|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:07:00 | Win2K-f | 118.236.169.2 (-): . |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
23 of 33 | 3b05a7e449 [Firefox: 2 hits: 06-29 to 06-30] |
none [none] | none:none |
none|none | none | none |
| 00:10:00 | WinXP | 217.218.253.231 (-): MARKAZI TELECOMUNICATION COMPANY, IR. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
other 9 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 00:14:00 | Win2K-f | 86.138.220.245 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | HK:proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | c789e64d64 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:16:00 | Win2K-f | 60.38.129.95 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 1f7c55af5a [Firefox: 2 hits: 06-27 to 06-28] |
none [none] | none:none |
none|none | none | none | |
| 00:20:00 | WinXP | 217.237.94.111 (T-IPCONNECT.DE): DEUTSCHE TELEKOM AG, TRIER, RHEINLAND-PFALZ, DE. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 20 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:165 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| 00:28:00 | WinXP | 78.8.21.75 (NET.PL): DIALOG, WROCLAW, DOLNOSLASKIE, PL. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
20 of 33 | 17739a55ad [Firefox:165 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| 00:30:00 | Win2K-f | 91.66.67.182 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | f0661a9806 NEW |
none [none] | none:none |
none|none | none | none | |
| 00:35:00 | WinXP | 121.115.108.58 (PLALA.OR.JP): PLALA NETWORKS INC, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 33 | 0d4eb498e6 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:37:00 | WinXP | 119.11.112.35 (-): . |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 33 | a896c13b26 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:44:00 | WinXP | 218.210.225.206 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH CO. LTD, TAIPEI, T'AI-PEI, TW. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 77 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 0 of 33 |
53bfe15e91 [Firefox:301 hits: 06-17 to 06-30] 73f1082158 [Firefox:128 hits: 06-18 to 06-30] e07c29c4ae [Firefox:46 hits: 06-19 to 06-30] |
none[4] 73f1082158[1] e07c29c4ae[1] e07c29c4ae[1] |
none:none ASM:Graph ASM:Graph |
tElock| Armadillo| FSG| |
none lines=81 lines=92 |
trace trace trace |
| 00:50:00 | Win2K-f | 77.198.205.21 (GAOLAND.NET): DYNAMIC POOLS, FR. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
8 of 33 | 646da52c64 NEW |
none [none] | none:none |
none|none | none | none |
| 00:50:00 | Win2K-f | 87.4.159.128 (RETAIL.TELECOMITALIA.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, MILANO, LOMBARDIA, IT. |
n/a | HK:proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 5f160b61fa NEW |
none [none] | none:none |
none|none | none | none |
| T:00:51:00 | Win2K-f | 91.141.109.12 (I-ONE.AT): NETWORK OF ONE GMBH, VIENNA, WIEN, AT. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 25 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox:109 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| 00:56:00 | Win2K-f | 122.221.13.92 (UCOM.NE.JP): UCOM CORP, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 33 | ffbcbff716 NEW |
none [none] | none:none |
none|none | none | none |
| T:00:56:00 | Win2K-f | 221.113.242.64 (OCN.NE.JP): OPEN COMPUTER NETWORK, OSAKA, OSAKA, JP. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
26 of 33 | ca15c09536 [Firefox:136 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none | |
| T:00:57:00 | WinXP | 98.30.146.23 (-): . |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 3ae357d17b [Firefox:727 hits: 05-01 to 06-29] |
462a7be171 [0] | ASM:Graph |
PolyEnE| | lines=73 | trace |
| 01:00:00 | WinXP | 221.126.128.32 (HUTCHCITY.COM): HUTCHISON GLOBAL COMMUNICATIONS, HONG KONG, HONG KONG (SAR), HK. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox:109 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| 01:06:00 | WinXP | 85.180.9.240 (ALICEDSL.DE): HANSENET-ADSL, STUTTGART, BADEN-WURTTEMBERG, DE. (DSL) |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox:109 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| T:01:11:00 | Win2K-f | 123.217.214.106 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 33 | 16df44dfe9 NEW |
none [none] | none:none |
none|none | none | none |
| 01:18:00 | Win2K-f | 82.234.83.146 (PROXAD.NET): PROXAD / FREE SAS, TOULOUSE, MIDI-PYRENEES, FR. |
n/a | HK:proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 32 | 00710a2ffa [Firefox: 2 hits: 06-28 to 06-30] |
none [none] | none:none |
none|none | none | none |
| T:01:20:00 | Win2K-f | 119.11.101.195 (-): . |
n/a | 445 | pcap | raw alerts ruleset |
ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | c4fe07012a [Firefox: 2 hits: 06-30 to 06-30] |
none [none] | none:none |
none|none | none | none | |
| 01:23:00 | Win2K-f | 125.192.176.254 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox:109 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| 01:30:00 | Win2K-f | 222.147.239.113 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
12 of 33 | a96d6f6d31 [Firefox: 4 hits: 06-28 to 06-30] |
none [none] | none:none |
none|none | none | none |
| T:01:31:00 | WinXP | 81.181.16.175 (-): GENIUS NETWORK SYSTEM SRL, GALATI, GALATI, RO. (DSL) |
n/a | HK:proxim.ircgalaxy.pl US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 54f0165aa3 NEW |
none [none] | none:none |
none|none | none | none |
| 01:37:00 | Win2K-f | 85.181.190.0 (ALICEDSL.DE): HANSENET-ADSL, DE. (DSL) |
n/a | US:chat-shqip.org US:w3bs.chat-shqip.org US:69.247.147.113:12351 US:69.247.147.113:13001 |
445 | pcap | raw alerts ruleset |
ftp 28 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | d2c26e07fd [Firefox:109 hits: 06-27 to 06-30] |
none [none] | none:none |
none|none | none | none |
| T:01:38:00 | Win2K-f | 217.202.74.139 (-): TELECOM ITALIA MOBILE, IT. |
n/a | HK:proxim.ircgalaxy.pl | 445 | pcap | raw alerts ruleset |
ftp 24 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | ff4b083ee6 NEW |
none [none] | none:none |
none|none | none | none |
| 01:39:00 | WinXP | 122.135.154.231 (MESH.AD.JP): NEC BIGLOBE LTD, TOKYO, TOKYO, JP. |