|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:14:00 | WinXP | 87.68.77.136 (012.NET.IL): GOLDENLINES-CABLE, IL. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2734 hits: 12-31 to 06-26] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 00:37:00 | WinXP | 92.80.142.51 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | 5a387593a6 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:37:00 | WinXP | 92.80.142.51 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | 5a387593a6 NEW |
none [none] | none:none |
none|none | none | none |
| 00:45:00 | Win2K-f | 222.239.30.93 (-): INCHON CABLE TV NAMDONG BROADCAST, INCHON, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com US:12.190.48.97:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 33 of 33 |
4c3df24b32 [Firefox:23 hits: 06-17 to 06-26] 53bfe15e91 [Firefox:228 hits: 06-17 to 06-26] |
4c3df24b32 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| T:01:04:00 | Win2K-f | 220.138.38.170 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 23 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:14:00 | WinXP | 118.168.2.62 (-): . |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2734 hits: 12-31 to 06-26] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 01:15:00 | WinXP | 86.155.14.87 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, SWANSEA, WALES, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:660 hits: 07-11 to 06-26] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| T:01:45:00 | Win2K-f | 122.146.121.164 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TW. |
n/a | CA:xx.ka3ek.com CA:nadsam0.info US:130.107.249.41:13412 |
135 | pcap | raw alerts ruleset |
irc http 458 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 13 of 33 none none none |
9d0f01f733 NEW a136e2219a NEW a2cf5b71d9 NEW c5622bb285 [Firefox: 3 hits: 06-23 to 06-23] ee20b91263 NEW |
none [none] none [none] none [none] none [4] none [none] |
none:none none:none none:none none:none none:none |
none|none none|none none|none none|none none|none |
none none none none none |
none none none trace none |
| 02:00:00 | Win2K-f | 118.231.100.207 (-): . |
n/a | PL:proxim.ircgalaxy.pl CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | 4a5caa8503 NEW |
none [none] | none:none |
none|none | none | none |
| 02:04:00 | WinXP | 66.153.173.250 (SCCOAST.NET): HTC - CABLE MODEM POOL, CONWAY, SOUTH CAROLINA, US. (DSL) |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 321052074e [Firefox:17 hits: 09-29 to 04-28] |
1a587de3ca [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
| T:02:05:00 | WinXP | 66.153.173.250 (SCCOAST.NET): HTC - CABLE MODEM POOL, CONWAY, SOUTH CAROLINA, US. (DSL) |
n/a | RU:moscow-advokat.ru RU:194.6.222.11:6667 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
31 of 32 | 321052074e [Firefox:17 hits: 09-29 to 04-28] |
1a587de3ca [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
| T:02:10:00 | Win2K-f | 71.7.196.121 (EASTLINK.CA): EASTLINK, HALIFAX, NOVA SCOTIA, CA. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.125:80 US:205.128.79.124:80 US:4.23.60.126:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:228 hits: 06-17 to 06-26] a08f3b74a4 [Firefox:81 hits: 06-18 to 06-26] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 02:15:00 | WinXP | 144.138.160.178 (TMNS.NET.AU): TELSTRAINTERNET31, CANBERRA, AUSTRALIAN CAPITAL TERRITORY, AU. |
n/a | 135 | pcap | raw alerts ruleset |
other 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 02:22:00 | WinXP | 222.148.207.140 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2734 hits: 12-31 to 06-26] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 02:38:00 | WinXP | 78.35.7.82 (NETCOLOGNE.DE): NETCOLOGNE, DE. |
n/a | US:hail.dns2go.com SA:scorti1.dns2go.com US:208.101.48.210:7000 CN:61.185.73.17:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1534 hits: 04-27 to 06-26] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| 02:43:00 | Win2K-f | 75.79.5.106 (-): . |
n/a | US:microsoft.com US:download.microsoft.com US:204.2.133.57:80 US:204.2.133.73:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:228 hits: 06-17 to 06-26] a08f3b74a4 [Firefox:81 hits: 06-18 to 06-26] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 03:45:00 | Win2K-f | 59.190.53.77 (EONET.NE.JP): K-OPTICOM CORPORATION, OSAKA, OSAKA, JP. |
n/a | US:hail.dns2go.com SA:scorti1.dns2go.com US:208.101.48.210:7000 CN:61.185.73.17:7000 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
12 of 30 | 76b4ab852e [Firefox:59 hits: 04-29 to 06-25] |
none [4] | none:none |
none|none | none | trace |
| 03:47:00 | WinXP | 58.107.120.11 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, SYDNEY, NEW SOUTH WALES, AU. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b [Firefox:722 hits: 05-01 to 06-25] |
462a7be171 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
| T:03:47:00 | WinXP | 58.107.120.11 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, SYDNEY, NEW SOUTH WALES, AU. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 3ae357d17b [Firefox:722 hits: 05-01 to 06-25] |
462a7be171 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
| T:03:48:00 | WinXP | 4.245.113.19 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SPARKS, NEVADA, US. (DIAL) |
n/a | US:microsoft.com US:download.microsoft.com US:198.78.220.124:80 US:205.128.79.125:80 US:206.33.45.125:80 |
135 | pcap | raw alerts ruleset |
other 78 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:228 hits: 06-17 to 06-26] 73f1082158 [Firefox:91 hits: 06-18 to 06-26] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:04:04:00 | Win2K-f | 61.231.161.203 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAOYUAN, T'AI-WAN, TW. |
217.170.244.2:443 | CZ:217.170.244.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2734 hits: 12-31 to 06-26] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 04:09:00 | WinXP | 71.105.247.58 (VERIZON.NET): VERIZON INTERNET SERVICES INC, LONG BEACH, CALIFORNIA, US. (DSL) |
n/a | PL:proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:199.93.41.124:80 US:204.160.126.124:80 US:205.128.79.125:80 |
135 | pcap | raw alerts ruleset |