|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| T:00:07:00 | WinXP | 221.7.82.4 (CECCOILS.COM): CNC GROUP CHONGQING PROVINCE NETWORK, BEIJING, BEIJING, CN. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 0.8 profile |
none | summary tarball |
31 of 33 | bce12aa21f [Firefox:20 hits: 05-12 to 07-03] |
none [4] | none:none |
PolyEnE| | none | trace |
| T:00:10:00 | Win2K-f | 82.53.136.107 (POOL8253.INTERBUSINESS.IT): TELECOM ITALIA S.P.A. TIN EASY LITE, LIVORNO, TOSCANA, IT. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 26 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | 605fe84c5c NEW |
none [none] | none:none |
none|none | none | none | |
| T:00:21:00 | Win2K-f | 75.36.121.141 (SBCGLOBAL.NET): IRIS MFG INC, PLANO, TEXAS, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:205.128.79.126:80 |
135 | pcap | raw alerts ruleset |
other 74 lines |
Yeah : 1.3 profile |
none | summary tarball |
1 of 33 33 of 33 |
4ca3056804 NEW 53bfe15e91 [Firefox:366 hits: 06-17 to 07-03] |
4ca3056804 [1] none [4] |
ASM:Graph none:none |
Armadillo| tElock| |
lines=81 none |
trace trace |
| T:00:31:00 | Win2K-f | 85.23.23.86 (SUOMI.NET): OULU TELEPHONE COMPANY, OULU, OULUN LAANI, FI. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 35 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | 605fe84c5c NEW |
none [none] | none:none |
none|none | none | none | |
| 00:42:00 | Win2K-f | 118.218.141.120 (-): . |
n/a | HK:proxima.ircgalaxy.pl US:microsoft.com US:download.microsoft.com US:192.221.110.126:80 US:199.93.46.126:80 US:207.123.46.126:80 HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
other 97 lines |
Yeah : 1.3 profile |
none | summary tarball |
31 of 33 31 of 33 |
168aab35a3 [Firefox:27 hits: 06-17 to 07-03] 667f0c59f3 NEW |
none [4] none [none] |
none:none none:none |
tElock| none|none |
none none |
trace none |
| 00:43:00 | WinXP | 61.231.150.15 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TAOYUAN, T'AI-WAN, TW. |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 17 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2817 hits: 12-31 to 07-03] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| T:00:49:00 | Win2K-f | 63.245.179.88 (KITUSA.COM): KANSAS INDEPENDENT TELECOMMUNICATIONS, MCPHERSON, KANSAS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 52 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 32 | 73f1082158 [Firefox:163 hits: 06-18 to 07-03] |
73f1082158 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
| T:00:57:00 | WinXP | 85.180.7.207 (ALICEDSL.DE): HANSENET-ADSL, STUTTGART, BADEN-WURTTEMBERG, DE. (DSL) |
n/a | 445 | pcap | raw alerts ruleset |
shell 4 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:00:58:00 | WinXP | 117.99.51.156 (XLRI.AC.IN): BHARTI AIRTEL LTD, DELHI, DELHI, IN. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | d42c1cc7c0 [Firefox:310 hits: 05-01 to 07-01] |
af9ca5bed1 [0] | ASM:Graph |
PolyEnE| | lines=54 | trace |
| 01:00:00 | WinXP | 24.84.182.249 (SHAWCABLE.NET): SHAW COMMUNICATIONS INC, VANCOUVER, BRITISH COLUMBIA, CA. |
n/a | 135 | pcap | raw alerts ruleset |
other 54 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | f9bf3a1e43 NEW |
f9bf3a1e43 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
| 01:19:00 | WinXP | 66.184.79.178 (LDMI.COM): TALK AMERICA, NORTH YORK, ONTARIO, CA. |
n/a | HK:proxim.ircgalaxy.pl HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
other 267 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 | 13cfd63045 NEW |
none [none] | none:none |
none|none | none | none |
| T:01:25:00 | WinXP | 12.77.9.217 (ATT.NET): AT&T WORLDNET SERVICES, VIRGINIA BEACH, VIRGINIA, US. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 1a2c0e6130 [Firefox:448 hits: 12-31 to 07-03] |
048df78048 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| 01:29:00 | WinXP | 122.120.13.63 (HINET.NET): CHTD CHUNGHWA TELECOM CO. LTD, TW. |
n/a | 445 | pcap | raw alerts ruleset |
shell 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | none | none | none | none | none | none | |
| T:01:45:00 | Win2K-f | 121.94.179.176 (INFOWEB.NE.JP): INFOWEB(FUJITSU LTD.), TOKYO, TOKYO, JP. |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2817 hits: 12-31 to 07-03] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace | |
| 02:04:00 | Win2K-f | 4.225.174.166 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, WHITNEY, TEXAS, US. (DIAL) |
n/a | US:microsoft.com US:download.microsoft.com US:208.111.173.52:80 US:208.111.173.53:80 |
135 | pcap | raw alerts ruleset |
other 118 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:366 hits: 06-17 to 07-03] 73f1082158 [Firefox:163 hits: 06-18 to 07-03] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 02:07:00 | WinXP | 220.239.224.211 (OPTUSNET.COM.AU): OPTUS INTERNET - RETAIL, SYDNEY, NEW SOUTH WALES, AU. |
n/a | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
21 of 32 | 063fecc528 NEW |
none [none] | none:none |
none|none | none | none |
| T:02:43:00 | Win2K-f | 60.254.212.190 (EMOBILE.AD.JP): EMOBILE LTD, TOKYO, TOKYO, JP. |
217.170.244.2:443 | 445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.8 profile |
none | summary tarball |
31 of 33 | 9aa3d60ce0 NEW |
none [none] | none:none |
none|none | none | none | |
| T:02:48:00 | Win2K-f | 60.40.251.49 (OCN.NE.JP): OPEN COMPUTER NETWORK, JP. |
217.170.244.2:443 | CZ:217.170.244.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 27 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2817 hits: 12-31 to 07-03] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 02:53:00 | Win2K-f | 4.245.102.206 (LEVEL3.NET): LEVEL 3 COMMUNICATIONS INC, MODESTO, CALIFORNIA, US. (DIAL) |
n/a | CZ:217.170.244.2:443 CZ:82.114.64.251:443 |
445 | pcap | raw alerts ruleset |
shell ftp 19 lines |
Yeah : 1.3 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2817 hits: 12-31 to 07-03] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| 02:55:00 | Win2K-f | 85.23.23.86 (SUOMI.NET): OULU TELEPHONE COMPANY, OULU, OULUN LAANI, FI. |
n/a | 445 | pcap | raw alerts ruleset |
ftp 35 lines |
Yeah : 1.3 profile |
none | summary tarball |
10 of 33 | 605fe84c5c NEW |
none [none] | none:none |
none|none | none | none | |
| 03:01:00 | WinXP | 219.251.84.103 (HANANET.NET): HANARO TELECOM INC, SEOUL, KYONGGI-DO, KR. |
n/a | US:microsoft.com US:download.microsoft.com HK:proxima.ircgalaxy.pl US:192.221.110.126:80 US:198.78.220.126:80 US:205.128.79.124:80 HK:210.245.211.11:65520 |
135 | pcap | raw alerts ruleset |
other 86 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 31 of 33 |
53bfe15e91 [Firefox:366 hits: 06-17 to 07-03] 8cf35e2a50 NEW |
none [4] none [none] |
none:none none:none |
tElock| none|none |
none none |
trace none |
| T:03:04:00 | WinXP | 60.238.169.14 (MESH.AD.JP): NEC CORPORATION, JP. |
217.170.244.2:443 | CZ:217.170.244.2:443 |
445 | pcap | raw alerts ruleset |
shell ftp irc 28 lines |
Yeah : 1.8 profile |
none | summary tarball |
25 of 28 | 7fdfe363d5 [Firefox:2817 hits: 12-31 to 07-03] |
10862ea8b8 [0] | ASM:Graph |
FSG| | lines=1933 embedded dns |
trace |
| T:03:09:00 | Win2K-f | 207.5.226.102 (SUSCOM-MAINE.NET): GREAT WORKS INTERNET, BRUNSWICK, MAINE, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 34 lines |
Yeah : 1.3 profile |
none | summary tarball |
2 of 33 | 9005e93bd0 NEW |
none [none] | none:none |
none|none | none | none | |
| T:03:09:00 | WinXP | 86.155.81.86 (BTCENTRALPLUS.COM): BT-CENTRAL-PLUS, UK. |
n/a | 445 | pcap | raw alerts ruleset |