|
| 2419 | MULTIMEDIA realplayer .ram playlist download attempt (more info ...) | misc-activity | | | | |
| 2420 | MULTIMEDIA realplayer .rmp playlist download attempt (more info ...) | misc-activity | | | | |
| 2421 | MULTIMEDIA realplayer .smi playlist download attempt (more info ...) | misc-activity | | | | |
| 2422 | MULTIMEDIA realplayer .rt playlist download attempt (more info ...) | misc-activity | | | | |
| 2423 | MULTIMEDIA realplayer .rp playlist download attempt (more info ...) | misc-activity | | | | |
| 2520 | WEB-MISC SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 2521 | WEB-MISC SSLv3 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 2527 | SMTP STARTTLS attempt (more info ...) | protocol-command-decode | | | | |
| 2529 | IMAP SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 2530 | IMAP SSLv3 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 2535 | POP3 SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 2536 | POP3 SSLv3 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 2542 | SMTP SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 2543 | SMTP SSLv3 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 2658 | WEB-MISC SSLv2 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 2659 | WEB-MISC SSLv2 Client_Hello with pad request (more info ...) | protocol-command-decode | | | | |
| 2660 | WEB-MISC SSLv2 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 2661 | WEB-MISC TLSv1 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 2662 | WEB-MISC TLSv1 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 2706 | WEB-CLIENT JPEG transfer (more info ...) | protocol-command-decode | | | | |
| 3009 | BACKDOOR NetBus Pro 2.0 connection request (more info ...) | misc-activity | | | | |
| 3013 | BACKDOOR Asylum 0.1 connection request (more info ...) | misc-activity | | | | |
| 3059 | WEB-MISC TLSv1 Client_Hello via SSLv2 handshake request (more info ...) | protocol-command-decode | | | | |
| 3063 | BACKDOOR Vampire 1.2 connection request (more info ...) | misc-activity | | | | |
| 3081 | BACKDOOR Y3KRAT 1.5 Connect (more info ...) | misc-activity | | | | |
| 3082 | BACKDOOR Y3KRAT 1.5 Connect Client Response (more info ...) | misc-activity | | | | |
| 3135 | NETBIOS SMB Trans2 QUERY_FILE_INFO attempt (more info ...) | protocol-command-decode | | | | |
| 3136 | NETBIOS SMB Trans2 QUERY_FILE_INFO andx attempt (more info ...) | protocol-command-decode | | | | |
| 3137 | NETBIOS SMB-DS Trans2 QUERY_FILE_INFO attempt (more info ...) | protocol-command-decode | | | | |
| 3138 | NETBIOS SMB-DS Trans2 QUERY_FILE_INFO andx attempt (more info ...) | protocol-command-decode | | | | |
| 3139 | NETBIOS SMB Trans2 FIND_FIRST2 attempt (more info ...) | protocol-command-decode | | | | |
| 3140 | NETBIOS SMB Trans2 FIND_FIRST2 andx attempt (more info ...) | protocol-command-decode | | | | |
| 3141 | NETBIOS SMB-DS Trans2 FIND_FIRST2 attempt (more info ...) | protocol-command-decode | | | | |
| 3142 | NETBIOS SMB-DS Trans2 FIND_FIRST2 andx attempt (more info ...) | protocol-command-decode | | | | |
| 3487 | IMAP SSLv2 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 3488 | IMAP SSLv2 Client_Hello with pad request (more info ...) | protocol-command-decode | | | | |
| 3489 | IMAP TLSv1 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 3490 | IMAP TLSv1 Client_Hello via SSLv2 handshake request (more info ...) | protocol-command-decode | | | | |
| 3491 | IMAP SSLv2 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 3492 | IMAP TLSv1 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 3493 | SMTP SSLv2 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 3494 | SMTP SSLv2 Client_Hello with pad request (more info ...) | protocol-command-decode | | | | |
| 3495 | SMTP TLSv1 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 3496 | SMTP TLSv1 Client_Hello via SSLv2 handshake request (more info ...) | protocol-command-decode | | | | |
| 3497 | SMTP SSLv2 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 3498 | SMTP TLSv1 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 3499 | POP3 SSLv2 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 3500 | POP3 SSLv2 Client_Hello with pad request (more info ...) | protocol-command-decode | | | | |
| 3501 | POP3 TLSv1 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 3502 | POP3 TLSv1 Client_Hello via SSLv2 handshake request (more info ...) | protocol-command-decode | | | | |
| 3503 | POP3 SSLv2 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 3504 | POP3 TLSv1 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 3535 | WEB-CLIENT GIF transfer (more info ...) | protocol-command-decode | | | | |
| 3551 | WEB-CLIENT .hta download attempt (more info ...) | not-suspicious | | | | |
| 3633 | WEB-CLIENT bitmap transfer (more info ...) | protocol-command-decode | | | | |
| 3665 | MYSQL server greeting (more info ...) | attempted-user | 2004-0627 | 10655 | 12639 | URL |
| 3666 | MYSQL server greeting finished (more info ...) | attempted-user | 2004-0627 | 10655 | 12639 | URL |
| 3819 | WEB-CLIENT multipacket CHM file transfer start (more info ...) | protocol-command-decode | | | | |
| 3822 | WEB-MISC Real Player realtext long URI request (more info ...) | protocol-command-decode | | | | |
| 4143 | EXPLOIT lpd receive printer job cascade adaptor protocol request (more info ...) | protocol-command-decode | | | | |
| 4194 | WEB-CLIENT multipacket CBO CBL CBM file transfer start (more info ...) | protocol-command-decode | | | | |
| 4678 | WEB-CLIENT quicktime movie file transfer (more info ...) | protocol-command-decode | | | | |
| 5685 | SMTP TLSv1 Client_Hello via SSLv2 handshake request (more info ...) | protocol-command-decode | | | | |
| 5686 | SMTP TLSv1 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 5687 | SMTP SSLv2 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 5688 | SMTP SSLv2 Client_Hello with pad request (more info ...) | protocol-command-decode | | | | |
| 5689 | SMTP TLSv1 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 5690 | SMTP SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 5691 | SMTP SSLv2 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 5740 | WEB-CLIENT Microsoft HTML help workshop file .hhp download attempt (more info ...) | misc-activity | | | | |
| 5771 | SPYWARE-PUT Screen-Scraper farsighter runtime detection - initial connection (more info ...) | successful-recon-limited | | | | URL |
| 5813 | SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - create redirection (more info ...) | misc-activity | | | | |
| 5815 | SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory redirection (more info ...) | misc-activity | | | | |
| 5817 | SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status (more info ...) | misc-activity | | | | |
| 5818 | SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - check status (more info ...) | misc-activity | | | | |
| 5820 | SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - destory log (more info ...) | misc-activity | | | | |
| 5822 | SPYWARE-PUT Hacker-Tool stealthredirector runtime detection - view netstat (more info ...) | misc-activity | | | | |
| 5873 | SPYWARE-PUT Snoopware pc acme pro runtime detection (more info ...) | successful-recon-limited | | | | URL |
| 5895 | SPYWARE-PUT Hacker-Tool timbuktu pro runtime detection - tcp port 407 (more info ...) | misc-activity | | | | |
| 5957 | SPYWARE-PUT Hacker-Tool ghostvoice 1.02 runtime detection (more info ...) | misc-activity | | | | |
| 6010 | EXPLOIT VERITAS NetBackup vnetd connection attempt (more info ...) | protocol-command-decode | | | | |
| 6012 | BACKDOOR coolcat runtime connection detection - tcp 1 (more info ...) | trojan-activity | | | | URL |
| 6013 | BACKDOOR coolcat runtime connection detection - tcp 2 (more info ...) | trojan-activity | | | | URL |
| 6015 | BACKDOOR dsk lite 1.0 runtime detection - initial connection (more info ...) | trojan-activity | | | | URL |
| 6030 | BACKDOOR fkwp 2.0 runtime detection - connection attempt client-to-server (more info ...) | trojan-activity | | | | URL |
| 6034 | BACKDOOR minicommand runtime detection - initial connection client-to-server (more info ...) | trojan-activity | | | | URL |
| 6040 | BACKDOOR fade 1.0 runtime detection - enable keylogger (more info ...) | trojan-activity | | | | URL |
| 6044 | BACKDOOR fear 0.2 runtime detection - initial connection (more info ...) | trojan-activity | | | | URL |
| 6045 | BACKDOOR fear 0.2 runtime detection - initial connection (more info ...) | trojan-activity | | | | URL |
| 6047 | BACKDOOR fun factory runtime detection - connect (more info ...) | trojan-activity | | | | URL |
| 6049 | BACKDOOR fun factory runtime detection - upload (more info ...) | trojan-activity | | | | URL |
| 6051 | BACKDOOR fun factory runtime detection - set volume (more info ...) | trojan-activity | | | | URL |
| 6053 | BACKDOOR fun factory runtime detection - do script remotely (more info ...) | trojan-activity | | | | URL |
| 6055 | BACKDOOR bifrose 1.1 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6056 | BACKDOOR bifrose 1.1 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6060 | BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...) | trojan-activity | | | | URL |
| 6061 | BACKDOOR neurotickat1.3 runtime detection - initial connection (more info ...) | trojan-activity | | | | URL |
| 6063 | BACKDOOR schwindler 1.82 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6065 | BACKDOOR optixlite 1.0 runtime detection - connection success client-to-server (more info ...) | trojan-activity | | | | URL |
| 6072 | BACKDOOR freak 1.0 runtime detection - initial connection client-to-server (more info ...) | trojan-activity | | | | URL |
| 6074 | BACKDOOR xhx 1.6 runtime detection - initial connection client-to-server (more info ...) | trojan-activity | | | | URL |
| 6077 | BACKDOOR autospy runtime detection - get information (more info ...) | trojan-activity | | | | |
| 6079 | BACKDOOR autospy runtime detection - show autospy (more info ...) | trojan-activity | | | | |
| 6081 | BACKDOOR autospy runtime detection - show nude pic (more info ...) | trojan-activity | | | | |
| 6083 | BACKDOOR autospy runtime detection - hide taskbar (more info ...) | trojan-activity | | | | |
| 6085 | BACKDOOR autospy runtime detection - make directory (more info ...) | trojan-activity | | | | |
| 6087 | BACKDOOR a trojan 2.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6089 | BACKDOOR a trojan 2.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6091 | BACKDOOR a trojan 2.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6093 | BACKDOOR a trojan 2.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6095 | BACKDOOR a trojan 2.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6097 | BACKDOOR alvgus 2000 runtime detection (more info ...) | trojan-activity | | | | |
| 6099 | BACKDOOR alvgus 2000 runtime detection (more info ...) | trojan-activity | | | | |
| 6101 | BACKDOOR alvgus 2000 runtime detection (more info ...) | trojan-activity | | | | |
| 6103 | BACKDOOR alvgus 2000 runtime detection (more info ...) | trojan-activity | | | | |
| 6105 | BACKDOOR alvgus 2000 runtime detection (more info ...) | trojan-activity | | | | |
| 6108 | BACKDOOR dagger v1.1.40 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6111 | BACKDOOR optix 1.32 runtime detection - init conn (more info ...) | trojan-activity | | | | URL |
| 6112 | BACKDOOR optix 1.32 runtime detection - init conn (more info ...) | trojan-activity | | | | URL |
| 6116 | BACKDOOR fore v1.0 beta runtime detection - init conn (more info ...) | trojan-activity | | | | URL |
| 6118 | BACKDOOR net runner runtime detection - initial connection client-to-server (more info ...) | trojan-activity | | | | URL |
| 6120 | BACKDOOR net runner runtime detection - download file client-to-server (more info ...) | trojan-activity | | | | URL |
| 6123 | BACKDOOR ambush 1.0 runtime detection - ping client-to-server (more info ...) | trojan-activity | | | | URL |
| 6125 | BACKDOOR dkangel runtime detection - smtp (more info ...) | trojan-activity | | | | URL |
| 6129 | BACKDOOR chupacabra 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6131 | BACKDOOR chupacabra 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 6140 | BACKDOOR hellzaddiction v1.0e runtime detection - init conn (more info ...) | trojan-activity | | | | URL |
| 6144 | BACKDOOR mantis runtime detection - sent notify option client-to-server 1 (more info ...) | trojan-activity | | | | URL |
| 6145 | BACKDOOR mantis runtime detection - sent notify option server-to-client (more info ...) | trojan-activity | | | | URL |
| 6147 | BACKDOOR mantis runtime detection - go to address client-to-server (more info ...) | trojan-activity | | | | URL |
| 6149 | BACKDOOR netcontrol v1.0.8 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6152 | BACKDOOR dirtxt runtime detection - chdir client-to-server (more info ...) | trojan-activity | | | | URL |
| 6154 | BACKDOOR dirtxt runtime detection - info client-to-server (more info ...) | trojan-activity | | | | URL |
| 6156 | BACKDOOR dirtxt runtime detection - view client-to-server (more info ...) | trojan-activity | | | | URL |
| 6164 | BACKDOOR psyrat 1.0 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6167 | BACKDOOR unicorn runtime detection - set wallpaper client-to-server (more info ...) | trojan-activity | | | | URL |
| 6169 | BACKDOOR digital rootbeer runtime detection (more info ...) | trojan-activity | | | | URL |
| 6171 | BACKDOOR cookie monster 0.24 runtime detection (more info ...) | trojan-activity | | | | |
| 6173 | BACKDOOR cookie monster 0.24 runtime detection (more info ...) | trojan-activity | | | | |
| 6180 | BACKDOOR netraider 0.0 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6285 | BACKDOOR antilamer 1.1 runtime detection - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6289 | BACKDOOR netspy runtime detection - command pattern client-to-server (more info ...) | trojan-activity | | | | URL |
| 6293 | BACKDOOR joker ddos v1.0.1 runtime detection - bomb - initial flowbit (more info ...) | trojan-activity | | | | URL |
| 6294 | BACKDOOR joker ddos v1.0.1 runtime detection - bomb - second flowbit (more info ...) | trojan-activity | | | | URL |
| 6302 | BACKDOOR cia runtime detection - initial connection - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6304 | BACKDOOR softwar shadowthief runtime detection - initial connection - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6307 | BACKDOOR lamespy runtime detection - initial connection - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6309 | BACKDOOR net demon runtime detection - initial connection - password request (more info ...) | trojan-activity | | | | URL |
| 6310 | BACKDOOR net demon runtime detection - initial connection - password send (more info ...) | trojan-activity | | | | URL |
| 6312 | BACKDOOR net demon runtime detection - message send (more info ...) | trojan-activity | | | | URL |
| 6314 | BACKDOOR net demon runtime detection - open browser request (more info ...) | trojan-activity | | | | URL |
| 6316 | BACKDOOR net demon runtime detection - file manager request (more info ...) | trojan-activity | | | | URL |
| 6320 | BACKDOOR ptakks2.1 runtime detection - keepalive (more info ...) | trojan-activity | | | | URL |
| 6323 | BACKDOOR 3xBackdoor runtime detection - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6326 | BACKDOOR fucktrojan 1.2 runtime detection - flood (more info ...) | trojan-activity | | | | |
| 6329 | BACKDOOR commando runtime detection - chat client-to-server (more info ...) | trojan-activity | | | | URL |
| 6335 | BACKDOOR buttman v0.9p runtime detection - remote control - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6337 | BACKDOOR hatredfriend file manage command - set flowbit (more info ...) | trojan-activity | | | | URL |
| 6390 | SPYWARE-PUT Adware esyndicate runtime detection - ads popup (more info ...) | misc-activity | | | | |
| 6400 | BACKDOOR snowdoor runtime detection client-to-server (more info ...) | trojan-activity | | | | URL |
| 6404 | EXPLOIT Veritas NetBackup Volume Manager connection attempt (more info ...) | protocol-command-decode | | | | |
| 6469 | EXPLOIT RealVNC connection attempt (more info ...) | protocol-command-decode | | | | |
| 6470 | EXPLOIT RealVNC authentication types sent attempt (more info ...) | protocol-command-decode | | | | |
| 6472 | BACKDOOR bugs runtime detection - file manager client-to-server (more info ...) | trojan-activity | | | | URL |
| 6475 | BACKDOOR badrat 1.1 runtime detection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 6497 | BACKDOOR exploiter 1.0 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6499 | BACKDOOR omerta 1.3 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6500 | BACKDOOR omerta 1.3 runtime detection (more info ...) | trojan-activity | | | | URL |
| 6688 | WEB-CLIENT PNG file transfer (more info ...) | protocol-command-decode | | | | |
| 7023 | WEB-CLIENT xls file download (more info ...) | misc-activity | | | | URL |
| 7047 | WEB-CLIENT excel object record overflow attempt (more info ...) | attempted-user | 2006-1306 | | | URL |
| 7058 | BACKDOOR charon runtime detection - download file flowbit 1 (more info ...) | trojan-activity | | | | URL |
| 7059 | BACKDOOR charon runtime detection - download file/log flowbit 2 (more info ...) | trojan-activity | | | | URL |
| 7061 | BACKDOOR charon runtime detection - download log flowbit 1 (more info ...) | trojan-activity | | | | URL |
| 7065 | BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1 (more info ...) | trojan-activity | | | | URL |
| 7066 | BACKDOOR cybernetic 1.62 runtime detection - reverse connection flowbit 1 (more info ...) | trojan-activity | | | | URL |
| 7078 | BACKDOOR up and run v1.0 beta runtime detection flowbit 1 (more info ...) | trojan-activity | | | | URL |
| 7079 | BACKDOOR up and run v1.0 beta runtime detection flowbit 2 (more info ...) | trojan-activity | | | | URL |
| 7080 | BACKDOOR up and run v1.0 beta runtime detection flowbit 3 (more info ...) | trojan-activity | | | | URL |
| 7082 | BACKDOOR mosucker3.0 runtime detection - client-to-server (more info ...) | trojan-activity | | | | URL |
| 7085 | BACKDOOR erazer v1.1 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7087 | BACKDOOR sinique 1.0 runtime detection - initial connection with correct password client-to-server (more info ...) | trojan-activity | | | | URL |
| 7089 | BACKDOOR sinique 1.0 runtime detection - initial connection with wrong password -client-to-server (more info ...) | trojan-activity | | | | URL |
| 7101 | BACKDOOR gwboy 0.92 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7104 | BACKDOOR aol admin runtime detection (more info ...) | trojan-activity | | | | URL |
| 7106 | BACKDOOR girlfriend runtime detection (more info ...) | trojan-activity | | | | URL |
| 7111 | BACKDOOR fearless lite 1.01 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7113 | BACKDOOR donalddick v1.5b3 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7119 | BACKDOOR y3k 1.2 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7121 | BACKDOOR y3k 1.2 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7157 | SPYWARE-PUT Keylogger win-spy runtime detection - remote conn client-to-server (more info ...) | successful-recon-limited | | | | URL |
| 7159 | SPYWARE-PUT Keylogger win-spy runtime detection - upload file client-to-server (more info ...) | successful-recon-limited | | | | URL |
| 7161 | SPYWARE-PUT Keylogger win-spy runtime detection - download file client-to-server (more info ...) | successful-recon-limited | | | | URL |
| 7163 | SPYWARE-PUT Keylogger win-spy runtime detection - execute file client-to-server (more info ...) | successful-recon-limited | | | | URL |
| 7165 | SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 1 (more info ...) | successful-recon-limited | | | | URL |
| 7166 | SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 2 (more info ...) | successful-recon-limited | | | | URL |
| 7167 | SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 3 (more info ...) | successful-recon-limited | | | | URL |
| 7168 | SPYWARE-PUT Keylogger ab system spy runtime detection - information exchange - flowbit set 4 (more info ...) | successful-recon-limited | | | | URL |
| 7175 | SPYWARE-PUT Keylogger ab system spy runtime detection - log retrieve (more info ...) | successful-recon-limited | | | | URL |
| 7178 | SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection (more info ...) | successful-recon-limited | | | | |
| 7179 | SPYWARE-PUT Keylogger desktop detective 2000 runtime detection - init connection (more info ...) | successful-recon-limited | | | | |
| 7506 | SPYWARE-PUT Hacker-Tool coma runtime detection - init connection - flowbit set (more info ...) | misc-activity | | | | |
| 7508 | SPYWARE-PUT Hacker-Tool coma runtime detection - ping - flowbit set (more info ...) | misc-activity | | | | |
| 7512 | SPYWARE-PUT Keylogger watchdog runtime detection - init connection - flowbit set (more info ...) | successful-recon-limited | | | | URL |
| 7544 | SPYWARE-PUT Keylogger PerfectKeylogger runtime detection - flowbit set 1 (more info ...) | successful-recon-limited | | | | URL |
| 7545 | SPYWARE-PUT Keylogger PerfectKeylogger runtime detection - flowbit set 2 (more info ...) | successful-recon-limited | | | | URL |
| 7583 | SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set big (more info ...) | misc-activity | | | | URL |
| 7584 | SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set open (more info ...) | misc-activity | | | | URL |
| 7585 | SPYWARE-PUT Hacker-Tool clandestine runtime detection - flowbit set image (more info ...) | misc-activity | | | | URL |
| 7591 | SPYWARE-PUT Keylogger keylogger pro runtime detection - flowbit set (more info ...) | successful-recon-limited | | | | |
| 7596 | SPYWARE-PUT Keylogger spy lantern keylogger runtime detection - flowbit set (more info ...) | successful-recon-limited | | | | URL |
| 7602 | SPYWARE-PUT Snoopware big brother v3.5.1 runtime detection - connect to receiver - flowbit set (more info ...) | successful-recon-limited | | | | URL |
| 7604 | BACKDOOR katux 2.0 runtime detection - screen capture - flowbit set (more info ...) | trojan-activity | | | | |
| 7606 | BACKDOOR katux 2.0 runtime detection - get system info - flowbit set (more info ...) | trojan-activity | | | | |
| 7608 | BACKDOOR katux 2.0 runtime detection - chat - flowbit set (more info ...) | trojan-activity | | | | |
| 7617 | BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 1 (more info ...) | trojan-activity | | | | |
| 7618 | BACKDOOR theef 2.0 runtime detection - connection request with password - flowbit 2 (more info ...) | trojan-activity | | | | |
| 7620 | BACKDOOR remote control 1.7 runtime detection - connection request flowbit 1 (more info ...) | trojan-activity | | | | |
| 7621 | BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 2 (more info ...) | trojan-activity | | | | |
| 7622 | BACKDOOR remote control 1.7 runtime detection - connection request - flowbit 3 (more info ...) | trojan-activity | | | | |
| 7625 | BACKDOOR skyrat show runtime detection - initial connection - flowbit 1 (more info ...) | trojan-activity | | | | |
| 7626 | BACKDOOR skyrat show runtime detection - initial connection - flowbit 2 (more info ...) | trojan-activity | | | | |
| 7627 | BACKDOOR skyrat show runtime detection - initial connection - flowbit 3 (more info ...) | trojan-activity | | | | |
| 7628 | BACKDOOR skyrat show runtime detection - initial connection - flowbit 4 (more info ...) | trojan-activity | | | | |
| 7631 | BACKDOOR hornet 1.0 runtime detection - fetch system info - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7633 | BACKDOOR hornet 1.0 runtime detection - irc connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7635 | BACKDOOR hornet 1.0 runtime detection - fetch process list - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7641 | BACKDOOR am remote client runtime detection - client-to-server (more info ...) | trojan-activity | | | | URL |
