|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| T:00:16:00 | WinXP | 61.230.86.191 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
217.170.244.2:443 | :proxim.ircgalaxy.pl CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 | 3e0b734da7 NEW |
none [4] | none:none |
FSG| | none | trace |
| 00:32:00 | WinXP | 69.148.180.38 (SWBELL.NET): PPPOX POOL - BRAS1 STLSMO, ST. LOUIS, MISSOURI, US. |
n/a | DE:siliconfireware.ru SE:kavkazcenter.com SE:kavkazcenter.net FI:kavkazchat.com US:chechenpress.info GB:chechenpress.co.uk US:shaheeds.org :daymohk.info :chripress.org :marsho.dk EU:ebookfinaltrash.ru :wpad DE:212.227.111.29:80 US:216.52.184.243:80 DE:217.11.54.126:80 GB:217.194.210.198:80 US:72.29.65.216:80 EU:78.47.200.154:80 FI:80.81.183.162:80 SE:88.80.5.157:80 SE:88.80.5.15:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | ab5e47bf8d [Firefox:49 hits: 05-10 to 06-20] |
none [3] | none:none |
ASPack| | none | trace |
| T:00:45:00 | WinXP | 118.237.51.169 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 27b945de66 NEW |
none [4] | none:none |
none|none | none | trace | |
| T:00:49:00 | WinXP | 24.64.242.103 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, CALGARY, ALBERTA, CA. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:207.123.46.126:80 |
135 | pcap | raw alerts ruleset |
http 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 23 of 33 |
bca9e0fb5f [Firefox: 2 hits: 06-18 to 06-18] e53a9ea82e [Firefox: 2 hits: 06-18 to 06-18] |
none[4] e53a9ea82e[1] e53a9ea82e[1] |
none:none ASM:Graph |
PolyEnE| Armadillo| |
none lines=81 |
trace trace |
| T:00:52:00 | Win2K-f | 211.135.43.56 (ZAQ.NE.JP): KEIHAN CABLE TELEVISION CO. LTD, JP. |
n/a | US:microsoft.com US:download.microsoft.com US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 33 of 33 |
07fabc79ef NEW 53bfe15e91 [Firefox:123 hits: 06-17 to 06-21] |
07fabc79ef [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| T:01:02:00 | WinXP | 122.50.177.165 (EXATT.NET): INTERNET SERVICE PROVIDER, BHUBANESHWAR, ORISSA, IN. |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:15:00 | WinXP | 119.72.44.112 (-): . |
n/a | :proxim.ircgalaxy.pl CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 | 721088fe83 NEW |
none [4] | none:none |
FSG| | none | trace |
| T:01:28:00 | WinXP | 85.181.58.145 (ALICEDSL.DE): HANSENET-ADSL, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell 5 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:30:00 | WinXP | 65.86.192.131 (-): NOVICK EDELSTEIN ET AL, YONKERS, NEW YORK, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:199.93.46.125:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:123 hits: 06-17 to 06-21] 73f1082158 [Firefox:43 hits: 06-18 to 06-21] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:01:36:00 | WinXP | 4.232.171.211 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, LONG BEACH, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:38:00 | Win2K-f | 24.76.71.117 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, BURNABY, BRITISH COLUMBIA, CA. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:207.123.46.125:80 US:4.23.60.125:80 |
135 | pcap | raw alerts ruleset |
http 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
28 of 33 30 of 33 0 of 32 |
12df83cb4f NEW 2e7dc3f066 NEW b5919931fe [Firefox:17 hits: 06-20 to 06-21] |
12df83cb4f [1] none [4] b5919931fe[1] b5919931fe[1] |
ASM:Graph none:none ASM:Graph |
Armadillo| tElock| ASProtect| |
lines=82 none lines=90 |
trace trace trace |
| 01:49:00 | Win2K-f | 218.168.170.95 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2679 hits: 12-31 to 06-21] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| T:01:57:00 | WinXP | 79.111.154.26 (G-M-I.NET): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:653 hits: 07-11 to 06-21] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| 02:07:00 | WinXP | 61.255.159.186 (HAEDONGTEK.CO.KR): THRUNET CO. LTD, SEOUL, KYONGGI-DO, KR. |
n/a | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:205.128.66.126:80 US:4.23.60.125:80 US:8.12.202.125:80 |
135 | pcap | raw alerts ruleset |
other 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 30 of 32 |
475d9a7753 NEW e9a7fa27d5 NEW |
none[4] e9a7fa27d5[1] e9a7fa27d5[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
| 02:29:00 | WinXP | 220.130.194.247 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 02:33:00 | WinXP | 212.27.0.26 (-): ALIKS-TELECOM COMPANY, MOSCOW, MOSKVA, RU. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 31 | ed6e30072f NEW |
none [4] | none:none |
PolyEnE| | none | trace |
| T:02:33:00 | WinXP | 212.27.0.26 (-): ALIKS-TELECOM COMPANY, MOSCOW, MOSKVA, RU. |
194.54.90.246:80 | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 31 | ed6e30072f NEW |
none [4] | none:none |
PolyEnE| | none | trace |
| T:02:42:00 | WinXP | 210.206.10.17 (KONICS.COM): BORANET-NET-210-206/, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 115 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 32 28 of 32 |
a1a5fa95b9 NEW e655846fa1 NEW |
none[4] e655846fa1[1] e655846fa1[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
| T:02:44:00 | Win2K-f | 70.67.174.63 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, DUNCAN, BRITISH COLUMBIA, CA. |
72.10.172.218:7382 | CA:italian.swiifatecihno.com | 135 | pcap | raw alerts ruleset |
irc http 587 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8acd7e1937 NEW f33628ba56 NEW |
8acd7e1937 [1] f33628ba56[1] f33628ba56[1] |
ASM:Graph ASM:Graph |
none|none ASPack| |
lines=0 lines=10 |
trace trace |
| T:02:44:00 | Win2K-f | 220.139.170.166 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:02:50:00 | Win2K-f | 222.234.97.168 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
72.10.172.218:7382 | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:207.123.37.125:80 |
135 | pcap | raw alerts ruleset |
http 98 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 30 of 32 |
1509c8d024 NEW f23b040440 NEW |
none[4] f23b040440[1] f23b040440[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
| 03:12:00 | WinXP | 122.30.229.204 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |