SGNET deployment
Query by Selection
Select
Group by
Generic parameters
Date Interval
From:
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
1
2
3
4
5
6
7
8
9
10
11
12
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Step:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
DAY
WEEK
MONTH
HOUR
To:
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
1
2
3
4
5
6
7
8
9
10
11
12
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Environment:
clear
-- select --
Partner 3
Partner 17
Partner 10
Partner 11
Partner 15
Partner 1
Partner 6
Partner 4
Partner 12
Partner 13
Partner 16
Partner 14
Partner 8
Partner 7
Partner 2
Partner 5
Partner 9
Partner 18
Destination address:
clear
-- select --
1.1.1.1
2.2.2.2
3.3.3.3
4.4.4.4
Information on the attacker
OS:
clear
-- select --
Windows
Linux
Sun OS
Other
Country:
clear
-- select --
A2
AD
AE
AF
AG
AI
AL
AM
AN
AO
AP
AR
AS
AT
AU
AW
AZ
BA
BB
BD
BE
BF
BG
BH
BI
BJ
BM
BN
BO
BR
BS
BT
BY
BZ
CA
CD
CG
CH
CI
CL
CM
CN
CO
CR
CV
CY
CZ
DE
DK
DM
DO
DZ
EC
EE
EG
ES
ET
EU
FI
FJ
FR
GA
GB
GD
GE
GF
GH
GI
GL
GM
GP
GQ
GR
GT
GU
HK
HN
HR
HT
HU
ID
IE
IL
IN
IQ
IR
IS
IT
JM
JO
JP
KE
KG
KH
KN
KR
KW
KY
KZ
LA
LB
LC
LI
LK
LS
LT
LU
LV
LY
MA
MC
MD
MK
ML
MM
MN
MO
MP
MQ
MR
MT
MU
MV
MW
MX
MY
MZ
NA
NC
NE
NG
NI
NL
NO
NP
NZ
OM
PA
PE
PF
PG
PH
PK
PL
PR
PS
PT
PY
QA
RO
RS
RU
RW
SA
SD
SE
SG
SI
SK
SL
SM
SN
SO
SR
SV
SY
SZ
TD
TH
TJ
TM
TN
TR
TT
TV
TW
TZ
UA
UG
US
UY
UZ
VA
VC
VE
VI
VN
YE
ZA
ZW
ISP:
clear
AV signature:
clear
-- select --
AVG
AhnLab-V3
AntiVir
Authentium
Avast
BitDefender
CAT-QuickHeal
ClamAV
DrWeb
Ewido
F-Prot
F-Secure
FileAdvisor
Fortinet
Ikarus
Kaspersky
McAfee
Microsoft
NOD32v2
Norman
Panda
Prevx1
Rising
Sophos
Sunbelt
Symantec
TheHacker
VBA32
VirusBuster
Webwasher-Gateway
eSafe
eTrust-Vet
Network parameters
IP protocol:
clear
-- select --
Destination port:
clear
-- select --
SG Path:
clear
Sequences
Compact Port Sequence ID:
clear
Extended Port Sequence ID:
clear
Activity type
Backscatter only
Code injection only
Recognized shellcode only
Malware downloaded only
Epsilon-Gamma-Pi-Mu model
Epsilon:
clear
Gamma:
clear
Pi:
clear
Mu:
clear
according to
Source
Injection
Packet
Rate threshold
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
View Others