
16291WEB-CLIENT Mozilla Network Security Services regexp heap overflow attempt (more info ...)attempted-user  2009-2404  35891    
16317EXPLOIT Internet Explorer mouse move during refresh memory corruption attempt (more info ...)attempted-user  2009-3673      URL
16319WEB-CLIENT Safari-IE SearchPath blended threat attempt (more info ...)attempted-user  2008-2540      URL
16326EXPLOIT Microsoft Internet Explorer 8 DOM memory corruption attempt (more info ...)attempted-user  2010-0246      URL
16339WEB-CLIENT Internet Explorer object clone deletion memory corruption attempt - obfuscated (more info ...)attempted-user  2009-0075      URL
16344SPECIFIC-THREATS Mozilla Firefox top-level script object offset calculation memory corruption attempt (more info ...)attempted-user  2009-3073  36343    
16347SPECIFIC-THREATS Mozilla Firefox browser engine memory corruption attempt (more info ...)attempted-user  2009-3382  36866    
16367WEB-CLIENT Microsoft Internet Explorer invalid object access memory corruption attempt (more info ...)attempted-user  2010-0249      URL
16369EXPLOIT Microsoft Internet Explorer deleted object access memory corruption attempt - public exploit (more info ...)attempted-user  2010-0249      URL
16376EXPLOIT Internet Explorer onPropertyChange deleteTable memory corruption attempt (more info ...)misc-activity  2010-0244      
16377EXPLOIT Internet Explorer DOM mergeAttributes memory corruption attempt (more info ...)misc-activity  2010-0247      
16392WEB-MISC Sun Java System Web Server 7.0u7 authorization digest heap overflow (more info ...)attempted-user  2010-0387  37896    
16426WEB-MISC Sun Java System Web Server 7.0 WebDAV format string exploit attempt - PROPFIND method (more info ...)attempted-user  2010-0388  37910    
16427WEB-MISC Sun Java System Web Server 7.0 WebDAV format string exploit attempt - LOCK method (more info ...)attempted-user  2010-0388  37910    
16442BOTNET-CNC Possible Zeus User-Agent - Mozilla (more info ...)trojan-activity        URL
16482WEB-CLIENT Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806      URL
16492WEB-CLIENT Safari inline text box use after free attempt (more info ...)attempted-user  2010-0049      
16501WEB-CLIENT Mozilla Firefox WOFF font processing integer overflow attempt - TrueType (more info ...)attempted-user  2010-1028  38298    URL
16502WEB-CLIENT Mozilla Firefox WOFF font processing integer overflow attempt - CFF-based (more info ...)attempted-user  2010-1028  38298    URL
16503EXPLOIT Microsoft Internet Explorer event handling remote code execution attempt (more info ...)attempted-user  2010-0267      URL
16504EXPLOIT Microsoft Internet Explorer 7 encoded content handling exploit attempt (more info ...)misc-attack  2010-0488      URL
16509EXPLOIT Microsoft Internet Explorer designMode-enabled information disclosure attempt (more info ...)misc-attack  2010-0494      URL
16547WEB-ACTIVEX Java Web Start ActiveX launch command by CLSID (more info ...)attempted-user  2010-1423  39346    
16548WEB-ACTIVEX Java Web Start ActiveX launch command by JavaScript CLSID (more info ...)attempted-user  2010-1423  39346    
16549WEB-CLIENT Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - npruntime-scriptable-plugin (more info ...)attempted-user  2010-1423  39346    
16550WEB-CLIENT Oracle JRE Java Platform SE and Java Deployment Toolkit plugins code execution attempt - java-deployment-toolkit (more info ...)attempted-user  2010-1423  39346    
16554WEB-CLIENT Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user  2009-0927  34169    
16584WEB-CLIENT Java Web Start arbitrary command execution attempt - Internet Explorer (more info ...)attempted-user  2010-1423  39346    
16585WEB-CLIENT Java Web Start arbitrary command execution attempt (more info ...)attempted-user  2010-1423  39346    
16592SPECIFIC-THREATS Opera asynchronous document modifications attempted memory corruption (more info ...)attempted-user        URL
16602SPECIFIC-THREATS Microsoft DirectShow 3 ActiveX exploit via JavaScript (more info ...)attempted-user  2008-0015      URL
16605SPECIFIC-THREATS Internet Explorer nested SPAN tag memory corruption attempt (more info ...)attempted-user  2008-4844  32721    
16635WEB-ACTIVEX Microsoft Internet Explorer 8 Developer Tool ActiveX clsid access (more info ...)attempted-user  2010-0811      URL
16637EXPLOIT Microsoft Internet Explorer security zone restriction bypass attempt (more info ...)attempted-user  2010-0255      URL
16658WEB-CLIENT Microsoft Internet Explorer 8 cross-site scripting attempt (more info ...)attempted-user  2010-1257      URL
16659EXPLOIT Microsoft Internet Explorer style sheet array memory corruption attempt (more info ...)attempted-user  2010-1262      URL
16666SPECIFIC-THREATS Apple Safari window.parent.close unspecified remote code execution vulnerability (more info ...)attempted-user  2010-1939  39990    URL
16667SPECIFIC-THREATS Google Chrome GURL cross origin bypass attempt - 1 (more info ...)attempted-user  2010-1663  39813    
16668SPECIFIC-THREATS Google Chrome GURL cross origin bypass attempt - 2 (more info ...)attempted-user  2010-1663  39813    
16690SPECIFIC-THREATS Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user  2006-1359  17196    
16716WEB-CLIENT Sun Java Web Start Splashscreen PNG processing buffer overflow attempt (more info ...)attempted-user  2009-1097  34240    
17058SPECIFIC-THREATS Trojan-Downloader.JS.Agent.ewh Javascript download attempt (more info ...)trojan-activity        URL
17109SPECIFIC-THREATS Sun Java Web Console logging functionality format string exploit attempt (more info ...)attempted-admin  2007-1681  23539    
17132EXPLOIT Microsoft Internet Explorer invalid object access attempt (more info ...)attempted-user  2010-2560      URL
17136EXPLOIT Microsoft Internet Explorer 6 race condition exploit attempt (more info ...)attempted-user  2010-2558      URL
17140WEB-MISC OpenView Network Node Manager OvJavaLocale buffer overflow attempt (more info ...)attempted-user  2010-2709  42154    
17165WEB-CLIENT Opera browser document writing uninitialized memory access attempt (more info ...)attempted-user  2010-1728  39855    
17166WEB-CLIENT Mozilla multiple products JavaScript string replace buffer overflow attempt (more info ...)attempted-user  2009-3075  36343    
17212WEB-CLIENT Mozilla Firefox JavaScript eval arbitrary code execution attempt (more info ...)attempted-user  2005-1532      URL
17213WEB-CLIENT Mozilla Firefox Chrome Page Loading Restriction Bypass attempt (more info ...)attempted-user  2005-2706      URL
17236WEB-CLIENT Mozilla Firefox nsPropertyTable PropertyList memory corruption attempt (more info ...)attempted-user  2009-3070      URL
17245WEB-CLIENT Mozilla Firefox image dragging exploit attempt (more info ...)attempted-user  2005-0230      
17258WEB-CLIENT Mozilla Firefox XUL tree element code execution attempt (more info ...)attempted-user  2009-1044  34181    
17260SPECIFIC-THREATS Mozilla Firefox Javascript contentWindow in an iframe exploit attempt (more info ...)attempted-user  2006-1993  17671    
17261WEB-CLIENT Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user  2006-1359  17196    
17262WEB-CLIENT Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user  2006-1359  17196    
17263SPECIFIC-THREATS Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user  2006-1359  17196    
17265WEB-CLIENT Mozilla Firefox plugin access control bypass attempt (more info ...)attempted-user  2005-0527  12655    
17268SPECIFIC-THREATS Mozilla Firefox sidebar panel arbitrary code execution attempt (more info ...)attempted-user  2005-0402  12884    
17355WEB-CLIENT Microsoft Internet Explorer JPEG Decoder Vulnerabilities attempt (more info ...)attempted-user  2005-2308  14282    
17360WEB-CLIENT Mozilla Firefox XBM image processing buffer overflow attempt (more info ...)attempted-user  2005-2701  14916    
17378WEB-CLIENT Mozilla Firefox Animated PNG Processing integer overflow (more info ...)attempted-user  2008-4064      
17379WEB-CLIENT Mozilla Firefox Animated PNG Processing integer overflow (more info ...)attempted-user  2008-4064      
17389SPECIFIC-THREATS mozilla firefox DOMNodeRemoved attack attempt (more info ...)attempted-user  2006-2779  18228    
17392SHELLCODE JavaScript var shellcode (more info ...)shellcode-detect        
17393SHELLCODE JavaScript var heapspray (more info ...)shellcode-detect        
17395SPECIFIC-THREATS Sun Java Web Start Splashscreen GIF decoding buffer overflow attempt (more info ...)attempted-user  2008-2086      
17398WEB-CLIENT Mozilla Firefox Javascript array.splice memory corruption attempt (more info ...)attempted-user  2009-0773  33990    
17399WEB-CLIENT Mozilla Firefox Javascript array.splice memory corruption attempt (more info ...)attempted-user  2009-0773  33990    
17400WEB-CLIENT rename of JavaScript unescape function - likely malware obfuscation (more info ...)attempted-user        
17401SPECIFIC-THREATS Internet Explorer nested tag memory corruption attempt - unescaped (more info ...)attempted-user  2008-4844  32721    URL
17402SPECIFIC-THREATS Internet Explorer nested tag memory corruption attempt (more info ...)attempted-user  2008-4844  32721    URL
17411SPECIFIC-THREATS Microsoft Internet Explorer CDF cross-domain scripting attempt (more info ...)attempted-user  2005-0056  12427    URL
17414SPECIFIC-THREATS Mozilla Firefox Javascript Engine Information Disclosure attempt (more info ...)attempted-user  2005-0989  12998    
17415SPECIFIC-THREATS Mozilla Firefox Javascript Engine Information Disclosure attempt (more info ...)attempted-user  2005-0989  12998    
17424SPECIFIC-THREATS Mozilla Firefox IconURL Arbitrary Javascript Execution attempt (more info ...)attempted-user  2005-1477  13544    
17434WEB-CLIENT Mozilla Firefox Unicode sequence handling stack corruption attempt (more info ...)attempted-user  2005-2702  14918    
17462WEB-CLIENT Microsoft Internet Explorer marquee object handling memory corruption attempt (more info ...)attempted-user  2009-0554      URL
17463SPECIFIC-THREATS Internet Explorer File Download Dialog Box Manipulation (more info ...)attempted-user  2005-2829  15823    URL
17471SPECIFIC-THREATS Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user  2009-0927  34169    
17472SPECIFIC-THREATS Adobe Acrobat JavaScript getIcon method buffer overflow attempt (more info ...)attempted-user  2009-0927  34169    
17482WEB-CLIENT Mozilla NNTP URL Handling Buffer Overflow attempt (more info ...)attempted-user  2004-1316  12131    
17487WEB-CLIENT Microsoft Internet Explorer Script Engine Stack Exhaustion Denial of Service attempt (more info ...)attempted-dos  2006-0753  16687    
17519SPECIFIC-THREATS Mozilla Firefox UTF-8 URL Handling Stack Buffer Overflow (more info ...)attempted-user  2008-0016  31346    
17522SPECIFIC-THREATS Sun Java Runtime Environment Pack200 Decompression Integer Overflow (more info ...)attempted-user  2008-4726  31879    
17549SPECIFIC-THREATS Internet Explorer Error Handling Code Execution (more info ...)attempted-admin  2007-3892  25916    
17554SPECIFIC-THREATS Microsoft Internet Explorer DOM object cache management memory corruption attempt (more info ...)attempted-user  2007-5344  26817    
17557WEB-ACTIVEX Novell iPrint ActiveX operation parameter overflow (more info ...)attempted-user  2008-2908  30986    URL
17562SPECIFIC-THREATS Sun Java Runtime Environment Pack200 Decompression Integer Overflow attempt (more info ...)misc-attack  2008-5352  32608    
17563SPECIFIC-THREATS Sun Java Runtime Environment JAR File Processing Stack Buffer Overflow (more info ...)attempted-user  2008-5354  32608    
17566SPECIFIC-THREATS Microsoft Internet Explorer 7 Event Handler Memory Corruption (more info ...)attempted-user  2009-1530  35224    
17570SPECIFIC-THREATS Mozilla Firefox IFRAME style change handling code execution (more info ...)attempted-user  2008-1236  28448    URL
17580SPECIFIC-THREATS Microsoft Internet Explorer span tag memory corruption attempt (more info ...)attempted-user  2006-1188  17468    
17581SPECIFIC-THREATS Mozilla Firefox tag order memory corruption attempt (more info ...)attempted-user  2006-0749  17516    
17585SPECIFIC-THREATS Internet Explorer possible javascript onunload event memory corruption (more info ...)attempted-user  2007-1094  22678    
17586WEB-CLIENT Sun Java Web Start malicious parameter value (more info ...)attempted-user  2004-1029  11726    
17588WEB-ACTIVEX Microsoft Internet Explorer Install Engine ActiveX clsid access (more info ...)attempted-user  2004-0216  11366    URL
17589WEB-ACTIVEX Microsoft Internet Explorer Install Engine ActiveX clsid unicode access (more info ...)attempted-user  2004-0216  11366    URL
17601WEB-CLIENT Mozilla Firefox file type memory corruption attempt (more info ...)attempted-user  2008-5016  32281    URL
17603WEB-CLIENT Mozilla Firefox file type memory corruption attempt (more info ...)attempted-user  2008-5021  32281    URL
17604SPECIFIC-THREATS Java AWT ConvolveOp memory corruption attempt (more info ...)attempted-user    21675    URL
17609WEB-MISC Sun Java Web Server Webdav Stack Buffer Overflow attempt (more info ...)attempted-admin  2010-0361  37874    
17613WEB-MISC Mozilla Firefox browser engine memory corruption attempt (more info ...)attempted-user  2009-1392  35326    
17622SPECIFIC-THREATS Microsoft Internet Explorer object reference memory corruption attempt (more info ...)attempted-user  2007-3902      URL
17623SPECIFIC-THREATS Sun Java Runtime Environment Type1 Font parsing integer overflow attempt (more info ...)attempted-user  2009-1099  34240    
17624SPECIFIC-THREATS Sun Java Runtime Environment Type1 Font parsing integer overflow attempt (more info ...)attempted-user  2009-1099  34240    
17628SPECIFIC-THREATS Sun Microsystems Java gif handling memory corruption attempt (more info ...)attempted-user  2007-0243  22085    
17629WEB-CLIENT Mozilla Firefox Chrome Page Loading Restriction Bypass attempt (more info ...)attempted-user  2005-2706  14920    
17630WEB-CLIENT Mozilla multiple products CSSValue array memory corruption attempt (more info ...)attempted-user  2008-2785  29802    
17631WEB-CLIENT Sun Java Web Start JNLP java-vm-args buffer overflow attempt (more info ...)attempted-user  2008-3111  30148    
17642WEB-CLIENT Mozilla Firefox ConstructFrame with floating first-letter memory corruption attempt (more info ...)attempted-user  2009-2462  35765    
17644SPECIFIC-THREATS Internet Explorer object clone deletion memory corruption attempt (more info ...)attempted-user  2009-0075      URL
17645WEB-CLIENT Microsoft Internet Explorer CSS strings parsing memory corruption attempt (more info ...)attempted-user  2007-0943      URL
17660SPECIFIC-THREATS Java Web Start arbitrary command execution attempt (more info ...)attempted-user  2010-1423  39346    
17685EXPLOITS Internet Explorer invalid pointer memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17686EXPLOITS Internet Explorer invalid pointer memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17687EXPLOITS Internet Explorer invalid pointer memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17688WEB-CLIENT Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17689WEB-CLIENT Internet Explorer userdata behavior memory corruption attempt (more info ...)attempted-user  2010-0806      URL
17692WEB-CLIENT Microsoft Internet Explorer ExecWB security zone bypass attempt (more info ...)attempted-user  2008-2259  30612    URL
17703SPECIFIC-THREATS Internet Explorer popup title bar spoofing attempt (more info ...)misc-activity  2005-0500  12602    
17709WEB-CLIENT Microsoft Internet Explorer EMBED element memory corruption attempt (more info ...)attempted-user  2009-0553  34424    URL
17719SPECIFIC-THREATS Mozilla Firefox ClearTextRun exploit attempt (more info ...)attempted-user  2009-1313  34743    
17720WEB-CLIENT Microsoft Internet Explorer static text range overflow attempt (more info ...)attempted-user  2008-2255      URL
17726SPECIFIC-THREATS Internet Explorer address bar spoofing attempt (more info ...)misc-activity  2006-1626  17404    
17729SPECIFIC-THREATS Microsoft Internet Explorer EMBED element memory corruption attempt (more info ...)attempted-user  2009-0553  34424    URL
17747EXPLOIT Microsoft Internet Explorer compressed HDMX font processing integer overflow attempt (more info ...)attempted-admin  2010-1883      URL
17771EXPLOIT Microsoft Internet Explorer cross-domain information disclosure attempt (more info ...)attempted-user  2010-3330      URL
17781SPECIFIC-THREATS Microsoft Internet Explorer createTextRange code execution attempt (more info ...)attempted-user  2006-1359  17196    
17804WEB-CLIENT Mozilla Firefox html tag attributes memory corruption (more info ...)attempted-user  2010-3765      
18062WEB-CLIENT Microsoft Internet Explorer CSS style memory corruption attempt (more info ...)attempted-user  2010-3962      URL
18077SPECIFIC-THREATS Mozilla products CSS rendering out-of-bounds array write attempt (more info ...)attempted-user  2006-1739      URL
18078SPECIFIC-THREATS Mozilla products CSS rendering out-of-bounds array write attempt (more info ...)attempted-user  2006-1739      URL
18102WEB-CLIENT Adobe Reader invalid PDF JavaScript extension call (more info ...)attempted-admin  2010-4091      URL
18167WEB-CLIENT Possible generic javascript heap spray attempt (more info ...)attempted-user    35660    
18168WEB-CLIENT Possible generic javascript heap spray attempt (more info ...)attempted-user    35660    
18174SPECIFIC-THREATS Microsoft Internet Explorer CSS memory corruption attempt (more info ...)attempted-user  2004-0842  10816    
18175SPECIFIC-THREATS Microsoft Internet Explorer CSS memory corruption attempt (more info ...)attempted-user  2004-0842  10816    
18186SPECIFIC-THREATS Mozilla products -moz-grid and -moz-grid-group display styles code execution attempt (more info ...)attempted-user  2006-1738  17516    
18187SPECIFIC-THREATS Mozilla Firefox InstallTrigger.install memory corruption attempt (more info ...)attempted-user  2006-1790  17516    
18196WEB-CLIENT Microsoft Internet Explorer CSS importer use-after-free attempt (more info ...)attempted-user  2010-3971      URL
18216WEB-CLIENT Microsoft Internet Explorer 6 #default#anim attempt (more info ...)attempted-user  2010-3343      URL
18217SPECIFIC-THREATS Microsoft Internet Explorer 8 select element execution attempt (more info ...)attempted-user  2010-3345      URL
18218SPECIFIC-THREATS Microsoft Internet Explorer html time manipulation attempt (more info ...)attempted-user  2010-3346      URL
18239WEB-CLIENT known malicious JavaScript decryption routine (more info ...)attempted-user        
18240WEB-CLIENT Microsoft Internet Explorer CSS importer use-after-free attempt (more info ...)attempted-user  2010-3971      URL
18244WEB-CLIENT Sun Java browswer plugin docbase overflow attempt (more info ...)attempted-user  2010-3552  44023    URL
18245SPECIFIC-THREATS Sun Java browswer plugin docbase overflow attempt (more info ...)attempted-user  2010-3552  44023    URL
18250SPECIFIC-THREATS Mozilla products EscapeAttributeValue integer overflow attempt (more info ...)attempted-user  2006-0297  16476    


# of warning rules in this group: 67

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
1667WEB-MISC cross site scripting HTML Image tag set to javascript attempt (more info ...)web-application-attack 2002-0902 4858  
1840WEB-CLIENT Javascript document.domain attempt (more info ...)attempted-user 2002-0815 5346  
1841WEB-CLIENT Javascript URL host spoofing attempt (more info ...)attempted-user  5293  
1874WEB-MISC Oracle Java Process Manager access (more info ...)web-application-activity   10851 
3534WEB-CLIENT Mozilla GIF single packet heap overflow - NETSCAPE2.0 (more info ...)attempted-user 2005-0399 12881 17605 
3536WEB-CLIENT Mozilla GIF multipacket heap overflow - NETSCAPE2.0 (more info ...)attempted-user 2005-0399 12881 17605 
3679WEB-CLIENT Web-client IFRAME src javascript code execution (more info ...)attempted-user 2008-2939 30560 18243 
3689WEB-CLIENT Internet Explorer tRNS overflow attempt (more info ...)attempted-user 2005-1211 13941 18490 URL
4916WEB-CLIENT internet explorer javascript onload document.write obfuscation overflow attempt (more info ...)attempted-user 2005-1790 13799  URL
6502WEB-CLIENT Mozilla GIF single packet heap overflow - ANIMEXTS1.0 (more info ...)attempted-user 2005-0399 12881 17605 
6503WEB-CLIENT Mozilla GIF multipacket heap overflow - ANIMEXTS1.0 (more info ...)attempted-user 2005-0399 12881 17605 
7071WEB-MISC encoded cross site scripting HTML Image tag set to javascript attempt (more info ...)web-application-attack 2002-0902 4858  
11000ORACLE dbms_snap_internal.delete_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11001ORACLE dbms_snap_internal.delete_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11002ORACLE dbms_snap_internal.generate_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11003ORACLE dbms_snap_internal.generate_refresh_operations buffer overflow attempt (more info ...)attempted-user 2007-2126 23532  URL
11966WEB-CLIENT Microsoft Internet Explorer CSS tag memory corruption attempt (more info ...)attempted-user 2007-1750 24423  URL
12014WEB-MISC Internet Explorer navcancl.htm url spoofing attempt (more info ...)misc-attack 2007-1499 22966  URL
12593EXPLOIT Firefox Quicktime chrome exploit (more info ...)attempted-user 2007-5045   
13840EXPLOIT Borland Interbase service attach operation buffer overflow (more info ...)attempted-admin 2007-5243   
13841EXPLOIT Borland Interbase create operation buffer overflow (more info ...)attempted-admin 2007-5243   
13842EXPLOIT Borland Interbase operation buffer overflow (more info ...)attempted-admin 2007-5243   
13974WEB-CLIENT Internet Explorer XHTML element memory corruption attempt (more info ...)attempted-user 2008-2257   URL
14037WEB-ACTIVEX Novell iPrint ActiveX operation or printer-url parameter overflow attempt (more info ...)attempted-user 2008-2908 29736  
15531WEB-CLIENT Microsoft Internet Explorer Unexpected method call remote code execution attempt (more info ...)attempted-user 2009-1141   URL
15538WEB-CLIENT Microsoft Internet Explorer onreadystatechange memory corruption attempt (more info ...)misc-attack 2009-1531   URL
15933WEB-CLIENT Internet Explorer URL canonicalization address bar spoofing attempt (more info ...)misc-activity 2003-1025   URL
16010SPECIFIC-THREATS Microsoft Internet Explorer Javascript Page update race condition attempt (more info ...)misc-activity 2007-3091 24283  
16011SPECIFIC-THREATS Microsoft Internet Explorer CSS property method handling memory corruption attempt (more info ...)attempted-user 2007-0945 23769  
16155WEB-CLIENT Internet Explorer indexing service malformed parameters (more info ...)attempted-user 2009-2507   URL
16292SPECIFIC-THREATS Mozilla CSS value counter overflow attempt (more info ...)attempted-user 2008-2785 29802  URL
16330WEB-CLIENT Microsoft Internet Explorer orphan DOM objects memory corruption attempt (more info ...)attempted-user 2009-3674   URL
16378WEB-CLIENT Internet Explorer deleted object cells reference memory corruption vulnerability (more info ...)attempted-user 2010-0248   
16481WEB-CLIENT Opera Content-Length header integer overflow attempt (more info ...)attempted-user  38519  URL
16507WEB-CLIENT Internet Explorer onreadystatechange memory corruption attempt (more info ...)attempted-user 2010-0491   URL
16596WEB-CLIENT Apple Safari information disclosure and remote code execution attempt (more info ...)attempted-user 2010-1939   URL
16631SPECIFIC-THREATS Safari image use after remove attempt (more info ...)attempted-user 2010-0054 38691  URL
16632SPECIFIC-THREATS Safari image use after reparent attempt (more info ...)attempted-user 2010-0054 38691  URL
17115WEB-CLIENT Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2010-1258   URL
17129WEB-CLIENT Internet Explorer use-after-free memory corruption attempt (more info ...)attempted-dos 2010-2556   URL
17153WEB-CLIENT Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 1 (more info ...)attempted-user 2010-2755 41933  
17154WEB-CLIENT Mozilla Firefox plugin parameter array dangling pointer exploit attempt - 2 (more info ...)attempted-user 2010-2755 41933  
17216WEB-CLIENT Apple Safari TABLE tag with large CELLSPACING attribute exploit attempt (more info ...)attempted-user 2006-1986 17634  
17217WEB-CLIENT Apple Safari invalid FRAME tag remote code execution attempt (more info ...)attempted-user 2006-1987 17634  
17218WEB-CLIENT Apple Safari LI tag with large VALUE attribute exploit attempt (more info ...)attempted-user 2006-1988 17634  
17303WEB-CLIENT Microsoft Internet Explorer clone object memory corruption attempt (more info ...)attempted-user 2007-3903 26816  
17311SPECIFIC-THREATS Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt (more info ...)attempted-user 2005-4089 15660  
17312SPECIFIC-THREATS Microsoft Internet Explorer CSS import cross-domain restriction bypass attempt (more info ...)attempted-user 2005-4089 15660  
17384WEB-CLIENT Microsoft Internet Explorer setRequestHeader overflow attempt (more info ...)attempted-user 2008-1544 28379  
17385WEB-CLIENT Microsoft Internet Explorer setRequestHeader overflow attempt (more info ...)attempted-user 2008-1544 28379  
17448SPECIFIC-THREATS Microsoft Internet Explorer HTTPS proxy information disclosure vulnerability (more info ...)misc-attack 2005-2830   URL
17494WEB-CLIENT Microsoft Internet Explorer Long URL Buffer Overflow attempt (more info ...)attempted-user 2006-3869 19667  
17512WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt (more info ...)attempted-user 2006-1245 17131  
17513WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt (more info ...)attempted-user 2006-1245 17131  
17514WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt (more info ...)attempted-user 2006-1245 17131  
17515WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt (more info ...)attempted-user 2006-1245 17131  
17516WEB-CLIENT Microsoft Internet Explorer Script Action Handler buffer overflow attempt (more info ...)attempted-user 2006-1245 17131  
17725WEB-CLIENT Opera file URI handling buffer overflow (more info ...)attempted-user 2008-5178 32323  
17776WEB-CLIENT Sun Java HsbParser.getSoundBank stack buffer overflow attempt (more info ...)attempted-user 2009-3867 36881  
18132SPECIFIC-THREATS malware-associated JavaScript obfuscation function (more info ...)trojan-activity    URL
18170SPECIFIC-THREATS Mozilla Firefox and SeaMonkey onUnload event handler memory corruption attempt (more info ...)attempted-user 2007-1092 22679  
18176SPECIFIC-THREATS Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt (more info ...)attempted-user 2006-3113 19197  
18177SPECIFIC-THREATS Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt (more info ...)attempted-user 2006-3113 19197  
18178SPECIFIC-THREATS Mozilla browsers memory corruption simultaneous XPCOM events code execution attempt (more info ...)attempted-user 2006-3113 19197  
18193SPECIFIC-THREATS Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2006-3280 18682  
18194SPECIFIC-THREATS Microsoft Internet Explorer cross domain information disclosure attempt (more info ...)attempted-user 2006-3280 18682  
18221WEB-CLIENT Internet Explorer malformed table remote code execution attempt (more info ...)attempted-user 2010-3962   URL

 goto Top

Group: Client / Email

# of attack rules in this group: 17

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
4150WEB-ACTIVEX Outlook View OVCtl ActiveX function call access (more info ...)attempted-user  2001-0538  3026    URL
4900WEB-ACTIVEX Outlook Progress Ctl ActiveX Object Access (more info ...)attempted-user  2005-2831      URL
7005WEB-ACTIVEX OutlookExpress.AddressBook ActiveX function call access (more info ...)attempted-user        
8371WEB-ACTIVEX Outlook.Application ActiveX CLSID access (more info ...)attempted-user        URL
8372WEB-ACTIVEX Outlook.Application ActiveX CLSID unicode access (more info ...)attempted-user        URL
8422WEB-ACTIVEX Outlook View OVCtl ActiveX clsid access (more info ...)attempted-user  2001-0538  3026    URL
8721WEB-ACTIVEX Outlook Data Object ActiveX CLSID access (more info ...)attempted-user        URL
8722WEB-ACTIVEX Outlook Data Object ActiveX CLSID unicode access (more info ...)attempted-user        URL
9668WEB-ACTIVEX Outlook Recipient Control ActiveX clsid access (more info ...)attempted-user    21649    
9669WEB-ACTIVEX Outlook Recipient Control ActiveX clsid unicode access (more info ...)attempted-user    21649    
9670WEB-ACTIVEX Outlook Recipient Control ActiveX function call access (more info ...)attempted-user    21649    
9819WEB-ACTIVEX Outlook View OVCtl ActiveX clsid unicode access (more info ...)attempted-user  2001-0538  3026    URL
9847WEB-CLIENT Outlook Saved Search download attempt (more info ...)attempted-user  2007-0034      URL
11236WEB-ACTIVEX OutlookExpress.AddressBook ActiveX clsid access (more info ...)attempted-user        
11237WEB-ACTIVEX OutlookExpress.AddressBook ActiveX clsid unicode access (more info ...)attempted-user        
11238WEB-ACTIVEX OutlookExpress.AddressBook ActiveX function call unicode access (more info ...)attempted-user        
17296WEB-MISC Outlook Web Access XSRF attempt (more info ...)attempted-user  2010-3213      URL


# of warning rules in this group: 3

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
13573WEB-CLIENT Microsoft Outlook arbitrary command line attempt (more info ...)misc-attack 2008-0110   URL
15947SPECIFIC-THREATS Microsoft Outlook Web Access Cross-Site Scripting attempt (more info ...)attempted-user 2005-0563 13952  
16428EXPLOIT Microsoft Outlook Express and Windows Mail NNTP handling buffer overflow attempt (more info ...)attempted-user 2007-3897   URL

 goto Top

Group: Client / Multimedia

# of attack rules in this group: 292

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3471WEB-CLIENT iTunes playlist URL overflow attempt (more info ...)attempted-user  2005-0043  12238    
3473WEB-CLIENT RealPlayer SMIL file overflow attempt (more info ...)attempted-user  2005-0455  12698    
4152WEB-ACTIVEX Windows Media Player 6.4 ActiveX Object Access (more info ...)attempted-user  1999-1110  793    
4158WEB-ACTIVEX Windows Media Player Active Movie ActiveX Object Access (more info ...)attempted-user  2000-0400  1221    
4678WEB-CLIENT quicktime movie file transfer (more info ...)protocol-command-decode        
4679WEB-CLIENT quicktime movie file component name integer overflow multipacket attempt (more info ...)attempted-user  2005-2754  15308    URL
5710WEB-CLIENT Windows Media Player Plugin for Non-IE browsers buffer overflow attempt (more info ...)attempted-user  2006-0005  16644    URL
5711WEB-CLIENT Windows Media Player zero length bitmap heap overflow attempt (more info ...)attempted-admin  2006-0006  16633    URL
5712WEB-CLIENT Windows Media Player invalid data offset bitmap heap overflow attempt (more info ...)attempted-admin  2006-0006  16633    URL
6368SPYWARE-PUT Adware flashtrack media/spoton runtime detection - update request (more info ...)misc-activity        URL
6371SPYWARE-PUT Adware flashtrack media/spoton runtime detection - pop up ads (more info ...)misc-activity        URL
6505WEB-CLIENT quicktime fpx file SectNumMiniFAT overflow attempt (more info ...)attempted-user  2006-1249  17074    
6506WEB-CLIENT quicktime udta atom overflow attempt (more info ...)attempted-user  2006-1460  17953    
6680WEB-ACTIVEX Windows Media Transform Effects ActiveX CLSID unicode access (more info ...)attempted-user        URL
6681WEB-ACTIVEX Windows Media Transform Effects ActiveX CLSID access (more info ...)attempted-user  2006-1303      URL
7142SPYWARE-PUT Adware ares flash downloader 2.04 runtime detection (more info ...)misc-activity        URL
7581SPYWARE-PUT Hijacker flashbar runtime detection - user-agent (more info ...)misc-activity        URL
7888WEB-ACTIVEX AOLFlash.AOLFlash ActiveX CLSID access (more info ...)attempted-user        
7889WEB-ACTIVEX AOLFlash.AOLFlash ActiveX CLSID unicode access (more info ...)attempted-user        
7978WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX clsid access (more info ...)attempted-user  2007-6244      URL
7979WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX clsid unicode access (more info ...)attempted-user  2007-6244      URL
7980WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash.9 ActiveX function call access (more info ...)attempted-user        URL
8091WEB-CLIENT RealNetworks RealPlayer error message format string vulnerability attempt (more info ...)attempted-user  2005-2710  14945    
8376WEB-ACTIVEX QuickTime Object ActiveX CLSID unicode access (more info ...)attempted-user        
8377WEB-ACTIVEX RealPlayer Download Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8378WEB-ACTIVEX RealPlayer Download Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
8381WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8382WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
8383WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8384WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
8385WEB-ACTIVEX RealPlayer Playback Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8386WEB-ACTIVEX RealPlayer Playback Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
8387WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8388WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
8389WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8390WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
8401WEB-ACTIVEX Windows Media Services DRM Storage ActiveX CLSID access (more info ...)attempted-user        
8402WEB-ACTIVEX Windows Media Services DRM Storage ActiveX CLSID unicode access (more info ...)attempted-user        
8409WEB-ACTIVEX RealPlayer Stream Handler ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
8410WEB-ACTIVEX RealPlayer Stream Handler ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
9429WEB-CLIENT Quicktime Movie link scripting security bypass attempt (more info ...)attempted-user  2006-4965  20138    
9430WEB-CLIENT Quicktime Movie link file URI security bypass attempt (more info ...)attempted-user  2006-4965  20138    
9625WEB-CLIENT Windows Media Player ASX file ref href buffer overflow attempt (more info ...)attempted-user  2006-6134  21247    URL
9637WEB-CLIENT Adobe Download Manger dm.ini stack overflow attempt (more info ...)attempted-user  2006-5856  21453    
9641WEB-CLIENT Windows Media Player ASF simple index object parsing buffer overflow attempt (more info ...)attempted-user  2006-4702      URL
9642WEB-CLIENT Windows Media Player ASF codec list object parsing buffer overflow attempt (more info ...)attempted-user  2006-4702      URL
9643WEB-CLIENT Windows Media Player ASF marker object parsing buffer overflow attempt (more info ...)attempted-user  2006-4702      URL
9671WEB-ACTIVEX RealPlayer AutoStream.AutoStream.1 ActiveX clsid access (more info ...)attempted-user  2006-6847  21802    
9672WEB-ACTIVEX RealPlayer AutoStream.AutoStream.1 ActiveX clsid unicode access (more info ...)attempted-user  2006-6847  21802    
9673WEB-ACTIVEX RealPlayer AutoStream.AutoStream.1 ActiveX function call access (more info ...)attempted-user  2006-6847  21802    
9801WEB-CLIENT Windows Media Player or Explorer Malformed RIFF File denial of service attempt (more info ...)attempted-dos  2006-6601  21612    URL
9823WEB-CLIENT QuickTime RTSP URI overflow attempt (more info ...)attempted-user  2007-0015  21829    URL
9840WEB-CLIENT QuickTime HREF Track Detected (more info ...)misc-activity  2007-0059      URL
10192WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX clsid access (more info ...)attempted-user  2008-3066  26586    
10193WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX clsid unicode access (more info ...)attempted-user  2008-3066  26586    
10194WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX function call access (more info ...)attempted-user  2008-3066  26586    
11180WEB-CLIENT quicktime movie ftyp buffer underflow (more info ...)attempted-user  2007-2296  23652    
11267WEB-CLIENT Adobe Photoshop PNG file handling stack buffer overflow attempt (more info ...)attempted-user  2007-2365  23698    
12183EXPLOIT Adobe FLV long string script data buffer overflow (more info ...)attempted-admin  2007-3456  24856    
12219WEB-CLIENT SMIL RealPlayer wallclock parsing buffer overflow (more info ...)attempted-user  2007-3410  24658    URL
12742EXPLOIT Apple Quicktime UDP RTSP sdp type buffer overflow attempt (more info ...)attempted-user  2007-6166  26549    
12746EXPLOIT Apple QuickTime STSD atom overflow attempt (more info ...)attempted-user  2007-3750  26341    
12757WEB-CLIENT Apple Quicktime uncompressed PICT stack overflow attempt (more info ...)attempted-user  2007-4672  26344    
12766WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
12767WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
12768WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
12769WEB-ACTIVEX RealPlayer RMOC3260.DLL ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
12775SPECIFIC-THREATS obfuscated RealPlayer Ierpplug.dll ActiveX exploit attempt (more info ...)attempted-user  2007-5601  26586    
13216WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX function call access (more info ...)attempted-user  2007-6244      URL
13217WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash ActiveX function call unicode access (more info ...)attempted-user  2007-6244      URL
13218WEB-ACTIVEX ShockwaveFlash.ShockwaveFlash.9 ActiveX function call unicode access (more info ...)attempted-user        URL
13293WEB-CLIENT QuickTime panorama atoms buffer overflow attempt (more info ...)attempted-user  2007-4675  26342    URL
13300WEB-CLIENT Adobe Flash Player embedded JPG image height overflow attempt (more info ...)attempted-admin  2007-6242  26951    
13301WEB-CLIENT Adobe Flash Player embedded JPG image width overflow attempt (more info ...)attempted-admin  2007-6242  26951    
13477SPECIFIC-THREATS Adobe PDF collab.collectEmailInfo exploit attempt - compressed (more info ...)attempted-user  2008-0655  27641    
13478SPECIFIC-THREATS Adobe PDF collab.collectEmailInfo exploit attempt (more info ...)attempted-user  2008-0655  27641    
13515WEB-CLIENT Quicktime user agent (more info ...)misc-activity        
13516WEB-CLIENT Quicktime HTTP error response buffer overflow (more info ...)attempted-user  2008-0234  27225    
13520EXPLOIT Winamp Ultravox streaming malicious metadata (more info ...)attempted-user  2008-0065      
13521EXPLOIT Winamp Ultravox streaming malicious metadata (more info ...)attempted-user  2008-0065      
13603WEB-ACTIVEX RealPlayer Download Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
13604WEB-ACTIVEX RealPlayer Download Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
13605WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
13606WEB-ACTIVEX RealPlayer RAM Download Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
13607WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    
13608WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    
13609WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX function call access (more info ...)attempted-user  2008-1309  28157    
13610WEB-ACTIVEX RealPlayer RMOC3260.DLL Vulnerble Property ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    
13820WEB-CLIENT Adobe Flash player SWF scene and label data memory corruption attempt (more info ...)attempted-user  2007-0071  29386    URL
13821WEB-CLIENT Adobe Flash player SWF scene and label data memory corruption attempt (more info ...)attempted-user  2007-0071  29386    URL
13822WEB-CLIENT Adobe Flash player SWF scene and label data memory corruption attempt (more info ...)attempted-user  2007-0071  29386    URL
13897EXPLOIT Apple Quicktime crgn atom parsing buffer overflow attempt (more info ...)attempted-user  2008-1017  28583    
13917WEB-CLIENT Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user  2005-2753  15306    
13918WEB-CLIENT Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user  2005-2753  15306    
13920WEB-CLIENT Apple Quicktime Obji Atom parsing stack buffer overflow attempt (more info ...)attempted-user  2008-1022  28583    
14042WEB-ACTIVEX RealPlayer General Property Page ActiveX clsid access (more info ...)attempted-user  2008-1309  28157    URL
14043WEB-ACTIVEX RealPlayer General Property Page ActiveX clsid unicode access (more info ...)attempted-user  2008-1309  28157    URL
14044WEB-ACTIVEX RealPlayer Playback Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
14045WEB-ACTIVEX RealPlayer Playback Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
14046WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
14047WEB-ACTIVEX RealPlayer RMP Download Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
14048WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
14049WEB-ACTIVEX RealPlayer RNX Download Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
14050WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
14051WEB-ACTIVEX RealPlayer SMIL Download Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
14052WEB-ACTIVEX RealPlayer Stream Handler ActiveX function call access (more info ...)attempted-user  2008-1309  28157    URL
14053WEB-ACTIVEX RealPlayer Stream Handler ActiveX function call unicode access (more info ...)attempted-user  2008-1309  28157    URL
14235WEB-ACTIVEX Microsoft Windows Media Services ActiveX clsid access (more info ...)attempted-user    30814    
14236WEB-ACTIVEX Microsoft Windows Media Services ActiveX clsid unicode access (more info ...)attempted-user    30814    
14237WEB-ACTIVEX Microsoft Windows Media Services ActiveX function call access (more info ...)attempted-user    30814    
14238WEB-ACTIVEX Microsoft Windows Media Services ActiveX function call unicode access (more info ...)attempted-user    30814    
14255WEB-ACTIVEX Windows Media Encoder 9 ActiveX clsid access (more info ...)attempted-user  2008-3008      URL
14257WEB-ACTIVEX Windows Media Encoder 9 ActiveX function call access (more info ...)attempted-user  2008-3008      URL
15007WEB-ACTIVEX NOS Microsystems / Adobe getPlus Download Manager ActiveX clsid access (more info ...)attempted-user  2008-4817  32105    
15008WEB-ACTIVEX NOS Microsystems / Adobe getPlus Download Manager ActiveX clsid unicode access (more info ...)attempted-user  2008-4817  32105    
15013WEB-MISC Adobe Portable Document Format file download attempt (more info ...)misc-activity        
15014WEB-CLIENT Adobe Reader and Acrobat util.printf buffer overflow attempt (more info ...)attempted-user  2008-2992      
15357WEB-CLIENT Adobe PDF JBIG2 remote code execution attempt (more info ...)attempted-user  2009-0658  33751    
15384WEB-CLIENT Apple QuickTime pict image poly structure memory corruption attempt (more info ...)attempted-user  2009-0010  34938    
15433WEB-CLIENT Winamp MAKI parsing integer overflow attempt (more info ...)attempted-user  2009-1831  35052    
15472WEB-CLIENT Nullsoft Winamp pls file player name handling buffer overflow attempt (more info ...)attempted-user  2006-0476  16410    
15478SPECIFIC-THREATS Adobe Flash Player invalid object reference code execution attempt (more info ...)attempted-user  2009-0520  33880    
15483WEB-MISC Adobe Shockwave Flash file request (more info ...)misc-activity        
15492SPECIFIC-THREATS Adobe PDF spell.customDictionaryOpen exploit attempt (more info ...)attempted-user  2009-1493  34740    
15493SPECIFIC-THREATS Adobe PDF getAnnots exploit attempt (more info ...)attempted-user  2009-1492  34736    
15517WEB-CLIENT AVI DirectShow quicktime parsing overflow attempt (more info ...)attempted-user  2009-1537  35139    URL
15559WEB-CLIENT Apple QuickTime Movie File Clipping Region handling heap buffer overflow attempt (more info ...)attempted-user  2009-0954  35167    URL
15562WEB-CLIENT Adobe Reader JPX malformed code-block width attempt (more info ...)attempted-user  2009-1859      
15680EXPLOIT Microsoft DirectShow QuickTime file atom size parsing heap corruption attempt (more info ...)attempted-user  2009-1539      URL
15682WEB-CLIENT Microsoft DirectShow QuickTime file stsc atom parsing heap corruption attempt (more info ...)attempted-user  2009-1538      URL
15703WEB-CLIENT Apple iTunes ITMS protocol handler stack buffer overflow attempt (more info ...)attempted-user  2009-0950  35157    
15704WEB-CLIENT Apple iTunes ITMSS protocol handler stack buffer overflow attempt (more info ...)attempted-user  2009-0950  35157    
15705WEB-CLIENT Apple iTunes PCAST protocol handler stack buffer overflow attempt (more info ...)attempted-user  2009-0950  35157    
15706WEB-CLIENT Apple iTunes DAAP protocol handler stack buffer overflow attempt (more info ...)attempted-user  2009-0950  35157    
15707WEB-CLIENT Apple iTunes ITPC protocol handler stack buffer overflow attempt (more info ...)attempted-user  2009-0950  35157    
15709WEB-CLIENT Adobe Acrobat and Adobe Reader FlateDecode integer overflow attempt (more info ...)attempted-user  2009-3459  36600    
15728EXPLOIT Possible Adobe PDF ActionScript byte_array heap spray attempt (more info ...)attempted-user  2009-1862  35759    URL
15729EXPLOIT Possible Adobe Flash ActionScript byte_array heap spray attempt (more info ...)attempted-user  2009-1862  35759    URL
15867WEB-CLIENT Adobe Acrobat PDF font processing memory corruption attempt (more info ...)attempted-user  2008-4813  32100    URL
15869WEB-CLIENT Adobe Flash Player ASnative command execution attempet (more info ...)attempted-user  2008-5499  32896    
15909WEB-CLIENT Apple QuickTime VR Track Header Atom heap corruption attempt (more info ...)attempted-user  2009-0002  33384    URL
15940SPECIFIC-THREATS RealNetworks RealPlayer Multiple Products RA file processing overflow attempt (more info ...)attempted-user  2007-2264  26214    
15993SPECIFIC-THREATS Adobe Flash Player ActionScript intrf_count integer overflow attempt (more info ...)attempted-user  2009-1869  35907    
16027WEB-CLIENT winamp midi file header overflow attempt (more info ...)attempted-user  2006-3228  18507    
16041SPECIFIC-THREATS Apple QuickTime FLIC animation file buffer overflow attempt (more info ...)attempted-user  2006-4384  19976    
16046SPECIFIC-THREATS RealNetworks RealPlayer RealMedia file format processing heap corruption attempt (more info ...)attempted-user  2007-5081  26214    
16054WEB-CLIENT Quicktime bitmap multiple header overflow (more info ...)attempted-user  2006-2238  17953    
16055WEB-CLIENT Apple iTunes AAC file handling integer overflow attempt (more info ...)attempted-user  2006-1467  18730    
16091SPECIFIC-THREATS Macromedia Flash Media Server administration service denial of service attempt (more info ...)attempted-dos  2005-4216  15822    
16148SPECIFIC-THREATS Apple QuickTime and iTunes heap memory corruption attempt (more info ...)attempted-user  2005-4092  15732    
16156WEB-CLIENT Windows Media Player 6.4 marker object memory corruption (more info ...)attempted-user  2009-2527      URL
16172EXPLOIT Adobe Acrobat Reader U3D line set heap corruption attempt (more info ...)attempted-user  2009-2997      
16173EXPLOIT Adobe Acrobat Reader U3D progressive mesh continuation pointer overwrite attempt (more info ...)attempted-user  2009-2998      
16174EXPLOIT Adobe Acrobat Reader U3D progressive mesh continuation off by one index attempt (more info ...)attempted-user  2009-3458      
16175EXPLOIT Adobe collab.removeStateModel denial of service attempt (more info ...)attempted-user  2009-2988      
16176EXPLOIT Adobe collab.addStateModel remote corruption attempt (more info ...)attempted-user  2009-2996      
16219WEB-CLIENT Adobe Director file format transfer (more info ...)misc-activity        
16220WEB-CLIENT Adobe Shockwave director file malformed lcsr block memory corruption attempt (more info ...)attempted-user  2009-3466      URL
16223WEB-CLIENT Adobe Shockwave tSAC pointer overwrite attempt (more info ...)attempted-user  2009-3464      URL
16225EXPLOIT Adobe Shockwave arbitrary memory access attempt (more info ...)attempted-user  2009-3465      URL
16293WEB-CLIENT Adobe Shockwave Flash memory corruption attempt (more info ...)attempted-user  2009-3463      
16316WEB-CLIENT Adobe Flash Player malformed getPropertyLate actioncode attempt (more info ...)attempted-user  2009-3797      
16320WEB-CLIENT Adobe PNG empty sPLT exploit attempt (more info ...)attempted-user  2009-2984      
16321WEB-CLIENT Adobe tiff oversized image length attempt (more info ...)attempted-user  2009-2995      
16322WEB-CLIENT Adobe Reader oversized object width attempt (more info ...)attempted-user  2009-2980      
16323EXPLOIT Adobe JPEG2k uninitialized QCC memory corruption attempt (more info ...)attempted-user  2009-2995      
16324WEB-CLIENT Adobe doc.export arbitrary file write attempt (more info ...)attempted-user  2009-2993      
16325EXPLOIT Adobe JPEG2k uninitialized QCC memory corruption attempt (more info ...)attempted-user  2009-2995      
16333WEB-CLIENT Adobe Reader media.newPlayer memory corruption attempt (more info ...)attempted-user  2009-4324  37331    
16334SPECIFIC-THREATS Adobe Reader compressed media.newPlayer memory corruption attempt (more info ...)attempted-user  2009-4324      
16337EXPLOIT Adobe Flash directory traversal attempt (more info ...)attempted-admin  2009-3792  37420    URL
16359WEB-CLIENT Adobe Illustrator DSC comment overflow attempt (more info ...)attempted-user  2009-4195  37192    
16360WEB-CLIENT Apple QuickTime Image Description Atom sign extension memory corruption attempt (more info ...)attempted-user  2009-0955  35166    URL
16370WEB-CLIENT Adobe Reader JP2C Region Atom CompNum memory corruption attempt (more info ...)attempted-user  2009-3955      
16371WEB-ACTIVEX NOS Microsystems Adobe atl_getcom ActiveX clsid access (more info ...)attempted-user  2009-3958  37759    URL
16373WEB-CLIENT Adobe Acrobat Reader U3D CLODMeshContinuation code execution attempt (more info ...)attempted-user  2009-2990  36665    URL
16490SPECIFIC-THREATS Adobe Reader malformed TIFF remote code execution attempt (more info ...)attempted-user  2010-0188      URL
16537EXPLOIT Windows Media Player ActiveX unknow compression algorithm use arbitrary code execution attempt (more info ...)attempted-user  2010-0268      URL
16541EXPLOIT Microsoft Windows Media Service stack overflow attempt (more info ...)attempted-admin  2010-0478      URL
16543WEB-CLIENT Microsoft Windows Media Player codec code execution attempt (more info ...)attempted-user  2010-0480      URL
16546EXPLOIT Adobe Reader/Acrobat Pro CFF font parsing heap overflow attempt (more info ...)attempted-user  2010-1241      
16561EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 1 (more info ...)attempted-user  2010-1279      URL
16562EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 2 (more info ...)attempted-user  2010-1279      URL
16563EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 3 (more info ...)attempted-user  2010-1279      URL
16564EXPLOIT Adobe Photoshop CS4 TIFF file exploit attempt - 4 (more info ...)attempted-user  2010-1279      URL
16578EXPLOIT Microsoft Windows Media Encoder 9 ActiveX buffer overflow attempt (more info ...)attempted-user  2008-3008      URL
16603WEB-CLIENT Adobe Reader U3D CLOD integer overflow (more info ...)attempted-user  2010-0196      URL
16607SPECIFIC-THREATS RealPlayer RAM Download Handler ActiveX exploit attempt (more info ...)attempted-user  2008-1309  28157    URL
16609SPECIFIC-THREATS RealPlayer ActiveX Import playlist name buffer overflow attempt (more info ...)attempted-user  2007-5601  26130    
16633WEB-CLIENT Adobe PDF File containing Flash use-after-free attack (more info ...)attempted-user  2010-1297      
16634WEB-CLIENT Adobe Flash use-after-free attack (more info ...)attempted-user  2010-1297      
16663WEB-CLIENT Windows Media Player JPG header record mismatch memory corruption attempt (more info ...)attempted-user  2010-1880      URL
16664SPECIFIC-THREATS Adobe Reader and Acrobat authplay.dll vulnerability exploit attempt (more info ...)attempted-user  2010-1297  40586    
16673WEB-CLIENT Adobe Shockwave DIR file PAMI chunk code execution attempt (more info ...)attempted-user  2010-1292      URL
16676SPECIFIC-THREATS Adobe Reader malformed FlateDecode colors declaration (more info ...)attempted-user  2009-3459  36600    
16677WEB-CLIENT Adobe Reader malformed FlateDecode colors declaration (more info ...)attempted-user  2009-3459  36600    
16683WEB-MISC Nullsoft Winamp CAF file processing integer overflow attempt (more info ...)attempted-user  2009-0186      
16801EXPLOIT Adobe Reader CoolType.dll remote memory corruption denial of service attempt (more info ...)attempted-dos  2010-2204  41130    
17096WEB-ACTIVEX AOL WinAmpX ActiveX clsid access (more info ...)attempted-user    35028    
17097WEB-ACTIVEX AOL WinAmpX ActiveX clsid unicode access (more info ...)attempted-user    35028    
17098SPECIFIC-THREATS AOL IWinAmpActiveX class ConvertFile buffer overflow attempt (more info ...)attempted-user    35028    
17141EXPLOIT Adobe Flash invalid data precision arbitrary code execution exploit attempt (more info ...)attempted-user  2010-2216      URL
17142EXPLOIT Adobe Flash Player SWF ActionScript exploit attempt (more info ...)attempted-user  2010-0209      URL
17143WEB-CLIENT Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 1 (more info ...)attempted-user  2010-1296  40389    
17144WEB-CLIENT Adobe Photoshop CS4 ABR file processing buffer overflow attempt - 2 (more info ...)attempted-user  2010-1296  40389    
17145WEB-CLIENT Adobe Photoshop CS4 ASL file processing buffer overflow attempt (more info ...)attempted-user  2010-1296  40389    
17146WEB-CLIENT Adobe Photoshop CS4 GRD file processing buffer overflow attempt (more info ...)attempted-user  2010-1296  40389    
17147SPECIFIC-THREATS Adobe Photoshop CS4 ABR file processing buffer overflow attempt (more info ...)attempted-user  2010-1296  40389    
17179WEB-CLIENT Adobe Director file pamm record exploit attempt (more info ...)attempted-user  2010-2869      
17180WEB-CLIENT Adobe Director file LsCM record exploit attempt (more info ...)attempted-user  2010-2864      
17181WEB-CLIENT Adobe Director file LsCM record exploit attempt (more info ...)attempted-user  2010-2864      
17182WEB-CLIENT Adobe Director file tSAC record exploit attempt (more info ...)attempted-user  2010-2869      
17183WEB-CLIENT Adobe Director file tSAC record exploit attempt (more info ...)attempted-user  2010-2869      
17184WEB-CLIENT Adobe Director file tSAC record exploit attempt (more info ...)attempted-user  2010-2869      
17185WEB-CLIENT Adobe Director file rcsL record exploit attempt (more info ...)attempted-user  2010-2869      
17186WEB-CLIENT Adobe Director file rcsL record exploit attempt (more info ...)attempted-user  2010-2869      
17187WEB-CLIENT Adobe Director file rcsL record exploit attempt (more info ...)attempted-user  2010-2869      
17188WEB-CLIENT Adobe Director file rcsL record exploit attempt (more info ...)attempted-user  2010-2869      
17189WEB-CLIENT Adobe Director file rcsL record exploit attempt (more info ...)attempted-user  2010-2869      
17190EXPLOIT Adobe Director remote code execution attempt (more info ...)attempted-user  2010-2871      
17191EXPLOIT Adobe Director remote code execution attempt (more info ...)attempted-user  2010-2872      
17192EXPLOIT Adobe Director remote code execution attempt (more info ...)attempted-user  2010-2873      
17193EXPLOIT Adobe Director remote code execution attempt (more info ...)attempted-user  2010-2874      
17194EXPLOIT Adobe Director file tSAC tag exploit attempt (more info ...)attempted-user  2010-2875      
17195EXPLOIT Adobe Director file exploit attempt (more info ...)attempted-user  2010-2876      
17196EXPLOIT Adobe Director file exploit attempt (more info ...)attempted-user  2010-2877      
17197EXPLOIT Adobe Director file exploit attempt (more info ...)attempted-user  2010-2879      
17198EXPLOIT Adobe Director file exploit attempt (more info ...)attempted-user  2010-2878      
17199WEB-CLIENT Adobe Director file file lRTX overflow attempt (more info ...)attempted-user  2010-2863      
17200WEB-CLIENT Adobe Director file LsCM overflow attempt (more info ...)attempted-user  2010-2864      
17201WEB-CLIENT Adobe Director file file LsCM overflow attempt (more info ...)attempted-user  2010-2865      
17202WEB-CLIENT Adobe Director file file Shockwave 3D overflow attempt (more info ...)attempted-user  2010-2866      
17203WEB-CLIENT Adobe Director file file rcsL overflow attempt (more info ...)attempted-user  2010-2867      
17204WEB-CLIENT Adobe Director file file mmap overflow attempt (more info ...)attempted-user  2010-2870      
17211WEB-CLIENT Quicktime marshaled punk remote code execution (more info ...)attempted-user  2010-1818      
17214SPECIFIC-THREATS Adobe Reader and Acrobat libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user  2010-0188      
17215SPECIFIC-THREATS Adobe Reader and Acrobat libtiff TIFFFetchShortPair stack buffer overflow attempt (more info ...)attempted-user  2010-0188      
17228SPECIFIC-THREATS Microsoft Windows Media Player skin decompression code execution attempt (more info ...)attempted-user  2007-3035  25307    
17233SPECIFIC-THREATS Adobe Reader and Acrobat TTF SING table parsing remote code execution attempt (more info ...)attempted-user  2010-2883      URL
17242WEB-CLIENT Windows Media Player ASF file arbitrary code execution attempt (more info ...)attempted-user  2010-0818      URL
17257SPECIFIC-THREATS Adobe Flash Player and Reader remote code execution attempt (more info ...)attempted-user  2010-2884      URL
17272WEB-CLIENT RealNetworks RealPlayer AVI parsing buffer overflow attempt (more info ...)attempted-user  2005-2052  13530    
17288SPECIFIC-THREATS Adobe Acrobat font parsing integer overflow attempt (more info ...)attempted-user  2010-2862  44203    
17290WEB-CLIENT Quicktime Plug-In Security Bypass (more info ...)attempted-user  2006-4965  20138    
17334SPECIFIC-THREATS RealPlayer SWF Flash File buffer overflow attempt (more info ...)attempted-user  2006-0323  17202    
17351WEB-CLIENT Winamp ID3v2 Tag Handling Buffer Overflow attempt (more info ...)attempted-user  2005-2310  14276    
17361SPECIFIC-THREATS Adobe Acrobat Reader PDF Catalog Handling denial of service attempt (more info ...)attempted-user  2007-0104  21910    URL
17372WEB-CLIENT Apple QuickTime udta atom parsing heap overflow vulnerability (more info ...)attempted-user  2007-0714  22844    
17373SPECIFIC-THREATS QuickTime panorama atoms buffer overflow attempt (more info ...)attempted-user  2007-4675  26342    URL
17381SPECIFIC-THREATS Apple QuickTime PDAT Atom parsing buffer overflow attempt (more info ...)attempted-user  2008-3625      URL
17425SPECIFIC-THREATS RealPlayer ActiveX Import playlist name buffer overflow attempt (more info ...)attempted-user  2007-5601  26130    
17461SPECIFIC-THREATS RealNetworks RealPlayer zipped skin file buffer overflow attempt (more info ...)attempted-user  2005-2630  15382    
17470SPECIFIC-THREATS Apple QuickTime STSD JPEG atom heap corruption attempt (more info ...)attempted-user  2009-0007  33390    
17523SPECIFIC-THREATS Apple QuickTime H.264 Movie File Buffer Overflow (more info ...)attempted-user  2009-2799  36328    
17526SPECIFIC-THREATS Adobe Acrobat and Adobe Reader U3D RHAdobeMeta Buffer Overflow (more info ...)attempted-user  2009-1855  35282    
17531SPECIFIC-THREATS Apple Quicktime MOV File JVTCompEncodeFrame Heap Overflow (more info ...)attempted-user  2007-2295  23650    
17547WEB-CLIENT Apple Quicktime SMIL transfer (more info ...)protocol-command-decode        
17548WEB-CLIENT Apple Quicktime SMIL File Handling Integer Overflow attempt (more info ...)attempted-user  2007-2394  24873    
17552WEB-CLIENT Adobe Pagemaker file request (more info ...)misc-activity        
17553SPECIFIC-THREATS Adobe Pagemaker Font Name Buffer Overflow attempt (more info ...)attempted-user  2007-5169  25989    
17561SPECIFIC-THREATS RealNetworks RealPlayer IVR Overly Long Filename Code Execution attempt (more info ...)attempted-user  2009-0375  33652    
17606SPECIFIC-THREATS Adobe Flash ASnative command execution attempt (more info ...)attempted-user  2008-5499  32896    URL
17608WEB-CLIENT Apple QuickTime color table atom movie file handling heap corruption attempt (more info ...)attempted-user  2007-4677  26338    
17610WEB-CLIENT GStreamer QuickTime file parsing multiple heap overflow attempt (more info ...)attempted-user  2009-0398  33405    
17611WEB-CLIENT GStreamer QuickTime file parsing multiple heap overflow attempt (more info ...)attempted-user  2009-0398  33405    
17612WEB-CLIENT GStreamer QuickTime file parsing multiple heap overflow attempt (more info ...)attempted-user  2009-0398  33405    
17633WEB-CLIENT RealNetworks RealPlayer SWF frame handling buffer overflow attempt (more info ...)attempted-user  2007-5400  30370    
17647WEB-CLIENT Adobe Flash Player multimedia file DefineSceneAndFrameLabelData code execution attempt (more info ...)attempted-user  2007-0071  28695    URL
17650SPECIFIC-THREATS Adobe Pagemaker Key Strings Stack Buffer Overflow attempt (more info ...)attempted-admin  2007-6432  31999    
17658SPECIFIC-THREATS Adobe Flash frame type identifier memory corruption attempt (more info ...)attempted-user  2005-2628  15332    
17666WEB-CLIENT RealNetworks RealPlayer invalid chunk size heap overflow attempt (more info ...)attempted-user  2005-2922  17202    
17678WEB-CLIENT Adobe BMP image handler buffer overflow attempt (more info ...)attempted-user  2008-1765  28874    
17698SPECIFIC-THREATS RealNetworks RealPlayer wav chunk string overflow attempt in email (more info ...)attempted-user  2005-0611  12697    
17700WEB-CLIENT RealNetworks RealPlayer wav chunk string overflow attempt (more info ...)attempted-user  2005-0611  12697    
17735SPECIFIC-THREATS Adobe Pagemaker Font Name Buffer Overflow attempt (more info ...)attempted-user  2007-5169  25989    
17773EXPLOIT Microsoft Windows Media Player Firefox plugin memory corruption attempt (more info ...)attempted-user  2010-2745      URL
17803WEB-CLIENT Adobe Shockwave Director rcsL chunk memory corruption attempt (more info ...)attempted-user  2010-2873  42682    URL
17806SPECIFIC-THREATS Adobe Shockwave Director rcsL chunk remote code execution attempt (more info ...)attempted-user  2010-3653  44291    
17807SPECIFIC-THREATS Adobe Shockwave Director rcsL chunk remote code execution attempt (more info ...)attempted-user  2010-3653  44291    
17808SPECIFIC-THREATS Adobe Flash authplay.dll memory corruption attempt (more info ...)attempted-user  2010-3654      URL
17809WEB-CLIENT quicktime movie file transfer (more info ...)protocol-command-decode        
18180EXPLOIT Adobe Flash Player ActionScript remote code execution attempt (more info ...)attempted-user  2010-3648  44684    URL
18222WEB-CLIENT Microsoft Windows Media Encoder wmerrorenu.dll dll-load exploit attempt (more info ...)attempted-user  2010-3965      URL
18223WEB-CLIENT Microsoft Windows Media Encoder winietenu.dll dll-load exploit attempt (more info ...)attempted-user  2010-3965      URL
18224WEB-CLIENT Microsoft Windows Media Encoder asferrorenu.dll dll-load attempt (more info ...)attempted-user  2010-3965      URL
18225NETBIOS Microsoft Windows Media Encoder wmerrorenu.dll dll-load exploit attempt (more info ...)attempted-user  2010-3965      URL
18226NETBIOS Microsoft Windows Media Encoder swinietenu.dll dll-load exploit attempt (more info ...)attempted-user  2010-3965      URL
18227NETBIOS Microsoft Windows Media Encoder asferrorenu.dll dll-load exploit attempt (more info ...)attempted-user  2010-3965      URL
18229SPECIFIC-THREAT Microsoft FlashPix tile length overflow attempt (more info ...)attempted-user  2010-3952      URL
18233WEB-CLIENT Microsoft Publisher Adobe Font Driver code execution attempt (more info ...)attempted-user  2010-3956      URL
18237WEB-CLIENT Flashpix graphics filter fpx32.flt remote code execution attempt (more info ...)attempted-user  2010-3951      URL
912182POLICY Adobe FLV file transfer (more info ...)misc-activity        


# of warning rules in this group: 34

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
2438WEB-CLIENT RealPlayer playlist file URL overflow attempt (more info ...)attempted-user 2005-0755 9579  
2439WEB-CLIENT RealPlayer playlist http URL overflow attempt (more info ...)attempted-user 2005-0755 9579  
2440WEB-CLIENT RealPlayer playlist rtsp URL overflow attempt (more info ...)attempted-user 2005-0755 9579  
2442WEB-MISC Quicktime User-Agent buffer overflow attempt (more info ...)web-application-attack 2004-0169 9735  
2550EXPLOIT winamp XM module name overflow (more info ...)attempted-user    URL
3088WEB-CLIENT winamp .cda file name overflow attempt (more info ...)attempted-user 2004-1119 11730 15817 
3470WEB-CLIENT RealPlayer VIDORV30 header length buffer overflow (more info ...)attempted-admin 2004-1481 11309  URL
4131EXPLOIT SHOUTcast URI format string attempt (more info ...)web-application-attack 2004-1373 12096  
4680WEB-CLIENT quicktime movie file component name integer overflow attempt (more info ...)attempted-user 2005-2754 15308  URL
8701WEB-MISC IceCast header buffer overflow attempt (more info ...)attempted-admin 2004-1561 11271  URL
8702EXPLOIT IceCast header buffer overflow attempt (more info ...)attempted-admin 2004-1561 11271  URL
8703EXPLOIT IceCast header buffer overflow attempt (more info ...)attempted-admin 2004-1561 11271  URL
9842WEB-CLIENT Adobe Acrobat Plugin Universal cross-site scripting attempt (more info ...)misc-attack 2007-0045   URL
12663WEB-ACTIVEX RealPlayer Ierpplug.dll ActiveX function call unicode access (more info ...)attempted-user 2008-3066 26586  
12707WEB-CLIENT RealNetworks RealPlayer lyrics heap overflow attempt (more info ...)attempted-user 2007-5080 26214  
12741EXPLOIT Apple Quicktime TCP RTSP sdp type buffer overflow attempt (more info ...)attempted-user 2007-6166 26549  
13919WEB-CLIENT Apple QuickTime MOV file string handling integer overflow attempt (more info ...)attempted-user 2005-2753 15306  
14256WEB-ACTIVEX Windows Media Encoder 9 ActiveX clsid unicode access (more info ...)attempted-user 2008-3008   URL
14258WEB-ACTIVEX Windows Media Encoder 9 ActiveX function call unicode access (more info ...)attempted-user 2008-3008   URL
15914WEB-CLIENT Microsoft Windows Media sample duration header RCE attempt (more info ...)attempted-user 2009-2498   URL
15915WEB-CLIENT Microsoft Windows Media Timecode header RCE attempt (more info ...)attempted-user 2009-2498   URL
15916WEB-CLIENT Microsoft Windows Media file name header RCE attempt (more info ...)attempted-user 2009-2498   URL
15917WEB-CLIENT Microsoft Windows Media content type header RCE attempt (more info ...)attempted-user 2009-2498   URL
15918WEB-CLIENT Microsoft Windows Media pixel aspect ratio header RCE attempt (more info ...)attempted-user 2009-2498   URL
15919WEB-CLIENT Microsoft Windows Media encryption sample ID header RCE attempt (more info ...)attempted-user 2009-2498   URL
16315WEB-MISC Adobe Flash PlugIn check if file exists attempt (more info ...)misc-activity 2009-3951   
16331WEB-CLIENT Adobe Flash Player JPEG parsing heap overflow attempt (more info ...)attempted-user 2009-3794   
16338WEB-CLIENT Microsoft Windows Media extended stream properties object RCE attempt (more info ...)attempted-user 2009-2498   URL
16372WEB-ACTIVEX NOS Microsystems Adobe atl_getcom ActiveX clsid unicode access (more info ...)attempted-user 2009-3958 37759  URL
16544WEB-CLIENT Adobe Reader Linux malformed U3D mesh deceleration block exploit attempt (more info ...)attempted-admin 2010-0196   
16545WEB-CLIENT Adobe Reader malformed Richmedia annotation exploit attempt (more info ...)attempted-admin 2010-0197   
17223SPECIFIC-THREATS Adobe Flash Player navigateToURL cross-site scripting attempt (more info ...)misc-activity 2007-6244 26960  
17457WEB-CLIENT Macromedia Flash ActionDefineFunction memory access vulnerability exploit attempt (more info ...)attempted-user 2005-2628 15334  
17529SPECIFIC-THREATS Adobe RoboHelp Server Arbitrary File Upload and Execute (more info ...)attempted-user 2009-1855 35282  

 goto Top

Group: Client / Peer to Peer

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Client / Instant Messenger

# of attack rules in this group: 8

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
9380SPECIFIC-THREATS jitux msn messenger propagation detection (more info ...)trojan-activity        URL
13292EXPLOIT Skype skype4com URI handler memory corruption attempt (more info ...)attempted-user  2007-5989  26748    
15939SPECIFIC-THREATS MSN Messenger IRC bot calling home attempt (more info ...)trojan-activity        URL
16718EXPLOIT Skype URI handler input validation exploit attempt (more info ...)misc-attack    38699    URL
17674WEB-ACTIVEX Skype Extras Manager ActiveX clsid access (more info ...)attempted-user  2009-4741  36459    
17675WEB-ACTIVEX Skype Extras Manager ActiveX clsid unicode access (more info ...)attempted-user  2009-4741  36459    
17676WEB-ACTIVEX Skype Extras Manager ActiveX function call access (more info ...)attempted-user  2009-4741  36459    
17677WEB-ACTIVEX Skype Extras Manager ActiveX function call unicode access (more info ...)attempted-user  2009-4741  36459    


# of warning rules in this group: 2

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
3085EXPLOIT AIM goaway message buffer overflow attempt (more info ...)misc-attack 2004-0636 10889  
3130EXPLOIT MSN Messenger png overflow (more info ...)attempted-user 2004-0957 10872  URL

 goto Top

Group: Protocol Anomaly

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / Invalid Traffic

# of attack rules in this group: 7

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
6128BACKDOOR dkangel runtime detection - icmp echo reply client-to-server (more info ...)trojan-activity        URL
10107BACKDOOR icmp cmd 1.0 runtime detection - pslist (more info ...)trojan-activity        URL
10108BACKDOOR icmp cmd 1.0 runtime detection - pskill (more info ...)trojan-activity        URL
10452BACKDOOR only 1 rat runtime detection - icmp request (more info ...)trojan-activity        URL
13288BAD-TRAFFIC Windows remote kernel tcp/ip icmp vulnerability exploit attempt (more info ...)attempted-admin  2007-0066      URL
16405ICMP Microsoft Windows Ipv6pHandleRouterAdvertisement Prefix Information stack buffer overflow attempt (more info ...)attempted-admin  2010-0239      URL
18249ICMP Microsoft Windows Ipv6pHandleRouterAdvertisement Route Information stack buffer overflow attempt (more info ...)attempted-admin  2010-0241      URL


# of warning rules in this group: 13

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
222DDOS tfn2k icmp possible communication (more info ...)attempted-dos 2000-0138   
272DOS IGMP dos attack (more info ...)attempted-dos 1999-0918 514  URL
465ICMP ISS Pinger (more info ...)attempted-recon    
467ICMP Nemesis v1.1 Echo (more info ...)attempted-recon    
476ICMP webtrends scanner (more info ...)attempted-recon    
480ICMP PING speedera (more info ...)misc-activity    
481ICMP TJPingPro1.1Build 2 Windows (more info ...)misc-activity    
482ICMP PING WhatsupGold Windows (more info ...)misc-activity    
484ICMP PING Sniffer Pro/NetXRay network scan (more info ...)misc-activity    
1813ICMP digital island bandwidth query (more info ...)misc-activity    
2462EXPLOIT IGMP IGAP account overflow attempt (more info ...)attempted-admin 2004-0367 9952  
2463EXPLOIT IGMP IGAP message overflow attempt (more info ...)attempted-admin 2004-0367 9952  
3626ICMP PATH MTU denial of service attempt (more info ...)attempted-dos 2004-1060 13124  

 goto Top

Group: Protocol Anomaly / ICMP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / IGMP

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / RPC

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Protocol Anomaly / Misc

# of attack rules in this group: 0

# of warning rules in this group: 0

 goto Top

Group: Malware

# of attack rules in this group: 1789

IDMessageClasstypeCVEBugtraqIDNessusIDCustom
494ATTACK-RESPONSES command completed (more info ...)bad-unknown    1806    
497ATTACK-RESPONSES file copied ok (more info ...)bad-unknown  2000-0884  1806    
498ATTACK-RESPONSES id check returned root (more info ...)bad-unknown        
1001WEB-MISC carbo.dll access (more info ...)attempted-recon  1999-1069  2126    
1464ATTACK-RESPONSES oracle one hour install (more info ...)bad-unknown      10737  
2278WEB-MISC client negative Content-Length attempt (more info ...)misc-attack  2006-2162  9576    
2412ATTACK-RESPONSES successful cross site scripting forced download attempt (more info ...)successful-user        
2430NNTP newgroup overflow attempt (more info ...)attempted-admin  2004-0045  9382  11984  
2431NNTP rmgroup overflow attempt (more info ...)attempted-admin  2004-0045  9382  11984  
2520WEB-MISC SSLv3 Client_Hello request (more info ...)protocol-command-decode        
2521WEB-MISC SSLv3 Server_Hello request (more info ...)protocol-command-decode        
2585WEB-MISC nessus 2.x 404 probe (more info ...)attempted-recon      10386  
2656WEB-MISC SSLv2 Client_Hello Challenge Length overflow attempt (more info ...)attempted-admin  2004-0826  11015    
2658WEB-MISC SSLv2 Client_Hello request (more info ...)protocol-command-decode        
2659WEB-MISC SSLv2 Client_Hello with pad request (more info ...)protocol-command-decode        
2660WEB-MISC SSLv2 Server_Hello request (more info ...)protocol-command-decode        
2661WEB-MISC TLSv1 Client_Hello request (more info ...)protocol-command-decode        
2662WEB-MISC TLSv1 Server_Hello request (more info ...)protocol-command-decode        
2705WEB-CLIENT JPEG parser heap overflow attempt (more info ...)attempted-user  2004-0200  11173    URL
3009BACKDOOR NetBus Pro 2.0 connection request (more info ...)misc-activity        
3010BACKDOOR RUX the Tick get windows directory attempt (more info ...)misc-activity        
3011BACKDOOR RUX the Tick get system directory attempt (more info ...)misc-activity        
3012BACKDOOR RUX the Tick upload/execute arbitrary file attempt (more info ...)misc-activity        
3013BACKDOOR Asylum 0.1 connection request (more info ...)misc-activity        
3014BACKDOOR Asylum 0.1 connection established (more info ...)misc-activity        
3015BACKDOOR Insane Network 4.0 connection established (more info ...)misc-activity        
3016BACKDOOR Insane Network 4.0 connection established port 63536 (more info ...)misc-activity        
3059WEB-MISC TLSv1 Client_Hello via SSLv2 handshake request (more info ...)protocol-command-decode        
3063BACKDOOR Vampire 1.2 connection request (more info ...)misc-activity        
3064BACKDOOR Vampire 1.2 connection confirmation (more info ...)misc-activity        
3081BACKDOOR Y3KRAT 1.5 Connect (more info ...)misc-activity        
3082BACKDOOR Y3KRAT 1.5 Connect Client Response (more info ...)misc-activity        
3083BACKDOOR Y3KRAT 1.5 Connection confirmation (more info ...)misc-activity        
3132WEB-CLIENT PNG large image width download attempt (more info ...)attempted-user  2007-5503  11523    URL
3133WEB-CLIENT PNG large image height download attempt (more info ...)attempted-user  2007-5503  11523    URL
3148WEB-CLIENT winhelp clsid attempt (more info ...)attempted-user  2004-1043  5874    URL
3155BACKDOOR BackOrifice 2000 Inbound Traffic (more info ...)trojan-activity        
3535WEB-CLIENT GIF transfer (more info ...)protocol-command-decode        
3551WEB-CLIENT .hta download attempt (more info ...)not-suspicious        
3632WEB-CLIENT Bitmap width integer overflow attempt (more info ...)attempted-admin  2008-3015  11171    URL
3633WEB-CLIENT bitmap transfer (more info ...)protocol-command-decode        
3634WEB-CLIENT Bitmap width integer overflow multipacket attempt (more info ...)attempted-admin  2008-3015  11171    URL
3635BACKDOOR Amanda 2.0 connection established (more info ...)trojan-activity        
3636BACKDOOR Crazzy Net 5.0 connection established (more info ...)trojan-activity        
3683WEB-CLIENT spoofed MIME-Type auto-execution attempt (more info ...)attempted-admin  2001-0154  2524    URL
3819WEB-CLIENT multipacket CHM file transfer start (more info ...)protocol-command-decode        
3821WEB-CLIENT CHM file transfer attempt (more info ...)attempted-user  2005-1208  13953  18482  URL
3822WEB-MISC Real Player realtext long URI request (more info ...)protocol-command-decode        
4132WEB-CLIENT msdds clsid attempt (more info ...)attempted-user  2005-2127  14594    URL
4133WEB-CLIENT devenum clsid attempt (more info ...)attempted-user  2005-1990  14511    URL
4134WEB-CLIENT blnmgr clsid attempt (more info ...)attempted-user  2005-1990  14511    URL
4140DOS tcpdump tcp LDP print zero length message denial of service attempt (more info ...)attempted-dos  2005-1279  13389    URL
4141DOS tcpdump udp LDP print zero length message denial of service attempt (more info ...)attempted-dos  2005-1279  13389    URL
4143EXPLOIT lpd receive printer job cascade adaptor protocol request (more info ...)protocol-command-decode        
4194WEB-CLIENT multipacket CBO CBL CBM file transfer start (more info ...)protocol-command-decode        
4195WEB-CLIENT multipacket CBO CBL CBM file transfer attempt (more info ...)attempted-user  2006-3448  13944  18492  URL
4643WEB-CLIENT malformed windows shortcut file buffer overflow attempt (more info ...)attempted-user  2005-2122  15070    URL
4644WEB-CLIENT malformed windows shortcut file with comment buffer overflow attempt (more info ...)attempted-user  2005-2122  15070    URL
5319WEB-CLIENT Metasploit Windows picture and fax viewer wmf arbitrary code execution attempt (more info ...)web-application-attack  2005-4560  16074    URL
5713WEB-CLIENT Windows Metafile invalid header size integer overflow (more info ...)attempted-admin  2006-0020  16516    URL
5742SPYWARE-PUT Keylogger activitylogger runtime detection (more info ...)successful-recon-limited        URL
5743SPYWARE-PUT Hijacker actualnames runtime detection - plugin list (more info ...)misc-activity        URL
5745SPYWARE-PUT Hijacker adultlinks runtime detection - redirect (more info ...)misc-activity        URL
5746SPYWARE-PUT Hijacker adultlinks runtime detection - load url (more info ...)misc-activity        URL
5747SPYWARE-PUT Hijacker adultlinks runtime detection - log hits (more info ...)misc-activity        URL
5748SPYWARE-PUT Hijacker adultlinks runtime detection - ads (more info ...)misc-activity        URL
5750SPYWARE-PUT Adware dogpile runtime detection (more info ...)misc-activity        URL
5751SPYWARE-PUT Adware exactsearch runtime detection - switch search engine 1 (more info ...)misc-activity        URL
5752SPYWARE-PUT Adware exactsearch runtime detection - switch search engine 2 (more info ...)misc-activity        URL
5753SPYWARE-PUT Adware exactsearch runtime detection - topsearches (more info ...)misc-activity        URL
5754SPYWARE-PUT Hijacker ezcybersearch runtime detection - ie auto search hijack (more info ...)misc-activity        URL
5755SPYWARE-PUT Hijacker ezcybersearch runtime detection - check update (more info ...)misc-activity        URL
5756SPYWARE-PUT Hijacker ezcybersearch runtime detection - add coolsites to ie favorites (more info ...)misc-activity        URL
5757SPYWARE-PUT Hijacker ezcybersearch runtime detection - check toolbar setting (more info ...)misc-activity        URL
5758SPYWARE-PUT Hijacker ezcybersearch runtime detection - download fastclick pop-under code (more info ...)misc-activity        URL
5759SPYWARE-PUT Keylogger fearlesskeyspy runtime detection (more info ...)successful-recon-limited        URL
5761SPYWARE-PUT Trickler bearshare runtime detection - ads popup (more info ...)misc-activity        URL
5762SPYWARE-PUT Trickler bearshare runtime detection - p2p information request (more info ...)misc-activity        URL
5763SPYWARE-PUT Trickler bearshare runtime detection - chat request (more info ...)misc-activity        URL
5765SPYWARE-PUT Hijacker begin2search runtime detection - ico query (more info ...)misc-activity        URL
5766SPYWARE-PUT Hijacker begin2search runtime detection - install spyware trafficsector (more info ...)misc-activity        URL
5767SPYWARE-PUT Hijacker begin2search runtime detection - download unauthorized code (more info ...)misc-activity        URL
5768SPYWARE-PUT Hijacker begin2search runtime detection - pass information (more info ...)misc-activity        URL
5769SPYWARE-PUT Hijacker begin2search runtime detection - play bingo ads (more info ...)misc-activity        URL
5770SPYWARE-PUT Snoopware casinoonnet runtime detection (more info ...)successful-recon-limited        URL
5771SPYWARE-PUT Screen-Scraper farsighter runtime detection - initial connection (more info ...)successful-recon-limited        URL
5773SPYWARE-PUT Adware forbes runtime detection (more info ...)misc-activity        URL
5774SPYWARE-PUT Hijacker freescratch runtime detection - get card (more info ...)misc-activity        URL
5775SPYWARE-PUT Hijacker freescratch runtime detection - scratch card (more info ...)misc-activity        URL
5776SPYWARE-PUT Trickler grokster runtime detection (more info ...)misc-activity        URL
5777SPYWARE-PUT Keylogger gurl watcher runtime detection (more info ...)successful-recon-limited        URL
5778SPYWARE-PUT Keylogger runtime detection - hwpe windows activity logs (more info ...)successful-recon-limited        URL
5779SPYWARE-PUT Keylogger runtime detection - hwpe shell file logs (more info ...)successful-recon-limited        URL
5781SPYWARE-PUT Keylogger runtime detection - hwae windows activity logs (more info ...)successful-recon-limited        URL
5783SPYWARE-PUT Keylogger runtime detection - hwae keystrokes log (more info ...)successful-recon-limited        URL
5784SPYWARE-PUT Keylogger runtime detection - hwae urls browsed log (more info ...)successful-recon-limited        URL
5785SPYWARE-PUT Adware hithopper runtime detection - get xml setting (more info ...)misc-activity        URL
5786SPYWARE-PUT Adware hithopper runtime detection - redirect (more info ...)misc-activity        URL
5787SPYWARE-PUT Adware hithopper runtime detection - search (more info ...)misc-activity        URL
5788SPYWARE-PUT Adware hithopper runtime detection - click toolbar buttons (more info ...)misc-activity        URL
5789SPYWARE-PUT keylogger pc actmon pro runtime detection - http (more info ...)successful-recon-limited        URL
5791SPYWARE-PUT Dialer pluginaccess runtime detection - get pin (more info ...)misc-activity        URL
5792SPYWARE-PUT Dialer pluginaccess runtime detection - active proxy (more info ...)misc-activity        URL
5793SPYWARE-PUT Dialer pluginaccess runtime detection - redirect (more info ...)misc-activity        URL
5794SPYWARE-PUT Hijacker coolwebsearch.aboutblank variant runtime detection (more info ...)misc-activity        URL
5795SPYWARE-PUT Adware ist powerscan runtime detection (more info ...)misc-activity        URL
5796SPYWARE-PUT Adware keenvalue runtime detection (more info ...)misc-activity        URL
5800SPYWARE-PUT Trackware myway speedbar runtime detection - request config (more info ...)successful-recon-limited        URL
5801SPYWARE-PUT Trackware myway speedbar / mywebsearch toolbar runtime detection - track activity 1 (more info ...)successful-recon-limited        URL
5803SPYWARE-PUT Trackware myway speedbar / mywebsearch toolbar runtime detection - collect information (more info ...)successful-recon-limited        URL
5805SPYWARE-PUT Trackware myway speedbar runtime detection - switch engines (more info ...)successful-recon-limited        URL
5807SPYWARE-PUT Hijacker shopathomeselect runtime detection (more info ...)misc-activity        URL
5808SPYWARE-PUT Hijacker shop at home search merchant redirect check (more info ...)misc-activity        
5809SPYWARE-PUT Hijacker shop at home select merchant redirect in progress (more info ...)misc-activity        
5810SPYWARE-PUT Hijacker shop at home select installation in progress (more info ...)misc-activity        
5811SPYWARE-PUT shop at home select installation in progress - clsid detected (more info ...)misc-activity        URL
5812SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - email notification (more info ...)misc-activity        URL
5813SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - create redirection (more info ...)misc-activity        
5814SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - create redirection (more info ...)misc-activity        URL
5815SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory redirection (more info ...)misc-activity        
5816SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory redirection (more info ...)misc-activity        URL
5817SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status (more info ...)misc-activity        
5818SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status (more info ...)misc-activity        
5819SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status (more info ...)misc-activity        URL
5820SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory log (more info ...)misc-activity        
5821SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory log (more info ...)misc-activity        URL
5822SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - view netstat (more info ...)misc-activity        
5823SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - view netstat (more info ...)misc-activity        URL
5824SPYWARE-PUT Dialer stripplayer runtime detection (more info ...)misc-activity        URL
5825SPYWARE-PUT Adware broadcasturban tuner runtime detection - start tuner (more info ...)misc-activity        URL
5826SPYWARE-PUT Adware broadcasturban tuner runtime detection - pass user info to server (more info ...)misc-activity        URL
5827SPYWARE-PUT Adware broadcasturban tuner runtime detection - get gateway (more info ...)misc-activity        URL
5828SPYWARE-PUT Adware broadcasturban tuner runtime detection - connect to station (more info ...)misc-activity        URL
5829SPYWARE-PUT Trickler clipgenie runtime detection (more info ...)misc-activity        URL
5835SPYWARE-PUT Adware gamespy_arcade runtime detection (more info ...)misc-activity        URL
5836SPYWARE-PUT Trickler nictech.bm2 runtime detection (more info ...)misc-activity        URL
5837SPYWARE-PUT Trackware ucmore runtime detection - track activity (more info ...)successful-recon-limited        URL
5838SPYWARE-PUT Trackware ucmore runtime detection - get sponsor/ad links (more info ...)successful-recon-limited        URL
5839SPYWARE-PUT Trackware ucmore runtime detection - click sponsor/ad link (more info ...)successful-recon-limited        URL
5840SPYWARE-PUT Hijacker sep runtime detection (more info ...)misc-activity        URL
5841SPYWARE-PUT Trickler minibug runtime detection - retrieve weather information (more info ...)misc-activity        URL
5842SPYWARE-PUT Trickler minibug runtime detection - ads (more info ...)misc-activity        URL
5843SPYWARE-PUT Hijacker surfsidekick runtime detection - hijack ie auto search (more info ...)misc-activity        URL
5844SPYWARE-PUT Hijacker surfsidekick runtime detection - post request (more info ...)misc-activity        URL
5845SPYWARE-PUT Hijacker surfsidekick runtime detection - update request (more info ...)misc-activity        URL
5846SPYWARE-PUT Trickler VX2/DLmax/BestOffers/Aurora runtime detection (more info ...)misc-activity        URL
5847SPYWARE-PUT Adware warez_p2p runtime detection - p2p client home (more info ...)misc-activity        URL
5849SPYWARE-PUT Adware warez_p2p runtime detection - update request (more info ...)misc-activity        URL
5850SPYWARE-PUT Adware warez_p2p runtime detection - check update (more info ...)misc-activity        URL
5851SPYWARE-PUT Adware warez_p2p runtime detection - .txt .dat and .lst requests (more info ...)misc-activity        URL
5852SPYWARE-PUT Adware warez_p2p runtime detection - cache.dat request (more info ...)misc-activity        URL
5853SPYWARE-PUT Adware warez_p2p runtime detection - download ads (more info ...)misc-activity        URL
5854SPYWARE-PUT Adware warez_p2p runtime detection - pass user information (more info ...)misc-activity        URL
5855SPYWARE-PUT Hijacker funbuddyicons runtime detection - request config (more info ...)misc-activity        URL
5857SPYWARE-PUT Hijacker funbuddyicons runtime detection - mysaconfg request (more info ...)misc-activity        URL
5858SPYWARE-PUT Adware praizetoolbar runtime detection (more info ...)misc-activity        URL
5859SPYWARE-PUT Hijacker daosearch runtime detection - information request (more info ...)misc-activity        URL
5860SPYWARE-PUT Hijacker daosearch runtime detection - search hijack (more info ...)misc-activity        URL
5861SPYWARE-PUT Hijacker isearch runtime detection - toolbar information request (more info ...)misc-activity        URL
5862SPYWARE-PUT Hijacker isearch runtime detection - search hijack 1 (more info ...)misc-activity        URL
5863SPYWARE-PUT Hijacker isearch runtime detection - search hijack 2 (more info ...)misc-activity        URL
5864SPYWARE-PUT Hijacker isearch runtime detection - search in toolbar (more info ...)misc-activity        URL
5865SPYWARE-PUT Adware zapspot runtime detection - pop up ads (more info ...)misc-activity        URL
5866SPYWARE-PUT Hijacker couponbar runtime detection - download new coupon offers and links (more info ...)misc-activity        URL
5867SPYWARE-PUT Hijacker couponbar runtime detection - get updates to toolbar buttons (more info ...)misc-activity        URL
5868SPYWARE-PUT Hijacker couponbar runtime detection - view coupon offers (more info ...)misc-activity        URL
5871SPYWARE-PUT Trickler VX2/ABetterInternet transponder thinstaller runtime detection - post information (more info ...)misc-activity        URL
5872SPYWARE-PUT Snoopware hyperlinker runtime detection (more info ...)successful-recon-limited        URL
5873SPYWARE-PUT Snoopware pc acme pro runtime detection (more info ...)successful-recon-limited        URL
5874SPYWARE-PUT Snoopware pc acme pro runtime detection (more info ...)successful-recon-limited        URL
5875SPYWARE-PUT Hacker-Tool eraser runtime detection - detonate (more info ...)misc-activity        URL
5876SPYWARE-PUT Hacker-Tool eraser runtime detection - disinfect (more info ...)misc-activity        URL
5882SPYWARE-PUT Keylogger spyagent runtime detect - alert notification (more info ...)successful-recon-limited        URL
5883SPYWARE-PUT Other-Technologies saria 1.0 runtime detection - send user information (more info ...)misc-activity        URL
5884SPYWARE-PUT Hijacker copernic meta toolbar runtime detection - check toolbar & category info (more info ...)misc-activity        URL
5885SPYWARE-PUT Hijacker copernic meta toolbar runtime detection - ie autosearch & search assistant hijack (more info ...)misc-activity        URL
5886SPYWARE-PUT Hijacker copernic meta toolbar runtime detection - pass info to server (more info ...)misc-activity        URL
5887SPYWARE-PUT Hijacker shopnav runtime detection - ie search assistant hijack (more info ...)misc-activity        URL
5888SPYWARE-PUT Hijacker shopnav runtime detection - ie auto search hijack (more info ...)misc-activity        URL
5889SPYWARE-PUT Hijacker shopnav runtime detection - collect information (more info ...)misc-activity        URL
5890SPYWARE-PUT Hijacker shopnav runtime detection - self-update request 1 (more info ...)misc-activity        URL
5891SPYWARE-PUT Hijacker shopnav runtime detection - self-update request 2 (more info ...)misc-activity        URL
5894SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - smb (more info ...)misc-activity        URL
5895SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - tcp port 407 (more info ...)misc-activity        
5896SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - tcp port 407 (more info ...)misc-activity        URL
5897SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - udp port 407 (more info ...)misc-activity        URL
5898SPYWARE-PUT Trackware adtools runtime detection - track user activity (more info ...)successful-recon-limited        URL
5899SPYWARE-PUT Trackware adtools-screenmate runtime detection - generate desktop alert (more info ...)successful-recon-limited        URL
5900SPYWARE-PUT Trackware adtools-communicator runtime detection - collect information (more info ...)successful-recon-limited        URL
5901SPYWARE-PUT Trackware adtools-communicator runtime detection - download self-update (more info ...)successful-recon-limited        URL
5903SPYWARE-PUT Adware download accelerator plus runtime detection - get ads (more info ...)misc-activity        URL
5904SPYWARE-PUT Adware download accelerator plus runtime detection - download files (more info ...)misc-activity        URL
5905SPYWARE-PUT Adware download accelerator plus runtime detection - games center request (more info ...)misc-activity        URL
5906SPYWARE-PUT Adware download accelerator plus runtime detection - update (more info ...)misc-activity        URL
5907SPYWARE-PUT Trackware e2give runtime detection - check update (more info ...)successful-recon-limited        URL
5908SPYWARE-PUT Trackware e2give runtime detection - redirect affiliate site request 1 (more info ...)successful-recon-limited        URL
5909SPYWARE-PUT Trackware e2give runtime detection - redirect affiliate site request 2 (more info ...)successful-recon-limited        URL
5910SPYWARE-PUT Trackware casalemedia runtime detection (more info ...)successful-recon-limited        URL
5911SPYWARE-PUT Adware smartpops runtime detection (more info ...)misc-activity        URL
5913SPYWARE-PUT Trickler smasoft webdownloader runtime detection (more info ...)misc-activity        URL
5914SPYWARE-PUT Hijacker locatorstoolbar runtime detection - configuration download (more info ...)misc-activity        URL
5915SPYWARE-PUT Hijacker locatorstoolbar runtime detection - autosearch hijack (more info ...)misc-activity        URL
5916SPYWARE-PUT Hijacker locatorstoolbar runtime detection - sidebar search (more info ...)misc-activity        URL
5917SPYWARE-PUT Hijacker locatorstoolbar runtime detection - toolbar search (more info ...)misc-activity        URL
5918SPYWARE-PUT Hijacker painter runtime detection - ping 'alive' signal (more info ...)misc-activity        URL
5919SPYWARE-PUT Hijacker painter runtime detection - redirect to klikvipsearch (more info ...)misc-activity        URL
5920SPYWARE-PUT Hijacker painter runtime detection - redirect yahoo search through online-casino-searcher (more info ...)misc-activity        URL
5921SPYWARE-PUT Trackware fftoolbar toolbar runtime detection - send user url request (more info ...)successful-recon-limited        URL
5922SPYWARE-PUT Trackware fftoolbar toolbar runtime detection - display advertisement news (more info ...)successful-recon-limited        URL
5923SPYWARE-PUT Adware active shopper runtime detection - side search request (more info ...)misc-activity        URL
5924SPYWARE-PUT Adware active shopper runtime detection - redirect (more info ...)misc-activity        URL
5925SPYWARE-PUT Adware active shopper runtime detection - check (more info ...)misc-activity        URL
5926SPYWARE-PUT Adware active shopper runtime detection - collect information (more info ...)misc-activity        URL
5927SPYWARE-PUT Adware cashbar runtime detection - .smx requests (more info ...)misc-activity        URL
5928SPYWARE-PUT Adware cashbar runtime detection - ads request (more info ...)misc-activity        URL
5929SPYWARE-PUT Adware cashbar runtime detection - pop-up ad 1 (more info ...)misc-activity        URL
5930SPYWARE-PUT Adware cashbar runtime detection - pop-up ad 2 (more info ...)misc-activity        URL
5932SPYWARE-PUT Adware cashbar runtime detection - stats track (more info ...)misc-activity        URL
5933SPYWARE-PUT Hijacker dropspam runtime detection - search request 1 (more info ...)misc-activity        URL
5934SPYWARE-PUT Hijacker dropspam runtime detection - search request 2 (more info ...)misc-activity        URL
5935SPYWARE-PUT Hijacker dropspam runtime detection - search request 3 (more info ...)misc-activity        URL
5936SPYWARE-PUT Hijacker dropspam runtime detection - side search (more info ...)misc-activity        URL
5937SPYWARE-PUT Hijacker dropspam runtime detection - pass information to its controlling server (more info ...)misc-activity        URL
5938SPYWARE-PUT Hijacker dropspam runtime detection - third party information collection (more info ...)misc-activity        URL
5939SPYWARE-PUT Trackware supreme toolbar runtime detection - get cfg (more info ...)successful-recon-limited        URL
5940SPYWARE-PUT Trackware supreme toolbar runtime detection - search request (more info ...)successful-recon-limited        URL
5941SPYWARE-PUT Trackware supreme toolbar runtime detection - track (more info ...)successful-recon-limited        URL
5942SPYWARE-PUT Trackware supreme toolbar runtime detection - pass information to its controlling server (more info ...)successful-recon-limited        URL
5943SPYWARE-PUT Trackware supreme toolbar runtime detection - third party information collection (more info ...)successful-recon-limited        URL
5944SPYWARE-PUT Adware free access bar runtime detection 1 (more info ...)misc-activity        URL
5946SPYWARE-PUT Adware weirdontheweb runtime detection - monitor user web activity (more info ...)misc-activity        URL
5947SPYWARE-PUT Adware weirdontheweb runtime detection - log url (more info ...)misc-activity        URL
5948SPYWARE-PUT Adware weirdontheweb runtime detection - update notifier (more info ...)misc-activity        URL
5949SPYWARE-PUT Trackware iggsey toolbar detection - simpleticker.htm request (more info ...)successful-recon-limited        URL
5950SPYWARE-PUT Trackware iggsey toolbar detection - pass information to server (more info ...)successful-recon-limited        URL
5951SPYWARE-PUT Trackware iggsey toolbar detection - search request (more info ...)successful-recon-limited        URL
5952SPYWARE-PUT Hijacker 123mania runtime detection - autosearch hijacking (more info ...)misc-activity        URL
5953SPYWARE-PUT Hijacker 123mania runtime detection - sidesearch hijacking (more info ...)misc-activity        URL
5954SPYWARE-PUT Trackware browserpal runtime detection - post user info to server (more info ...)successful-recon-limited        URL
5955SPYWARE-PUT Trackware browserpal runtime detection - adblocker function (more info ...)successful-recon-limited        URL
5956SPYWARE-PUT Hacker-Tool ghostvoice 1.02 icq notification of server installation (more info ...)misc-activity        URL
5957SPYWARE-PUT Hacker-Tool ghostvoice 1.02 runtime detection (more info ...)misc-activity        
5960SPYWARE-PUT Hijacker raxsearch detection - pop-up raxsearch window (more info ...)misc-activity        URL
5961SPYWARE-PUT Hijacker searchfast detection - news ticker (more info ...)misc-activity        URL
5963SPYWARE-PUT Hijacker searchfast detection - search request (more info ...)misc-activity        URL
5964SPYWARE-PUT Hijacker searchfast detection - track user activity & get 'relates links' of the toolbar (more info ...)misc-activity        URL
5965SPYWARE-PUT Hijacker searchfast detection - get toolbar cfg (more info ...)misc-activity        URL
5966SPYWARE-PUT trackware searchinweb detection - search request (more info ...)successful-recon-limited        URL
5967SPYWARE-PUT trackware searchinweb detection - click result links (more info ...)successful-recon-limited        URL
5968SPYWARE-PUT trackware searchinweb detection - redirect (more info ...)successful-recon-limited        URL
5969SPYWARE-PUT trackware searchinweb detection - collect information (more info ...)successful-recon-limited        URL
5970SPYWARE-PUT hijacker smart finder detection - keys update (more info ...)misc-activity        URL
5971SPYWARE-PUT hijacker smart finder detection - track hits (more info ...)misc-activity        URL
5972SPYWARE-PUT hijacker smart finder detection - ie autosearch hijack 1 (more info ...)misc-activity        URL
5973SPYWARE-PUT hijacker smart finder detection - search engines hijack (more info ...)misc-activity        URL
5974SPYWARE-PUT hijacker smart finder detection - pop-up ads (more info ...)misc-activity        URL
5975SPYWARE-PUT hijacker topfive searchassistant detection - search request (more info ...)misc-activity        URL
5976SPYWARE-PUT hijacker topfive searchassistant detection - side search (more info ...)misc-activity        URL
5977SPYWARE-PUT hijacker topfive searchassistant detection - post user information to server (more info ...)misc-activity        URL
5978SPYWARE-PUT hijacker topfive searchassistant detection - update (more info ...)misc-activity        URL
5979SPYWARE-PUT Trackware anwb toolbar runtime detection - track user ip address (more info ...)successful-recon-limited        URL
5980SPYWARE-PUT Trackware anwb toolbar runtime detection - display advertisement (more info ...)successful-recon-limited        URL
5981SPYWARE-PUT Hijacker seeqtoolbar runtime detection - autosearch hijack or search in toolbar (more info ...)misc-activity        URL
5982SPYWARE-PUT Hijacker seeqtoolbar runtime detection - email login page (more info ...)misc-activity        URL
5983SPYWARE-PUT Adware powerstrip runtime detection (more info ...)misc-activity        URL
5984SPYWARE-PUT Trackware push toolbar installtime detection - user information collect (more info ...)successful-recon-limited        URL
5985SPYWARE-PUT Trackware push toolbar runtime detection - toolbar information request (more info ...)successful-recon-limited        URL
5986SPYWARE-PUT Trickler teomasearchbar runtime detection (more info ...)misc-activity        URL
5987SPYWARE-PUT Hijacker wishbone runtime detection (more info ...)misc-activity        URL
5988SPYWARE-PUT Trackware windupdates-mediagateway runtime detection - post data (more info ...)successful-recon-limited        URL
5989SPYWARE-PUT Adware broadcastpc runtime detection - get config (more info ...)misc-activity        URL
5990SPYWARE-PUT Adware broadcastpc runtime detection - get up-to-date movie/tv/ad information (more info ...)misc-activity        URL
5991SPYWARE-PUT Hijacker getmirar runtime detection - search request (more info ...)misc-activity        URL
5993SPYWARE-PUT Hijacker getmirar runtime detection - track activity (more info ...)misc-activity        URL
5994SPYWARE-PUT Hijacker getmirar runtime detection - click related button (more info ...)misc-activity        URL
5995SPYWARE-PUT Adware offeragent runtime detection - information checking (more info ...)misc-activity        URL
5996SPYWARE-PUT Adware offeragent runtime detection - ads request (more info ...)misc-activity        URL
6012BACKDOOR coolcat runtime connection detection - tcp 1 (more info ...)trojan-activity        URL
6013BACKDOOR coolcat runtime connection detection - tcp 2 (more info ...)trojan-activity        URL
6015BACKDOOR dsk lite 1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
6016BACKDOOR dsk lite 1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
6018BACKDOOR dsk lite 1.0 runtime detection - icq notification (more info ...)trojan-activity        URL
6021BACKDOOR silent spy 2.10 command response port 4225 (more info ...)trojan-activity        URL
6022BACKDOOR silent spy 2.10 command response port 4226 (more info ...)trojan-activity        URL
6023BACKDOOR silent spy 2.10 runtime detection - icq notification (more info ...)trojan-activity        URL
6024BACKDOOR nuclear rat v6_21 runtime detection (more info ...)trojan-activity        URL
6026BACKDOOR dimbus 1.0 runtime detection - get pc info (more info ...)trojan-activity        URL
6028BACKDOOR cyberpaky runtime detection (more info ...)trojan-activity        URL
6029BACKDOOR fkwp 2.0 runtime detection - icq notification (more info ...)trojan-activity        URL
6035BACKDOOR minicommand runtime detection - initial connection server-to-client (more info ...)trojan-activity        URL
6037BACKDOOR netbus 1.7 runtime detection - email notification (more info ...)trojan-activity        URL
6039BACKDOOR fade 1.0 runtime detection - notification (more info ...)trojan-activity        URL
6040BACKDOOR fade 1.0 runtime detection - enable keylogger (more info ...)trojan-activity        URL
6044BACKDOOR fear 0.2 runtime detection - initial connection (more info ...)trojan-activity        URL
6045BACKDOOR fear 0.2 runtime detection - initial connection (more info ...)trojan-activity        URL
6046BACKDOOR fear 0.2 runtime detection - initial connection (more info ...)trojan-activity        URL
6047BACKDOOR fun factory runtime detection - connect (more info ...)trojan-activity        URL
6048BACKDOOR fun factory runtime detection - connect (more info ...)trojan-activity        URL
6049BACKDOOR fun factory runtime detection - upload (more info ...)trojan-activity        URL
6050BACKDOOR fun factory runtime detection - upload (more info ...)trojan-activity        URL
6051BACKDOOR fun factory runtime detection - set volume (more info ...)trojan-activity        URL
6052BACKDOOR fun factory runtime detection - set volume (more info ...)trojan-activity        URL
6053BACKDOOR fun factory runtime detection - do script remotely (more info ...)trojan-activity        URL
6054BACKDOOR fun factory runtime detection - do script remotely (more info ...)trojan-activity        URL
6055BACKDOOR bifrose 1.1 runtime detection (more info ...)trojan-activity        URL
6056BACKDOOR bifrose 1.1 runtime detection (more info ...)trojan-activity        URL
6058BACKDOOR neurotickat1.3 runtime detection - icq notification (more info ...)trojan-activity        URL
6060BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...)trojan-activity        URL
6061BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...)trojan-activity        URL
6062BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...)trojan-activity        URL
6063BACKDOOR schwindler 1.82 runtime detection (more info ...)trojan-activity        URL
6064BACKDOOR schwindler 1.82 runtime detection (more info ...)trojan-activity        URL
6066BACKDOOR optixlite 1.0 runtime detection - connection success server-to-client (more info ...)trojan-activity        URL
6069BACKDOOR optixlite 1.0 runtime detection - icq notification (more info ...)trojan-activity        URL
6070BACKDOOR freak 1.0 runtime detection - irc notification (more info ...)trojan-activity        URL
6071BACKDOOR freak 1.0 runtime detection - icq notification (more info ...)trojan-activity        URL
6073BACKDOOR freak 1.0 runtime detection - initial connection server-to-client (more info ...)trojan-activity        URL
6074BACKDOOR xhx 1.6 runtime detection - initial connection client-to-server (more info ...)trojan-activity        URL
6075BACKDOOR xhx 1.6 runtime detection - initial connection server-to-client (more info ...)trojan-activity        URL
6076BACKDOOR amiboide uploader runtime detection - init connection (more info ...)trojan-activity        URL
6077BACKDOOR autospy runtime detection - get information (more info ...)trojan-activity        
6078BACKDOOR autospy runtime detection - get information (more info ...)trojan-activity        URL
6079BACKDOOR autospy runtime detection - show autospy (more info ...)trojan-activity        
6080BACKDOOR autospy runtime detection - show autospy (more info ...)trojan-activity        URL
6081BACKDOOR autospy runtime detection - show nude pic (more info ...)trojan-activity        
6082BACKDOOR autospy runtime detection - show nude pic (more info ...)trojan-activity        URL
6083BACKDOOR autospy runtime detection - hide taskbar (more info ...)trojan-activity        
6084BACKDOOR autospy runtime detection - hide taskbar (more info ...)trojan-activity        URL
6085BACKDOOR autospy runtime detection - make directory (more info ...)trojan-activity        
6086BACKDOOR autospy runtime detection - make directory (more info ...)trojan-activity        URL
6087BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity        
6088BACKDOOR a trojan 2.0 runtime detection - init connection (more info ...)trojan-activity        URL
6089BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity        
6090BACKDOOR a trojan 2.0 runtime detection - get memory info (more info ...)trojan-activity        URL
6091BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity        
6092BACKDOOR a trojan 2.0 runtime detection - get harddisk info (more info ...)trojan-activity        URL
6093BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity        
6094BACKDOOR a trojan 2.0 runtime detection - get drive info (more info ...)trojan-activity        URL
6095BACKDOOR a trojan 2.0 runtime detection (more info ...)trojan-activity        
6096BACKDOOR a trojan 2.0 runtime detection - get system info (more info ...)trojan-activity        URL
6097BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity        
6098BACKDOOR alvgus 2000 runtime detection - check server (more info ...)trojan-activity        URL
6099BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity        
6100BACKDOOR alvgus 2000 runtime detection - view content of directory (more info ...)trojan-activity        URL
6101BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity        
6102BACKDOOR alvgus 2000 runtime detection - execute command (more info ...)trojan-activity        URL
6103BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity        
6104BACKDOOR alvgus 2000 runtime detection - upload file (more info ...)trojan-activity        URL
6105BACKDOOR alvgus 2000 runtime detection (more info ...)trojan-activity        
6106BACKDOOR alvgus 2000 runtime detection - download file (more info ...)trojan-activity        URL
6107BACKDOOR backage 3.1 runtime detection (more info ...)trojan-activity        URL
6108BACKDOOR dagger v1.1.40 runtime detection (more info ...)trojan-activity        URL
6109BACKDOOR dagger v1.1.40 runtime detection (more info ...)trojan-activity        URL
6110BACKDOOR forced entry v1.1 beta runtime detection (more info ...)trojan-activity        URL
6111BACKDOOR optix 1.32 runtime detection - init conn (more info ...)trojan-activity        URL
6112BACKDOOR optix 1.32 runtime detection - init conn (more info ...)trojan-activity        URL
6113BACKDOOR optix 1.32 runtime detection - init conn (more info ...)trojan-activity        URL
6114BACKDOOR optix 1.32 runtime detection - email notification (more info ...)trojan-activity        URL
6115BACKDOOR optix 1.32 runtime detection - icq notification (more info ...)trojan-activity        URL
6116BACKDOOR fore v1.0 beta runtime detection - init conn (more info ...)trojan-activity        URL
6117BACKDOOR fore v1.0 beta runtime detection - init conn (more info ...)trojan-activity        URL
6118BACKDOOR net runner runtime detection - initial connection client-to-server (more info ...)trojan-activity        URL
6119BACKDOOR net runner runtime detection - initial connection server-to-client (more info ...)trojan-activity        URL
6120BACKDOOR net runner runtime detection - download file client-to-server (more info ...)trojan-activity        URL
6121BACKDOOR net runner runtime detection - download file server-to-client (more info ...)trojan-activity        URL
6122BACKDOOR millenium v1.0 runtime detection (more info ...)trojan-activity        URL
6123BACKDOOR ambush 1.0 runtime detection - ping client-to-server (more info ...)trojan-activity        URL
6124BACKDOOR ambush 1.0 runtime detection - ping server-to-client (more info ...)trojan-activity        URL
6127BACKDOOR dkangel runtime detection - udp client-to-server (more info ...)trojan-activity        URL
6129BACKDOOR chupacabra 1.0 runtime detection (more info ...)trojan-activity        
6130BACKDOOR chupacabra 1.0 runtime detection - get computer name (more info ...)trojan-activity        URL
6131BACKDOOR chupacabra 1.0 runtime detection (more info ...)trojan-activity        
6132BACKDOOR chupacabra 1.0 runtime detection - get user name (more info ...)trojan-activity        URL
6133BACKDOOR chupacabra 1.0 runtime detection - send messages (more info ...)trojan-activity        URL
6134BACKDOOR chupacabra 1.0 runtime detection - delete file (more info ...)trojan-activity        URL
6136BACKDOOR clindestine 1.0 runtime detection - capture big screen (more info ...)trojan-activity        URL
6137BACKDOOR clindestine 1.0 runtime detection - capture small screen (more info ...)trojan-activity        URL
6138BACKDOOR clindestine 1.0 runtime detection - get computer info (more info ...)trojan-activity        URL
6139BACKDOOR clindestine 1.0 runtime detection - get system directory (more info ...)trojan-activity        URL
6143BACKDOOR dark connection inside v1.2 runtime detection (more info ...)trojan-activity        URL
6144BACKDOOR mantis runtime detection - sent notify option client-to-server 1 (more info ...)trojan-activity        URL
6145BACKDOOR mantis runtime detection - sent notify option server-to-client (more info ...)trojan-activity        URL
6146BACKDOOR mantis runtime detection - sent notify option client-to-server 2 (more info ...)trojan-activity        URL
6147BACKDOOR mantis runtime detection - go to address client-to-server (more info ...)trojan-activity        URL
6148BACKDOOR mantis runtime detection - go to address server-to-client (more info ...)trojan-activity        URL
6149BACKDOOR netcontrol v1.0.8 runtime detection (more info ...)trojan-activity        URL
6150BACKDOOR netcontrol v1.0.8 runtime detection (more info ...)trojan-activity        URL
6151BACKDOOR back attack v1.4 runtime detection (more info ...)trojan-activity        URL
6152BACKDOOR dirtxt runtime detection - chdir client-to-server (more info ...)trojan-activity        URL
6153BACKDOOR dirtxt runtime detection - chdir server-to-client (more info ...)trojan-activity        URL
6154BACKDOOR dirtxt runtime detection - info client-to-server (more info ...)trojan-activity        URL
6155BACKDOOR dirtxt runtime detection - info server-to-client (more info ...)trojan-activity        URL
6156BACKDOOR dirtxt runtime detection - view client-to-server (more info ...)trojan-activity        URL
6157BACKDOOR dirtxt runtime detection - view server-to-client (more info ...)trojan-activity        URL
6159BACKDOOR delirium of disorder runtime detection - enable keylogger (more info ...)trojan-activity        URL
6160BACKDOOR delirium of disorder runtime detection - stop keylogger (more info ...)trojan-activity        URL
6161BACKDOOR furax 1.0 b2 runtime detection (more info ...)trojan-activity        URL
6164BACKDOOR psyrat 1.0 runtime detection (more info ...)trojan-activity        URL
6165BACKDOOR psyrat 1.0 runtime detection (more info ...)trojan-activity        URL
6166BACKDOOR unicorn runtime detection - initial connection (more info ...)trojan-activity        URL
6167BACKDOOR unicorn runtime detection - set wallpaper client-to-server (more info ...)trojan-activity        URL
6168BACKDOOR unicorn runtime detection - set wallpaper server-to-client (more info ...)trojan-activity        URL
6169BACKDOOR digital rootbeer runtime detection (more info ...)trojan-activity        URL
6170BACKDOOR digital rootbeer runtime detection (more info ...)trojan-activity        URL
6171BACKDOOR cookie monster 0.24 runtime detection (more info ...)trojan-activity        
6172BACKDOOR cookie monster 0.24 runtime detection - get version info (more info ...)trojan-activity        URL
6173BACKDOOR cookie monster 0.24 runtime detection (more info ...)trojan-activity        
6174BACKDOOR cookie monster 0.24 runtime detection - file explorer (more info ...)trojan-activity        URL
6175BACKDOOR cookie monster 0.24 runtime detection - kill kernel (more info ...)trojan-activity        URL
6176BACKDOOR guptachar 2.0 runtime detection (more info ...)trojan-activity        URL
6177BACKDOOR ultimate destruction runtime detection - kill process client-to-server (more info ...)trojan-activity        URL
6178BACKDOOR ultimate destruction runtime detection - kill windows client-to-server (more info ...)trojan-activity        URL
6179BACKDOOR bladerunner 0.80 runtime detection (more info ...)trojan-activity        URL
6180BACKDOOR netraider 0.0 runtime detection (more info ...)trojan-activity        URL
6181BACKDOOR netraider 0.0 runtime detection (more info ...)trojan-activity        URL
6183SPYWARE-PUT Adware 180Search assistant runtime detection - tracked event URL (more info ...)misc-activity        URL
6184SPYWARE-PUT Adware 180Search assistant runtime detection - config upload (more info ...)misc-activity        URL
6186SPYWARE-PUT Other-Technologies SpywareStrike Runtime Detection (more info ...)misc-activity        URL
6187SPYWARE-PUT Adware ISTBar runtime detection - scripts (more info ...)misc-activity        URL
6188SPYWARE-PUT Adware ISTBar runtime detection - bar (more info ...)misc-activity        URL
6189SPYWARE-PUT Trackware try2find detection (more info ...)successful-recon-limited        URL
6190SPYWARE-PUT Keylogger eblaster 5.0 runtime detection (more info ...)successful-recon-limited        URL
6191SPYWARE-PUT Trackware onetoolbar runtime detection (more info ...)successful-recon-limited        URL
6193SPYWARE-PUT Adware seekmo runtime detection - pop up ads (more info ...)misc-activity        URL
6194SPYWARE-PUT Adware seekmo runtime detection - config upload (more info ...)misc-activity        URL
6195SPYWARE-PUT Adware seekmo runtime detection - download .cab (more info ...)misc-activity        URL
6196SPYWARE-PUT Hijacker smart shopper runtime detection - services requests (more info ...)misc-activity        URL
6197SPYWARE-PUT Hijacker smart shopper runtime detection - track/upgrade/report activities (more info ...)misc-activity        URL
6198SPYWARE-PUT Trackware squaretrade side bar runtime detection - collect user information (more info ...)successful-recon-limited        URL
6199SPYWARE-PUT Hijacker smart search runtime detection - hijack/ads (more info ...)misc-activity        URL
6200SPYWARE-PUT Hijacker smart search runtime detection - get settings (more info ...)misc-activity        URL
6201SPYWARE-PUT Adware twaintec runtime detection (more info ...)misc-activity        URL
6202SPYWARE-PUT Trickler farmmext installtime/update request (more info ...)misc-activity        URL
6203SPYWARE-PUT Trickler farmmext runtime detection - drk.syn request (more info ...)misc-activity        URL
6204SPYWARE-PUT Trickler farmmext runtime detection - track activity (more info ...)misc-activity        URL
6205SPYWARE-PUT Hacker-Tool freak 88 das runtime detection (more info ...)misc-activity        URL
6206SPYWARE-PUT Hacker-Tool sin stealer 1.1 runtime detection (more info ...)misc-activity        URL
6209SPYWARE-PUT Adware deskwizz/zquest runtime detection - get config information / ad banner (more info ...)misc-activity        URL
6211SPYWARE-PUT Adware deskwizz runtime detection - pop-up ad request (more info ...)misc-activity        URL
6212SPYWARE-PUT Adware commonname runtime detection (more info ...)misc-activity        URL
6213SPYWARE-PUT Hijacker 7fasst runtime detection - auto requests (more info ...)misc-activity        URL
6214SPYWARE-PUT Hijacker 7fasst runtime detection - search (more info ...)misc-activity        URL
6215SPYWARE-PUT Hijacker 7fasst runtime detection - track (more info ...)misc-activity        URL
6216SPYWARE-PUT Adware aornum/iwon copilot runtime detection - config (more info ...)misc-activity        URL
6218SPYWARE-PUT Adware aornum/iwon copilot runtime detection - ads (more info ...)misc-activity        URL
6219SPYWARE-PUT Adware bonzibuddy runtime detection (more info ...)misc-activity        URL
6220SPYWARE-PUT Keylogger boss everyware runtime detection (more info ...)successful-recon-limited        URL
6221SPYWARE-PUT Keylogger computerspy runtime detection (more info ...)successful-recon-limited        URL
6222SPYWARE-PUT Adware delfin media viewer runtime detection - contact server (more info ...)misc-activity        URL
6223SPYWARE-PUT Adware delfin media viewer runtime detection - retrieve schedule (more info ...)misc-activity        URL
6224SPYWARE-PUT Hijacker ieplugin runtime detection - search (more info ...)misc-activity        URL
6230SPYWARE-PUT Hijacker i-lookup runtime detection (more info ...)misc-activity        URL
6232SPYWARE-PUT Adware mirar runtime detection - thumbnail (more info ...)misc-activity        URL
6233SPYWARE-PUT Adware mirar runtime detection - delayed (more info ...)misc-activity        URL
6234SPYWARE-PUT Adware mirar runtime detection - ads (more info ...)misc-activity        URL
6236SPYWARE-PUT Adware lop runtime detection - pass info to server (more info ...)misc-activity        URL
6237SPYWARE-PUT Adware lop runtime detection - check update request (more info ...)misc-activity        URL
6238SPYWARE-PUT Adware lop runtime detection - collect info request 1 (more info ...)misc-activity        URL
6239SPYWARE-PUT Adware lop runtime detection - collect info request 2 (more info ...)misc-activity        URL
6240SPYWARE-PUT Adware lop runtime detection - pop up ads (more info ...)misc-activity        URL
6241SPYWARE-PUT Adware lop runtime detection - ie autosearch hijack (more info ...)misc-activity        URL
6242SPYWARE-PUT Hijacker coolwebsearch.cameup runtime detection (more info ...)misc-activity        URL
6243SPYWARE-PUT Hijacker coolwebsearch cameup runtime detection - home page hijack (more info ...)misc-activity        URL
6244SPYWARE-PUT Hijacker coolwebsearch cameup runtime detection - ie auto search hijack (more info ...)misc-activity        URL
6245SPYWARE-PUT Hijacker coolwebsearch startpage runtime detection (more info ...)misc-activity        URL
6246SPYWARE-PUT Hijacker exact navisearch runtime detection - search hijack (more info ...)misc-activity        URL
6247SPYWARE-PUT Adware ezula toptext runtime detection - help redirect (more info ...)misc-activity        URL
6248SPYWARE-PUT Adware ezula toptext runtime detection - popup (more info ...)misc-activity        URL
6249SPYWARE-PUT Adware ezula toptext runtime detection - redirect (more info ...)misc-activity        URL
6250SPYWARE-PUT Adware hotbar runtime detection - hotbar user-agent (more info ...)misc-activity        URL
6251SPYWARE-PUT Adware hotbar runtime detection - hostie user-agent (more info ...)misc-activity        URL
6252SPYWARE-PUT Trackware quicksearch toolbar runtime detection - search request (more info ...)successful-recon-limited        URL
6253SPYWARE-PUT Trackware quicksearch toolbar runtime detection - log user ativity (more info ...)successful-recon-limited        URL
6254SPYWARE-PUT Trackware quicksearch toolbar runtime detection - redirect (more info ...)successful-recon-limited        URL
6255SPYWARE-PUT Trackware quicksearch toolbar runtime detection - update (more info ...)successful-recon-limited        URL
6256SPYWARE-PUT Adware searchsquire installtime/auto-update (more info ...)misc-activity        URL
6257SPYWARE-PUT Adware searchsquire runtime detection - testgeonew query (more info ...)misc-activity        URL
6258SPYWARE-PUT Adware searchsquire runtime detection - get engine file (more info ...)misc-activity        URL
6259SPYWARE-PUT Adware searchsquire runtime detection - search forward (more info ...)misc-activity        URL
6260SPYWARE-PUT Adware overpro runtime detection (more info ...)misc-activity        URL
6261SPYWARE-PUT Trickler slinkyslate toolbar runtime detection (more info ...)misc-activity        URL
6263SPYWARE-PUT Hijacker gigatech superbar runtime detection - collect information (more info ...)misc-activity        URL
6264SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - movie (more info ...)misc-activity        URL
6265SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - engine (more info ...)misc-activity        URL
6266SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - check update (more info ...)misc-activity        URL
6267SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - get update (more info ...)misc-activity        URL
6268SPYWARE-PUT Hijacker gigatech superbar runtime detection - self update - download exe (more info ...)misc-activity        URL
6269SPYWARE-PUT Hijacker gigatech superbar runtime detection - track event (more info ...)misc-activity        URL
6270SPYWARE-PUT Hijacker topicks runtime detection (more info ...)misc-activity        URL
6271SPYWARE-PUT Trickler bundleware runtime detection (more info ...)misc-activity        URL
6274SPYWARE-PUT Trickler clickalchemy runtime detection (more info ...)misc-activity        URL
6275SPYWARE-PUT Hijacker incredifind runtime detection - cookie (more info ...)misc-activity        URL
6279SPYWARE-PUT Hijacker sidefind runtime detection (more info ...)misc-activity        URL
6280SPYWARE-PUT Hijacker sidefind runtime detection - cookie (more info ...)misc-activity        URL
6281SPYWARE-PUT Hijacker yoursitebar runtime detection (more info ...)misc-activity        URL
6282SPYWARE-PUT Hijacker customtoolbar runtime detection (more info ...)misc-activity        URL
6283SPYWARE-PUT Hijacker websearch runtime detection - sitereview (more info ...)misc-activity        URL
6284SPYWARE-PUT Hijacker websearch runtime detection - webstat (more info ...)misc-activity        URL
6285BACKDOOR antilamer 1.1 runtime detection - set flowbit (more info ...)trojan-activity        URL
6286BACKDOOR antilamer 1.1 runtime detection (more info ...)trojan-activity        URL
6287BACKDOOR fictional daemon 4.4 runtime detection - telent (more info ...)trojan-activity        URL
6289BACKDOOR netspy runtime detection - command pattern client-to-server (more info ...)trojan-activity        URL
6290BACKDOOR netspy runtime detection - command pattern server-to-client (more info ...)trojan-activity        URL
6291BACKDOOR justjoke v2.6 runtime detection (more info ...)trojan-activity        URL
6292BACKDOOR joker ddos v1.0.1 runtime detection - initial connection (more info ...)trojan-activity        URL
6293BACKDOOR joker ddos v1.0.1 runtime detection - bomb - initial flowbit (more info ...)trojan-activity        URL
6294BACKDOOR joker ddos v1.0.1 runtime detection - bomb - second flowbit (more info ...)trojan-activity        URL
6295BACKDOOR joker ddos v1.0.1 runtime detection - bomb (more info ...)trojan-activity        URL
6296BACKDOOR insurrection 1.1.0 runtime detection - icq notification 1 (more info ...)trojan-activity        URL
6297BACKDOOR insurrection 1.1.0 runtime detection - icq notification 2 (more info ...)trojan-activity        URL
6298BACKDOOR insurrection 1.1.0 runtime detection - reverse connection (more info ...)trojan-activity        URL
6299BACKDOOR insurrection 1.1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
6300BACKDOOR cia 1.3 runtime detection - icq notification (more info ...)trojan-activity        URL
6302BACKDOOR cia runtime detection - initial connection - set flowbit (more info ...)trojan-activity        URL
6303BACKDOOR cia runtime detection - initial connection (more info ...)trojan-activity        URL
6304BACKDOOR softwar shadowthief runtime detection - initial connection - set flowbit (more info ...)trojan-activity        URL
6305BACKDOOR softwar shadowthief runtime detection - initial connection (more info ...)trojan-activity        URL
6306BACKDOOR shit heep runtime detection (more info ...)trojan-activity        URL
6307BACKDOOR lamespy runtime detection - initial connection - set flowbit (more info ...)trojan-activity        URL
6308BACKDOOR lamespy runtime detection - initial connection (more info ...)trojan-activity        URL
6312BACKDOOR net demon runtime detection - message send (more info ...)trojan-activity        URL
6313BACKDOOR net demon runtime detection - message response (more info ...)trojan-activity        URL
6314BACKDOOR net demon runtime detection - open browser request (more info ...)trojan-activity        URL
6315BACKDOOR net demon runtime detection - open browser response (more info ...)trojan-activity        URL
6316BACKDOOR net demon runtime detection - file manager request (more info ...)trojan-activity        URL
6317BACKDOOR net demon runtime detection - file manager response (more info ...)trojan-activity        URL
6318BACKDOOR rtb666 runtime detection (more info ...)trojan-activity        URL
6320BACKDOOR ptakks2.1 runtime detection - keepalive (more info ...)trojan-activity        URL
6321BACKDOOR ptakks2.1 runtime detection - keepalive acknowledgement (more info ...)trojan-activity        URL
6322BACKDOOR ptakks2.1 runtime detection - command pattern (more info ...)trojan-activity        URL
6323BACKDOOR 3xBackdoor runtime detection - set flowbit (more info ...)trojan-activity        URL
6324BACKDOOR 3xBackdoor runtime detection (more info ...)trojan-activity        URL
6325BACKDOOR fucktrojan 1.2 runtime detection - initial connection (more info ...)trojan-activity        URL
6326BACKDOOR fucktrojan 1.2 runtime detection - flood (more info ...)trojan-activity        
6327BACKDOOR fucktrojan 1.2 runtime detection - flood (more info ...)trojan-activity        URL
6328BACKDOOR commando runtime detection - initial connection (more info ...)trojan-activity        URL
6329BACKDOOR commando runtime detection - chat client-to-server (more info ...)trojan-activity        URL
6330BACKDOOR commando runtime detection - chat server-to-client (more info ...)trojan-activity        URL
6331BACKDOOR globalkiller1.0 runtime detection - notification (more info ...)trojan-activity        URL
6332BACKDOOR globalkiller1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
6333BACKDOOR wincrash 2.0 runtime detection (more info ...)trojan-activity        URL
6334BACKDOOR backlash runtime detection (more info ...)trojan-activity        URL
6335BACKDOOR buttman v0.9p runtime detection - remote control - set flowbit (more info ...)trojan-activity        URL
6336BACKDOOR buttman v0.9p runtime detection - remote control (more info ...)trojan-activity        URL
6337BACKDOOR hatredfriend file manage command - set flowbit (more info ...)trojan-activity        URL
6338BACKDOOR hatredfriend file manage command (more info ...)trojan-activity        URL
6339BACKDOOR hatredfriend email notification detection (more info ...)trojan-activity        URL
6340SPYWARE-PUT Keylogger handy keylogger runtime detection (more info ...)successful-recon-limited        URL
6341SPYWARE-PUT Hijacker spediabar user-agent string detected (more info ...)misc-activity        URL
6342SPYWARE-PUT Hijacker spediabar runtime detection - info check (more info ...)misc-activity        URL
6343SPYWARE-PUT Adware targetsaver runtime detection (more info ...)misc-activity        URL
6344SPYWARE-PUT Adware excite search bar runtime detection - config (more info ...)misc-activity        URL
6345SPYWARE-PUT Adware excite search bar runtime detection - search (more info ...)misc-activity        URL
6346SPYWARE-PUT Adware stationripper update detection (more info ...)misc-activity        URL
6347SPYWARE-PUT Adware stationripper ad display detection (more info ...)misc-activity        URL
6348SPYWARE-PUT Snoopware zenosearch runtime detection (more info ...)successful-recon-limited        URL
6349SPYWARE-PUT Hijacker richfind update detection (more info ...)misc-activity        URL
6350SPYWARE-PUT Hijacker richfind auto search redirect detection (more info ...)misc-activity        URL
6351SPYWARE-PUT Hijacker adblock update detection (more info ...)misc-activity        URL
6352SPYWARE-PUT Hijacker adblock auto search redirect detection (more info ...)misc-activity        URL
6353SPYWARE-PUT Hijacker adblock ie search assistant redirect detection (more info ...)misc-activity        URL
6354SPYWARE-PUT Trickler wsearch runtime detection - auto update (more info ...)misc-activity        URL
6355SPYWARE-PUT Trickler wsearch runtime detection - mp3 search (more info ...)misc-activity        URL
6356SPYWARE-PUT Trickler wsearch runtime detection - desktop search (more info ...)misc-activity        URL
6357SPYWARE-PUT Hijacker need2find initial configuration detection (more info ...)misc-activity        URL
6358SPYWARE-PUT Hijacker need2find search query detection (more info ...)misc-activity        URL
6359SPYWARE-PUT Adware altnet runtime detection - initial retrieval (more info ...)misc-activity        URL
6360SPYWARE-PUT Adware altnet runtime detection - update (more info ...)misc-activity        URL
6361SPYWARE-PUT Adware altnet runtime detection - status report (more info ...)misc-activity        URL
6362SPYWARE-PUT Hijacker microgaming runtime detection (more info ...)misc-activity        URL
6363SPYWARE-PUT adware surfaccuracy runtime detection (more info ...)misc-activity        URL
6364SPYWARE-PUT Hijacker imeshbar runtime detection (more info ...)misc-activity        URL
6365SPYWARE-PUT Other-Technologies sony rootkit runtime detection (more info ...)misc-activity        URL
6366SPYWARE-PUT Trickler eacceleration downloadreceiver user-agent string detected (more info ...)misc-activity        URL
6367SPYWARE-PUT Trickler eacceleration downloadreceiver runtime detection - stop-sign ads (more info ...)misc-activity        URL
6372SPYWARE-PUT Trickler spyblocs eblocs detection - get wsliveup.dat (more info ...)misc-activity        URL
6373SPYWARE-PUT Trickler spyblocs eblocs detection - stbarpat.dat (more info ...)misc-activity        URL
6374SPYWARE-PUT Trickler spyblocs eblocs detection - get spyblpat.dat/spyblini.ini (more info ...)misc-activity        URL
6375SPYWARE-PUT Trickler spyblocs.eblocs detection - register request (more info ...)misc-activity        URL
6376SPYWARE-PUT Hijacker girafa toolbar - toolbar update (more info ...)misc-activity        URL
6377SPYWARE-PUT Hijacker girafa toolbar - browser hijack (more info ...)misc-activity        URL
6378SPYWARE-PUT Hijacker adbars runtime detection - homepage hijack (more info ...)misc-activity        URL
6379SPYWARE-PUT Hijacker adbars runtime detection - search in toolbar (more info ...)misc-activity        URL
6380SPYWARE-PUT Hijacker dotcomtoolbar runtime detection - toolbar information retrieve (more info ...)misc-activity        URL
6381SPYWARE-PUT Hijacker dotcomtoolbar runtime detection - search in toolbar (more info ...)misc-activity        URL
6382SPYWARE-PUT Hijacker dotcomtoolbar runtime detection - url hook (more info ...)misc-activity        URL
6383SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - tcp connection setup (more info ...)successful-recon-limited        URL
6385SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - agent status monitoring (more info ...)successful-recon-limited        URL
6386SPYWARE-PUT Keylogger stealthwatcher 2000 runtime detection - agent up notification (more info ...)successful-recon-limited        URL
6387SPYWARE-PUT Hijacker internet optimizer runtime detection - autosearch hijack (more info ...)misc-activity        URL
6388SPYWARE-PUT Hijacker internet optimizer runtime detection - error page hijack (more info ...)misc-activity        URL
6389SPYWARE-PUT Adware esyndicate runtime detection - postinstall request (more info ...)misc-activity        URL
6390SPYWARE-PUT Adware esyndicate runtime detection - ads popup (more info ...)misc-activity        
6391SPYWARE-PUT Adware esyndicate runtime detection - ads popup (more info ...)misc-activity        URL
6392SPYWARE-PUT Hijacker zeropopup runtime detection (more info ...)misc-activity        URL
6394SPYWARE-PUT Hijacker adstart runtime detection (more info ...)misc-activity        URL
6395BACKDOOR a-311 death runtime detection - initial connection server-to-client (more info ...)trojan-activity        URL
6396BACKDOOR a-311 death user-agent string detected (more info ...)trojan-activity        URL
6398BACKDOOR http rat runtime detection - http (more info ...)trojan-activity        URL
6399BACKDOOR rad 1.2.3 runtime detection (more info ...)trojan-activity        URL
6400BACKDOOR snowdoor runtime detection client-to-server (more info ...)trojan-activity        URL
6401BACKDOOR snowdoor runtime detection server-to-client (more info ...)trojan-activity        URL
6402BACKDOOR netangel connection client-to-server (more info ...)trojan-activity        URL
6469EXPLOIT RealVNC connection attempt (more info ...)protocol-command-decode        
6470EXPLOIT RealVNC authentication types without None type sent attempt (more info ...)protocol-command-decode        
6472BACKDOOR bugs runtime detection - file manager client-to-server (more info ...)trojan-activity        URL
6473BACKDOOR bugs runtime detection - file manager server-to-client (more info ...)trojan-activity        URL
6474BACKDOOR w32.loosky.gen@mm runtime detection - notification (more info ...)trojan-activity        URL
6475BACKDOOR badrat 1.1 runtime detection - flowbit set (more info ...)trojan-activity        URL
6476BACKDOOR badrat 1.1 runtime detection (more info ...)trojan-activity        URL
6478SPYWARE-PUT Trackware searchingall toolbar runtime detection - send user url request (more info ...)successful-recon-limited        URL
6479SPYWARE-PUT Snoopware totalvelocity zsearch runtime detection (more info ...)successful-recon-limited        URL
6480SPYWARE-PUT Hijacker cws.cameup runtime detection - home page (more info ...)misc-activity        URL
6481SPYWARE-PUT Hijacker cws.cameup runtime detection - search (more info ...)misc-activity        URL
6482SPYWARE-PUT Hijacker makemesearch toolbar runtime detection - get info (more info ...)misc-activity        URL
6483SPYWARE-PUT Hijacker makemesearch toolbar runtime detection - home page hijacker (more info ...)misc-activity        URL
6484SPYWARE-PUT Hijacker makemesearch toolbar runtime detection - search (more info ...)misc-activity        URL
6487SPYWARE-PUT Adware searchnugget toolbar runtime detection - check updates (more info ...)misc-activity        URL
6488SPYWARE-PUT Adware searchnugget toolbar runtime detection - redirect mistyped urls (more info ...)misc-activity        URL
6489SPYWARE-PUT Hijacker analyze IE runtime detection - default page hijacker (more info ...)misc-activity        URL
6490SPYWARE-PUT Dialer yeaknet runtime detection - home page hijacker (more info ...)misc-activity        URL
6491SPYWARE-PUT Dialer yeaknet runtime detection - post-installation (more info ...)misc-activity        URL
6492SPYWARE-PUT Trickler Backdoor-BAC.gen.e runtime detection - notification (more info ...)misc-activity        URL
6493SPYWARE-PUT Trickler Backdoor-BAC.gen.e runtime detection - post data (more info ...)misc-activity        URL
6494SPYWARE-PUT Adware yourenhancement runtime detection (more info ...)misc-activity        URL
6495SPYWARE-PUT Hijacker troj_spywad.x runtime detection (more info ...)misc-activity        URL
6496SPYWARE-PUT Adware adpowerzone runtime detection (more info ...)misc-activity        URL
6497BACKDOOR exploiter 1.0 runtime detection (more info ...)trojan-activity        URL
6498BACKDOOR exploiter 1.0 runtime detection (more info ...)trojan-activity        URL
6499BACKDOOR omerta 1.3 runtime detection (more info ...)trojan-activity        URL
6688WEB-CLIENT PNG file transfer (more info ...)protocol-command-decode        
6691WEB-CLIENT Malformed PNG detected sBIT overflow attempt (more info ...)attempted-user  2006-0025  18385    URL
6693WEB-CLIENT Malformed PNG detected bKGD overflow attempt (more info ...)attempted-user  2006-0025  18385    URL
6694WEB-CLIENT Malformed PNG detected hIST overflow attempt (more info ...)attempted-user  2006-0025  18385    URL
6695WEB-CLIENT Malformed PNG detected tRNS overflow attempt (more info ...)attempted-user  2006-0025  18385    URL
6696WEB-CLIENT Malformed PNG detected pHYs overflow attempt (more info ...)attempted-user  2006-0025  18385    URL
6698WEB-CLIENT Malformed PNG detected tIME overflow attempt (more info ...)attempted-user  2006-0025  18385    URL
7022WEB-CLIENT windows explorer invalid url file overflow attempt (more info ...)denial-of-service  2006-3351  18838    
7049SPYWARE-PUT Hijacker extreme biz runtime detection - uniq1 (more info ...)misc-activity        URL
7050SPYWARE-PUT Hijacker freecruise toolbar runtime detection (more info ...)misc-activity        
7051SPYWARE-PUT Trickler generic downloader.g runtime detection - spyware injection (more info ...)misc-activity        URL
7052SPYWARE-PUT Trickler generic downloader.g runtime detection - adv (more info ...)misc-activity        URL
7053SPYWARE-PUT Adware webredir runtime detection (more info ...)misc-activity        URL
7054SPYWARE-PUT Trickler download arq variant runtime detection (more info ...)misc-activity        URL
7055SPYWARE-PUT Hijacker vip01 biz runtime detection - adv (more info ...)misc-activity        URL
7057BACKDOOR charon runtime detection - initial connection (more info ...)trojan-activity        URL
7058BACKDOOR charon runtime detection - download file flowbit 1 (more info ...)trojan-activity        URL
7059BACKDOOR charon runtime detection - download file/log flowbit 2 (more info ...)trojan-activity        URL
7060BACKDOOR charon runtime detection - download file/log (more info ...)trojan-activity        URL
7061BACKDOOR charon runtime detection - download log flowbit 1 (more info ...)trojan-activity        URL
7064BACKDOOR cybernetic 1.62 runtime detection - email notification (more info ...)trojan-activity        URL
7065BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1 (more info ...)trojan-activity        URL
7066BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1 (more info ...)trojan-activity        URL
7067BACKDOOR cybernetic 1.62 runtime detection - reverse connection (more info ...)trojan-activity        URL
7068BACKDOOR delta source 0.5 beta runtime detection - ping (more info ...)trojan-activity        URL
7069BACKDOOR delta source 0.5 beta runtime detection - pc info (more info ...)trojan-activity        URL
7072BACKDOOR fraggle rock 2.0 lite runtime detection - pc info (more info ...)trojan-activity        URL
7073BACKDOOR w32.dumaru.gen@mm runtime detection - notification (more info ...)trojan-activity        URL
7074BACKDOOR w32.dumaru.gen@mm runtime detection - cmd (more info ...)trojan-activity        URL
7075BACKDOOR bandook 1.0 runtime detection (more info ...)trojan-activity        URL
7077BACKDOOR minimo v0.6 runtime detection - icq notification (more info ...)trojan-activity        
7078BACKDOOR up and run v1.0 beta runtime detection flowbit 1 (more info ...)trojan-activity        URL
7079BACKDOOR up and run v1.0 beta runtime detection flowbit 2 (more info ...)trojan-activity        URL
7080BACKDOOR up and run v1.0 beta runtime detection flowbit 3 (more info ...)trojan-activity        URL
7081BACKDOOR up and run v1.0 beta runtime detection (more info ...)trojan-activity        URL
7082BACKDOOR mosucker3.0 runtime detection - client-to-server (more info ...)trojan-activity        URL
7084BACKDOOR erazer v1.1 runtime detection - sin notification (more info ...)trojan-activity        URL
7085BACKDOOR erazer v1.1 runtime detection (more info ...)trojan-activity        URL
7086BACKDOOR erazer v1.1 runtime detection - init connection (more info ...)trojan-activity        URL
7091BACKDOOR serveme runtime detection (more info ...)trojan-activity        URL
7096BACKDOOR remote hack 1.5 runtime detection - logon (more info ...)trojan-activity        URL
7097BACKDOOR remote hack 1.5 runtime detection - execute file (more info ...)trojan-activity        URL
7099BACKDOOR remote hack 1.5 runtime detection - start keylogger (more info ...)trojan-activity        URL
7101BACKDOOR gwboy 0.92 runtime detection (more info ...)trojan-activity        URL
7103BACKDOOR gwboy 0.92 runtime detection - init connection (more info ...)trojan-activity        URL
7104BACKDOOR aol admin runtime detection (more info ...)trojan-activity        URL
7105BACKDOOR aol admin runtime detection (more info ...)trojan-activity        URL
7106BACKDOOR girlfriend runtime detection (more info ...)trojan-activity        URL
7108BACKDOOR undetected runtime detection (more info ...)trojan-activity        URL
7111BACKDOOR fearless lite 1.01 runtime detection (more info ...)trojan-activity        URL
7112BACKDOOR fearless lite 1.01 runtime detection (more info ...)trojan-activity        URL
7113BACKDOOR donalddick v1.5b3 runtime detection (more info ...)trojan-activity        URL
7114BACKDOOR donalddick v1.5b3 runtime detection (more info ...)trojan-activity        URL
7115BACKDOOR ghost 2.3 runtime detection (more info ...)trojan-activity        URL
7116BACKDOOR y3k 1.2 runtime detection - icq notification (more info ...)trojan-activity        URL
7118BACKDOOR y3k 1.2 runtime detection - user-agent string detected (more info ...)trojan-activity        URL
7119BACKDOOR y3k 1.2 runtime detection (more info ...)trojan-activity        URL
7120BACKDOOR y3k 1.2 runtime detection - init connection 1 (more info ...)trojan-activity        URL
7121BACKDOOR y3k 1.2 runtime detection (more info ...)trojan-activity        URL
7122BACKDOOR y3k 1.2 runtime detection - init connection 2 (more info ...)trojan-activity        URL
7123SPYWARE-PUT Other-Technologies alfacleaner runtime detection - update (more info ...)misc-activity        URL
7124SPYWARE-PUT Other-Technologies alfacleaner runtime detection - buy (more info ...)misc-activity        URL
7125SPYWARE-PUT Hijacker traffbest biz runtime detection - adv (more info ...)misc-activity        URL
7126SPYWARE-PUT Hijacker trojan proxy atiup runtime detection - notification (more info ...)misc-activity        URL
7127SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - tracking (more info ...)misc-activity        URL
7128SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - advertising 1 (more info ...)misc-activity        URL
7129SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - advertising 2 (more info ...)misc-activity        URL
7130SPYWARE-PUT Hijacker wowok mp3 bar runtime detection - search assissant hijacking (more info ...)misc-activity        URL
7135SPYWARE-PUT Hijacker dsrch runtime detection - config info retrieval (more info ...)misc-activity        URL
7136SPYWARE-PUT Hijacker dsrch runtime detection - search assistant redirect (more info ...)misc-activity        URL
7137SPYWARE-PUT Hijacker dsrch runtime detection - side search redirect (more info ...)misc-activity        URL
7138SPYWARE-PUT Other-Technologies clicktrojan runtime detection - version check (more info ...)misc-activity        URL
7139SPYWARE-PUT Other-Technologies clicktrojan runtime detection - fake search query (more info ...)misc-activity        URL
7140SPYWARE-PUT Adware pay-per-click runtime detection - configuration (more info ...)misc-activity        URL
7141SPYWARE-PUT Adware pay-per-click runtime detection - update (more info ...)misc-activity        URL
7143SPYWARE-PUT Adware digink.com runtime detection (more info ...)misc-activity        URL
7144SPYWARE-PUT Hijacker cool search runtime detection (more info ...)misc-activity        URL
7145SPYWARE-PUT Other-Technologies spam maxy runtime detection (more info ...)misc-activity        URL
7146SPYWARE-PUT Hacker-Tool sars notifier runtime detection - sin notification (more info ...)misc-activity        URL
7147SPYWARE-PUT Hacker-Tool sars notifier runtime detection - icq notification (more info ...)misc-activity        URL
7150SPYWARE-PUT Hacker-Tool sars notifier runtime detection - irc notification (more info ...)misc-activity        URL
7151SPYWARE-PUT Hacker-Tool sars notifier runtime detection - net send notification (more info ...)misc-activity        URL
7152SPYWARE-PUT Hijacker cnsmin 3721 runtime detection - installation (more info ...)misc-activity        URL
7153SPYWARE-PUT Hijacker cnsmin 3721 runtime detection - hijacking (more info ...)misc-activity        URL
7154SPYWARE-PUT Keylogger active keylogger home runtime detection (more info ...)successful-recon-limited        URL
7155SPYWARE-PUT Trickler jubster runtime detection (more info ...)misc-activity        URL
7156SPYWARE-PUT Keylogger win-spy runtime detection - email delivery (more info ...)successful-recon-limited        URL
7157SPYWARE-PUT Keylogger win-spy runtime detection - remote conn client-to-server (more info ...)successful-recon-limited        URL
7158SPYWARE-PUT Keylogger win-spy runtime detection - remote conn server-to-client (more info ...)successful-recon-limited        URL
7159SPYWARE-PUT Keylogger win-spy runtime detection - upload file client-to-server (more info ...)successful-recon-limited        URL
7160SPYWARE-PUT Keylogger win-spy runtime detection - upload file server-to-client (more info ...)successful-recon-limited        URL
7161SPYWARE-PUT Keylogger win-spy runtime detection - download file client-to-server (more info ...)successful-recon-limited        URL
7162SPYWARE-PUT Keylogger win-spy runtime detection - download file server-to-client (more info ...)successful-recon-limited        URL
7163SPYWARE-PUT Keylogger win-spy runtime detection - execute file client-to-server (more info ...)successful-recon-limited        URL
7164SPYWARE-PUT Keylogger win-spy runtime detection - execute file server-to-client (more info ...)successful-recon-limited        URL
7175SPYWARE-PUT Keylogger ab system spy runtime detection - log retrieve (more info ...)successful-recon-limited        URL
7176SPYWARE-PUT Keylogger ab system spy runtime detection - log retrieve (more info ...)successful-recon-limited        URL
7177SPYWARE-PUT Keylogger ab system spy runtime detection - info send through email (more info ...)successful-recon-limited        URL
7178SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection (more info ...)successful-recon-limited        
7179SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection (more info ...)successful-recon-limited        
7180SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection (more info ...)successful-recon-limited        URL
7183SPYWARE-PUT Snoopware barok runtime detection (more info ...)successful-recon-limited        URL
7186SPYWARE-PUT Keylogger kgb Keylogger runtime detection (more info ...)successful-recon-limited        URL
7187SPYWARE-PUT Trackware shopathome user-agent detected (more info ...)successful-recon-limited        URL
7188SPYWARE-PUT Hijacker shop at home select - merchant redirect in progress (more info ...)successful-recon-limited        URL
7189SPYWARE-PUT Trackware shopathome runtime detection - setcookie request (more info ...)successful-recon-limited        URL
7190SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - host retrieval (more info ...)misc-activity        URL
7191SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - url retrieval (more info ...)misc-activity        URL
7192SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - sponsor selection (more info ...)misc-activity        URL
7193SPYWARE-PUT Adware trustyfiles v3.1.0.1 runtime detection - startup access (more info ...)misc-activity        URL
7194SPYWARE-PUT Hijacker shopprreports runtime detection - services requests (more info ...)misc-activity        URL
7195SPYWARE-PUT Hijacker shopprreports runtime detection - track/upgrade/report activities (more info ...)misc-activity        URL
7506SPYWARE-PUT Hacker-Tool coma runtime detection - init connection - flowbit set (more info ...)misc-activity        
7507SPYWARE-PUT Hacker-Tool coma runtime detection - init connection (more info ...)misc-activity        URL
7508SPYWARE-PUT Hacker-Tool coma runtime detection - ping - flowbit set (more info ...)misc-activity        
7509SPYWARE-PUT Hacker-Tool coma runtime detection - ping (more info ...)misc-activity        URL
7510SPYWARE-PUT Trickler edonkey2000 runtime detection - version verification (more info ...)misc-activity        URL
7511SPYWARE-PUT Trickler edonkey2000 runtime detection - get ads page (more info ...)misc-activity        URL
7512SPYWARE-PUT Keylogger watchdog runtime detection - init connection - flowbit set (more info ...)successful-recon-limited        URL
7513SPYWARE-PUT Keylogger watchdog runtime detection - init connection (more info ...)successful-recon-limited        URL
7514SPYWARE-PUT Keylogger watchdog runtime detection - send out info to server periodically (more info ...)successful-recon-limited        URL
7515SPYWARE-PUT Keylogger watchdog runtime detection - remote monitoring (more info ...)successful-recon-limited        URL
7516SPYWARE-PUT Trickler hmtoolbar runtime detection (more info ...)misc-activity        URL
7518SPYWARE-PUT Trackware earthlink toolbar runtime detection - get up-to-date news info (more info ...)successful-recon-limited        URL
7519SPYWARE-PUT Trackware earthlink toolbar runtime detection - track activity (more info ...)successful-recon-limited        URL
7520SPYWARE-PUT Trackware earthlink toolbar runtime detection - ie autosearch hijack (more info ...)successful-recon-limited        URL
7521SPYWARE-PUT Trackware earthlink toolbar runtime detection - search toolbar request 1 (more info ...)successful-recon-limited        URL
7522SPYWARE-PUT Trackware earthlink toolbar runtime detection - search toolbar request 2 (more info ...)successful-recon-limited        URL
7523SPYWARE-PUT Trackware earthlink toolbar runtime detection - click news button links (more info ...)successful-recon-limited        URL
7525SPYWARE-PUT Trackware hotblox toolbar runtime detection - barad.asp request (more info ...)successful-recon-limited        URL
7526SPYWARE-PUT Trackware hotblox toolbar runtime detection - stat counter (more info ...)successful-recon-limited        URL
7527SPYWARE-PUT Trackware hotblox toolbar runtime detection - toolbar find function (more info ...)successful-recon-limited        URL
7528SPYWARE-PUT Trackware hotblox toolbar runtime detection - ie autosearch hijack (more info ...)successful-recon-limited        URL
7529SPYWARE-PUT Snoopware halflife jacker runtime detection (more info ...)successful-recon-limited        URL
7530SPYWARE-PUT Trickler mediaseek.pl client runtime detection - trickler (more info ...)misc-activity        URL
7531SPYWARE-PUT Trickler mediaseek.pl client runtime detection - login (more info ...)misc-activity        URL
7532SPYWARE-PUT Adware piolet runtime detection - user-agent (more info ...)misc-activity        URL
7533SPYWARE-PUT Adware piolet runtime detection - ads request (more info ...)misc-activity        URL
7534SPYWARE-PUT Hijacker clearsearch variant runtime detection - ie hijacking (more info ...)misc-activity        URL
7535SPYWARE-PUT Hijacker clearsearch variant runtime detection - pass information (more info ...)misc-activity        URL
7536SPYWARE-PUT Hijacker clearsearch variant runtime detection - popup (more info ...)misc-activity        URL
7537SPYWARE-PUT Trackware arrow search runtime detection (more info ...)successful-recon-limited        URL
7539SPYWARE-PUT Keylogger eye spy pro 1.0 runtime detection (more info ...)successful-recon-limited        URL
7541SPYWARE-PUT Keylogger starlogger runtime detection (more info ...)successful-recon-limited        URL
7542SPYWARE-PUT Hacker-Tool mini oblivion runtime detection - successful init connection (more info ...)misc-activity        URL
7543SPYWARE-PUT Hijacker 2020search runtime detection (more info ...)misc-activity        URL
7544SPYWARE-PUT Keylogger PerfectKeylogger runtime detection - flowbit set 1 (more info ...)successful-recon-limited        URL
7545SPYWARE-PUT Keylogger PerfectKeylogger runtime detection - flowbit set 2 (more info ...)successful-recon-limited        URL
7546SPYWARE-PUT Keylogger PerfectKeylogger runtime detection (more info ...)successful-recon-limited        URL
7547SPYWARE-PUT Keylogger activity monitor 3.8 runtime detection - agent status monitoring (more info ...)successful-recon-limited        URL
7548SPYWARE-PUT Keylogger activity monitor 3.8 runtime detection - agent up notification (more info ...)successful-recon-limited        URL
7549SPYWARE-PUT Keylogger activity monitor 3.8 runtime detection (more info ...)successful-recon-limited        URL
7550SPYWARE-PUT Adware adroar runtime detection (more info ...)misc-activity        URL
7553SPYWARE-PUT Adware hxdl runtime detection - hxlogonly user-agent (more info ...)misc-activity        URL
7554SPYWARE-PUT Adware hxdl runtime detection - hxdownload user-agent (more info ...)misc-activity        URL
7556SPYWARE-PUT Hijacker blazefind runtime detection - search bar (more info ...)misc-activity        URL
7557SPYWARE-PUT Trackware purityscan runtime detection - start up (more info ...)successful-recon-limited        URL
7558SPYWARE-PUT Trackware purityscan runtime detection - installation notify (more info ...)successful-recon-limited        URL
7559SPYWARE-PUT Trackware purityscan runtime detection - track user activity and status (more info ...)successful-recon-limited        URL
7560SPYWARE-PUT Trackware purityscan runtime detection - self update (more info ...)successful-recon-limited        URL
7561SPYWARE-PUT Trackware purityscan runtime detection - opt out of interstitial advertising (more info ...)successful-recon-limited        URL
7562SPYWARE-PUT Adware morpheus runtime detection - ad 1 (more info ...)misc-activity        URL
7563SPYWARE-PUT Adware morpheus runtime detection - ad 2 (more info ...)misc-activity        URL
7564SPYWARE-PUT Hijacker startnow runtime detection (more info ...)misc-activity        URL
7565SPYWARE-PUT Hijacker adshooter.searchforit runtime detection - search engine (more info ...)misc-activity        URL
7566SPYWARE-PUT Hijacker adshooter.searchforit runtime detection - redirector (more info ...)misc-activity        URL
7568SPYWARE-PUT Trackware webhancer runtime detection (more info ...)successful-recon-limited        URL
7569SPYWARE-PUT Adware lordofsearch runtime detection (more info ...)misc-activity        URL
7570SPYWARE-PUT Hijacker linkspider search bar runtime detection - ads (more info ...)misc-activity        URL
7571SPYWARE-PUT Hijacker linkspider search bar runtime detection - toolbar search (more info ...)misc-activity        URL
7572SPYWARE-PUT Trickler album galaxy runtime detection - startup data (more info ...)misc-activity        URL
7573SPYWARE-PUT Trickler album galaxy runtime detection - p2p gnutella (more info ...)misc-activity        URL
7574SPYWARE-PUT Keylogger proagent 2.0 runtime detection (more info ...)successful-recon-limited        URL
7575SPYWARE-PUT Hijacker starware toolbar runtime detection - weather request (more info ...)misc-activity        URL
7576SPYWARE-PUT Hijacker starware toolbar runtime detection - hijack ie browser (more info ...)misc-activity        URL
7577SPYWARE-PUT Hijacker starware toolbar runtime detection - collect information (more info ...)misc-activity        URL
7578SPYWARE-PUT Hijacker starware toolbar runtime detection - reference (more info ...)misc-activity        URL
7579SPYWARE-PUT Hijacker starware toolbar runtime detection - smileys (more info ...)misc-activity        URL
7580SPYWARE-PUT Hijacker starware toolbar runtime detection - update (more info ...)misc-activity        URL
7582SPYWARE-PUT Trickler pcast runtime detection - update checking (more info ...)misc-activity        URL
7583SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set big (more info ...)misc-activity        URL
7584SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set open (more info ...)misc-activity        URL
7585SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set image (more info ...)misc-activity        URL
7586SPYWARE-PUT Hacker-Tool clandestine runtime detection - image transferred (more info ...)misc-activity        URL
7587SPYWARE-PUT Trickler urlblaze runtime detection - software information request (more info ...)misc-activity        URL
7588SPYWARE-PUT Trickler urlblaze runtime detection - files search or download (more info ...)misc-activity        URL
7589SPYWARE-PUT Trickler urlblaze runtime detection - irc notification (more info ...)misc-activity        URL
7590SPYWARE-PUT Hijacker swbar runtime detection (more info ...)misc-activity        URL
7591SPYWARE-PUT Keylogger keylogger pro runtime detection - flowbit set (more info ...)successful-recon-limited        
7592SPYWARE-PUT Keylogger keylogger pro runtime detection (more info ...)successful-recon-limited        URL
7593SPYWARE-PUT Trackware trellian toolbarbrowser runtime detection (more info ...)successful-recon-limited        URL
7594SPYWARE-PUT Adware comedy planet runtime detection - ads (more info ...)misc-activity        URL
7595SPYWARE-PUT Adware comedy planet runtime detection - collect user information (more info ...)misc-activity        URL
7596SPYWARE-PUT Keylogger spy lantern keylogger runtime detection - flowbit set (more info ...)successful-recon-limited        URL
7597SPYWARE-PUT Keylogger spy lantern keylogger runtime detection (more info ...)successful-recon-limited        URL
7598SPYWARE-PUT Snoopware 2-seek runtime detection - search in toolbar (more info ...)successful-recon-limited        URL
7599SPYWARE-PUT Snoopware 2-seek runtime detection - user info collection (more info ...)successful-recon-limited        URL
7600SPYWARE-PUT Hijacker adtraffic runtime detection - notfound website search hijack and redirection (more info ...)misc-activity        URL
7601SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to keyserver (more info ...)successful-recon-limited        URL
7602SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to receiver - flowbit set (more info ...)successful-recon-limited        URL
7603SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to receiver (more info ...)successful-recon-limited        URL
7604BACKDOOR katux 2.0 runtime detection - screen capture - flowbit set (more info ...)trojan-activity        
7605BACKDOOR katux 2.0 runtime detection - screen capture (more info ...)trojan-activity        URL
7606BACKDOOR katux 2.0 runtime detection - get system info - flowbit set (more info ...)trojan-activity        
7607BACKDOOR katux 2.0 runtime detection - get system info (more info ...)trojan-activity        URL
7608BACKDOOR katux 2.0 runtime detection - chat - flowbit set (more info ...)trojan-activity        
7609BACKDOOR katux 2.0 runtime detection - chat (more info ...)trojan-activity        URL
7620BACKDOOR remote control 1.7 runtime detection - connection request flowbit 1 (more info ...)trojan-activity        
7621BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 2 (more info ...)trojan-activity        
7622BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 3 (more info ...)trojan-activity        
7623BACKDOOR remote control 1.7 runtime detection - connection request (more info ...)trojan-activity        URL
7624BACKDOOR remote control 1.7 runtime detection - data communication (more info ...)trojan-activity        URL
7625BACKDOOR skyrat show runtime detection - initial connection - flowbit 1 (more info ...)trojan-activity        
7626BACKDOOR skyrat show runtime detection - initial connection - flowbit 2 (more info ...)trojan-activity        
7627BACKDOOR skyrat show runtime detection - initial connection - flowbit 3 (more info ...)trojan-activity        
7628BACKDOOR skyrat show runtime detection - initial connection - flowbit 4 (more info ...)trojan-activity        
7629BACKDOOR skyrat show runtime detection - initial connection (more info ...)trojan-activity        URL
7630BACKDOOR helios 3.1 runtime detection - initial connection (more info ...)trojan-activity        URL
7631BACKDOOR hornet 1.0 runtime detection - fetch system info - flowbit set (more info ...)trojan-activity        URL
7632BACKDOOR hornet 1.0 runtime detection - fetch system info (more info ...)trojan-activity        URL
7633BACKDOOR hornet 1.0 runtime detection - irc connection - flowbit set (more info ...)trojan-activity        URL
7634BACKDOOR hornet 1.0 runtime detection - irc connection (more info ...)trojan-activity        URL
7635BACKDOOR hornet 1.0 runtime detection - fetch process list - flowbit set (more info ...)trojan-activity        URL
7636BACKDOOR hornet 1.0 runtime detection - fetch processes list (more info ...)trojan-activity        URL
7637BACKDOOR hornet 1.0 runtime detection - icq notification (more info ...)trojan-activity        URL
7638BACKDOOR ncph runtime detection - initial connection (more info ...)trojan-activity        URL
7640BACKDOOR air runtime detection - webmail notification (more info ...)trojan-activity        URL
7641BACKDOOR am remote client runtime detection - client-to-server (more info ...)trojan-activity        URL
7642BACKDOOR am remote client runtime detection - server-to-client (more info ...)trojan-activity        URL
7644BACKDOOR ullysse runtime detection - client-to-server (more info ...)trojan-activity        URL
7645BACKDOOR snipernet 2.1 runtime detection - flowbit set (more info ...)trojan-activity        URL
7646BACKDOOR snipernet 2.1 runtime detection (more info ...)trojan-activity        URL
7648BACKDOOR minicom lite runtime detection - client-to-server (more info ...)trojan-activity        URL
7650BACKDOOR small uploader 1.01 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        
7658BACKDOOR jodeitor 1.1 runtime detection - initial connection (more info ...)trojan-activity        URL
7659BACKDOOR lan filtrator 1.1 runtime detection - sin notification (more info ...)trojan-activity        URL
7660BACKDOOR lan filtrator 1.1 runtime detection - initial connection request - flowbit set (more info ...)trojan-activity        
7661BACKDOOR lan filtrator 1.1 runtime detection - initial connection request (more info ...)trojan-activity        URL
7662BACKDOOR snid x2 v1.2 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        
7663BACKDOOR snid x2 v1.2 runtime detection - initial connection (more info ...)trojan-activity        URL
7664BACKDOOR screen control 1.0 runtime detection - flowbit set (more info ...)trojan-activity        URL
7665BACKDOOR screen control 1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
7667BACKDOOR screen control 1.0 runtime detection - capture on port 2208 (more info ...)trojan-activity        URL
7668BACKDOOR screen control 1.0 runtime detection - capture on port 2213 - flowbit set (more info ...)trojan-activity        URL
7669BACKDOOR screen control 1.0 runtime detection - capture on port 2213 (more info ...)trojan-activity        URL
7670BACKDOOR digital upload runtime detection - initial connection (more info ...)trojan-activity        URL
7671BACKDOOR digital upload runtime detection - chat (more info ...)trojan-activity        URL
7672BACKDOOR remoter runtime detection - initial connection (more info ...)trojan-activity        URL
7673BACKDOOR remote havoc runtime detection - flowbit set 1 (more info ...)trojan-activity        URL
7674BACKDOOR remote havoc runtime detection - flowbit set 2 (more info ...)trojan-activity        URL
7675BACKDOOR remote havoc runtime detection (more info ...)trojan-activity        URL
7676BACKDOOR cool remote control or crackdown runtime detection - initial connection - flowbit set (more info ...)trojan-activity        URL
7677BACKDOOR cool remote control or crackdown runtime detection - initial connection (more info ...)trojan-activity        URL
7678BACKDOOR cool remote control 1.12 runtime detection - upload file - flowbit set (more info ...)trojan-activity        URL
7679BACKDOOR cool remote control 1.12 runtime detection - upload file (more info ...)trojan-activity        URL
7680BACKDOOR cool remote control 1.12 runtime detection - download file - flowbit set (more info ...)trojan-activity        URL
7681BACKDOOR cool remote control 1.12 runtime detection - download file (more info ...)trojan-activity        URL
7682BACKDOOR acid head 1.00 runtime detection - flowbit set (more info ...)trojan-activity        URL
7683BACKDOOR acid head 1.00 runtime detection (more info ...)trojan-activity        URL
7684BACKDOOR hrat 1.0 runtime detection (more info ...)trojan-activity        URL
7685BACKDOOR illusion runtime detection - get remote info client-to-server (more info ...)trojan-activity        URL
7686BACKDOOR illusion runtime detection - get remote info server-to-client (more info ...)trojan-activity        URL
7687BACKDOOR illusion runtime detection - file browser client-to-server (more info ...)trojan-activity        URL
7688BACKDOOR illusion runtime detection - file browser server-to-client (more info ...)trojan-activity        URL
7689BACKDOOR evade runtime detection - initial connection (more info ...)trojan-activity        URL
7690BACKDOOR evade runtime detection - file manager - flowbit set (more info ...)trojan-activity        URL
7691BACKDOOR evade runtime detection - file manager (more info ...)trojan-activity        URL
7692BACKDOOR exception 1.0 runtime detection - notification (more info ...)trojan-activity        URL
7695BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 1 (more info ...)trojan-activity        URL
7696BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 2 (more info ...)trojan-activity        URL
7698BACKDOOR brain wiper runtime detection - launch application - flowbit set (more info ...)trojan-activity        URL
7699BACKDOOR brain wiper runtime detection - launch application (more info ...)trojan-activity        URL
7700BACKDOOR brain wiper runtime detection - chat - flowbit set (more info ...)trojan-activity        URL
7701BACKDOOR brain wiper runtime detection - chat (more info ...)trojan-activity        URL
7702BACKDOOR roach 1.0 runtime detection - remote control actions - flowbit set (more info ...)trojan-activity        
7703BACKDOOR roach 1.0 runtime detection - remote control actions (more info ...)trojan-activity        URL
7704BACKDOOR roach 1.0 server installation notification - email (more info ...)trojan-activity        URL
7705BACKDOOR omniquad instant remote control runtime detection - initial connection - flowbit set (more info ...)trojan-activity        
7706BACKDOOR omniquad instant remote control runtime detection - initial connection (more info ...)trojan-activity        URL
7707BACKDOOR omniquad instant remote control runtime detection - file transfer setup (more info ...)trojan-activity        URL
7708BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        URL
7709BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        URL
7710BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
7711BACKDOOR amitis runtime command detection attacker to victim (more info ...)trojan-activity        URL
7712BACKDOOR amitis runtime detection victim to attacker (more info ...)trojan-activity        URL
7713BACKDOOR amitis v1.3 runtime detection - email notification (more info ...)trojan-activity        URL
7714BACKDOOR netdevil runtime detection - flowbit set 1 (more info ...)trojan-activity        URL
7715BACKDOOR netdevil runtime detection - flowbit set 2 (more info ...)trojan-activity        URL
7716BACKDOOR netdevil runtime detection (more info ...)trojan-activity        URL
7717BACKDOOR snake trojan runtime detection (more info ...)trojan-activity        URL
7718BACKDOOR dameware mini remote control runtime detection - initial connection - flowbit set (more info ...)trojan-activity        URL
7719BACKDOOR dameware mini remote control runtime detection - initial connection (more info ...)trojan-activity        URL
7721BACKDOOR prorat 1.9 initial connection detection (more info ...)trojan-activity        URL
7724BACKDOOR reversable ver1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        
7726BACKDOOR reversable ver1.0 runtime detection - execute command - flowbit set (more info ...)trojan-activity        
7727BACKDOOR reversable ver1.0 runtime detection - execute command (more info ...)trojan-activity        URL
7728BACKDOOR radmin runtime detection - client-to-server (more info ...)trojan-activity        URL
7729BACKDOOR radmin runtime detection - server-to-client (more info ...)trojan-activity        URL
7730BACKDOOR outbreak_0.2.7 runtime detection - reverse connection (more info ...)trojan-activity        URL
7731BACKDOOR outbreak_0.2.7 runtime detection - ring server-to-client (more info ...)trojan-activity        URL
7732BACKDOOR outbreak_0.2.7 runtime detection - ring client-to-server (more info ...)trojan-activity        URL
7733BACKDOOR outbreak_0.2.7 runtime detection - initial connection (more info ...)trojan-activity        URL
7734BACKDOOR bionet 4.05 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        URL
7738BACKDOOR alexmessomalex runtime detection - initial connection (more info ...)trojan-activity        URL
7739BACKDOOR alexmessomalex runtime detection - grab (more info ...)trojan-activity        URL
7740BACKDOOR nova 1.0 runtime detection - initial connection with pwd set - flowbit set (more info ...)trojan-activity        URL
7744BACKDOOR phoenix 2.1 runtime detection - flowbit set (more info ...)trojan-activity        
7745BACKDOOR phoenix 2.1 runtime detection (more info ...)trojan-activity        URL
7746BACKDOOR bobo 1.0 runtime detection - initial connection - flowbit set (more info ...)trojan-activity        
7747BACKDOOR bobo 1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
7748BACKDOOR bobo 1.0 runtime detection - send message - flowbit set (more info ...)trojan-activity        
7749BACKDOOR bobo 1.0 runtime detection - send message (more info ...)trojan-activity        URL
7750BACKDOOR buschtrommel 1.22 runtime detection - initial connection - flowbit set 1 (more info ...)trojan-activity        
7751BACKDOOR buschtrommel 1.22 runtime detection - initial connection - flowbit set 2 (more info ...)trojan-activity        
7752BACKDOOR buschtrommel 1.22 runtime detection - initial connection (more info ...)trojan-activity        URL
7753BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 1 (more info ...)trojan-activity        
7754BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 2 (more info ...)trojan-activity        
7755BACKDOOR buschtrommel 1.22 runtime detection - spy function (more info ...)trojan-activity        URL
7758BACKDOOR glacier runtime detection - initial connection and directory browse (more info ...)trojan-activity        URL
7759BACKDOOR glacier runtime detection - screen capture (more info ...)trojan-activity        URL
7760BACKDOOR netthief runtime detection (more info ...)trojan-activity        URL
7763BACKDOOR nt remote controller 2000 runtime detection - services client-to-server (more info ...)trojan-activity        URL
7764BACKDOOR nt remote controller 2000 runtime detection - sysinfo client-to-server (more info ...)trojan-activity        URL
7765BACKDOOR nt remote controller 2000 runtime detection - sysinfo server-to-client (more info ...)trojan-activity        URL
7766BACKDOOR nt remote controller 2000 runtime detection - foldermonitor client-to-server (more info ...)trojan-activity        URL
7767BACKDOOR nt remote controller 2000 runtime detection - foldermonitor server-to-client (more info ...)trojan-activity        URL
7770BACKDOOR messiah 4.0 runtime detection - get server info - flowbit set (more info ...)trojan-activity        
7771BACKDOOR messiah 4.0 runtime detection - get server info (more info ...)trojan-activity        URL
7772BACKDOOR messiah 4.0 runtime detection - enable keylogger - flowbit set (more info ...)trojan-activity        
7773BACKDOOR messiah 4.0 runtime detection - enable keylogger (more info ...)trojan-activity        URL
7774BACKDOOR messiah 4.0 runtime detection - screen capture - flowbit set (more info ...)trojan-activity        
7775BACKDOOR messiah 4.0 runtime detection - screen capture (more info ...)trojan-activity        URL
7776BACKDOOR messiah 4.0 runtime detection - get drives - flowbit set (more info ...)trojan-activity        
7777BACKDOOR messiah 4.0 runtime detection - get drives (more info ...)trojan-activity        URL
7778BACKDOOR elfrat runtime detection - initial connection (more info ...)trojan-activity        URL
7782BACKDOOR netdevil runtime detection - file manager - flowbit set (more info ...)trojan-activity        URL
7783BACKDOOR netdevil runtime detection - file manager (more info ...)trojan-activity        URL
7791BACKDOOR remote anything 5.11.22 runtime detection - victim response (more info ...)trojan-activity        URL
7792BACKDOOR remote anything 5.11.22 runtime detection - chat with victim (more info ...)trojan-activity        URL
7793BACKDOOR remote anything 5.11.22 runtime detection - chat with attacker (more info ...)trojan-activity        URL
7794BACKDOOR fraggle rock 2.0 lite runtime detection - pc info - flowbit set (more info ...)trojan-activity        URL
7795BACKDOOR incommand 1.7 runtime detection - init connection (more info ...)trojan-activity        
7796BACKDOOR incommand 1.7 runtime detection - init connection (more info ...)trojan-activity        URL
7797BACKDOOR incommand 1.7 runtime detection - file manage 1 (more info ...)trojan-activity        
7798BACKDOOR incommand 1.7 runtime detection - file manage 1 (more info ...)trojan-activity        URL
7799BACKDOOR incommand 1.7 runtime detection - file manage 2 (more info ...)trojan-activity        
7800BACKDOOR incommand 1.7 runtime detection - file manage 2 (more info ...)trojan-activity        URL
7801BACKDOOR portal of doom runtime detection - udp cts (more info ...)trojan-activity        URL
7802BACKDOOR portal of doom runtime detection - udp stc (more info ...)trojan-activity        URL
7803BACKDOOR war trojan ver1.0 runtime detection - send messages (more info ...)trojan-activity        URL
7804BACKDOOR war trojan ver1.0 runtime detection - disable ctrl+alt+del (more info ...)trojan-activity        URL
7805BACKDOOR war trojan ver1.0 runtime detection - ie hijacker (more info ...)trojan-activity        URL
7806BACKDOOR fatal wound 1.0 runtime detection - initial connection (more info ...)trojan-activity        URL
7807BACKDOOR fatal wound 1.0 runtime detection - execute file (more info ...)trojan-activity        URL
7808BACKDOOR fatal wound 1.0 runtime detection - upload (more info ...)trojan-activity        URL
7809BACKDOOR fatal wound 1.0 runtime detection - upload (more info ...)trojan-activity        URL
7811BACKDOOR abacab runtime detection - telnet initial (more info ...)trojan-activity        URL
7812BACKDOOR abacab runtime detection - banner (more info ...)trojan-activity        URL
7813BACKDOOR darkmoon initial connection detection - cts (more info ...)trojan-activity        URL
7814BACKDOOR darkmoon initial connection detection - stc (more info ...)trojan-activity        URL
7815BACKDOOR darkmoon reverse connection detection - stc (more info ...)trojan-activity        URL
7816BACKDOOR darkmoon reverse connection detection - cts (more info ...)trojan-activity        URL
7817BACKDOOR infector v1.0 runtime detection - init conn (more info ...)trojan-activity        URL
7818BACKDOOR infector v1.0 runtime detection - init conn (more info ...)trojan-activity        URL
7822BACKDOOR xbkdr runtime detection (more info ...)trojan-activity        URL
7823SPYWARE-PUT Adware whenu runtime detection - datachunksgz (more info ...)misc-activity        URL
7824SPYWARE-PUT Trickler whenu.clocksync runtime detection (more info ...)misc-activity        URL
7825SPYWARE-PUT Adware whenu.savenow runtime detection (more info ...)misc-activity        URL
7826SPYWARE-PUT Trickler whenu.weathercast runtime detection - check (more info ...)misc-activity        URL
7827SPYWARE-PUT Adware whenu runtime detection - search request 1 (more info ...)misc-activity        URL
7828SPYWARE-PUT Adware whenu runtime detection - search request 2 (more info ...)misc-activity        URL
7829SPYWARE-PUT Adware gator user-agent detected (more info ...)misc-activity        URL
7830SPYWARE-PUT Botnet dacryptic runtime detection (more info ...)trojan-activity        URL
7831SPYWARE-PUT Adware downloadplus runtime detection (more info ...)misc-activity        URL
7834SPYWARE-PUT Hacker-Tool nettracker runtime detection - report browsing (more info ...)misc-activity        
7835SPYWARE-PUT Hacker-Tool nettracker runtime detection - report browsing (more info ...)misc-activity        URL
7836SPYWARE-PUT Hacker-Tool nettracker runtime detection - report send through email (more info ...)misc-activity        URL
7837SPYWARE-PUT Keylogger spyoutside runtime detection - email delivery (more info ...)successful-recon-limited        URL
7838SPYWARE-PUT Adware smiley central runtime detection (more info ...)misc-activity        URL
7839SPYWARE-PUT Hijacker rx toolbar runtime detection (more info ...)misc-activity        URL
7840SPYWARE-PUT Hijacker instafinder initial configuration detection (more info ...)misc-activity        URL
7841SPYWARE-PUT Hijacker instafinder error redirect detection (more info ...)misc-activity        URL
7842SPYWARE-PUT Hacker-Tool davps runtime detection (more info ...)misc-activity        URL
7843SPYWARE-PUT Hijacker avenuemedia.dyfuca runtime detection - search engine hijack (more info ...)misc-activity        URL
7844SPYWARE-PUT Hijacker avenuemedia.dyfuca runtime detection - post data (more info ...)misc-activity        URL
7845SPYWARE-PUT Keylogger clogger 1.0 runtime detection (more info ...)successful-recon-limited        
7846SPYWARE-PUT Keylogger clogger 1.0 runtime detection (more info ...)successful-recon-limited        
7847SPYWARE-PUT Keylogger clogger 1.0 runtime detection - send log through email (more info ...)successful-recon-limited        URL
7848SPYWARE-PUT Hijacker netguide runtime detection (more info ...)misc-activity        URL
7849SPYWARE-PUT Trickler maxsearch runtime detection - toolbar download (more info ...)misc-activity        URL
7850SPYWARE-PUT Trickler maxsearch runtime detection - retrieve command (more info ...)misc-activity        URL
7851SPYWARE-PUT Trickler maxsearch runtime detection - ack (more info ...)misc-activity        URL
7852SPYWARE-PUT Trickler maxsearch runtime detection - advertisement (more info ...)misc-activity        URL
7853SPYWARE-PUT Adware web-nexus runtime detection - ad url 1 (more info ...)misc-activity        URL
7854SPYWARE-PUT Adware web-nexus runtime detection - config retrieval (more info ...)misc-activity        URL
7855SPYWARE-PUT Adware web-nexus runtime detection - ad url 2 (more info ...)misc-activity        URL
7857SPYWARE-PUT Keylogger EliteKeylogger runtime detection (more info ...)successful-recon-limited        URL
8056DOS ISC DHCP server 2 client_id length denial of service attempt (more info ...)attempted-dos  2006-3122      URL
8071SPYWARE-PUT Hijacker findthewebsiteyouneed runtime detection - search hijack (more info ...)misc-activity        URL
8072SPYWARE-PUT Hijacker findthewebsiteyouneed runtime detection - surf monitor (more info ...)misc-activity        URL
8073SPYWARE-PUT Adware zango toolbar runtime detection (more info ...)misc-activity        URL
8074BACKDOOR mithril runtime detection - init connection (more info ...)trojan-activity        URL
8075BACKDOOR mithril runtime detection - get system information (more info ...)trojan-activity        URL
8076BACKDOOR mithril runtime detection - get system information (more info ...)trojan-activity        URL
8077BACKDOOR mithril runtime detection - get process list (more info ...)trojan-activity        URL
8078BACKDOOR mithril runtime detection - get process list (more info ...)trojan-activity        URL
8079BACKDOOR x2a runtime detection - init connection (more info ...)trojan-activity        URL
8080BACKDOOR x2a runtime detection - client update (more info ...)trojan-activity        URL
8350WEB-CLIENT pub file download (more info ...)misc-activity  2006-0001  19951    URL
8352SPYWARE-PUT Adware desktopmedia runtime detection - ads popup (more info ...)misc-activity        URL
8353SPYWARE-PUT Adware desktopmedia runtime detection - auto update (more info ...)misc-activity        URL
8354SPYWARE-PUT Adware desktopmedia runtime detection - surf monitoring (more info ...)misc-activity        URL
8355SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection (more info ...)successful-recon-limited        
8356SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection - send log out through email (more info ...)successful-recon-limited        URL
8357SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection - send alert out through email (more info ...)successful-recon-limited        URL
8359SPYWARE-PUT Hijacker yok supersearch runtime detection - target website display (more info ...)misc-activity        URL
8360SPYWARE-PUT Hijacker yok supersearch runtime detection - search info collect (more info ...)misc-activity        URL
8361BACKDOOR black curse 4.0 runtime detection - inverse init connection (more info ...)trojan-activity        URL
8362BACKDOOR black curse 4.0 runtime detection - normal init connection (more info ...)trojan-activity        URL
8416WEB-CLIENT VML fill method overflow attempt (more info ...)attempted-user  2006-4868  20096    URL
8445WEB-CLIENT RTF file with embedded object package download attempt (more info ...)misc-activity  2006-4692      URL
8461SPYWARE-PUT Trackware duduaccelerator runtime detection - send userinfo (more info ...)successful-recon-limited        URL
8462SPYWARE-PUT Trackware duduaccelerator runtime detection - trace info downloaded (more info ...)successful-recon-limited        URL
8463SPYWARE-PUT Trackware duduaccelerator runtime detection - trace login info (more info ...)successful-recon-limited        URL
8464SPYWARE-PUT Adware henbang runtime detection (more info ...)misc-activity        URL
8465SPYWARE-PUT Keylogger netobserve runtime detection - email notification (more info ...)successful-recon-limited        URL
8466SPYWARE-PUT Keylogger netobserve runtime detection - email notification (more info ...)successful-recon-limited        URL
8467SPYWARE-PUT Keylogger netobserve runtime detection - remote login response (more info ...)successful-recon-limited        URL
8468SPYWARE-PUT Hijacker accoona runtime detection - collect info (more info ...)misc-activity        URL
8469SPYWARE-PUT Hijacker accoona runtime detection - open sidebar search url (more info ...)misc-activity        URL
8542SPYWARE-PUT Trackware deluxecommunications runtime detection - collect info (more info ...)successful-recon-limited        URL
8543SPYWARE-PUT Trackware deluxecommunications runtime detection - display popup ads (more info ...)successful-recon-limited        URL
8545SPYWARE-PUT Adware roogoo runtime detection - surfing monitor (more info ...)misc-activity        URL
8546SPYWARE-PUT Adware roogoo runtime detection - show ads (more info ...)misc-activity        URL
8547BACKDOOR zzmm 2.0 runtime detection - init connection (more info ...)trojan-activity        
8548BACKDOOR zzmm 2.0 runtime detection - init connection (more info ...)trojan-activity        URL
8549BACKDOOR zxshell runtime detection - setting information retrieve (more info ...)trojan-activity        URL
8730DOS record route rr denial of service attempt (more info ...)attempted-dos  2001-0752  870    
9339SPECIFIC-THREATS klez.g web propagation detection (more info ...)trojan-activity        URL
9340SPECIFIC-THREATS klez.i web propagation detection (more info ...)trojan-activity        URL
9346SPECIFIC-THREATS klez.b web propagation detection (more info ...)trojan-activity        URL
9347SPECIFIC-THREATS klez.b netshare propagation detection (more info ...)trojan-activity        URL
9351SPECIFIC-THREATS lovgate.a netshare propagation detection (more info ...)trojan-activity        URL
9353SPECIFIC-THREATS deborm.x netshare propagation detection (more info ...)trojan-activity        URL
9354SPECIFIC-THREATS deborm.y netshare propagation detection (more info ...)trojan-activity        URL
9355SPECIFIC-THREATS deborm.u netshare propagation detection (more info ...)trojan-activity        URL
9356SPECIFIC-THREATS deborm.q netshare propagation detection (more info ...)trojan-activity        URL
9357SPECIFIC-THREATS deborm.r netshare propagation detection (more info ...)trojan-activity        URL
9363SPECIFIC-THREATS klez.d web propagation detection (more info ...)trojan-activity        URL
9364SPECIFIC-THREATS klez.e web propagation detection (more info ...)trojan-activity        URL
9387SPECIFIC-THREATS klez.j web propagation detection (more info ...)trojan-activity        URL
9390SPECIFIC-THREATS deborm.d netshare propagation detection (more info ...)trojan-activity        URL
9395SPECIFIC-THREATS deborm.j netshare propagation detection (more info ...)trojan-activity        URL
9396SPECIFIC-THREATS deborm.t netshare propagation detection (more info ...)trojan-activity        URL
9401SPECIFIC-THREATS gokar http propagation detectiot (more info ...)trojan-activity        URL
9407SPECIFIC-THREATS lovgate.b netshare propagation detection (more info ...)trojan-activity        URL
9412SPECIFIC-THREATS sinmsn.b msn propagation detection (more info ...)trojan-activity        URL
9418BOTNET-CNC bagle.a http notification detection (more info ...)trojan-activity        URL
9419SPECIFIC-THREATS sasser attempt (more info ...)trojan-activity  2003-0533  10108  12205  URL
9420SPECIFIC-THREATS korgo attempt (more info ...)trojan-activity  2003-0533  10108  12205  URL
9421SPECIFIC-THREATS zotob attempt (more info ...)trojan-activity  2005-1983  14513    URL
9422SPECIFIC-THREATS msblast attempt (more info ...)trojan-activity  2003-0352  8205    URL
9423SPECIFIC-THREATS lovegate attempt (more info ...)trojan-activity  2003-0352  8205    URL
9424SPECIFIC-THREATS /winnt/explorer.exe unicode klez infection attempt attempt (more info ...)trojan-activity        
9425SPECIFIC-THREATS netsky attachment (more info ...)trojan-activity        
9426SPECIFIC-THREATS mydoom.ap attachment (more info ...)trojan-activity        
9434WEB-CLIENT Ultravox-Max-Msg header integer overflow attempt (more info ...)attempted-user  2006-5567  20744    URL
9619WEB-CLIENT Gnu gv buffer overflow attempt (more info ...)attempted-user  2006-5864  20978    
9639WEB-CLIENT Windows Address Book download attempt (more info ...)attempted-user  2006-2386      URL
9644SPYWARE-PUT Adware imnames runtime detection (more info ...)misc-activity        URL
9646SPYWARE-PUT Hijacker sogou runtime detection - search through sogou toolbar (more info ...)misc-activity        URL
9647SPYWARE-PUT Keylogger system surveillance pro runtime detection (more info ...)successful-recon-limited        URL
9648SPYWARE-PUT Keylogger emailspypro runtime detection (more info ...)successful-recon-limited        URL
9649SPYWARE-PUT Keylogger ghost Keylogger runtime detection - flowbit set (more info ...)successful-recon-limited        URL
9650SPYWARE-PUT Keylogger ghost Keylogger runtime detection (more info ...)successful-recon-limited        URL
9651SPYWARE-PUT Hijacker ricercadoppia runtime detection (more info ...)misc-activity        URL
9652SPYWARE-PUT Hijacker oemji bar runtime detection (more info ...)misc-activity        URL
9654BACKDOOR apofis 1.0 runtime detection - remote controlling (more info ...)trojan-activity        
9655BACKDOOR apofis 1.0 runtime detection - remote controlling (more info ...)trojan-activity        URL
9656BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity        
9657BACKDOOR bersek 1.0 runtime detection - init connection (more info ...)trojan-activity        URL
9658BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity        
9659BACKDOOR bersek 1.0 runtime detection - file manage (more info ...)trojan-activity        URL
9660BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity        
9661BACKDOOR bersek 1.0 runtime detection - show processes (more info ...)trojan-activity        URL
9662BACKDOOR bersek 1.0 runtime detection (more info ...)trojan-activity        
9663BACKDOOR bersek 1.0 runtime detection - start remote shell (more info ...)trojan-activity        URL
9664BACKDOOR crossbow 1.12 runtime detection (more info ...)trojan-activity        
9665BACKDOOR crossbow 1.12 runtime detection - init connection (more info ...)trojan-activity        URL
9666BACKDOOR superra runtime detection - success init connection (more info ...)trojan-activity        
9667BACKDOOR superra runtime detection - issue remote control command (more info ...)trojan-activity        
9830SPYWARE-PUT Keylogger supreme spy runtime detection (more info ...)successful-recon-limited        URL
9831SPYWARE-PUT Adware u88 runtime detection (more info ...)misc-activity        URL
9832BACKDOOR ieva 1.0 runtime detection - send message (more info ...)trojan-activity        URL
9833BACKDOOR ieva 1.0 runtime detection - fake delete harddisk message (more info ...)trojan-activity        URL
9834BACKDOOR ieva 1.0 runtime detection - black screen (more info ...)trojan-activity        URL
9835BACKDOOR ieva 1.0 runtime detection - swap mouse (more info ...)trojan-activity        URL
9836BACKDOOR ieva 1.0 runtime detection - crazy mouse (more info ...)trojan-activity        URL
9837BACKDOOR sun shadow 1.70 runtime detection - init connection (more info ...)trojan-activity        
9838BACKDOOR sun shadow 1.70 runtime detection - init connection (more info ...)trojan-activity        URL
9839BACKDOOR sun shadow 1.70 runtime detection - keep alive (more info ...)trojan-activity        URL
9844WEB-CLIENT VLC Media Player udp URI format string attempt - single packet (more info ...)attempted-user  2007-0017  21852    URL
9845WEB-CLIENT M3U File Download Detected (more info ...)misc-activity        
9846WEB-CLIENT VLC Media Player udp URI format string attempt - multipacket (more info ...)attempted-user  2007-0017  21852    URL
9848WEB-CLIENT Vector Markup Language recolorinfo tag numfills parameter buffer overflow attempt (more info ...)attempted-user  2007-0024      URL
9849WEB-CLIENT Vector Markup Language recolorinfo tag numcolors parameter buffer overflow attempt (more info ...)attempted-user  2007-0024      URL
10063WEB-CLIENT Firefox query interface suspicious function call access attempt (more info ...)attempted-user  2006-0295  16476    URL
10090SPYWARE-PUT Trickler zango easymessenger runtime detection (more info ...)misc-activity        URL
10091SPYWARE-PUT Hacker-Tool spylply.a runtime detection (more info ...)misc-activity        URL
10092SPYWARE-PUT Trackware russian searchbar runtime detection (more info ...)successful-recon-limited        URL
10093SPYWARE-PUT Hijacker kuaiso toolbar runtime detection (more info ...)misc-activity        URL
10094SPYWARE-PUT Adware borlan runtime detection (more info ...)misc-activity        URL
10095SPYWARE-PUT Trackware bydou runtime detection (more info ...)successful-recon-limited        URL
10096SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection - keylog (more info ...)successful-recon-limited        URL
10097SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection (more info ...)successful-recon-limited        
10098SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection - get system info (more info ...)successful-recon-limited        URL
10099SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection (more info ...)successful-recon-limited        
10100SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection - open website (more info ...)successful-recon-limited        URL
10101BACKDOOR crossfires trojan 3.0 runtime detection - delete file (more info ...)trojan-activity        URL
10102BACKDOOR crossfires trojan 3.0 runtime detection - chat with victim (more info ...)trojan-activity        URL
10103BACKDOOR hav-rat 1.1 runtime detection (more info ...)trojan-activity        
10104BACKDOOR hav-rat 1.1 runtime detection (more info ...)trojan-activity        
10105BACKDOOR hav-rat 1.1 runtime detection - retrieve pc info (more info ...)trojan-activity        URL
10109BACKDOOR k-msnrat 1.0.0 runtime detection - init connection (more info ...)trojan-activity        URL
10110BACKDOOR poison ivy 2.1.2 runtime detection (more info ...)trojan-activity        
10111BACKDOOR poison ivy 2.1.2 runtime detection - init connection (more info ...)trojan-activity        URL
10112BACKDOOR rix3 1.0 runtime detection - init connection (more info ...)trojan-activity        URL
10113BOTNET-CNC Trojan Peacomm command and control propagation detected (more info ...)trojan-activity        
10114BOTNET-CNC Trojan Peacomm command and control propagation detected (more info ...)trojan-activity        
10116WEB-CLIENT AIM GoChat URL access attempt (more info ...)misc-attack  2007-0021  22146    URL
10164SPYWARE-PUT Adware adclicker-ej runtime detection (more info ...)misc-activity        URL
10165SPYWARE-PUT Keylogger mybr Keylogger runtime detection (more info ...)successful-recon-limited        URL
10166SPYWARE-PUT Trackware baigoo runtime detection (more info ...)successful-recon-limited        URL
10168BACKDOOR one runtime detection (more info ...)trojan-activity        URL
10169BACKDOOR matrix 1.03 by mtronic runtime detection - init connection (more info ...)trojan-activity        URL
10179SPYWARE-PUT Trackware bysoo runtime detection (more info ...)successful-recon-limited        URL
10180SPYWARE-PUT Adware eqiso runtime detection (more info ...)misc-activity        URL
10181SPYWARE-PUT Keylogger systemsleuth runtime detection (more info ...)successful-recon-limited        URL
10182SPYWARE-PUT Adware newweb runtime detection (more info ...)misc-activity        URL
10183SPYWARE-PUT Keylogger activity Keylogger runtime detection (more info ...)successful-recon-limited        URL
10184BACKDOOR wow 23 runtime detection (more info ...)trojan-activity        URL
10187EXPLOIT HP Mercury Loadrunner command line buffer overflow (