|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:16:00 | WinXP | 68.89.232.222 (SWBELL.NET): PPPOX POOL - RBACK1 BUMTTX, BEAUMONT, TEXAS, US. (DIAL) |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.126:80 US:199.93.44.124:80 US:205.128.79.124:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:202 hits: 06-17 to 06-25] 73f1082158 [Firefox:82 hits: 06-18 to 06-25] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:00:19:00 | WinXP | 59.112.141.62 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
217.170.244.2:443 | CZ:217.170.244.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2723 hits: 12-31 to 06-25] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 00:38:00 | Win2K-f | 125.58.75.125 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 |
135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 [Firefox:202 hits: 06-17 to 06-25] b7082104e4 [Firefox: 9 hits: 06-18 to 06-24] |
none [4] none [4] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
| T:00:45:00 | WinXP | 125.58.75.125 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 US:198.78.220.124:80 US:199.93.44.126:80 |
135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 [Firefox:202 hits: 06-17 to 06-25] b7082104e4 [Firefox: 9 hits: 06-18 to 06-24] |
none [4] none [4] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
| T:00:55:00 | Win2K-f | 65.255.191.174 (SPEAKEASY.NET): US. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 0 of 32 |
53bfe15e91 [Firefox:202 hits: 06-17 to 06-25] 73f1082158 [Firefox:82 hits: 06-18 to 06-25] b5919931fe [Firefox:31 hits: 06-20 to 06-25] |
none[4] 73f1082158[1] b5919931fe[1] b5919931fe[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| ASProtect| |
none lines=81 lines=90 |
trace trace trace |
| T:00:59:00 | WinXP | 152.66.57.2 (BME.HU): BUDAPEST UNIVERSITY OF TECHNOLOGY AND ECONOMICS, BUDAPEST, BUDAPEST, HU. |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2723 hits: 12-31 to 06-25] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace | |
| T:01:01:00 | Win2K-f | 116.123.138.219 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com US:192.221.110.126:80 US:192.221.99.124:80 US:199.93.41.124:80 |
135 | pcap | raw alerts ruleset |
other 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 32 of 33 |
0a2b1894da NEW 414b95a784 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| T:01:07:00 | Win2K-f | 218.169.51.23 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:13:00 | Win2K-f | 75.49.225.67 (SBCGLOBAL.NET): PPPOX POOL - BRAS6.STLSMO, SOUTH FORK, MISSOURI, US. (DSL) |
n/a | 135 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:41:00 | WinXP | 116.126.135.34 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:64.62.216.56:80 |
135 | pcap | raw alerts ruleset |
http 106 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 33 0 of 33 31 of 33 |
68bda5c857 NEW e07c29c4ae [Firefox:33 hits: 06-19 to 06-25] f611613956 NEW |
none[none] e07c29c4ae[1] e07c29c4ae[1] none [none] |
none:none ASM:Graph none:none |
none|none FSG| none|none |
none lines=92 none |
none trace none |
| 01:42:00 | Win2K-f | 116.126.135.34 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:64.62.216.56:80 |
135 | pcap | raw alerts ruleset |
other 105 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 33 31 of 33 |
68bda5c857 NEW f611613956 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| T:02:01:00 | WinXP | 122.100.32.143 (-): SEODAEGU CABLE TV, TAEGU, KYONGSANG-BUKTO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 176 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 30 of 33 |
9963e9c1ff NEW a647a60592 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| 02:18:00 | WinXP | 91.124.247.148 (UKRTEL.NET): UKRTELECOM, BROVARY, KYYIVS'KA OBLAST', UA. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 1e5df7ba74 [Firefox:24 hits: 03-24 to 06-18] |
a5331b711f [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| T:02:22:00 | WinXP | 124.100.179.201 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 741e3b03b3 [Firefox:72 hits: 09-28 to 06-25] |
e0197e8a64 [0] | ASM:Graph |
none|none | lines=62 | trace | |
| T:03:02:00 | Win2K-f | 208.77.183.46 (MYCOMSPAN.COM): COMSPAN BANDON NETWORK LLC, BANDON, OREGON, US. |
n/a | US:microsoft.com US:download.microsoft.com US:64.62.216.10:80 US:64.62.216.56:80 |
135 | pcap | raw alerts ruleset |
other 59 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 8 of 33 |
53bfe15e91 [Firefox:202 hits: 06-17 to 06-25] b7082104e4 [Firefox: 9 hits: 06-18 to 06-24] |
none [4] none [4] |
none:none none:none |
tElock| tElock| |
none none |
trace trace |
| 03:06:00 | WinXP | 121.102.210.202 (HI-HO.NE.JP): PANASONIC NETWORK SERVICES INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:656 hits: 07-11 to 06-24] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| T:03:13:00 | WinXP | 65.68.19.187 (-): POPLAR PCS, JONESBORO, ARKANSAS, US. (100Mbps) |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:205.128.66.126:80 |
135 | pcap | raw alerts ruleset |
http 114 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 28 of 32 0 of 33 |
3f0a5b2ebe [Firefox: 3 hits: 06-18 to 06-20] c6bfb5f0f2 [Firefox: 3 hits: 06-18 to 06-20] e07c29c4ae [Firefox:33 hits: 06-19 to 06-25] |
none[4] c6bfb5f0f2[1] e07c29c4ae[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |
PolyEnE| Armadillo| FSG| |
none lines=81 lines=92 |
trace trace trace |
| 03:45:00 | Win2K-f | 202.157.62.37 (KCN-TV.NE.JP): KUMAMOTO CABLE NETWORK CORPORATION, JP. |
n/a | US:microsoft.com US:download.microsoft.com US:64.62.216.10:80 US:64.62.216.56:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:202 hits: 06-17 to 06-25] 73f1082158 [Firefox:82 hits: 06-18 to 06-25] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 03:58:00 | Win2K-f | 211.74.249.230 (SEED.NET.TW): DIGITAL UNITED INC, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2723 hits: 12-31 to 06-25] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 04:05:00 | WinXP | 118.237.15.107 (-): . |
n/a | 445 | pcap |