|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| T:00:21:00 | WinXP | 122.25.251.106 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:671 hits: 07-11 to 07-02] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| T:00:26:00 | Win2K-f | 125.225.138.73 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
217.170.244.2:443 | CZ:217.170.244.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2804 hits: 12-31 to 07-02] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 00:31:00 | WinXP | 216.201.28.52 (RTECEXPRESS.NET): RIDGEVILLE TELEPHONE COMPANY, MANSFIELD, OHIO, US. |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.110.125:80 US:199.93.41.126:80 US:199.93.44.124:80 |
135 | pcap | raw alerts ruleset |
other 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:351 hits: 06-17 to 07-02] a08f3b74a4 [Firefox:123 hits: 06-18 to 07-02] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:00:33:00 | Win2K-f | 86.136.29.38 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, LONDON, ENGLAND, UK. |
n/a | HK:proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:192.221.110.125:80 HK:210.245.211.11:65520 |
445 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
| 01:04:00 | WinXP | 86.168.80.205 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, UK. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:446 hits: 12-31 to 07-02] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| T:01:10:00 | WinXP | 117.99.40.124 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | DE:siliconfireware.ru :www.proxy-socks.net :wpad US:searchportal.information.com US:sprw.information.com US:spi.domainsponsor.com DE:212.227.111.29:80 DE:217.11.54.126:80 EU:78.47.200.154:80 |
445 | pcap | raw alerts ruleset |
http http 6 lines |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a12cab51ef [Firefox:1094 hits: 05-01 to 07-02] |
40f7f463c4 [0] | ASM:Graph |
ASPack| | lines=281 embedded dns |
trace |
| 01:16:00 | WinXP | 60.236.107.202 (MESH.AD.JP): NEC CORPORATION, JP. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 18 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2804 hits: 12-31 to 07-02] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 01:32:00 | WinXP | 217.43.120.117 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, RUNCORN, ENGLAND, UK. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
32 of 32 | 03f912899b [Firefox:28 hits: 12-14 to 07-02] |
83893bd25d [0] | ASM:Graph |
none|none | lines=65 | trace | |
| T:01:38:00 | Win2K-f | 78.159.50.16 (APEXCOVANTAGE.COM): EU-ZZ, UK. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| T:01:38:00 | WinXP | 88.147.226.168 (-): VTSARATOV, RU. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| 01:40:00 | WinXP | 212.46.227.27 (VSLUH.RU): JSC COPYLAND NETWORK, RU. (100Mbps) |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:41:00 | Win2K-f | 61.20.166.38 (-): FAR EASTONE TELECOMMUNICATION CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:43:00 | Win2K-f | 122.121.242.195 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| T:01:46:00 | Win2K-f | 82.240.208.113 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
n/a | 445 | pcap | raw alerts ruleset |
other 0 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:51:00 | WinXP | 85.250.100.12 (NETVISION.NET.IL): BROADBAND-PT, YAVNE, YERUSHALAYIM (JERUSALEM), IL. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| T:01:51:00 | WinXP | 91.66.5.145 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 01:52:00 | Win2K-f | 89.136.90.240 (-): ASTRAL MIERCUREA CIUC DOCSIS NETWORK, RO. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| T:01:53:00 | WinXP | 91.66.73.62 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
69.42.216.90:9890 | :f.unicat.org | 445 | pcap | raw alerts ruleset |
ftp irc 29 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | fa841b35ff NEW |
none [none] | none:none |
none|none | none | none |
| T:01:56:00 | Win2K-f | 91.65.62.174 (SUPERKABEL.DE): KABEL-DEUTSCHLAND-CUSTOMER-SERVICES, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
21 of 33 | 52d5117a94 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:57:00 | WinXP | 89.136.90.240 (-): ASTRAL MIERCUREA CIUC DOCSIS NETWORK, RO. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| 02:00:00 | Win2K-f | 89.28.96.105 (89-28-0-10.STARNET.MD): STARNET, CHISINAU, CHISINAU, MD. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 12 lines |
Yeah : 0.8 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| 02:00:00 | WinXP | 91.66.73.62 (SUPERKABEL.DE): KABEL DEUTSCHLAND BREITBAND SERVICE GMBH, DE. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 | fa841b35ff NEW |
none [none] | none:none |
none|none | none | none |
| T:02:02:00 | WinXP | 218.164.181.246 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAINAN, KAO-HSIUNG, TW. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp irc 21 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |
ASProtect| | lines=583 embedded dns |
trace |
| 02:09:00 | Win2K-f | 218.164.181.246 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAINAN, KAO-HSIUNG, TW. |
69.42.216.90:9890 | :f.unicat.org 69.42.216.90:9890 |
445 | pcap | raw alerts ruleset |
ftp 14 lines |
Yeah : 1.3 profile |
none | summary tarball |
13 of 31 | e8d4d8cde1 [Firefox:293 hits: 03-31 to 06-26] |
fda109a6fd [0] | ASM:Graph |