| 7645 | BACKDOOR snipernet 2.1 runtime detection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7648 | BACKDOOR minicom lite runtime detection - client-to-server (more info ...) | trojan-activity | | | | URL |
| 7650 | BACKDOOR small uploader 1.01 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7652 | BACKDOOR small uploader 1.01 runtime detection - get server information - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7654 | BACKDOOR small uploader 1.01 runtime detection - remote shell - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7656 | BACKDOOR diems mutter runtime detection - client-to-server (more info ...) | trojan-activity | | | | URL |
| 7660 | BACKDOOR lan filtrator 1.1 runtime detection - initial connection request - flowbit set (more info ...) | trojan-activity | | | | |
| 7662 | BACKDOOR snid x2 v1.2 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | |
| 7664 | BACKDOOR screen control 1.0 runtime detection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7668 | BACKDOOR screen control 1.0 runtime detection - capture on port 2213 - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7673 | BACKDOOR remote havoc runtime detection - flowbit set 1 (more info ...) | trojan-activity | | | | URL |
| 7674 | BACKDOOR remote havoc runtime detection - flowbit set 2 (more info ...) | trojan-activity | | | | URL |
| 7676 | BACKDOOR cool remote control or crackdown runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7678 | BACKDOOR cool remote control 1.12 runtime detection - upload file - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7680 | BACKDOOR cool remote control 1.12 runtime detection - download file - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7682 | BACKDOOR acid head 1.00 runtime detection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7685 | BACKDOOR illusion runtime detection - get remote info client-to-server (more info ...) | trojan-activity | | | | URL |
| 7687 | BACKDOOR illusion runtime detection - file browser client-to-server (more info ...) | trojan-activity | | | | URL |
| 7690 | BACKDOOR evade runtime detection - file manager - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7695 | BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 1 (more info ...) | trojan-activity | | | | URL |
| 7696 | BACKDOOR hanky panky 1.1 runtime detection - initial connection - flowbit set 2 (more info ...) | trojan-activity | | | | URL |
| 7698 | BACKDOOR brain wiper runtime detection - launch application - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7700 | BACKDOOR brain wiper runtime detection - chat - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7702 | BACKDOOR roach 1.0 runtime detection - remote control actions - flowbit set (more info ...) | trojan-activity | | | | |
| 7705 | BACKDOOR omniquad instant remote control runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | |
| 7708 | BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7709 | BACKDOOR fear1.5/aciddrop1.0 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7714 | BACKDOOR netdevil runtime detection - flowbit set 1 (more info ...) | trojan-activity | | | | URL |
| 7715 | BACKDOOR netdevil runtime detection - flowbit set 2 (more info ...) | trojan-activity | | | | URL |
| 7718 | BACKDOOR dameware mini remote control runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7726 | BACKDOOR reversable ver1.0 runtime detection - execute command - flowbit set (more info ...) | trojan-activity | | | | |
| 7728 | BACKDOOR radmin runtime detection - client-to-server (more info ...) | trojan-activity | | | | URL |
| 7731 | BACKDOOR outbreak_0.2.7 runtime detection - ring server-to-client (more info ...) | trojan-activity | | | | URL |
| 7734 | BACKDOOR bionet 4.05 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7736 | BACKDOOR bionet 4.05 runtime detection - file manager - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7740 | BACKDOOR nova 1.0 runtime detection - initial connection with pwd set - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7742 | BACKDOOR nova 1.0 runtime detection - cgi notification client-to-server (more info ...) | trojan-activity | | | | URL |
| 7744 | BACKDOOR phoenix 2.1 runtime detection - flowbit set (more info ...) | trojan-activity | | | | |
| 7746 | BACKDOOR bobo 1.0 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | |
| 7748 | BACKDOOR bobo 1.0 runtime detection - send message - flowbit set (more info ...) | trojan-activity | | | | |
| 7750 | BACKDOOR buschtrommel 1.22 runtime detection - initial connection - flowbit set 1 (more info ...) | trojan-activity | | | | |
| 7751 | BACKDOOR buschtrommel 1.22 runtime detection - initial connection - flowbit set 2 (more info ...) | trojan-activity | | | | |
| 7753 | BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 1 (more info ...) | trojan-activity | | | | |
| 7754 | BACKDOOR buschtrommel 1.22 runtime detection - spy function - flowbit set 2 (more info ...) | trojan-activity | | | | |
| 7756 | BACKDOOR beast 2.02 runtime detection - initial connection - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7764 | BACKDOOR nt remote controller 2000 runtime detection - sysinfo client-to-server (more info ...) | trojan-activity | | | | URL |
| 7766 | BACKDOOR nt remote controller 2000 runtime detection - foldermonitor client-to-server (more info ...) | trojan-activity | | | | URL |
| 7768 | BACKDOOR data rape runtime detection - execute program client-to-server (more info ...) | trojan-activity | | | | URL |
| 7770 | BACKDOOR messiah 4.0 runtime detection - get server info - flowbit set (more info ...) | trojan-activity | | | | |
| 7772 | BACKDOOR messiah 4.0 runtime detection - enable keylogger - flowbit set (more info ...) | trojan-activity | | | | |
| 7774 | BACKDOOR messiah 4.0 runtime detection - screen capture - flowbit set (more info ...) | trojan-activity | | | | |
| 7776 | BACKDOOR messiah 4.0 runtime detection - get drives - flowbit set (more info ...) | trojan-activity | | | | |
| 7782 | BACKDOOR netdevil runtime detection - file manager - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7784 | BACKDOOR forced control uploader runtime detection - connection with password - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7786 | BACKDOOR forced control uploader runtime detection directory listing - flowbit set 1 (more info ...) | trojan-activity | | | | URL |
| 7787 | BACKDOOR forced control uploader runtime detection directory listing - flowbit set 2 (more info ...) | trojan-activity | | | | URL |
| 7788 | BACKDOOR forced control uploader runtime detection directory listing - flowbit set 3 (more info ...) | trojan-activity | | | | URL |
| 7789 | BACKDOOR forced control uploader runtime detection directory listing - flowbit set 4 (more info ...) | trojan-activity | | | | URL |
| 7794 | BACKDOOR fraggle rock 2.0 lite runtime detection - pc info - flowbit set (more info ...) | trojan-activity | | | | URL |
| 7795 | BACKDOOR incommand 1.7 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 7797 | BACKDOOR incommand 1.7 runtime detection - file manage 1 (more info ...) | trojan-activity | | | | |
| 7799 | BACKDOOR incommand 1.7 runtime detection - file manage 2 (more info ...) | trojan-activity | | | | |
| 7808 | BACKDOOR fatal wound 1.0 runtime detection - upload (more info ...) | trojan-activity | | | | URL |
| 7811 | BACKDOOR abacab runtime detection - telnet initial (more info ...) | trojan-activity | | | | URL |
| 7813 | BACKDOOR darkmoon initial connection detection - cts (more info ...) | trojan-activity | | | | URL |
| 7815 | BACKDOOR darkmoon reverse connection detection - stc (more info ...) | trojan-activity | | | | URL |
| 7817 | BACKDOOR infector v1.0 runtime detection - init conn (more info ...) | trojan-activity | | | | URL |
| 7819 | BACKDOOR nightcreature beta 0.01 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7820 | BACKDOOR nightcreature beta 0.01 runtime detection (more info ...) | trojan-activity | | | | URL |
| 7834 | SPYWARE-PUT Hacker-Tool nettracker runtime detection - report browsing (more info ...) | misc-activity | | | | |
| 7845 | SPYWARE-PUT Keylogger clogger 1.0 runtime detection (more info ...) | successful-recon-limited | | | | |
| 7846 | SPYWARE-PUT Keylogger clogger 1.0 runtime detection (more info ...) | successful-recon-limited | | | | |
| 8075 | BACKDOOR mithril runtime detection - get system information (more info ...) | trojan-activity | | | | URL |
| 8077 | BACKDOOR mithril runtime detection - get process list (more info ...) | trojan-activity | | | | URL |
| 8355 | SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection (more info ...) | successful-recon-limited | | | | |
| 8465 | SPYWARE-PUT Keylogger netobserve runtime detection - email notification (more info ...) | successful-recon-limited | | | | URL |
| 8470 | BACKDOOR superspy 2.0 beta runtime detection - get system info (more info ...) | trojan-activity | | | | |
| 8472 | BACKDOOR superspy 2.0 beta runtime detection - screen capture 2 (more info ...) | trojan-activity | | | | |
| 8474 | BACKDOOR superspy 2.0 beta runtime detection - processes/active windows manage 2 (more info ...) | trojan-activity | | | | |
| 8547 | BACKDOOR zzmm 2.0 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 8704 | SMTP YPOPS Banner (more info ...) | not-suspicious | | | | |
| 9649 | SPYWARE-PUT Keylogger ghost Keylogger runtime detection - flowbit set (more info ...) | successful-recon-limited | | | | URL |
| 9654 | BACKDOOR apofis 1.0 runtime detection - remote controlling (more info ...) | trojan-activity | | | | |
| 9656 | BACKDOOR bersek 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 9658 | BACKDOOR bersek 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 9660 | BACKDOOR bersek 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 9662 | BACKDOOR bersek 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 9664 | BACKDOOR crossbow 1.12 runtime detection (more info ...) | trojan-activity | | | | |
| 9837 | BACKDOOR sun shadow 1.70 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 9845 | WEB-CLIENT M3U File Download Detected (more info ...) | misc-activity | | | | |
| 10097 | SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection (more info ...) | successful-recon-limited | | | | |
| 10099 | SPYWARE-PUT Keylogger win32.remotekeylog.b runtime detection (more info ...) | successful-recon-limited | | | | |
| 10103 | BACKDOOR hav-rat 1.1 runtime detection (more info ...) | trojan-activity | | | | |
| 10104 | BACKDOOR hav-rat 1.1 runtime detection (more info ...) | trojan-activity | | | | |
| 10110 | BACKDOOR poison ivy 2.1.2 runtime detection (more info ...) | trojan-activity | | | | |
| 10450 | BACKDOOR only 1 rat runtime detection - control command (more info ...) | trojan-activity | | | | |
| 10455 | BACKDOOR [x]-ztoo 1.0 runtime detection - get system info (more info ...) | trojan-activity | | | | |
| 10460 | BACKDOOR winicabras 1.1 runtime detection - get system info (more info ...) | trojan-activity | | | | |
| 10462 | BACKDOOR winicabras 1.1 runtime detection - explorer (more info ...) | trojan-activity | | | | |
| 10996 | WEB-MISC SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 11322 | BACKDOOR sohoanywhere runtime detection (more info ...) | trojan-activity | | | | |
| 11671 | WEB-MISC SSLv2 Server_Hello request from SSLv3 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 11953 | BACKDOOR supervisor plus runtime detection (more info ...) | trojan-activity | | | | |
| 11965 | WEB-MISC SSLv2 Server_Hello request from TLSv1 Client_Hello request (more info ...) | protocol-command-decode | | | | |
| 12054 | BACKDOOR tron runtime detection - init connection - flowbit set (more info ...) | trojan-activity | | | | |
| 12129 | SPYWARE-PUT Keylogger remotekeylog.b runtime detection - get sys info (more info ...) | successful-recon-limited | | | | |
| 12131 | SPYWARE-PUT Keylogger remotekeylog.b runtime detection - keylogging (more info ...) | successful-recon-limited | | | | |
| 12133 | SPYWARE-PUT Keylogger remotekeylog.b runtime detection - open url (more info ...) | successful-recon-limited | | | | |
| 12135 | SPYWARE-PUT Keylogger remotekeylog.b runtime detection - fun (more info ...) | successful-recon-limited | | | | |
| 12142 | BACKDOOR access remote pc runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12144 | BACKDOOR access remote pc runtime detection - rpc setup (more info ...) | trojan-activity | | | | |
| 12146 | BACKDOOR blue eye 1.0b runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12148 | BACKDOOR back orifice 2006 - v1.1.5 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12150 | BACKDOOR cafeini 1.0 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12153 | BACKDOOR optix pro v1.32 runtime detection - download file (more info ...) | trojan-activity | | | | |
| 12154 | BACKDOOR optix pro v1.32 runtime detection - download file (more info ...) | trojan-activity | | | | |
| 12156 | BACKDOOR optix pro v1.32 runtime detection - upload file (more info ...) | trojan-activity | | | | |
| 12157 | BACKDOOR optix pro v1.32 runtime detection - upload file (more info ...) | trojan-activity | | | | |
| 12160 | BACKDOOR optix pro v1.32 runtime detection - screen capturing (more info ...) | trojan-activity | | | | |
| 12161 | BACKDOOR optix pro v1.32 runtime detection - screen capturing (more info ...) | trojan-activity | | | | |
| 12163 | BACKDOOR cobra uploader 1.0 runtime detection (more info ...) | trojan-activity | | | | |
| 12165 | BACKDOOR lithium 1.02 runtime detection (more info ...) | trojan-activity | | | | |
| 12233 | BACKDOOR theef 2.10 runtime detection - connect with no password (more info ...) | trojan-activity | | | | |
| 12235 | BACKDOOR theef 2.10 runtime detection - connect with password (more info ...) | trojan-activity | | | | |
| 12237 | BACKDOOR theef 2.10 runtime detection - ftp (more info ...) | trojan-activity | | | | |
| 12240 | BACKDOOR genie 1.7 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12242 | BACKDOOR hotmail hacker log edition 5.0 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12283 | WEB-CLIENT xlw file download (more info ...) | misc-activity | | | | URL |
| 12285 | WEB-CLIENT Excel Workspace file download (more info ...) | misc-activity | | | | URL |
| 12297 | BACKDOOR bifrost v1.2.1 runtime detection (more info ...) | trojan-activity | | | | |
| 12373 | BACKDOOR radmin 3.0 runtime detection - initial connection (more info ...) | trojan-activity | | | | |
| 12375 | BACKDOOR radmin 3.0 runtime detection - login & remote control (more info ...) | trojan-activity | | | | |
| 12377 | BACKDOOR shark 2.3.2 runtime detection (more info ...) | trojan-activity | | | | |
| 12699 | BACKDOOR poison ivy 2.3.0 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 12701 | BACKDOOR poison ivy 2.3.0 runtime detection - server connection (more info ...) | trojan-activity | | | | |
| 12724 | BACKDOOR dark moon 4.11 runtime detection (more info ...) | trojan-activity | | | | |
| 12726 | BACKDOOR bandook 1.35 runtime detection (more info ...) | trojan-activity | | | | |
| 12758 | SPYWARE-PUT Keylogger/RAT digi watcher 2.32 runtime detection (more info ...) | successful-recon-limited | | | | |
| 12760 | SPYWARE-PUT Keylogger powered Keylogger 2.2 runtime detection (more info ...) | successful-recon-limited | | | | |
| 12792 | SPYWARE-PUT Keylogger spy lantern Keylogger pro 6.0 runtime detection (more info ...) | successful-recon-limited | | | | |
| 13236 | SPYWARE-PUT Keylogger active Keylogger 3.9.2 runtime detection (more info ...) | successful-recon-limited | | | | |
| 13243 | SPYWARE-PUT Keylogger computer monitor 1.1 by lastcomfort runtime detection (more info ...) | successful-recon-limited | | | | |
| 13245 | BACKDOOR troya 1.4 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 13247 | BACKDOOR yuri 1.2 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 13278 | SPYWARE-PUT Keylogger advanced spy 4.0 runtime detection (more info ...) | successful-recon-limited | | | | |
| 13280 | SPYWARE-PUT Keylogger email spy monitor 6.9 runtime detection (more info ...) | successful-recon-limited | | | | |
| 13346 | SPYWARE-PUT Snoopware remote desktop inspector runtime detection - init connection (more info ...) | successful-recon-limited | | | | |
| 13465 | WEB-CLIENT Microsoft Works file download request (more info ...) | misc-activity | | | | |
| 13473 | EXPLOIT Microsoft Publisher file download (more info ...) | misc-activity | | | | |
| 13479 | SPYWARE-PUT Keylogger findnot guarddog 4.0 runtime detection (more info ...) | successful-recon-limited | | | | |
| 13483 | SPYWARE-PUT Hijacker baidu toolbar runtime detection - updates automatically (more info ...) | misc-activity | | | | |
| 13506 | BACKDOOR evilotus 1.3.2 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 13508 | BACKDOOR xploit 1.4.5 runtime detection (more info ...) | trojan-activity | | | | |
| 13515 | WEB-CLIENT Quicktime user agent (more info ...) | misc-activity | | | | |
| 13584 | WEB-CLIENT csv file download request (more info ...) | misc-activity | 2008-0112 | | | URL |
| 13611 | EXPLOIT RealVNC client response (more info ...) | misc-activity | 2006-2369 | 17978 | | URL |
| 13627 | WEB-CLIENT Microsoft Access file download request (more info ...) | misc-activity | | | | URL |
| 13654 | BACKDOOR nuclear rat 2.1 runtime detection - init connection (more info ...) | trojan-activity | | | | |
| 13678 | MISC Microsoft EMF metafile access detected (more info ...) | attempted-user | 2008-1087 | | | URL |
| 13709 | MYSQL yaSSL SSLv2 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 13710 | MYSQL yaSSL TLSv1 Server_Hello request (more info ...) | protocol-command-decode | | | | |
| 13767 | SPYWARE-PUT Keylogger cyber sitter runtime detection (more info ...) | successful-recon-limited | | | | |
| 13797 | WEB-CLIENT pe compact binary download (more info ...) | misc-activity | | | | |
| 13801 | WEB-CLIENT RTF file download (more info ...) | protocol-command-decode | | | | |
| 13877 | BACKDOOR trojan-spy.win32.delf.uv runtime detection (more info ...) | trojan-activity | | | | |
| 13880 | EXPLOIT RealVNC server authentication version array check (more info ...) | misc-activity | 2006-2369 | 17978 | | URL |
| 13915 | WEB-MISC backup file download attempt (more info ...) | misc-activity | | | | |
| 13938 | SPYWARE-PUT Hijacker adware.win32.ejik.ec variant runtime detection (more info ...) | misc-activity | | | | |
| 13943 | SPYWARE-PUT Trickler dropper agent.rqg runtime detection (more info ...) | trojan-activity | | | | |
| 13982 | WEB-CLIENT Microsoft Powerpoint file download attempt (more info ...) | misc-activity | | | | |
| 13983 | WEB-CLIENT Microsoft Office eps file download (more info ...) | misc-activity | | | | |
| 14017 | WEB-CLIENT MPEG Layer 3 playlist file request (more info ...) | misc-activity | | | | |
| 14018 | WEB-CLIENT PLS multimedia playlist file request (more info ...) | misc-activity | | | | |
| 14264 | MULTIMEDIA Windows Media Player playlist download (more info ...) | misc-activity | | | | |
| 15013 | WEB-MISC Adobe Portable Document Format file download attempt (more info ...) | misc-activity | | | | |
| 15079 | WEB-MISC WAV Formatfile download attempt (more info ...) | misc-activity | | | | |
| 15123 | WEB-CLIENT Rich Text Format file request (more info ...) | misc-activity | | | | |
| 15158 | WEB-MISC XML Shareable Playlist Format file download attempt (more info ...) | misc-activity | | | | |
| 15237 | WEB-MISC Java .class file download attempt (more info ...) | misc-activity | | | | |
| 15239 | WEB-MISC RealMedia format file download attempt (more info ...) | misc-activity | | | | |
| 15240 | WEB-MISC RealMedia format file download attempt (more info ...) | misc-activity | | | | |
| 15294 | WEB-CLIENT Microsoft Visio file download request (more info ...) | misc-activity | | | | |
| 15319 | NETBIOS-DG SMB /sql/query create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15320 | NETBIOS-DG SMB /sql/query unicode create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15321 | NETBIOS SMB /sql/query create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15322 | NETBIOS SMB /sql/query unicode create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15323 | NETBIOS-DG SMB /sql/query andx create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15324 | NETBIOS-DG SMB /sql/query unicode andx create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15325 | NETBIOS SMB /sql/query andx create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15326 | NETBIOS SMB /sql/query unicode andx create tree attempt (more info ...) | protocol-command-decode | | | | |
| 15426 | WEB-CLIENT MAKI file request (more info ...) | misc-activity | | | | |
| 15427 | WEB-MISC SVG file request (more info ...) | misc-activity | | | | |
| 15463 | WEB-CLIENT Microsoft Excel file request (more info ...) | misc-activity | | | | |
| 15464 | WEB-CLIENT Microsoft Excel file request (more info ...) | misc-activity | | | | |
| 15471 | WEB-CLIENT asp file upload (more info ...) | misc-activity | | | | |
| 15516 | WEB-CLIENT AVI multimedia file request (more info ...) | misc-activity | | | | |
| 15582 | WEB-MISC ARJ format file download attempt (more info ...) | misc-activity | | | | |
| 15586 | WEB-CLIENT Powerpoint file download request (more info ...) | protocol-command-decode | | | | |
| 15587 | WEB-CLIENT Word file download request (more info ...) | protocol-command-decode | | | | |
| 15865 | WEB-CLIENT MP4 file request (more info ...) | misc-activity | | | | |
| 15870 | WEB-MISC 4xm file request (more info ...) | misc-activity | | | | |
| 15898 | WEB-MISC Audio Interchange File Format download request (more info ...) | misc-activity | | | | |
| 15899 | WEB-MISC Audio Interchange File Format file request (more info ...) | misc-activity | | | | |
| 15900 | WEB-MISC Audio Interchange File Format request (more info ...) | misc-activity | | | | |
| 15921 | WEB-CLIENT Microsoft media format file download request (more info ...) | misc-activity | | | | |
| 15922 | WEB-CLIENT mp3 file download request (more info ...) | misc-activity | | | | |
| 15945 | WEB-CLIENT RSS file download request (more info ...) | misc-activity | | | | |
| 15987 | WEB-MISC Microsoft Visio DXF file download request (more info ...) | misc-activity | | | | |
| 16026 | WEB-CLIENT midi file download attempt (more info ...) | misc-activity | | | | |
| 16061 | MISC X PixMap file download (more info ...) | misc-activity | | | | |
| 16093 | BACKDOOR bugsprey runtime detection - initial connection (more info ...) | trojan-activity | | | | |
| 16103 | BACKDOOR lost door 3.0 runtime detection - init (more info ...) | trojan-activity | | | | |
| 16106 | BACKDOOR synrat 2.1 pro runtime detection - init (more info ...) | trojan-activity | | | | |
| 16143 | WEB-CLIENT Microsoft asf file download (more info ...) | misc-activity | | | | |
| 16205 | WEB-MISC bitmap file download request (more info ...) | misc-activity | | | | |
| 16219 | WEB-CLIENT Adobe Director file format transfer (more info ...) | misc-activity | | | | |
| 16254 | BACKDOOR rogue software system security 2009 installtime detection (more info ...) | trojan-activity | | | | URL |
| 16270 | BACKDOOR srat 1.6 runtime detection (more info ...) | trojan-activity | | | | |
| 16286 | WEB-MISC TrueType font file download request (more info ...) | misc-activity | | | | |
| 16381 | NETBIOS SMB session negotiation request (more info ...) | misc-activity | | | | |
| 16473 | WEB-MISC Microsoft Windows Movie Maker project file download request (more info ...) | misc-activity | | | | |
| 16474 | WEB-MISC Microsoft Compound File Binary v3 file download (more info ...) | misc-activity | | | | |
| 16475 | WEB-MISC Microsoft Compound File Binary v4 file download (more info ...) | misc-activity | | | | |
| 16476 | WEB-MISC Microsoft .MSProducer file download request (more info ...) | misc-activity | | | | |
| 16477 | WEB-MISC Microsoft .MSProducerZ file download request (more info ...) | misc-activity | | | | |
| 16478 | WEB-MISC Microsoft .MSProducerBF file download request (more info ...) | misc-activity | | | | |