[Silicon Defense logo]

SnortSnarf alert page

Source: 65.24.2.12

SnortSnarf v021111.1

Signature section (91123)Top 20 source IPsTop 20 dest IPs

13 such alerts found using input module SnortFileInput, with sources:
Earliest: 17:09:53.670178 on 05/21/2003
Latest: 00:25:03.409689 on 06/13/2003

2 different signatures are present for 65.24.2.12 as a source

There are 2 distinct destination IPs in the alerts of the type on this page.

65.24.2.12 Whois lookup at: ARIN RIPE APNIC Geektools
DNS lookup at: Amenesi TRIUMF Princeton
More lookup links: Dshield Sam Spade


[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
05/21-17:09:53.670178 65.24.2.12:119 -> 192.168.1.101:2250
TCP TTL:247 TOS:0x0 ID:35054 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9A17E506 Ack: 0xFA4A1EFC Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
05/21-17:11:11.640412 65.24.2.12:119 -> 192.168.1.101:2249
TCP TTL:247 TOS:0x0 ID:54024 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9A5A88C6 Ack: 0xFA4950C7 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
05/21-17:11:12.628314 65.24.2.12:119 -> 192.168.1.101:2250
TCP TTL:247 TOS:0x0 ID:54280 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x9A7A0636 Ack: 0xFA4A20AC Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
05/21-17:11:17.261007 65.24.2.12:119 -> 192.168.1.101:2248
TCP TTL:247 TOS:0x0 ID:55325 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x99BBDC6C Ack: 0xFA486185 Win: 0x2238 TcpLen: 20
[**] [1:1394:3] SHELLCODE x86 NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
05/30-00:35:10.675583 65.24.2.12:119 -> 192.168.1.100:1235
TCP TTL:247 TOS:0x0 ID:23166 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x3C54B26F Ack: 0xF1EE1851 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.387588 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4950 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE550337A Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.388935 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4951 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE550392E Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.390309 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4952 IpLen:20 DgmLen:1500 DF
***AP*** Seq: 0xE5503EE2 Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.404352 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4961 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE5506CD7 Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.405705 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4962 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE550728B Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.407027 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4963 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE550783F Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.408375 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4964 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0xE5507DF3 Ack: 0x536316E2 Win: 0x2238 TcpLen: 20
[**] [1:1390:3] SHELLCODE x86 inc ebx NOOP [**]
[Classification: Executable code was detected] [Priority: 1]
06/13-00:25:03.409689 65.24.2.12:119 -> 192.168.1.100:1546
TCP TTL:247 TOS:0x0 ID:4965 IpLen:20 DgmLen:1500 DF
***AP*** Seq: 0xE55083A7 Ack: 0x536316E2 Win: 0x2238 TcpLen: 20

SnortSnarf brought to you courtesy of Silicon Defense
Authors: Jim Hoagland and Stuart Staniford
See also the Snort Page by Marty Roesch
Page generated at Tue Jun 17 09:03:53 2003