|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:10:00 | WinXP | 123.222.128.144 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:81 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none |
| 00:12:00 | WinXP | 92.47.253.240 (IKBCC.COM): EU-ZZ, UK. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:81 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none |
| T:00:15:00 | Win2K-f | 91.196.53.253 (-): PP KOM I TEX, LVIV, L'VIVS'KA OBLAST', UA. |
210.245.211.11:65520 | :proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:206.251.244.226:80 HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
irc 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none |
| 00:16:00 | WinXP | 213.77.199.26 (TPNET.PL): TELEKOMUNIKACJA POLSKA S.A. CST, LUBLIN, LUBELSKIE, PL. |
n/a | RU:moscow-advokat.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
25 of 25 | 7f60162c2c [Firefox:1367 hits: 12-31 to 06-28] |
1aad8e4632 [0] | ASM:Graph |
PolyEnE| | lines=93 embedded dns |
trace |
| T:00:21:00 | Win2K-f | 76.216.91.204 (SBCGLOBAL.NET): PPPOX POOL - BRAS6.STLSMO, DALLAS, TEXAS, US. |
n/a | US:microsoft.com US:download.microsoft.com US:12.190.48.65:80 US:12.190.48.97:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:255 hits: 06-17 to 06-28] a08f3b74a4 [Firefox:96 hits: 06-18 to 06-28] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 00:22:00 | Win2K-f | 122.19.146.101 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 32 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:81 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none | |
| T:00:23:00 | Win2K-f | 202.247.95.110 (MESH.AD.JP): C&C INTERNET SERVICE MESH (NEC CORPORATION), TOKYO, TOKYO, JP. |
217.170.244.2:443 | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 29 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2762 hits: 12-31 to 06-28] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| T:00:26:00 | WinXP | 121.114.92.29 (PLALA.OR.JP): PLALA NETWORKS INC, JP. |
210.245.211.11:65520 | :proxim.ircgalaxy.pl DE:dl2.teenpassage.com US:ksn.a1001186.wrs.mcboo.com US:chat-shqip.org US:wr.mcboo.com US:w3bs.chat-shqip.org US:206.251.244.226:80 US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp irc http 70 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 25 of 33 27 of 33 |
851f546ec1 NEW 897d59617c [Firefox:17 hits: 06-28 to 06-28] a014934a72 [Firefox:19 hits: 06-28 to 06-28] |
none [none] none [none] none [none] |
none:none none:none none:none |
none|none none|none none|none |
none none none |
none none none |
| T:00:27:00 | Win2K-f | 122.29.93.162 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
210.245.211.11:65520 | :proxim.ircgalaxy.pl DE:dl2.teenpassage.com HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
ftp irc 34 lines |
Yeah : 1.8 profile |
none | summary tarball |
32 of 33 | 26ac4391e0 NEW |
none [none] | none:none |
none|none | none | none |
| 00:28:00 | Win2K-f | 77.20.208.34 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | d601941576 NEW |
none [none] | none:none |
none|none | none | none | |
| T:00:40:00 | WinXP | 118.105.191.112 (-): . |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 505238d7ef [Firefox: 2 hits: 06-28 to 06-28] |
none [none] | none:none |
none|none | none | none |
| 00:40:00 | WinXP | 121.87.17.195 (EONET.NE.JP): K-OPTICOM CORPORATION, JP. |
n/a | :proxima.ircgalaxy.pl HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | 7cf4ee51d1 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:44:00 | Win2K-f | 118.160.16.204 (-): . |
217.170.244.2:443 | CZ:217.170.244.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2762 hits: 12-31 to 06-28] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 00:44:00 | WinXP | 213.55.66.177 (TELECOM.NET.ET): ETHIOPIAN TELECOMMUNICATION CORPORATION, ET. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:00:56:00 | WinXP | 221.171.48.68 (MESH.AD.JP): BIGLOBE-CIDR-BLK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 3c90603ba6 NEW |
none [none] | none:none |
none|none | none | none | |
| T:00:57:00 | Win2K-f | 124.86.145.115 (OCN.NE.JP): NTT COMMUNICATIONS CORPORATION, TOKYO, TOKYO, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox:53 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none | |
| T:01:02:00 | Win2K-f | 203.136.71.84 (MESH.AD.JP): C&C INTERNET SERVICE MESH (NEC CORPORATION), JP. |
217.170.244.2:443 | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 32 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2762 hits: 12-31 to 06-28] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 01:08:00 | WinXP | 118.236.21.22 (-): . |
n/a | :proxim.ircgalaxy.pl US:chat-shqip.org US:w3bs.chat-shqip.org HK:210.245.211.11:65520 US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 33 | 0d0fa96607 NEW |
none [none] | none:none |
none|none | none | none |
| 01:09:00 | Win2K-f | 124.101.227.194 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | :proxim.ircgalaxy.pl HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 32 | f996d83caa NEW |
none [none] | none:none |
none|none | none | none |
| 01:10:00 | WinXP | 83.131.91.23 (APEXCOVANTAGE.COM): T-COM CROATIA INTERNET NETWORK, ZAGREB, GRAD ZAGREB, HR. (DSL) |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox:41 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none |
| T:01:14:00 | Win2K-f | 119.11.35.209 (-): . |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 33 | f1b47fc2d7 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:15:00 | WinXP | 125.102.38.55 (UCOM.NE.JP): G-OS0025N, JP. (100Mbps) |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:81 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none |
| 01:16:00 | Win2K-f | 119.11.105.112 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
other 11 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:17:00 | WinXP | 4.246.225.92 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, SAN JOSE, CALIFORNIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 16 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:18:00 | WinXP | 71.104.25.56 (VERIZON.NET): VERIZON INTERNET SERVICES INC, POMONA, CALIFORNIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.99.126:80 US:198.78.220.126:80 |
135 | pcap | raw alerts ruleset |
http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 0 of 33 |
53bfe15e91 [Firefox:255 hits: 06-17 to 06-28] 73f1082158 [Firefox:100 hits: 06-18 to 06-28] e07c29c4ae [Firefox:43 hits: 06-19 to 06-28] |
none[4] 73f1082158[1] e07c29c4ae[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |