|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:10:00 | WinXP | 70.69.77.203 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, MAPLE RIDGE, BRITISH COLUMBIA, CA. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 236 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | b9cdf4ca69 NEW |
none [4] | none:none |
none|none | none | trace | |
| 00:30:00 | Win2K-f | 71.136.17.66 (-): MILANO DESIGN, PLANO, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.133.57:80 |
135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
3 of 33 33 of 33 |
73ce2b74da NEW 79c01ec060 [Firefox: 2 hits: 06-18 to 06-19] |
73ce2b74da [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| 00:31:00 | WinXP | 4.248.64.47 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, BELLEVILLE, NEW JERSEY, US. (DIAL) |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.133.43:80 US:204.2.133.57:80 US:204.2.133.73:80 US:204.2.133.81:80 |
135 | pcap | raw alerts ruleset |
other 104 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:123 hits: 06-17 to 06-21] 73f1082158 [Firefox:43 hits: 06-18 to 06-21] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 00:43:00 | Win2K-f | 68.179.126.170 (TERAGO.CA): TERAGO NETWORKS INC, EVANSVILLE, INDIANA, US. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:192.221.99.124:80 US:199.93.53.126:80 US:205.128.79.124:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 29 of 33 |
196b916474 [Firefox: 2 hits: 06-18 to 06-21] d0ad254fd0 [Firefox: 2 hits: 06-18 to 06-21] |
none[4] d0ad254fd0[1] d0ad254fd0[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 00:51:00 | Win2K-f | 202.87.42.232 (NETMAGICSOLUTIONS.COM): NETMAGIC DATACENTER, IN. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.126:80 US:199.93.44.124:80 US:204.160.126.126:80 |
135 | pcap | raw alerts ruleset |
other 112 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 28 of 32 |
133401d618 [Firefox: 2 hits: 06-18 to 06-21] 847d491ed3 NEW |
none[4] 847d491ed3[1] 847d491ed3[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
| 01:12:00 | WinXP | 24.39.10.215 (RR.COM): ROAD RUNNER HOLDCO LLC, SACO, MAINE, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 10 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:17:00 | WinXP | 92.40.214.55 (IKBCC.COM): EU-ZZ, UK. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 33 | ef846e4a0a [Firefox: 2 hits: 06-18 to 06-18] |
none [4] | none:none |
PolyEnE| | none | trace |
| 01:18:00 | WinXP | 92.40.214.55 (IKBCC.COM): EU-ZZ, UK. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 33 | ef846e4a0a [Firefox: 2 hits: 06-18 to 06-18] |
none [4] | none:none |
PolyEnE| | none | trace |
| T:01:26:00 | WinXP | 93.156.48.67 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3077 hits: 12-31 to 06-21] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| 01:35:00 | WinXP | 98.140.251.237 (-): . |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:301 hits: 05-01 to 06-21] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
| T:01:45:00 | Win2K-f | 67.116.236.69 (-): PPPOX POOL - RBACK1.PLTNCA 05182006-1157, VACAVILLE, CALIFORNIA, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 02:17:00 | WinXP | 4.254.162.55 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.79.125:80 US:207.123.37.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 74 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 [Firefox:123 hits: 06-17 to 06-21] b7082104e4 [Firefox: 7 hits: 06-18 to 06-20] |
none [4] none [4] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
| 02:19:00 | Win2K-f | 61.37.147.200 (BORA.NET): DACOM CORP, SEOUL, KYONGGI-DO, KR. (100Mbps) |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:205.128.79.125:80 US:207.123.37.126:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 30 of 33 |
3690b64ca2 [Firefox: 2 hits: 06-18 to 06-21] a6fb77fd26 [Firefox: 2 hits: 06-18 to 06-21] |
none[4] a6fb77fd26[1] a6fb77fd26[1] |
none:none ASM:Graph |
PolyEnE| Armadillo| |
none lines=82 |
trace trace |
| 02:42:00 | WinXP | 218.239.93.139 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 US:199.93.46.126:80 US:207.123.37.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 [Firefox:16 hits: 06-17 to 06-21] 53bfe15e91 [Firefox:123 hits: 06-17 to 06-21] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| 03:04:00 | Win2K-f | 87.19.37.238 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, REGGIO EMILIA, EMILIA-ROMAGNA, IT. |
n/a | US:hail.dns2go.com **:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1522 hits: 04-27 to 06-18] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| 03:22:00 | WinXP | 65.68.44.78 (SWBELL.NET): AT&T INTERNET SERVICES, KANSAS CITY, MISSOURI, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 28 of 32 |
3f0a5b2ebe [Firefox: 3 hits: 06-18 to 06-20] c6bfb5f0f2 [Firefox: 3 hits: 06-18 to 06-20] |
none[4] c6bfb5f0f2[1] c6bfb5f0f2[1] |
none:none ASM:Graph |
PolyEnE| Armadillo| |
none lines=81 |
trace trace |
|
| 03:33:00 | WinXP | 118.160.22.63 (-): . |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | f43bfbc3bd NEW |
none [4] | none:none |
PolyEnE| | none | trace |
| 03:37:00 | WinXP | 124.85.165.93 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:52 hits: 09-28 to 06-21] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
| T:03:41:00 | Win2K-f | 210.108.201.141 (BORA.NET): BORANET-NET, ULSAN, KYONGSANG-NAMDO, KR. |
n/a | 135 | pcap | raw alerts ruleset |
other 111 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:03:55:00 | WinXP | 80.102.20.87 (DYNAMIC.ORANGE.ES): UNI2 IP DATA NETWORK, SEVILLA, ANDALUCIA, ES. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
26 of 28 | 7d99b0e910 [Firefox:3077 hits: 12-31 to 06-21] |
7a70e1b592 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| 03:56:00 | WinXP | 80.102.20.87 (DYNAMIC.ORANGE.ES): UNI2 IP DATA NETWORK, SEVILLA, ANDALUCIA, ES. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
23 of 32 |