|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:15:00 | WinXP | 222.15.161.102 (DION.NE.JP): DION (KDDI CORPORATION), JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:64 hits: 09-28 to 06-24] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
| T:00:18:00 | Win2K-f | 217.229.112.143 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, DE. (DIAL) |
n/a | US:hail.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
12 of 30 | 76b4ab852e [Firefox:58 hits: 04-29 to 06-08] |
none [4] | none:none |
none|none | none | trace |
| 00:23:00 | WinXP | 77.253.253.77 (COM.PL): NETIA, PL. |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 31 | 4ab5b0788c [Firefox:12 hits: 04-21 to 06-21] |
272da55ef8 [0] | ASM:Graph |
PolyEnE| | lines=114 | trace |
| 00:26:00 | Win2K-f | 71.2.176.27 (EMBARQHSD.NET): EMBARQ CORPORATION, CHANDLER, TEXAS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:32:00 | WinXP | 87.205.192.157 (INETIA.PL): INTERNETIA, PL. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
32 of 33 | ef641cacaa NEW |
none [none] | none:none |
none|none | none | none |
| 00:41:00 | WinXP | 121.15.111.10 (163DATA.COM.CN): CHINANET GUANGDONG PROVINCE NETWORK, GUANGZHOU, GUANGDONG, CN. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | f502585714 [Firefox:87 hits: 05-03 to 06-19] |
ae590430c5 [0] | ASM:Graph |
PolyEnE| | lines=63 | trace |
| T:00:49:00 | WinXP | 85.26.62.59 (217-117-34-10.TELEDISNET.BE): TELEDISNET ISP, BE. |
n/a | US:hail.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 22 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1522 hits: 04-27 to 06-18] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| T:00:51:00 | WinXP | 123.214.204.138 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:192.221.99.124:80 US:205.128.66.126:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
24 of 33 32 of 33 |
740e3bffe0 NEW 76dc1c23e1 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| 00:56:00 | Win2K-f | 216.27.114.73 (PRIMELINK1.NET): PRIMELINK INC, PLATTSBURGH, NEW YORK, US. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:205.128.66.126:80 |
135 | pcap | raw alerts ruleset |
other 116 lines |
Yeah : 1.3 profile |
none | summary tarball |
none none |
dc20b6fe59 NEW f97070ef2b NEW |
dc20b6fe59 [1] none [4] |
ASM:Graph none:none |
Armadillo| PolyEnE| |
lines=81 none |
trace trace |
| 00:56:00 | WinXP | 122.118.10.65 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | US:hail.dns2go.com CN:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1522 hits: 04-27 to 06-18] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| 00:59:00 | Win2K-f | 92.113.35.140 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2715 hits: 12-31 to 06-24] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 01:01:00 | WinXP | 218.168.173.221 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:01:00 | Win2K-f | 89.146.164.67 (NET.BA): BRAS PPPOE POOL UPGRADE, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. |
n/a | CN:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
11 of 32 | e5d062be59 [Firefox:10 hits: 12-28 to 06-10] |
none [4] | none:none |
ASPack| | none | trace |
| T:01:03:00 | Win2K-f | 87.196.99.151 (NET.NOVIS.PT): NOVIS TELECOM S.A, LISBON, LISBOA, PT. (DSL) |
n/a | US:hail.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 26 lines |
Yeah : 0.8 profile |
none | summary tarball |
30 of 33 | 78206cf024 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:04:00 | WinXP | 85.186.76.138 (-): ASTRAL ZALAU DOCSIS, RO. (100Mbps) |
n/a | CN:scorti1.dns2go.com | 445 | pcap | raw alerts ruleset |
ftp irc 40 lines |
Yeah : 0.8 profile |
none | summary tarball |
14 of 32 | 8f367186c3 [Firefox:92 hits: 12-27 to 06-17] |
01a06977c4 [0] | ASM:Graph |
TXT2COM| | lines=0 | trace |
| 01:14:00 | WinXP | 123.213.15.53 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:64.62.216.10:80 US:64.62.216.56:80 |
135 | pcap | raw alerts ruleset |
other 125 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 29 of 33 |
ae0d40ac58 NEW fc0aa80688 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| T:01:25:00 | WinXP | 4.226.75.224 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, US. (DIAL) |
n/a | 135 | pcap | raw alerts ruleset |
other 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:26:00 | WinXP | 217.156.118.105 (TOPNET.RO): ELCOMINTERNATIONAL SA, RO. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 4f887ca272 [Firefox:38 hits: 01-26 to 06-17] |
4f887ca272 [1] | ASM:Graph |
Stranik| | lines=6 | trace | |
| 01:37:00 | Win2K-f | 218.86.236.21 (AGENT1.GZ.CN): CHINANET GUIZHOU PROVINCE NETWORK, GUIZHOU, GUIZHOU, CN. |
n/a | 135 | pcap | raw alerts ruleset |
other 179 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 4f8d6c0a4d NEW |
none [4] | none:none |
none|none | none | trace | |
| 01:40:00 | WinXP | 60.53.22.168 (TM.NET.MY): TELEKOM MALAYSIA BERHAD, MALACCA, MELAKA, MY. (DIAL) |
n/a | US:hail.dns2go.com CN:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1522 hits: 04-27 to 06-18] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| 01:42:00 | WinXP | 85.152.148.137 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | d3c8b52b45 NEW |
none [4] | none:none |
PolyEnE| | none | trace |
| T:01:43:00 | WinXP | 85.152.148.137 (CM-85-152-150-10.TELECABLE.ES): TELECABLE, GIJON, ASTURIAS, ES. (DSL) |
n/a | :proxim.ircgalaxy.pl UA:citi-bank.ru |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | d3c8b52b45 NEW |
none [4] | none:none |
PolyEnE| | none | trace |
| 02:10:00 | Win2K-f | 89.166.185.165 (OSNANET.DE): OSNATEL-SUBNET FOR ADSL DIAL-UP, FARSUND, VEST-AGDER, NO. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 02:18:00 | WinXP | 77.64.172.254 (PRIMACOM.NET): PRIMACOM-HEADENDS, LEIPZIG, SACHSEN, DE. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:303 hits: 05-01 to 06-24] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
| 02:27:00 | Win2K-f | 88.19.188.96 (RIMA-TDE.NET): TELEFONICA DE ESPANA, ES. |
n/a | CN:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
13 of 32 |