|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| T:00:07:00 | Win2K-f | 77.20.209.218 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | d601941576 NEW |
none [none] | none:none |
none|none | none | none | |
| 00:20:00 | WinXP | 123.254.2.25 (PIKARA.NE.JP): STNET INCORPORATED, TAKAMATSU, KAGAWA, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox: 9 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none |
| T:00:20:00 | Win2K-f | 118.240.193.171 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox: 9 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none | |
| T:00:21:00 | Win2K-f | 118.237.17.166 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | da36e2acf7 NEW |
none [none] | none:none |
none|none | none | none | |
| 00:22:00 | WinXP | 60.239.55.63 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:662 hits: 07-11 to 06-27] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| 00:22:00 | Win2K-f | 85.179.18.67 (ALICEDSL.DE): HANSENET-ADSL, DE. (DSL) |
n/a | :proxim.ircgalaxy.pl US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 32 | 80887f3824 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:23:00 | Win2K-f | 220.102.214.109 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:12 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none | |
| 00:26:00 | WinXP | 59.103.14.57 (-): . |
n/a | DE:siliconfireware.ru GB:welcome3.smile.co.uk :wpad GB:195.92.84.198:80 DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1073 hits: 05-01 to 06-27] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
| 00:27:00 | Win2K-f | 222.146.121.197 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | 9d32aaa9ba NEW |
none [none] | none:none |
none|none | none | none |
| T:00:29:00 | WinXP | 220.138.39.229 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2746 hits: 12-31 to 06-27] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace | |
| T:00:31:00 | Win2K-f | 217.30.154.30 (NET.PL): STATIC BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:12 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none | |
| T:00:32:00 | Win2K-f | 91.64.178.71 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 | 037d04feed NEW |
none [none] | none:none |
none|none | none | none | |
| T:00:33:00 | WinXP | 78.97.26.164 (ASTRAL.RO): ASTRAL TELECOM SA, RO. |
69.247.147.113:13001 | US:chat-shqip.org | 445 | pcap | raw alerts ruleset |
ftp irc 46 lines |
Yeah : 1.8 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox: 9 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none |
| 00:40:00 | Win2K-f | 218.43.172.21 (OCN.NE.JP): OPEN COMPUTER NETWORK, SASEBO, NAGASAKI, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox: 5 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none |
| 00:45:00 | Win2K-f | 77.20.208.195 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
other 24 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
| T:00:48:00 | Win2K-f | 221.188.188.11 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox: 9 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none | |
| T:00:49:00 | WinXP | 118.6.139.236 (-): . |
69.247.147.113:12351 | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp irc 49 lines |
Yeah : 1.8 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox: 5 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none |
| T:00:53:00 | WinXP | 123.254.9.137 (PIKARA.NE.JP): STNET INCORPORATED, TAKAMATSU, KAGAWA, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | e3460d2a4a NEW |
none [none] | none:none |
none|none | none | none | |
| 00:54:00 | Win2K-f | 210.151.139.129 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:12 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none | |
| 00:55:00 | WinXP | 88.134.88.123 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 32 | 3dab831bee NEW |
none [none] | none:none |
none|none | none | none |
| 00:58:00 | Win2K-f | 83.234.145.57 (-): (IR001812) BAYKALPHONECOMPANY, RU. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 33 | 18101f06ca NEW |
none [none] | none:none |
none|none | none | none |
| T:01:00:00 | WinXP | 222.149.49.183 (OCN.NE.JP): OPEN COMPUTER NETWORK, TOKYO, TOKYO, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp irc 37 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox: 9 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none |
| T:01:11:00 | Win2K-f | 92.47.84.247 (IKBCC.COM): EU-ZZ, UK. |
n/a | US:hail.dns2go.com SA:scorti1.dns2go.com US:208.101.48.210:7000 |
445 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 5f78ff609d [Firefox:1542 hits: 04-27 to 06-27] |
d4a06bdc3a [0] | ASM:Graph |
none|none | lines=4 | trace |
| 01:11:00 | Win2K-f | 123.254.1.48 (PIKARA.NE.JP): STNET INCORPORATED, TAKAMATSU, KAGAWA, JP. |
n/a | :proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 | c9825e1fd3 NEW |
none [none] | none:none |
none|none | none | none |
| 01:11:00 | WinXP | 119.94.163.212 (-): . |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:204.2.133.57:80 US:204.2.133.73:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 32 32 of 33 |
43efc9961b NEW e816be3cf1 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| 01:11:00 | Win2K-f | 78.8.22.73 (NET.PL): DIALOG, WROCLAW, DOLNOSLASKIE, PL. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox: 5 hits: 06-27 to 06-27] |
none [none] | none:none |
none|none | none | none |
| 01:15:00 | WinXP | 118.3.249.57 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary |