|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:05:00 | WinXP | 12.214.237.156 (MCHSI.COM): MEDIACOM COMMUNICATIONS CORP, CHENOA, ILLINOIS, US. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:44 hits: 09-28 to 06-20] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
| T:00:06:00 | WinXP | 70.74.202.183 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. |
72.10.172.218:7382 | CA:italian.swiifatecihno.com CA:done.blacktiehsbdcs.com CA:fuck.urpal43sourpalhuh.com CA:72.10.169.26:3938 CA:72.10.172.218:7382 CA:72.10.172.218:7763 |
135 | pcap | raw alerts ruleset |
other 589 lines |
Yeah : 1.8 profile |
none | summary tarball |
28 of 30 | 2aa59ba425 [Firefox:43 hits: 06-30 to 06-19] |
2aa59ba425 [1] | ASM:Graph |
ASPack| | lines=10 | trace |
| T:00:20:00 | WinXP | 86.11.100.247 (NTL.COM): NTL INFRASTRUCTURE - BROMLEY, LONDON, ENGLAND, UK. (DSL) |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | f41d65b459 [Firefox:78 hits: 08-28 to 06-19] |
none [3] | none:none |
PolyEnE| | none | trace |
| 00:21:00 | WinXP | 86.11.100.247 (NTL.COM): NTL INFRASTRUCTURE - BROMLEY, LONDON, ENGLAND, UK. (DSL) |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | f41d65b459 [Firefox:78 hits: 08-28 to 06-19] |
none [3] | none:none |
PolyEnE| | none | trace |
| 00:38:00 | Win2K-f | 222.239.30.74 (-): INCHON CABLE TV NAMDONG BROADCAST, INCHON, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.126:80 US:199.93.41.126:80 US:205.128.66.124:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 [Firefox:10 hits: 06-17 to 06-20] 53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| T:00:53:00 | WinXP | 87.61.169.4 (IP.TELE.DK): TDC-TELEDANMARK-BREDBAANDSADSL-NET, DK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | c05385e600 [Firefox:19 hits: 06-24 to 06-19] |
6a383b021d [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| T:00:54:00 | WinXP | 58.52.129.190 (163DATA.COM.CN): CHINANET HUBEI PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:00:55:00 | Win2K-f | 70.62.67.113 (RR.COM): ROAD RUNNER HOLDCO LLC, COLUMBIA, SOUTH CAROLINA, US. |
n/a | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com US:204.2.160.90:80 US:204.2.160.91:80 |
135 | pcap | raw alerts ruleset |
other 188 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
2110c8100f NEW 89366f61bb NEW |
none[4] 89366f61bb[1] 89366f61bb[1] |
none:none ASM:Graph |
PolyEnE| Armadillo| |
none lines=81 |
trace trace |
| 00:58:00 | WinXP | 122.148.40.194 (DODO.COM.AU): LAYER 2 BROADBAND CUSTOMER NETWORK, AU. |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.160.90:80 US:204.2.160.91:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 73f1082158 [Firefox:34 hits: 06-18 to 06-20] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:00:59:00 | WinXP | 41.214.180.203 (-): . |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 32 | a3f358bd55 [Firefox: 6 hits: 08-25 to 06-19] |
none [4] | none:none |
PolyEnE| | none | trace |
| 01:05:00 | WinXP | 99.164.38.227 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.160.90:80 US:204.2.160.91:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] a08f3b74a4 [Firefox:34 hits: 06-18 to 06-20] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:01:23:00 | WinXP | 218.169.57.37 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell shell ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| T:02:01:00 | WinXP | 218.52.172.96 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.124:80 US:205.128.66.124:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 [Firefox:10 hits: 06-17 to 06-20] 53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| 02:18:00 | Win2K-f | 12.74.162.108 (ATT.NET): AT&T WORLDNET SERVICES, ALABAMA, US. (DIAL) |
12.74.162.108:21 | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.8 profile |
none | summary tarball |
none | c8f6429e83 NEW |
none [4] | none:none |
FSG| | none | trace | |
| T:04:12:00 | Win2K-f | 118.231.76.116 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2667 hits: 12-31 to 06-20] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| T:04:12:00 | WinXP | 41.214.135.124 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 04:13:00 | WinXP | 64.134.122.161 (WAYPORT.NET): WAYPORT INC, AUSTIN, TEXAS, US. |
n/a | US:microsoft.com US:download.microsoft.com CA:64.86.142.18:80 CA:64.86.142.27:80 |
135 | pcap | raw alerts ruleset |
other 85 lines |
Yeah : 1.3 profile |
none | summary tarball |
none 33 of 33 |
3ed16ae12d NEW 79c01ec060 [Firefox: 2 hits: 06-18 to 06-19] |
3ed16ae12d [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| T:04:27:00 | WinXP | 86.155.8.231 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:651 hits: 07-11 to 06-20] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| 04:30:00 | Win2K-f | 61.218.193.250 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.44.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 04:39:00 | WinXP | 121.254.95.217 (TCOL.COM.TW): MONAD DIGITNAMIC CORP, TW. |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:205.128.66.126:80 US:206.33.45.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:105 hits: 06-17 to 06-20] 57ce4acac2 [Firefox:16 hits: 06-17 to 06-20] |
none[4] 57ce4acac2[1] 57ce4acac2[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 04:42:00 | WinXP | 86.140.230.154 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | 445 |