|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:05:00 | WinXP | 212.233.218.203 (-): NTL, FR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| T:00:06:00 | Win2K-f | 122.52.29.92 (PLDT.NET): IPG, PH. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| T:00:06:00 | Win2K-f | 89.136.63.48 (UPCNET.RO): ASTRAL UPC PLOIESTI, PLOIESTI, PRAHOVA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f [Firefox:32 hits: 06-14 to 06-14] |
none [3] | none:none |
TXT2COM| | none | trace | |
| T:00:12:00 | Win2K-f | 218.220.116.230 (ZAQ.NE.JP): J-COM KANSAI CO. LTD, OSAKA, OSAKA, JP. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:00:14:00 | Win2K-f | 116.123.57.165 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:21:00 | Win2K-f | 61.227.11.186 (HINET.NET): DATA COMMUNICATION BUSINESS GROUP CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| T:00:24:00 | WinXP | 123.50.68.101 (-): MANA INTERNET SERVICE PROVIDER, PAPEETE, FRENCH POLYNESIA, PF. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:31 hits: 09-28 to 06-12] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
| 00:25:00 | WinXP | 211.212.204.222 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:26:00 | Win2K-f | 89.28.18.162 (89-28-0-10.STARNET.MD): STARNET, CHISINAU, CHISINAU, MD. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee [Firefox:25 hits: 06-14 to 06-14] |
none [3] | none:none |
ASPack| | none | trace | |
| T:00:30:00 | Win2K-f | 78.96.184.153 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f [Firefox:32 hits: 06-14 to 06-14] |
none [3] | none:none |
TXT2COM| | none | trace | |
| T:00:30:00 | WinXP | 85.186.122.186 (-): ASTRAL BUZAU CPE, BUZAU, BUZAU, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| 00:31:00 | WinXP | 78.96.84.245 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| T:00:33:00 | Win2K-f | 218.168.71.147 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:49:00 | Win2K-f | 92.114.163.84 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| 00:51:00 | Win2K-f | 92.80.104.202 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f [Firefox:32 hits: 06-14 to 06-14] |
none [3] | none:none |
TXT2COM| | none | trace | |
| 00:52:00 | WinXP | 85.217.136.112 (VT.EVO.BG): EVO IP ADDRESS SPACE, SOFIA, SOFIYA, BG. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:58:00 | Win2K-f | 220.136.247.246 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f [Firefox:32 hits: 06-14 to 06-14] |
none [3] | none:none |
TXT2COM| | none | trace | |
| 01:05:00 | WinXP | 92.49.211.236 (IKBCC.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 3c80772ad2 NEW |
none [3] | none:none |
none|none | none | trace | |
| T:01:08:00 | Win2K-f | 58.124.53.155 (HANANET.NET): HANARO TELECOM INC, KR. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| T:01:12:00 | WinXP | 81.243.157.173 (ISP.BELGACOM.BE): BELGACOM-ADSL, NAMUR, NAMUR, BE. (DSL) |
n/a | :adware.rxmods.net | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 [Firefox:12 hits: 06-14 to 06-14] |
none [3] | none:none |
ASPack| | none | trace |
| 01:14:00 | WinXP | 81.243.157.173 (ISP.BELGACOM.BE): BELGACOM-ADSL, NAMUR, NAMUR, BE. (DSL) |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
17 of 32 | 8ed2e75017 [Firefox:12 hits: 06-14 to 06-14] |
none [3] | none:none |
ASPack| | none | trace | |
| T:01:15:00 | WinXP | 85.66.75.78 (BACS-NET.HU): FIBERNET COMMUNICATION CO, DEBRECEN, HAJDU-BIHAR, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| 01:18:00 | WinXP | 92.84.119.230 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | f7f466aa6f [Firefox:32 hits: 06-14 to 06-14] |
none [3] | none:none |
TXT2COM| | none | trace | |
| T:01:18:00 | Win2K-f | 87.205.178.196 (INETIA.PL): INTERNETIA, KATOWICE, SLASKIE, PL. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
27 of 32 | b65a426bee [Firefox:25 hits: 06-14 to 06-14] |
none [3] | none:none |
ASPack| | none | trace | |
| 01:22:00 | WinXP | 85.67.111.210 (-): FIBERNET, HU. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 | 0f143d3856 [Firefox:86 hits: 06-14 to 06-14] |
none [3] | none:none |
none|none | none | trace | |
| T:01:22:00 | Win2K-f | 78.84.4.201 (MICROLINK.LV): TELEKOM, RIGA, RIGA, LV. |
n/a | 139 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |