|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| T:00:13:00 | Win2K-f | 79.119.97.0 (RDSNET.RO): RDS, BUCHAREST, BUCURESTI, RO. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1522 hits: 04-27 to 06-18] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| T:01:23:00 | Win2K-f | 116.125.161.168 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:34:00 | Win2K-f | 216.201.9.151 (BRIGHT.NET): TSC, WAPAKONETA, OHIO, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 108 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:52:00 | Win2K-f | 70.164.249.57 (COX.NET): COX COMMUNICATIONS, TUCSON, ARIZONA, US. |
n/a | DE:d.vncsvr.net | 135 | pcap | raw alerts ruleset |
irc 218 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 33 | 4580d3e452 NEW |
4580d3e452 [1] | ASM:Graph |
StarForce| | lines=2 | trace |
| T:02:13:00 | Win2K-f | 61.116.193.14 (ODN.AD.JP): OPEN DATA NETWORK(JAPAN TELECOM CO. LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 0db5ae4dc2 NEW |
none [3] | none:none |
PolyEnE| | none | trace | |
| T:02:24:00 | WinXP | 60.53.138.237 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, KOTA KINABALU, SABAH, MY. |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | a2a036466a [Firefox:268 hits: 05-05 to 06-17] |
none [4] | none:none |
none|none | none | trace |
| T:02:34:00 | WinXP | 62.11.117.42 (DIALUP.TISCALI.IT): TISCALI ITALIA SPA, IT. (DIAL) |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com GB:new.egg.com :wpad RU:www.bbin.ru RU:195.200.213.52:80 DE:212.227.111.29:80 DE:217.11.54.126:80 GB:217.145.225.22:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | df17a625ee [Firefox:470 hits: 05-04 to 06-21] |
9bbdd086c5 [0] | ASM:Graph |
ASPack| | lines=186 embedded dns |
trace |
| T:03:08:00 | WinXP | 75.79.5.20 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:03:29:00 | WinXP | 124.98.224.2 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:52 hits: 09-28 to 06-21] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
| T:03:38:00 | Win2K-f | 61.209.155.25 (ODN.AD.JP): OPEN DATA NETWORK(JAPAN TELECOM CO. LTD.), TOKYO, TOKYO, JP. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | b39dc45f85 NEW |
none [4] | none:none |
PolyEnE| | none | trace | |
| T:04:18:00 | WinXP | 71.101.177.6 (VERIZON.NET): VERIZON INTERNET SERVICES INC, PALMETTO, FLORIDA, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:05:45:00 | Win2K-f | 87.61.136.189 (IP.TELE.DK): TELEDANMARK, COPENHAGEN, COPENHAGEN, DK. |
n/a | US:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 4f887ca272 [Firefox:38 hits: 01-26 to 06-17] |
4f887ca272 [1] | ASM:Graph |
Stranik| | lines=6 | trace |
| T:06:03:00 | Win2K-f | 122.146.80.197 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:07:36:00 | WinXP | 218.211.222.153 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH CO. LTD, KAOHSIUNG, KAO-HSIUNG, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:07:55:00 | Win2K-f | 61.34.136.15 (BORA.NET): DACOM CORP, SEOUL, KYONGGI-DO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:08:16:00 | WinXP | 98.140.229.160 (-): . |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:08:48:00 | Win2K-f | 78.159.132.137 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | US:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | f515fcc0f7 [Firefox:16 hits: 12-28 to 06-17] |
dc7696e295 [0] | ASM:Graph |
ASProtect| | lines=422 embedded dns |
trace |
| T:09:36:00 | Win2K-f | 117.195.168.154 (-): . |
n/a | US:hail.dns2go.com US:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1522 hits: 04-27 to 06-18] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| T:10:05:00 | WinXP | 70.182.30.253 (COX.NET): COX COMMUNICATIONS, FT. SMITH, ARKANSAS, US. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3077 hits: 12-31 to 06-21] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| 10:17:00 | Win2K-f | 24.66.43.94 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, WINNIPEG, MANITOBA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 10:33:00 | WinXP | 220.210.232.71 (MEGAEGG.NE.JP): ENERGIA COMMUNICATIONS INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | 56f53343ce NEW |
none [4] | none:none |
PolyEnE| | none | trace | |
| T:10:42:00 | Win2K-f | 85.96.31.162 (TTNET.NET.TR): ADSL-ALC-IZMIR-DYNAMIC POOL, ISTANBUL, ISTANBUL, TR. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 33 | 8907c36532 NEW |
none [2] | none:none |
ASPack| | none | trace | |
| 10:55:00 | WinXP | 63.27.1.35 (UU.NET): UUNET TECHNOLOGIES INC, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 11:14:00 | WinXP | 24.39.233.58 (RR.COM): ROAD RUNNER HOLDCO LLC, BATAVIA, NEW YORK, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 11:19:00 | WinXP | 67.9.254.40 (RR.COM): ROAD RUNNER HOLDCO LLC, HOUSTON, TEXAS, US. |
n/a | DE:siliconfireware.ru US:searchportal.information.com US:spi.domainsponsor.com :landdev1.lap.internal GB:new.egg.com :wpad |
445 | pcap | raw alerts ruleset |
http http http http 33 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1064 hits: 05-01 to 06-21] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
| 11:39:00 | Win2K-f | 208.127.141.220 (DSLEXTREME.COM): DSL EXTREME, WINNETKA, CALIFORNIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 11:44:00 | WinXP | 151.118.180.184 (QWEST.NET): QWEST BROADBAND, PHOENIX, ARIZONA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:11:52:00 | Win2K-f | 70.183.185.151 (COX.NET): COX COMMUNICATIONS, BATON ROUGE, LOUISIANA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 |