|
Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
| 00:05:00 | Win2K-f | 71.115.135.68 (VERIZON.NET): VERIZON INTERNET SERVICES INC, DENTON, TEXAS, US. (100Mbps) |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.126.124:80 US:207.123.37.124:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 33 |
53bfe15e91 [Firefox:3641 hits: 06-17 to 11-01] a08f3b74a4 [Firefox:1297 hits: 06-18 to 11-01] |
none[4] a08f3b74a4[1] a08f3b74a4[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 00:11:00 | Win2K-f | 122.146.226.224 (SPARQNET.NET): NEW CENTURY INFOCOMM TECH. CO. LTD, TAIPEI, T'AI-PEI, TW. |
n/a | US:microsoft.com US:download.microsoft.com |
135 | pcap | raw alerts ruleset |
http 211 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 29 of 33 |
4960618323 NEW c7cd332f22 NEW |
none[4] c7cd332f22[1] c7cd332f22[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=82 |
trace trace |
| 00:20:00 | WinXP | 89.41.110.129 (HOST-89-41-64-10.MOLDTELECOM.MD): JSC MOLDTELECOM SA, CHISINAU, CHISINAU, MD. |
n/a | :proxim.ircgalaxy.pl 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | 7fd7475c63 [Firefox: 3 hits: 10-29 to 10-31] |
none [none] | none:none |
none|none | none | none |
| 00:22:00 | WinXP | 130.234.185.195 (JYU.FI): UNIVERSITY OF JYVASKYLA NETWORK, JYVäSKYLä, LANSI-SUOMEN LAANI, FI. |
n/a | US:mail.fucuzzy.com US:mail.TIKTIKZ.COM US:www.topgameland.com US:209.205.196.2:80 US:209.205.196.3:80 |
445 | pcap | raw alerts ruleset |
other 1 line |
Yeah : 0.8 profile |
none | summary tarball |
5 of 36 | fd419eefad [Firefox: 7 hits: 10-31 to 11-01] |
none [none] | none:none |
none|none | none | none |
| T:00:33:00 | WinXP | 89.137.200.14 (-): ASTRAL CONSTANTA DOCSIS NETWORK, CONSTANTA, CONSTANTA, RO. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
29 of 29 | a0139d7ad8 [Firefox:196 hits: 01-03 to 11-01] |
d9e9662db1 [0] | ASM:Graph |
PolyEnE| | lines=68 | trace |
| T:00:37:00 | WinXP | 123.48.75.175 (R-123-48-0-10.COMMUFA.JP): CHUBU TELECOMMUNICATIONS CO. INC, JP. |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
29 of 29 | 831f4ee0a7 [Firefox:644 hits: 01-01 to 11-01] |
eb7546c600 [0] | ASM:Graph |
none|none | lines=61 | trace | |
| 00:42:00 | WinXP | 58.231.167.91 (-): THRUNET-INFRA-DAEJEON05, SEOUL, KYONGGI-DO, KR. |
n/a | :proxim.ircgalaxy.pl US:microsoft.com US:download.microsoft.com 115.126.2.121:65520 US:198.78.201.126:80 US:204.160.104.126:80 US:205.128.70.126:80 |
135 | pcap | raw alerts ruleset |
other 113 lines |
Yeah : 1.3 profile |
none | summary tarball |
30 of 33 32 of 33 |
0a2b1894da [Firefox:11 hits: 06-26 to 10-26] 414b95a784 [Firefox:11 hits: 06-26 to 10-26] |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| T:01:14:00 | Win2K-f | 208.105.94.33 (RR.COM): ROAD RUNNER HOLDCO LLC, HERNDON, VIRGINIA, US. |
n/a | US:microsoft.com US:download.microsoft.com US:207.123.37.124:80 US:207.123.37.126:80 |
135 | pcap | raw alerts ruleset |
http 76 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:3641 hits: 06-17 to 11-01] 73f1082158 [Firefox:1810 hits: 06-18 to 11-01] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 01:32:00 | WinXP | 66.156.88.21 (BELLSOUTH.NET): BELLSOUTH.NET INC, ALPHARETTA, GEORGIA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:204.160.126.126:80 US:207.123.42.126:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
other 75 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 33 0 of 32 |
53bfe15e91 [Firefox:3641 hits: 06-17 to 11-01] 73f1082158 [Firefox:1810 hits: 06-18 to 11-01] |
none[4] 73f1082158[1] 73f1082158[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| 01:32:00 | WinXP | 64.38.71.22 (SPEAKEASY.NET): US. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | 45d3b6bd28 [Firefox: 5 hits: 10-15 to 10-29] |
none [none] | none:none |
none|none | none | none |
| 01:34:00 | Win2K-f | 202.30.239.12 (-): HYUNDAI MOTOR SERVICE, SEOUL, KYONGGI-DO, KR. |
115.126.2.121:65520 | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com :fleshkatera.cn :lolika.cn :www.upononjob.cn :mulfika.cn :do-make-progress.com :do-progress.com :do-managed-scan.com US:do-power-scan.com 115.126.2.110:80 115.126.2.121:65520 US:204.160.126.126:80 US:207.123.42.126:80 US:207.123.46.125:80 |
135 | pcap | raw alerts ruleset |
irc http 251 lines |
Yeah : 1.8 profile |
none | summary tarball |
34 of 36 32 of 36 none 11 of 36 |
1fa62445aa NEW 963d5f92ac [Firefox: 2 hits: 10-28 to 11-01] f5bad3f09c NEW fb8f82fcb3 [Firefox:23 hits: 10-24 to 10-28] |
none [none] none [none] none [none] none [none] |
none:none none:none none:none none:none |
none|none none|none none|none none|none |
none none none none |
none none none none |
| T:01:41:00 | WinXP | 85.121.119.68 (-): SC METRONETWORK SRL, BUZAU, BUZAU, RO. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
35 of 36 | 7e8bfa9b49 [Firefox:27 hits: 10-01 to 10-28] |
none [none] | none:none |
none|none | none | none |
| 01:54:00 | WinXP | 64.130.101.238 (ANDYCABLE.COM): TV CABLE COMPANY OF ANDALUSIA INC, KENNER, LOUISIANA, US. (DSL) |
n/a | US:microsoft.com US:download.microsoft.com US:192.221.96.126:80 US:205.128.70.126:80 US:207.123.37.124:80 |
135 | pcap | raw alerts ruleset |
other 178 lines |
Yeah : 1.3 profile |
none | summary tarball |
33 of 36 33 of 36 |
8eeed71f19 NEW fdc86dd410 NEW |
none [none] none [none] |
none:none none:none |
none|none none|none |
none none |
none none |
| 01:58:00 | WinXP | 79.163.52.205 (-): IDEA, PL. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
35 of 36 | 6b3beaea1a [Firefox:18 hits: 10-21 to 11-01] |
none [none] | none:none |
none|none | none | none |
| T:01:02:00 | Win2K-f | 118.222.98.47 (-): . |
115.126.2.121:65520 | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com US:192.221.110.125:80 US:204.160.104.126:80 US:205.128.73.126:80 |
135 | pcap | raw alerts ruleset |
irc 130 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 32 28 of 32 |
8a75955033 [Firefox:42 hits: 06-20 to 11-01] 9276c8b36b [Firefox:42 hits: 06-20 to 11-01] |
none[4] 9276c8b36b[1] 9276c8b36b[1] |
none:none ASM:Graph |
tElock| Armadillo| |
none lines=81 |
trace trace |
| T:01:18:00 | WinXP | 79.163.88.39 (-): IDEA, PL. |
115.126.2.121:65520 | :proxim.ircgalaxy.pl 115.126.2.121:65520 |
445 | pcap | raw alerts ruleset |
http irc 27 lines |
Yeah : 1.3 profile |
none | summary tarball |
34 of 36 | c8ed7380d2 NEW |
none [none] | none:none |
none|none | none | none |
| 01:20:00 | Win2K-f | 24.170.56.77 (RR.COM): ROAD RUNNER HOLDCO LLC, INGLESIDE, TEXAS, US. |
n/a | 135 | pcap | raw alerts ruleset |
other 61 lines |
Yeah : 1.3 profile |
none | summary tarball |
0 of 33 | a08f3b74a4 [Firefox:1297 hits: 06-18 to 11-01] |
a08f3b74a4 [1] | ASM:Graph |
Armadillo| | lines=81 | trace | |
| 01:28:00 | WinXP | 217.201.23.162 (-): TELECOM ITALIA MOBILE, IT. |
194.54.90.246:80 | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | fb03f4310d NEW |
none [none] | none:none |
none|none | none | none |
| T:01:29:00 | WinXP | 217.201.23.162 (-): TELECOM ITALIA MOBILE, IT. |
n/a | UA:citi-bank.ru UA:194.54.90.246:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
none | fb03f4310d NEW |
none [none] | none:none |
none|none | none | none |
| 01:34:00 | Win2K-f | 122.52.73.120 (PLDT.NET): IPG, PH. |
115.126.2.121:65520 | US:microsoft.com US:download.microsoft.com :proxim.ircgalaxy.pl |
135 | pcap | raw alerts ruleset |
http irc 132 lines |
Yeah : 1.8 profile |
none | summary tarball |
29 of 33 33 of 33 |
16874933ea [Firefox:58 hits: 06-18 to 10-31] 76ee340669 [Firefox:58 hits: 06-18 to 10-31] |
16874933ea [1] none [4] |
ASM:Graph none:none |
Armadillo| PolyEnE| |
lines=82 none |
trace trace |
| 01:37:00 | WinXP | 82.234.179.125 (PROXAD.NET): PROXAD / FREE SAS, NICE, PROVENCE-ALPES-COTE D'AZUR, FR. |
194.54.90.246:80 | UA:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 55f9895cb6 NEW |
none [none] | none:none |
none|none | none | none |
| 01:37:00 | Win2K-f | 116.123.55.194 (-): HANARO TELECOM, SEOUL, KYONGGI-DO, KR. |
115.126.2.121:65520 | US:microsoft.com :proxim.ircgalaxy.pl US:download.microsoft.com US:192.221.110.126:80 US:199.93.41.126:80 US:199.93.44.124:80 |
135 | pcap | raw alerts ruleset |